Your data

Privacy

Last updated: September 20, 2026.

Contact

Privacy and support questions about tarotreflect.com can be sent to support@tarotreflect.com.

Accounts

Google sign-in is provided through Supabase Authentication. Google and Supabase process the information required to authenticate you. TarotReflect uses your Supabase user ID to associate one complimentary AI interpretation with your account; the entitlement record contains that user ID, the remaining credit count, and timestamps.

Authentication uses secure session cookies. TarotReflect does not use your account to save card selections, questions, or reading history.

Standard interpretations

Card selections and the optional question remain in the current page state while you use the standard interpreter. The standard result is generated in your browser from editorial card data and deterministic rules. TarotReflect does not save the reading to an account, localStorage, or a reading database. Refreshing the page clears it.

Optional AI synthesis

If you explicitly request the limited AI synthesis, TarotReflect sends the AI service only the selected card names, orientations, derived spread positions, standard card meanings, detected patterns, and a general category such as career or relationship. Your optional written question is not included. Names, email addresses, reading history, IP addresses, device identifiers, and arbitrary text are not included in the AI request.

A third-party AI service processes this limited input to return an AI-generated synthesis. Do not use this optional feature if you do not want the listed reading fields sent to an external AI service.

Hosting and abuse prevention

The application is deployed on Vercel, while Cloudflare manages DNS, edge protection, and Turnstile human verification. These service providers may process ordinary technical request data under their own privacy terms.

Because Vercel Functions do not share reliable process memory, a Redis service stores only atomic network quota counters and AI cost totals. The server converts the requesting IP address into a short-lived keyed hash before using it in a counter; Redis does not store the raw IP address, questions, cards, or interpretations. These counters expire after their quota windows.

Operational logs

AI operational logs may contain a random request ID, model name, token counts, estimated cost, latency, status, and quota result. They must not contain your user ID, email, question, prompt payload, card selection, or generated interpretation.

Product analytics

TarotReflect records a small set of first-party product events in structured Vercel application logs. These events cover an interpreter visit, source choice, selection start and completion, standard interpretation completion, repeat interpretations in the same session, and usefulness feedback.

An HTTP-only analytics cookie stores a random identifier plus first-seen and last-seen timestamps for up to 30 days. It is used to distinguish a new visit, activity in the same session, and a return visit within 14 days. It is not connected to a TarotReflect account and does not contain card identities, questions, answers, names, or email addresses.

Question text, selected card identities, and interpretation text are never included in product analytics events.

Your choice

Signing in and using AI are optional. If you do not request AI, no reading data is sent to an external AI service. The unlimited standard interpretation remains available without an account or AI.

Interpret your cards