1. Overview
This Privacy Policy describes what data the Vesper: Tarot Card Reading app (the "App") collects and uses, and how we protect it. By using the App, you agree to the terms of this Policy.
Data Controller: Vesper, contact — support@vespercards.com.
2. Data we collect
- Account data: name, email, password (stored only as a bcrypt hash), gender, date of birth, selected interests — provided during registration/onboarding.
- Usage data: saved spreads, AI interpretations, learning progress, achievements, activity streak, and the transaction history of the in-app currency (coins).
- AI messages: the text of your messages in the AI chat and the context of selected cards — used to generate responses. Not linked to any advertising profile.
- Push token: if you enabled notifications, we store your device's Expo push token to deliver reminders.
- Avatar: the photo you choose is stored locally only on your device and is never uploaded to the server.
- Technical data: device type, OS version, app version — for diagnostics and to ensure correct operation.
3. Purpose of processing and legal bases (GDPR)
- Providing the App's features and performing our contract with you — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Generating AI card interpretations and chatting with AI guides — performance of a contract.
- Push notifications for reminders, activity streaks and available free spreads — consent (Art. 6(1)(a)), which you can withdraw in your device settings.
- Service security, abuse prevention, and statistics in anonymized form — legitimate interest (Art. 6(1)(f)).
- Processing purchases/subscriptions — performance of a contract.
We do not sell personal data and do not use it for targeted advertising.
4. Sharing with third parties (Subprocessors)
- Anthropic, PBC (USA) — processing requests to the Claude model for the AI chat and interpretations. The text of your messages and selected cards is sent without your name or email. See Anthropic Privacy Policy.
- Google LLC — Firebase Analytics and Crashlytics (USA/EU) — collection of aggregated usage statistics (screens opened, session duration) and crash diagnostics (stack traces, app version, device model). Your name, email or AI conversation content is not shared. See Firebase Privacy.
- Google LLC — Sign-In — if you sign in with Google, your Google account provides us your email and public name to create/link your account. We receive no other Google account data.
- RevenueCat, Inc. (USA) — processing the subscription lifecycle and purchase events. Receives an anonymous user ID and purchase events. Does not receive your name, email or payment details. See RevenueCat Privacy.
- Expo (Expo Application Services, USA) — delivery of push notifications via the Expo Push Service. Only the push token and notification text are transmitted.
- Apple App Store / Google Play — processing payments for subscriptions and coin purchases. We have no access to your payment details (card number, etc.); we only receive a purchase confirmation.
- No other third parties have access to your data.
5. International data transfers
Some subprocessors (Anthropic, Expo, Apple, Google) are located in the USA. Transfers are made on the basis of the EU Standard Contractual Clauses (SCC) or equivalent safeguards.
6. Data retention
Account data is stored on a secure server in Europe (Hetzner, Germany). Passwords are hashed with bcrypt and never stored in plain text.
Your data is retained while your account is active. After you tap "Delete account" in the Profile, the account enters a soft-delete state: sign-in is blocked immediately, but data is kept for another 30 days in case you change your mind (contact support and we'll restore it). After 30 days, an automated cron process (daily at 04:30 UTC) permanently deletes the account and all related records (spreads, progress, dreams, horoscopes) cascading in the database.
Anonymized aggregated statistics records (not linked to a specific user) may be retained longer for product analytics.
7. Your rights (GDPR / local law)
- Right of access — obtain a copy of your data.
- Right to rectification — edit your profile in the App settings.
- Right to erasure ("right to be forgotten") — the Delete account feature under "Profile".
- Right to restriction of processing and to object.
- Right to data portability (in a machine-readable format) — on request.
- Right to withdraw consent at any time (including for push).
- Right to lodge a complaint with a supervisory authority (for the EU — your local DPA).
To exercise any of these rights, write to support@vespercards.com. We respond within 30 days.
8. Children
The App is not intended for persons under 13 (16 in EU countries where local law establishes this). We do not knowingly collect children's data. If you believe a child has provided us with data, contact us and we will delete it.
9. Security
We use HTTPS/TLS for all traffic, bcrypt for passwords, and JWT for authorization. Access to the production server is restricted by SSH keys. Nonetheless, no transmission method is 100% secure — we do everything we can but cannot guarantee absolute security.
10. Changes to this Policy
We may update this Policy. We will notify you of material changes in the App. The date of the latest update is shown at the top of the page.