← Tarot Grimoire

Privacy Policy

Tarot Grimoire

Effective date: June 2, 2026 · Last updated: September 1, 2026

1. Who I am

This Privacy Policy explains how Veliy Molfar, an independent software developer (the “Provider”, “I”, “me”, “my”), collects, uses, and safeguards information in connection with the mobile application Tarot Grimoire (the “App”) and related websites.

For the purposes of the EU General Data Protection Regulation (GDPR) and applicable data protection laws, Veliy Molfar acts as the data controller. If you have any questions about this policy or your personal data, you can contact me directly at veliymolfar@gmail.com.

By accessing or using the App, you acknowledge and agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.

2. What data I collect

The App is intentionally built to be used without requiring a traditional personal account. I do not ask for your email address, password, legal name, or phone number to sign in, and I do not track or collect your precise GPS location. The App contains no third-party advertising SDKs and does not track you across other apps.

2.1 Anonymous user identifier

When you first open the App, a secure anonymous identifier (UID) is generated through Firebase Authentication (anonymous sign-in). This pseudonymous identifier lets me keep your subscription entitlement and a few server-side counters attached to your installation. It is not linked to your real-world identity, email address, or social accounts. The same UID is also set as the user identifier in the analytics and crash-reporting tools described in Section 4.

2.2 Birth date (optional, stored on your device)

You may optionally enter your birth date. It is stored locally on your device only and is used on-device to derive your zodiac sign and a personalised “card of the day” via a numerology calculation. Your birth date itself is never transmitted to my servers. Only the resulting tarot card identifier (one of the 22 Major Arcana) is sent so the same personal card can be shown to you for that day. Whether or not you have set a birth date is also recorded as a yes/no analytics property (the date is not included).

2.3 Data linked to your anonymous identifier (stored on my backend)

To run the App’s core features, I store the following on my backend server, keyed solely to your anonymous UID:

DataPurpose & description
Subscription / entitlement statePurchase, renewal and expiry events received from RevenueCat (product id, entitlement, environment, trial-conversion flag, purchase/expiry timestamps) so Pro content can be unlocked on your devices
Yes/No reading quotaThe date and drawn card of your Yes/No readings, to enforce the free daily limit and prevent abuse
Personal card of the dayOne record per day: the card shown, whether it was reversed, and whether you opened it

Card unlocking is determined solely by your Pro entitlement — the backend does not record which cards you have drawn, how often, or any “collection” progress.

2.4 Journal, custom spreads & history (on your device only)

Your journal notes, personal tags, custom spreads, card-draw history, draw frequencies and streaks are stored only in the App’s local database on your device. They are not transmitted to my servers and are not backed up or synced anywhere. Uninstalling the App or clearing its data permanently removes them. Please do not enter sensitive personal data (such as health, financial, or confidential information) into free-text journal fields.

2.5 Time zone & deep link signals

The App sends your device’s time zone with certain requests to reset daily features (such as the Daily Card and Yes/No reading) at local midnight. For deferred deep links (so that tapping a link before installing the App still opens the right card or spread), the website records a small set of device signals — IP address, platform, OS version, device model, screen parameters, language and time zone — and the App queries once after install to match them. An unmatched record is deleted within 24 hours; a matched record is deleted immediately.

2.6 Analytics & product-usage data (Firebase Analytics / Google Analytics for Firebase)

In published builds the App uses Firebase Analytics to understand how features are used and where people run into friction. It records a defined set of events — for example screen views, onboarding steps, spread and reading flows, deck browsing (search term length only, never the text), paywall views and plan selection, and a purchase event on a successful subscription (including the currency, amount and store transaction identifier). Alongside events, a small number of non-identifying user properties are set: subscriber status, content language, whether a birth date is set (yes/no), install source, and coarse usage buckets (e.g. number of favourite or custom spreads). Events and properties are associated with your anonymous UID (via setUserId) and with an analytics-generated app-instance identifier.

I do not send your name, birth date, journal text, search queries, or any special-category data to analytics. This data is processed by Google as described in Section 4; it is not exported to any separate database of mine. Analytics is off in development builds.

2.7 Crash & diagnostic data

Firebase Crashlytics automatically collects diagnostic data when the App crashes or misbehaves — approximate IP address, operating-system version, device model, app version, and a stack trace — so I can fix defects. Your anonymous UID is attached to crash reports. This data is handled under the third-party policies listed in Section 4.

