Legal

Privacy Policy

Last updated: March 28, 2026

1. Information We Collect

Information you provide:

  • Name and email address (on signup)
  • Quiz answers (15 questions for archetype scoring)
  • Newsletter opt-in

Information collected automatically:

  • Usage data (pages visited, features used)
  • Device type and browser
  • Reading history and engagement patterns

We do not collect payment information directly. Payments are handled by Stripe and subject to their privacy policy.

2. How We Use Your Information

  • To generate personalized tarot readings and archetype analysis
  • To manage your account and subscription
  • To send transactional emails (receipts, reading notifications)
  • To send newsletter content, if you have subscribed
  • To improve the platform through aggregate analytics
  • To detect and prevent fraud and abuse

3. Data Sharing

We do not sell your personal data to third parties. We share data only with:

  • Supabase — database and authentication hosting
  • Stripe — payment processing
  • Resend — transactional email delivery
  • PostHog / Plausible — anonymous usage analytics (if enabled)

Each service processes data under their own privacy policies and data processing agreements.

4. Data Storage and Security

Your data is stored on Supabase infrastructure with encryption at rest and in transit. Row-level security policies ensure users can only access their own data. We implement industry-standard security practices and review them regularly.

5. Your Rights (GDPR / CCPA)

Depending on your location, you may have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data
  • Portability — receive your data in a portable format
  • Objection — object to certain types of processing

To exercise any of these rights, email privacy@arcana.app. We respond within 30 days.

6. Data Deletion

To delete your account and all associated data, email privacy@arcana.app with the subject "Delete my account". We will process your request within 30 days. Some data may be retained for legal or fraud-prevention purposes.

7. Cookies

Arcana uses session cookies for authentication (via Supabase) and analytics cookies (if you consent). We do not use advertising or tracking cookies. You can disable cookies in your browser settings, though this may affect login functionality.

8. Children

Arcana is not directed at individuals under 18. We do not knowingly collect data from minors. If we become aware of such collection, we will delete it immediately.

9. Changes

We may update this policy periodically. Material changes will be communicated by email. Continued use of the Service after updates constitutes acceptance.

10. Contact

Privacy questions: privacy@arcana.app