Lumara Tarot is an entertainment and self-reflection app. It is not a medical, legal, financial, or professional advice service.
1. Who We Are
Lumara Tarot is operated by Yunlong Zhai, an individual developer ("Lumara Tarot," "we," "us," or "our"). We provide AI-assisted tarot readings, card drawing experiences, reading history, and subscription features. For privacy questions or data-rights requests, contact us at support@lumaratarot.com.
2. Information We Collect
App identifiers and device information
We use a pseudonymous, device-based account model. The app generates a random identifier that does not contain your name or email address. We process that identifier together with app version, platform, locale, timezone, subscription plan, and authentication tokens needed to operate the service.
Cloudflare may transiently process network metadata such as IP address, request timing, and security signals to route, secure, and operate requests. Lumara does not include the client IP address in the application-level payload that its backend creates for Doubao.
Reading inputs and card data
In the launch version, you choose a reading category and draw cards; the app does not provide a free-text AI prompt field. We process the selected category, drawn cards, card orientations, spread positions, response language, and the prewritten question supplied by the app for that category. Our backend may store one-way hashes of the question and card selection to support caching, credits, abuse prevention, and service reliability.
Reading results
AI-generated reading results may be temporarily stored on our backend cache for up to 24 hours so the app can reconnect, replay, or retrieve a recent reading. Reading history may also be stored locally on your device by the app.
Subscription and purchase information
If you subscribe, Apple and RevenueCat process purchase information. We receive subscription status, product identifiers, expiration dates, entitlement status, credit balance and refresh state, and related transaction metadata needed to provide paid features. We do not receive your full payment card number.
Diagnostics and support
We may process crash diagnostics, performance information, error reports, and support messages. We use this information to improve reliability, fix bugs, prevent abuse, and provide support.
The public launch build does not send product interaction analytics to PostHog. Diagnostics providers may create their own pseudonymous device or session identifiers. We do not use this information to track you across apps or websites owned by other companies.
3. How We Use Information
- Provide tarot readings, app features, account state, and subscriptions.
- Generate and stream AI-assisted reading text.
- Maintain credit balances, refresh schedules, rate limits, authentication, and security controls.
- Cache recent readings for reconnection and reliability.
- Improve the app through diagnostics and user feedback.
- Comply with legal obligations and App Store requirements.
4. AI Processing
The current launch data path is: the app sends the reading request to Lumara's backend on Cloudflare, and the backend sends only the fields needed for generation to the Doubao model service operated by Volcano Engine. Those fields are the app-supplied prewritten question and category, selected card identifiers and orientations, spread positions, response language, and necessary prompt context.
The application-level Doubao payload created by our backend does not include your Lumara account or device identifier, purchase identifier, reading identifier, reading history, authentication token, or client IP address. Network infrastructure may still process metadata as described in Section 2. The app never stores AI provider API keys on your device. Volcano Engine processes the request and generated response under the production service configuration and its applicable service terms.
The launch reading flow does not accept user-entered free text and does not show a separate AI data-sharing interstitial.
AI output is generated automatically and may be inaccurate, incomplete, or unexpected. You should treat readings as reflective entertainment, not as factual predictions or professional advice.
5. Service Providers
We rely on service providers that help us operate the app, including:
- Cloudflare for hosting, backend infrastructure, cache, database, and security.
- Volcano Engine and its Doubao model service for AI reading generation.
- RevenueCat and Apple for subscriptions, purchases, entitlements, and receipts.
- Sentry, when enabled for a release, for crash reporting and diagnostics.
We limit information sent to these providers to what is needed for the purposes described in this Policy. Provider processing is governed by applicable law, our agreement with the provider where applicable, and the provider's published terms.
6. Data Retention
- The launch reading flow does not collect a user-entered AI question.
- Question/card hashes and reading metadata are retained for up to 30 days for service operation, credits, abuse prevention, and reliability.
- Backend cached reading results are designed to expire after approximately 24 hours.
- Security audit records and completed deletion-request tombstones are retained for up to 365 days. A tombstone contains a one-way device hash rather than the original device identifier after deletion completes.
- Subscription records are retained as needed to provide paid features, resolve disputes, and meet accounting or platform requirements.
- Crash and diagnostic data is retained for a limited period according to our provider settings.
- Local reading history remains on your device until you delete it, clear app data, or uninstall the app.
AI-provider retention, deletion, and any model-improvement use depend on the production account configuration and applicable service terms. Contact us if you want information about the configuration applicable to your request.
7. Your Choices and Rights
Depending on where you live, you may have rights to access, delete, correct, export, or object to certain processing of your personal information. You can request help by contacting support@lumaratarot.com.
The app includes an account deletion flow. While a request is processing, the old pseudonymous account remains locked and the app does not create a replacement account. When deletion completes, Lumara deletes server-side account data tied to that identity and rejects all still-valid Lumara authentication tokens for it. The app creates a new guest identity only after you choose to continue. Security tombstones, Apple purchase records, or provider-side records may remain for the periods and purposes described above or required by law or platform rules.
8. Children
Lumara Tarot is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us so we can take appropriate action.
9. Security
We use technical and organizational safeguards such as HTTPS, server-side secret storage, limited logging, rate limiting, and data minimization. No system is perfectly secure, and we cannot guarantee absolute security.
10. International Transfers
We and our service providers may process information in countries other than where you live. The current Doubao AI service endpoint processes the reading fields described in Section 4 in mainland China; other infrastructure and subscription providers may process data in other regions. Where required, we take the measures required by applicable law for international transfers.
11. Changes to This Policy
We may update this Privacy Policy as the app, legal requirements, or service providers change. The effective date above shows when this version became effective.
12. Contact
For privacy questions or requests, contact support@lumaratarot.com.