Privacy Policy
Last updated: September 20, 2026
ArcaSeer limits collection to data used to run readings, protect the service, support optional accounts, and measure product reliability.
Operator and privacy contact
ArcaSeer is an independently operated online service. The independent operator is the controller of the personal data described in this Privacy Policy. Privacy requests can be sent to [email protected]. The governing law is stated in the Terms.
Reading requests and generated results
A reading request can contain the spread, intent, source page, random seed, selected card indices, a request ID, and an optional question. The Worker validates these fields. It resolves identity and access, checks quota and verification eligibility, and rejects supported high-risk categories before reserving quota for a successful reading. When AI is enabled, the Worker sends an eligible question and fixed card context to the configured AI provider. Do not enter names, contact details, account numbers, health records, or other sensitive personal information.
The application does not write an anonymous reading to the long-term readings table. It may hold the exact cards, generated
summary, advice, and provider metadata long enough to finish and replay the same request safely. One copy remains in a request-specific
Cloudflare Durable Object until database finalization succeeds. Another can remain in the quota claim response cache for no more than 10
minutes. Both copies are cleared automatically.
Generated text can reflect the substance of a question. ArcaSeer treats it as user content during this short window. A configured AI provider processes the request under that provider's own terms and data practices.
A completed result is saved long term only after you choose Save this reading. The saved record contains the spread, intent, your question if provided, displayed answer, cards and orientations, generated summary and advice, limited provider and model metadata, and save timestamps. ArcaSeer restores card images from the saved card identities and its fixed on-site deck. The saved record does not contain quota state, sponsored links, access tokens, email addresses, cookies, or IP addresses.
Cookies and browser storage
The API sets a signed, pseudonymous arcaseer_visitor cookie to apply quotas and bind retries. In production it is HttpOnly, Secure,
SameSite=Lax, scoped to the site, and configured for a maximum age of one year. JavaScript cannot read this cookie. Clearing it does not
remove existing server records.
ArcaSeer does not store questions or reading results in custom local storage. The Supabase authentication client persists and refreshes an optional account session in browser storage. The Worker validates the bearer token, uses the resolved user ID for quota and private saved-reading access, and does not send the token, account ID, or email address to the AI provider.
If you choose Save before signing in, the Worker creates a server-side pending save for no more than 30 minutes and sets a separate
HttpOnly, Secure, SameSite=Lax tp_pending_save cookie. The cookie contains an opaque random token, not the reading or
question, and JavaScript cannot read it. After authentication in the same browser, the Worker consumes the pending save once or deletes
it when it expires.
Abuse prevention and Turnstile
Before requesting reading quota or an AI interpretation, the Worker checks whether the configured AI provider supports the network location. It uses Cloudflare's two-letter country or territory code in request memory. For OpenAI-backed readings, the check uses OpenAI's published supported-country list. The browser receives an availability decision and a fixed reason. Application code does not return, persist, or log the country code. If the location is unsupported or cannot be verified, AI-generated readings are disabled. Card-only tools and editorial pages remain available.
Cloudflare receives network request data while serving the site. The Worker converts the connecting IP address into a secret-keyed hash tied to one UTC day. It uses this hash for daily and per-minute abuse controls. IPv4 remains exact before hashing. IPv6 is reduced to its /64 network. Application code does not persist the full IP address.
Higher-risk reading requests may receive a visible Cloudflare Turnstile challenge. Only then does the Worker send the reading-specific
Turnstile token and connecting IP to Cloudflare's verification service. After a successful check, the Worker sets a signed HttpOnly,
Secure, SameSite=Lax arcaseer_risk_pass cookie. It expires by the next UTC midnight and is bound to the same browser, account,
and daily network hash. This avoids a new check for every reading. JavaScript cannot read the cookie. Hashes are pseudonymous security
data, not anonymous data.
Email one-time-code send and resend requests use a separate invisible Turnstile check. This check does not apply to Google sign-in or code entry. It produces a short-lived, single-use security token that the browser sends to Supabase Auth. Supabase validates the token with Cloudflare before accepting the email request. Cloudflare may process ordinary browser and connection data for this abuse-prevention check as described in the Cloudflare Turnstile Privacy Addendum.
Analytics and cookie choices
Optional Google Analytics 4 and Cloudflare Web Analytics run only after you choose “Accept all”. Choosing “Essential only”
keeps both off and does not restrict readings, sign-in, saving, or other requested features. You can change your choice
through “Cookie settings” in the footer. We remember your choice in this browser for up to 180 days using
arcaseer:analytics-consent:v1 in local storage. If browser storage is unavailable, your choice applies only
to the current page. Withdrawing consent reloads the page to stop the loaded analytics tools and clears accessible GA cookies;
it does not delete data already received by the providers.
GA4 uses cookies such as _ga to distinguish browsers and helps us measure page views, engagement time,
feature use, reading completion or failure, and optional referral clicks. Cloudflare Web Analytics uses a cookie-free
browser beacon for aggregate traffic and real-user performance measurements. We include it in the same optional choice.
Neither tool is loaded before consent, and behavior before consent is not replayed afterwards.
