Privacy Policy
Last updated: July 17, 2026
The short version: your journal is yours. We collect the least we can get away with, we don't sell any of it, and you can export or delete everything yourself without asking us. The rest of this page is the detail behind that.
If you don't have an account
You can use most of the site without telling us who you are. Cards you draw and anything you write stay in your browser's localStorage. They never reach our servers, which also means we can't recover them: clearing your browser data deletes them, and they don't follow you to your phone. The export button on the journal page is your backup.
There's one exception. The reflection prompts have a daily limit, and to count your use without accounts we store a one-way hash of your IP address plus a secret salt, with the day. We never write down the address itself, the hash can't be turned back into one, and the counters are deleted after seven days.
If you make an account
We ask for as little as we can:
- Email address. Required, so you can sign in and reset a password.
- Password. Handled by Supabase Auth and stored as a hash. We never see it.
- Display name. Optional, only so the site can say hello properly.
- Birthday. Optional, and only if you want the birthday pull. Leave it out and everything else still works.
- Journal entries. The card, whether it came up reversed, what kind of pull it was, anything you typed as context, the prompts you were given, and the reflection conversation if you saved one.
No name-of-employer, no phone number, no address book, no third-party sign-in that hands us your social graph.
Where it lives
Account data sits in Supabase, a hosted Postgres database, encrypted at rest. Every table that belongs to a user is protected by row-level security, which enforces ownership in the database itself rather than trusting the app to remember. In practice that means no other user can read your entries, and it isn't a policy we promise to follow — it's a rule the database applies to every single query.
Being straight with you about the limit of that: we don't encrypt entries on your device before they're sent, so someone with administrative access to the database could in principle read them. We don't. Nobody reads your journal, and there's no internal tool that surfaces entries to us. We're telling you this because a policy that claimed your entries were mathematically unreadable by us would be a lie, and you'd have no way to check.
What the AI sees
Reflection prompts and the Reflection Room are generated by Anthropic's Claude. When you ask for a prompt, we send the card, its orientation, and whatever context you typed to Anthropic's API to write a response. That's the whole payload.
Two things are worth knowing about what happens on their end. Anthropic does not train its models on what we send through the API. And they delete API inputs and outputs within 30 days, with longer retention only where their usage policy or the law requires it. So your words aren't permanent there, but they aren't discarded the instant the response comes back either. If you'd rather a thought never left your device, don't put it in the context box: draw the card and journal on it without asking for a prompt.
Anthropic's own terms cover their handling in full and are worth a look if this matters to you.
If you subscribe to the weekly digest, your address goes to Resend, who send it for us. We use confirmed opt-in, so you get one email asking whether you meant it, and nothing else until you click. Every digest has an unsubscribe link that works immediately. We don't rent, sell, or share the list, and subscribing doesn't create an account or touch your journal.
Cookies and analytics
We use Google Analytics to see which pages people read. It sets cookies, so we ask first, and it does not load at all unless you accept. Decline and no analytics script reaches your browser. You can change your mind whenever you like using the Cookie choices button at the bottom of any page.
What we don't do: nothing you write is sent to analytics. Not your entries, not your context, not your reflections. We don't run advertising trackers on the journal or any signed-in page, and we don't build advertising profiles from your reading.
Cookies we do set regardless are the ones that make signing in work, plus the one remembering the answer you just gave about cookies. Those don't track you between sites.
Tarot Digest does not currently serve ads. If that changes, ads will be gated behind the same consent, and this page will say so before it happens rather than after.
Affiliate links
Some links on the shop page go to Amazon with an affiliate tag. If you buy something, we may earn a small commission at no extra cost to you. Amazon knows you arrived from here; they don't learn which card you drew, because we never send them that.
The recommendations are hand-picked, and nobody pays us to be on the list. If a deck is there, it's because it's worth owning.
Taking your data with you, or deleting it
Both live on your account page, and neither needs our permission.
- Export hands you a JSON file with your profile and every entry, readable without our software.
- Delete removes your account, and your profile and entries go with it. It's immediate and we can't undo it, which is why you have to type the phrase to confirm. Export first if you want a copy.
Without an account, your journal is already only in your browser: clear your site data and it's gone.
Children
Tarot Digest isn't meant for children under 13, and we don't knowingly keep accounts for them. If one exists, write to us and we'll remove it.
Changes
If this policy changes in a way that affects what we collect or who sees it, we'll update the date at the top and say what moved. We won't quietly start doing something this page says we don't.
Contact
Questions, or want something removed? Email thefool@tarotdigest.com. A person reads it.
See also the Terms of Use.