Privacy Policy
Last updated: July 21, 2026
This policy explains what personal data Tarot Místico IA (the "Service") collects, for what purpose, and what rights you have over it, in accordance with the General Data Protection Regulation (GDPR) and applicable Spanish data protection law (LOPDGDD).
1. Data Controller
Owner: Javier Becerra, an individual.
Tax ID: 06246423Z
Address for notifications: Alcalá de Henares, Madrid, Spain
Contact email: 1901javier@gmail.com
2. What data we collect
- Registration data: email and password (always stored encrypted, never in plain text).
- Service usage data: your tarot readings, questions asked, horoscopes checked, and the date of each consultation, so we can show you your history.
- Subscription and payment data: the status of your subscription (active, canceled) and a Stripe customer identifier. We do not store your card details — these are handled directly by Stripe, our payment processor.
- Minimal technical data: a session token stored in your browser to keep you signed in while using the Service.
3. Purpose of processing your data
- Creating and managing your user account.
- Generating and showing you your tarot readings, horoscopes, and their history.
- Managing your subscription and processing the corresponding payments.
- Sending you transactional communications (welcome email, password recovery).
- Complying with applicable legal obligations.
The legal basis for this processing is the performance of the service contract (Art. 6.1.b GDPR) that you accept when registering, and the consent you give when creating your account.
4. Who we share your data with
To provide the Service, some data is shared with the following providers, acting as data processors:
- Supabase (database hosting).
- Vercel (web application hosting and execution).
- Anthropic (the AI model provider that generates the text of your readings — it receives the content of your question and the cards/sign involved, but not your email or identifying data).
- Stripe (subscription payment processing).
- Resend (transactional email delivery).
We do not sell or share your data with third parties for advertising purposes.
5. International transfers
Some of the above providers may process data outside the European Economic Area (for example, in the United States). In those cases, the provider has adequate transfer mechanisms in place under GDPR, such as the European Commission's Standard Contractual Clauses.
6. How long we keep your data
We keep your data for as long as your account remains active. If you request deletion of your account, we will delete your personal data within a reasonable period, unless there is a legal obligation to retain it longer (for example, billing records).
7. Your rights
You can exercise the following rights at any time:
- Access to your personal data.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten").
- Restriction of and objection to processing.
- Data portability.
To exercise them, write to us at 1901javier@gmail.com indicating which right you wish to exercise, attaching a copy of an ID document. You also have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We apply reasonable technical and organizational measures to protect your data, including password encryption and HTTPS communications. No system is 100% invulnerable, but we work actively to minimize risk.