Product events use an allowlist of coarse fields such as tool, spread, intent, card count, source route, viewport class, quota remaining, retry status, fixed error category, placement, and offer ID. We do not send question text, reading content, email addresses, authentication tokens, or internal visitor/account/request identifiers as analytics event properties. Analytics page URLs omit query strings and fragments; external referrers retain only the site origin. Approved campaign labels may be retained for source attribution. Advertising personalization and Google signals are disabled in our tag configuration. Account pages, private saved readings, and authentication callbacks do not load analytics. The providers may process ordinary browser and connection data under their own policies. GA4 reports cover consented, observable browsers and are not a count of every person who visits the site. Affiliate clicks do not establish that a purchase happened on another website.
Accounts, saved readings, and email
Account sign-in uses whichever production method is configured, such as Google or an email one-time code. Guest readings of every available type do not require an account or email address. Signing in does not save a reading. Saved readings remain until you permanently delete an individual reading or the account. ArcaSeer does not run automatic inactivity deletion at this time.
The Account page lets you view and delete saved readings. You can also request deletion of the saved content, ArcaSeer profile, and Supabase Auth account. Saved-reading content is removed and the profile is locked when the request starts. If the Auth deletion service is unavailable, a bounded retry job continues the Auth deletion. The account cascade then removes the profile. Authentication and account-security email is a service message, not marketing consent.
When email follow-up is enabled, a completed-reading page may offer to email that reading. This option includes the displayed marketing consent. ArcaSeer records the email address, source route, spread identifier, exact consent wording and time, signed reading payload, and account ID when a signed-in user makes the request.
ArcaSeer sends only the email address and first-party source URL to Kit, the email marketing provider. The same explicit action creates an active subscription and adds the address to ArcaSeer's configured Kit form; a second confirmation message is not part of the new-subscriber path. Anonymous submissions use a separate Cloudflare Turnstile action before the Worker accepts the request. ArcaSeer does not send the question, selected cards, reading result, authentication token, visitor cookie, account ID, or saved-reading payload to Kit.
After Kit returns the exact active subscriber, ArcaSeer sends the one requested reading through ZeptoMail, the transactional-email provider. That message contains the recipient address, question if entered, selected cards and orientations, generated reading, practical advice, and a first-party return link. If several readings are requested while the same address awaits confirmation, ArcaSeer keeps the newest pending reading. Earlier pending payloads are cleared as superseded. The remaining queued payload expires after six hours. It is cleared when delivery succeeds, expires, is cancelled, or permanently fails. Content-free delivery metadata remains for up to 30 days as retry and incident evidence. ZeptoMail does not receive ArcaSeer's Kit audience or later marketing broadcasts.
Marketing consent is optional for generating and viewing a reading on the site. It is required only if you choose the optional email-copy feature. That button combines the requested copy with the displayed subscription consent. You can withdraw consent through the unsubscribe link in any marketing email. A signed-in user can also use Account settings. Kit applies the provider-side unsubscribe state, and ArcaSeer records the withdrawal locally.
A previously unsubscribed address may require Kit's separate provider-side reactivation flow before it can receive another requested reading. Bounce and spam-complaint suppressions are never cleared automatically. Marketing subscriptions are separate from the Supabase sign-in account. Deleting the account does not replace the marketing unsubscribe process. To request deletion instead of suppression of provider-held email data, contact the privacy address above.
Account access records acceptance of the current Terms and acknowledgement of this Privacy Policy in a server-only legal-acceptance table. Each immutable acceptance row contains the account ID, document type and version, reviewed-copy hash, server acceptance time, source page, authentication provider, authentication intent, and release identifier. The browser cannot read or write this table directly. A repeated submission of the same document version is idempotent, and the rows are deleted with the authentication account.
Affiliate links
Sponsored links are absent when no approved destination is configured. If enabled, the redirect service records an opaque click ID, offer ID, destination host, request trace ID, and time. It does not store the tarot question, full destination URL, raw IP address, raw user agent, cookie value, or full referrer query as affiliate-click data. If an optional CTA cannot be prepared, the reading succeeds without it. The redirect remains unavailable unless its owner-managed destination passes the server's HTTPS and redirect-safety checks.
Server logs, access, and retention
Structured application logs contain a trace ID, event category, route or fixed product context, and error category. Logging code excludes raw questions, prompts, model output, email, IP addresses, cookies, bearer tokens, and secrets. Database access is restricted to the server service role for saved-reading content. The browser uses Supabase directly only for authentication and the limited profile fields shown in Account; saved-reading list, detail, save, and delete operations all pass through the ArcaSeer Worker with an owner check.
The database cleanup runs every five minutes in bounded batches. It clears complete replay results after 10 minutes and expires result-free claim metadata after 24 hours. It removes minute-level IP admission data after 48 hours. Visitor and IP daily quota detail and identity links are removed after 7 days. Expired pending saves are deleted after 30 minutes. Content-free daily AI budget totals remain for 90 days. Completed account-deletion job metadata contains no saved-reading content and is deleted after 90 days. Claim expiry releases visitor and IP reservations. A provider attempt already made remains counted in the aggregate AI budget.
Cloudflare log retention is configured outside this repository. The launch target is the shortest period that supports incident investigation and no more than 14 days, but that external setting must be verified before launch; this policy does not claim that an unverified account setting is already active.