3. How I use data & legal bases

PurposeLegal basis (GDPR Art. 6)
Providing core features (card draws, spreads, daily cards)Performance of a contract (Terms of Use), Art. 6(1)(b)
Managing Pro subscriptions & entitlementsPerformance of a contract, Art. 6(1)(b)
Preventing abuse, fraud, and ensuring service securityLegitimate interest, Art. 6(1)(f)
Crash diagnostics and product-usage analytics (Sections 2.6–2.7)Legitimate interest, Art. 6(1)(f)

Analytics choices. The App does not yet offer an in-app toggle to disable product-usage analytics; adding one is planned. In the meantime you can limit or reset this collection through your device settings (for example Android’s “Delete advertising ID” / “Opt out of Ads personalisation”, or iOS tracking and analytics-sharing controls), or by uninstalling the App. If you are in the EU/EEA or UK and want your analytics data erased, email me (see Section 6). Crash reporting cannot currently be disabled separately from within the App.

4. Third-party services

The App relies on trusted third-party service providers. Each provider processes technical data under its own privacy policy:

ProviderPurposePrivacy Policy
Google — Firebase Authentication, Firebase Analytics (Google Analytics for Firebase), Firebase Crashlytics Anonymous sign-in, product-usage analytics, and crash / performance diagnostics. Google acts as a processor for analytics and crash data and may also process it for its own purposes as described in its policy. firebase.google.com/support/privacy
RevenueCat Subscription purchase validation and entitlement management. RevenueCat receives the store purchase token / receipt and related metadata (store, country, price, currency) from the app stores; my backend stores only the resulting entitlement state (see Section 2.3). revenuecat.com/privacy
Google Play / Apple App Store App distribution and in-app purchase / billing processing Google Privacy / Apple Privacy

The App does not use advertising networks, does not sell or share user data for advertising, and does not use cross-app tracking frameworks.

The website at tarot.veliymolfar.com uses no cookies, no analytics, and no advertising.

5. Data storage & retention

6. Account deletion & right to erasure (GDPR Art. 17)

You can permanently delete your account and all associated data directly inside the App at any time:

  1. Open Settings in the App (the gear icon).
  2. Tap Delete Account.
  3. Confirm your choice in the confirmation dialog.

This action triggers an immediate and permanent hard deletion:

You may also request erasure by emailing me directly at veliymolfar@gmail.com.

Important note on subscriptions: Paid subscriptions are billed and managed directly by Apple (App Store) or Google (Google Play). Deleting your account inside the App does not automatically cancel an active subscription in the App Store or Google Play. To avoid future renewal charges, you must cancel your subscription in your Apple or Google account settings.

7. Your privacy rights

7.1 If you are in the EU/EEA or UK (GDPR)

Subject to applicable law, you have the right to:

Because data is tied to a pseudonymous anonymous identifier rather than your name or email, I may require diagnostic details from your device to locate your specific records if you submit a manual request via email.

7.2 If you are a California resident (CCPA/CPRA)

You have the right to know what personal information is collected, request its deletion, correct inaccuracies, and not receive discriminatory treatment for exercising your privacy rights. I do not sell or share personal information for cross-context behavioral advertising. You can exercise deletion directly via the in-app Delete Account feature or by emailing veliymolfar@gmail.com.

8. Children

The App is intended for individuals aged 16 and older. I do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided personal data, please contact me at veliymolfar@gmail.com, and I will promptly delete such information.

9. Security

I implement appropriate technical and organizational safeguards to protect data against unauthorized access, loss, or alteration. All data transmission between the App and backend services is encrypted using HTTPS/TLS. While no method of electronic storage or transmission is 100% secure, reasonable industry standards are applied to protect your information.

10. International data transfers

Third-party service providers (such as Google) may process data on servers located outside of your country of residence, including in the United States. Where required, such transfers rely on recognized legal transfer mechanisms, including the European Commission’s Standard Contractual Clauses (SCCs).

11. Changes to this policy & contact

I may update this Privacy Policy periodically to reflect app updates or legal requirements. When changes are made, the “Last updated” date at the top of this page will be revised. Continued use of the App following any changes indicates your acceptance of the updated policy.

For any questions, requests, or concerns regarding this Privacy Policy, please contact me at:

Veliy Molfar
Email: veliymolfar@gmail.com
Website: tarot.veliymolfar.com