Privacy Policy
Last updated: September 9, 2025
Welcome to Diary Tarot ("we", "us", or "our"). We value your privacy and are committed to being transparent about how we collect, use, and share your information. This Privacy Policy explains what data we collect when you use Diary Tarot at diarytarot.com, including our web app, services, and related communications (collectively, the "Services").
1) Data we collect
- Account & Profile: name (optional), email, password hash, subscription plan.
- Content you create: your tarot questions, saved readings, card history, notes, and preferences. These can be personalâsave only what youâre comfortable storing.
- Payment: handled by Stripe, Inc.. We never store your full card details. We may store Stripe customer and subscription IDs and related metadata (e.g., plan, renewal/expiry dates, status) to manage your access.
- Usage & device: IP address, device/browser type, timestamps, referral URLs, and diagnostic logs. We may use privacyâfriendly analytics to improve features and fix issues.
- Support: messages you send us (email, forms) and their metadata.
2) How we use data
- Provide, maintain, and improve the Services (including AIâassisted reading interpretations).
- Authenticate you, manage subscriptions, and enforce fairâuse/quotas.
- Process payments and renewals via Stripe, Inc..
- Personalize features (e.g., your Diary, saved cards, patterns & insights).
- Communicate with you (service messages, support; marketing only with your consent).
- Prevent abuse, fraud, and violations of our Terms.
- Comply with legal obligations and resolve disputes.
3) Legal bases (GDPR / PIPEDA / CCPA)
We process personal data under one or more of the following legal bases: (i) your consent; (ii) performance of a contract (providing the Services you request); (iii) legitimate interests (such as securing and improving the Services); and/or (iv) compliance with legal obligations.
6) Data retention
We retain your information while your account is active. If you delete your account or request deletion, we will delete or anonymize personal data within a reasonable period, except where we are required to retain certain records (e.g., billing/transaction data) for legal, tax, or security purposes.
7) Your rights & choices
- Access, correct, export, or delete your data (subject to legal exceptions).
- Opt out of nonâessential emails. Essential service messages will still be sent.
- Residents of certain regions (e.g., EU/UK, California, Quebec) may have additional rights such as data portability, restriction/objection to processing, and the right to limit the use/disclosure of sensitive personal information.
To exercise rights, contact us at privacy@diarytarot.com. We may need to verify your identity before responding.
8) Security
We use industryâstandard safeguards to protect personal information, including TLS (HTTPS) in transit and encryption at rest via Google Firebase (Google LLC). No system is 100% secure; please use a strong, unique password and keep your login details confidential.
9) International data transfers
We are based in Canada. Our service providers may process data in Canada, the United States, and other jurisdictions. Where required, we rely on appropriate safeguards for crossâborder transfers.
10) Childrenâs privacy
The Services are not directed to individuals under 16. If you are a parent/guardian and believe a minor provided us personal information, please contact us to request removal.
11) Changes to this policy
We may update this Privacy Policy to reflect changes to our practices or for legal, operational, or regulatory reasons. We will post the updated version here and revise the âLast updatedâ date above. Material changes may also be communicated by email or inâapp notice.
12) Contact
If you have questions or concerns about this Privacy Policy or our data practices, contact us at privacy@diarytarot.com.
Diary Tarot · Coquitlam, BC, Canada