Skip to content

Privacy Policy

Privacy Policy for Reflection Cards

Effective date: May 1st 2026

Last updated: May 10th 2026

The Internet Oracle, provides tarot-style reflective readings based on questions you choose to submit. This privacy policy explains how we collect, use, store, share and delete your personal data when you use the app and related services.

Who we are

The controller of your personal data is:

Dan Ballance

Email: privacy@bitshield.dev

If you are in the UK, EEA or another jurisdiction with privacy rights, you can contact us using the details above about any privacy question, complaint or data-rights request.

What data we collect

We collect the following categories of data:

Account and identity data

  • Email address
  • Authentication identifiers such as your account ID or user ID
  • Email-verification status and related account metadata
  • Session or authentication tokens stored securely on your device

Tarot reading data

  • The question you type into the app
  • The deck or reading options you choose
  • The date and time a reading is created
  • The cards drawn and the generated interpretation
  • Reading history associated with your account

Device, app and diagnostic data

  • Basic technical information needed to operate the app and API
  • Crash reports and diagnostics, if enabled
  • Security and abuse-prevention logs
  • Limited request metadata needed to run and secure the service

We do not intentionally ask you to provide government ID numbers, financial account numbers, or advertising identifiers to receive a reading.

Sensitive nature of your questions

Questions submitted to the app may include highly personal or sensitive information. For example, a question may reveal information about your health, mental health, relationships, religion or beliefs, sex life, sexual orientation or other intimate matters.

Because of that, we treat reading content as sensitive, even where the law may classify a particular question differently depending on context. We ask you to avoid including personal information that is not necessary for your reading.

Where required by law, we ask for your explicit consent before processing sensitive question content.

How we use your data

We use your data to:

  • create and manage your account;
  • authenticate you and keep your account secure;
  • generate tarot readings from the question you submit;
  • save your readings so you can view them later;
  • provide customer support;
  • maintain, secure and improve the reliability of the service;
  • investigate misuse, abuse, fraud or security incidents; and
  • comply with legal obligations.

We do not sell your personal data.

We do not use your tarot questions or saved readings for advertising profiling.

Our lawful bases

Depending on your location, the lawful bases we rely on may include:

  • Contract: to create your account, authenticate you and provide the reading service you ask us to provide.
  • Legitimate interests: to secure the app, prevent abuse, maintain logs necessary for reliability, and defend legal claims, provided those interests are not overridden by your rights.
  • Legal obligation: where we must retain or disclose information to comply with law.
  • Explicit consent: where your question or reading content includes sensitive personal data, or where law otherwise requires consent.

If we rely on consent, you can withdraw it at any time. Withdrawal will not affect processing already carried out before withdrawal, but it may mean we can no longer provide new readings that depend on that consent.

How readings are generated

When you ask for a reading:

  • your question is sent securely from the app to our backend;
  • the backend prepares the reading request, including the cards/spread used for the reading;
  • the request is sent to the model provider strictly for the purpose of generating your reading;
  • the resulting reading is returned to you and, if saving is enabled, stored with your account.

Please do not include more personal information than necessary in your question.

Encryption and security

We use technical and organisational measures designed to protect your data.

These measures include:

  • encryption of data in transit using secure network connections;
  • access controls and authentication for administrative systems;
  • separation of duties and least-privilege access where practicable;
  • monitoring, logging and security review processes;
  • secure storage of authentication tokens on the device where supported by the platform; and
  • encryption of saved reading content in the database, with saved reading content decrypted in the app when displayed to you.

No method of transmission or storage is completely secure. However, we design our controls to reflect the sensitivity of the questions submitted through this app.

Third parties and processors

We currently use, or the sampled code indicates we use, the following categories of third party service providers:

  • Clerk — authentication and account management
  • Google Cloud Firestore / Google Cloud services — storage and related infrastructure
  • Google Gemini / Google GenAI services — generation of reading content
  • Sentry — crash reporting and diagnostics, if enabled in the shipped version

We require processors to handle personal data on our instructions and with appropriate safeguards.

If our live production setup changes, we will update this policy before or at the time the change takes effect.

International transfers

Some of our service providers may process personal data outside the UK or EEA.

Where we transfer personal data internationally, we use appropriate safeguards required by applicable law, such as:

  • adequacy regulations or adequacy decisions; or
  • standard contractual clauses and related supplementary measures where required.

You can contact us if you want more information about the safeguards we rely on for a particular transfer.

How long we keep your data

Unless a different period is required by law or clearly stated in the app, we recommend and intend to apply the following retention periods:

  • Account data and saved readings: kept until you delete them or close your account
  • Deleted account / deleted reading data in primary systems: removed within 7 days
  • Backups containing deleted data: overwritten or removed within 30 days
  • Security logs: kept for up to 30 days, unless needed longer to investigate abuse or defend legal claims
  • Crash and diagnostics data: kept for 30 to 90 days
  • Data retained for legal, fraud-prevention or security reasons: kept only for as long as necessary for that specific purpose

If we need to keep some data after a deletion request for legal, fraud-prevention or security reasons, we will explain that in our response.

Your rights

Depending on your location, you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • delete your data;
  • restrict or object to certain processing;
  • withdraw consent where we rely on consent;
  • receive a copy of relevant personal data in a portable format, where applicable; and
  • complain to a supervisory authority.

To exercise your rights, contact privacy@bitshield.dev or use the in-app tools described below.

We will respond within the time required by applicable law. Where UK GDPR or GDPR applies, that is usually within one month, although this can be extended in limited circumstances.

Account deletion and data erasure

You can request deletion in either of the following ways:

In the app

  • Go to Settings > Delete account
  • Follow the confirmation steps

When we process a valid deletion request, we will:

  • delete or disable the app account so it can no longer be used;
  • delete saved readings and associated account data from primary systems;
  • remove data from backups on the next scheduled backup rotation window;
  • retain only the limited data we must keep for security, fraud prevention, legal compliance or the establishment, exercise or defence of legal claims.

Signing out, uninstalling the app, or stopping use of the service does not by itself delete your account.

Children’s privacy

This app is not directed to children.

If we learn that we have collected personal data from a child in a way that is not permitted by applicable law, we will delete that data as soon as reasonably practicable.

If you believe a child has provided personal data to us, please contact privacy@bitshield.dev.

Automated processing

The app uses automated systems to generate tarot-style reading text from the question you submit and the cards drawn. The output is intended for reflective and entertainment purposes and should not be treated as medical, legal, financial or other professional advice.

Changes to this policy

We may update this privacy policy from time to time. If we make a material change, we will post the updated version in the app and on the public privacy-policy page, and where appropriate we will notify you directly.