Your data
Privacy
Last updated: September 20, 2026.
Contact
Privacy and support questions about tarotreflect.com can be sent to support@tarotreflect.com.
Accounts
Google sign-in is provided through Supabase Authentication. Google and Supabase process the information required to authenticate you. TarotReflect uses your Supabase user ID to associate one complimentary AI interpretation with your account; the entitlement record contains that user ID, the remaining credit count, and timestamps.
Authentication uses secure session cookies. TarotReflect does not use your account to save card selections, questions, or reading history.
Standard interpretations
Card selections and the optional question remain in the current page state while you use the standard interpreter. The standard result is generated in your browser from editorial card data and deterministic rules. TarotReflect does not save the reading to an account, localStorage, or a reading database. Refreshing the page clears it.
Optional AI synthesis
If you explicitly request the limited AI synthesis, TarotReflect sends the AI service only the selected card names, orientations, derived spread positions, standard card meanings, detected patterns, and a general category such as career or relationship. Your optional written question is not included. Names, email addresses, reading history, IP addresses, device identifiers, and arbitrary text are not included in the AI request.
A third-party AI service processes this limited input to return an AI-generated synthesis. Do not use this optional feature if you do not want the listed reading fields sent to an external AI service.
Hosting and abuse prevention
The application is deployed on Vercel, while Cloudflare manages DNS, edge protection, and Turnstile human verification. These service providers may process ordinary technical request data under their own privacy terms.
Because Vercel Functions do not share reliable process memory, a Redis service stores only atomic network quota counters and AI cost totals. The server converts the requesting IP address into a short-lived keyed hash before using it in a counter; Redis does not store the raw IP address, questions, cards, or interpretations. These counters expire after their quota windows.
Operational logs
AI operational logs may contain a random request ID, model name, token counts, estimated cost, latency, status, and quota result. They must not contain your user ID, email, question, prompt payload, card selection, or generated interpretation.
Product analytics
TarotReflect records a small set of first-party product events in structured Vercel application logs. These events cover an interpreter visit, source choice, selection start and completion, standard interpretation completion, repeat interpretations in the same session, and usefulness feedback.
An HTTP-only analytics cookie stores a random identifier plus first-seen and last-seen timestamps for up to 30 days. It is used to distinguish a new visit, activity in the same session, and a return visit within 14 days. It is not connected to a TarotReflect account and does not contain card identities, questions, answers, names, or email addresses.
Question text, selected card identities, and interpretation text are never included in product analytics events.
Your choice
Signing in and using AI are optional. If you do not request AI, no reading data is sent to an external AI service. The unlimited standard interpretation remains available without an account or AI.