Version 1.0 ยท Effective 4 October 2026

Who we are

Taro is a tarot journal app made by Volodymyr Shyrochuk, an individual developer and trader under the EU Digital Services Act ("we", "us"). Contact: volodymyr.shyrochuk@gmail.com. Trader address and phone: Skrypnuka St 278, Lviv 79049, Ukraine; phone +380 93 815 0581.

Summary

  • There is no account. Taro creates a random installation ID; we never ask for your name, email or phone number.
  • Your journal, cards and readings live on your device. Your journal is included in your device backup.
  • When you ask for an AI reading, your question, the spread, the cards you drew and your app language go to our server, which asks OpenAI to write the interpretation. Your question is not stored on our server.
  • Ads are shown by Google AdMob, and only after you have made your consent choices.
  • You can export your data and delete it from the app at any time.

Data we process

  • Installation ID: a random ID created on first launch. It keeps track of your reading credits, your free daily reading and fraud prevention.
  • Device key (Android only): a one-way hash of the Android device ID, used only to prevent abuse of free readings. On iOS, Apple's DeviceCheck stores one bit for the same purpose; we never see a device identifier.
  • Timezone and app language: to reset your free daily reading at your local midnight and to write readings in your language.
  • Purchase records: the store transaction ID, the product and the credits granted. We never receive your payment details.
  • Reading metadata: spread, number of cards, language, prompt version, token counts, cost, safety category and outcome. No question text.
  • Questions for AI readings: sent to the AI provider to write the reading, and not stored on our server.
  • Reading texts: kept encrypted on our server only until your device has received them.
  • Reports: if you report a reading, we store the question, the reading text and your optional note, encrypted, so that we can review it.
  • Analytics: how the app is used (for example, which screens are opened), through Google Analytics for Firebase, only after you have made your consent choices. We never send your question, reading or journal text to analytics.
  • Crash data: crash reports and performance data, through Firebase Crashlytics.
  • Advertising data: handled by Google AdMob (see Advertising).

AI processing

AI readings are written by OpenAI (GPT models), which acts as our processor. The same provider checks questions and readings for safety (moderation). Which model writes a reading depends on our server configuration; if we add or change a provider, we update this policy and ask for your permission again in the app.

  • What is sent: your question, the spread, the drawn cards and the app language. We never send your name, email, installation ID or advertising ID.
  • Training: under OpenAI's API terms, data sent through the API is not used to train its models.
  • Provider retention: OpenAI may keep API requests for up to 30 days to detect abuse, then deletes them; moderation requests are not retained.
  • Accuracy: readings are generated by AI. They may be wrong or unexpected, and they are for entertainment and reflection only.

Before the first AI reading, the app explains this and asks for your permission. You can withdraw it any time in Settings โ†’ AI readings; classic readings keep working without AI.

Advertising

Taro shows banner ads and optional reward videos from Google AdMob. Before any ad is requested, Google's consent form (UMP) asks for your choices where the law requires it. On iOS, we then ask for tracking permission through Apple's App Tracking Transparency. If you decline, you see non-personalized ads. You can change your choices any time in Settings โ†’ Privacy choices. AdMob may process your advertising ID, an approximate location derived from your IP address and ad interactions under Google's own terms. Buying Remove Banner Ads removes banners.

Purchases

Purchases are processed by Apple (App Store) or Google (Google Play) under their terms. We receive only the transaction information needed to grant your readings. Reading credits are tied to this installation: they are not restored after you delete the app or its data, and the export file does not contain them. Remove Banner Ads can be restored.

Legal bases (GDPR)

  • Contract: AI readings you request, including sending your question to the AI provider; purchases and reading credits.
  • Consent: personalized ads and, where required, analytics.
  • Legitimate interest: fraud prevention, including the device key; crash data to keep the app working.

The in-app AI permission step is about transparency and your choice; it is not the legal basis for the processing.

Retention

  • Your question is not stored on our server.
  • Reading text is kept encrypted until your device confirms receipt, at most 7 days, then deleted.
  • Reported readings are kept for 90 days.
  • Ledger and purchase records are kept for 7 years (tax, refunds and fraud prevention) in pseudonymous form.
  • Reading metadata is kept for 13 months.
  • Rewarded-ad records are kept for 13 months.
  • Daily usage counters are kept for 90 days.
  • Device counters (keyed by the device key on Android) are kept for 90 days.
  • Server logs are kept for 7 days.
  • Inactive installs (no activity for 24 months and no remaining credits) are pseudonymised after 24 months.

Your rights

  • Access and portability: Settings โ†’ Export backup creates a file with your journal and readings.
  • Erasure: Settings โ†’ Delete all data erases the data on your device and asks our server to erase your readings, reports and usage history. Your remaining reading credits and Remove Banner Ads are kept, because they are purchased goods.
  • Objection and withdrawal of consent: Settings โ†’ Privacy choices and Settings โ†’ AI readings.
  • Complaint: you can complain to your data protection supervisory authority.
  • US state privacy laws: we do not sell your personal information. You can opt out of "sharing" for targeted advertising through the privacy choices form shown in US states.

For any request, write to volodymyr.shyrochuk@gmail.com and include the Support ID shown in Settings.

Children

Taro is not directed at children under 16, and we do not knowingly collect their data.

Security and international transfers

Data is encrypted in transit (HTTPS). Reading texts and reports are encrypted at rest. Our server runs on Cloudflare; our processors are Cloudflare, OpenAI and Google (Firebase, AdMob). They may process data outside your country, including in the United States, under the European Commission's Standard Contractual Clauses or an equivalent safeguard.

Changes

We will update this policy when our processing changes and show the new version and effective date here. If a change affects AI processing, the app asks for your permission again.