Privacy Policy
Effective date: 26 September 2026
Life in Cards is operated by Arca Digital Ltd (“we”, “us”, “our”). We are committed to protecting your privacy and handling your personal data transparently. This policy explains what data we collect, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the California Consumer Privacy Act (CCPA).
1. Data Controller
Arca Digital Ltd is the data controller responsible for your personal data. Our company is registered in England and Wales (company number 17084212). For data protection enquiries, contact us at support@lifeincards.com.
2. Data We Collect
When you use Life in Cards, we may collect the following categories of personal data:
- Account information: your email address and name, collected when you sign up.
- Optional profile data: birth date, sun sign, personal goals, current life situation, and relationship context. You choose whether to provide this.
- Questions and prompts: text you submit when requesting readings or asking follow-up questions. This includes the content of your questions and any additional context you provide.
- Reading history: the tarot spreads you receive, cards drawn, AI-generated interpretations, and follow-up conversation threads.
- AI-generated memories: contextual notes created by our AI to personalise future readings based on your past sessions.
- Payment information: payment details are collected and processed by our payment processor. We do not store your credit card numbers or bank details. We receive your subscription status, transaction history, and billing email from our payment provider.
- Usage metadata: timestamps of your readings and interactions, subscription tier, and credit balances.
- Support conversations: the messages you send us through the support chat, and the email address you give us to reply to. Section 5 explains where those conversations are handled.
3. How We Use Your Data
We use your personal data to generate personalised tarot readings, remember context across sessions so that follow-up readings build on previous ones, manage your account and subscription, deliver the core service functionality, and communicate with you about your account. We do not use your data for advertising or marketing profiling.
4. AI Processing and Automated Decision-Making
Your tarot readings are generated entirely through automated processing by artificial intelligence models, without human review. When you request a reading, your question, any profile context you have provided, and relevant memories from past readings are sent to the AI model to produce an interpretation.
Your inputs are processed solely to generate your readings and to create contextual memories for personalisation. Your data is not used to train or fine-tune AI models.
Under Article 22 of the UK GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects. Tarot readings are provided for entertainment and reflection only and do not produce legal or similarly significant effects on you.
5. Data Sharing and Processors
We do not sell your personal data. We do not share your data with third parties for their own marketing purposes. We share data only with the following service providers, who act as data processors and process your data on our behalf and only according to our instructions:
- Stripe — payment processing and invoicing. Stripe processes your payment details directly; we never see or store your card information.
- Resend — transactional email delivery (e.g. magic link sign-in emails).
- Google — provides OAuth sign-in (name, email, and profile picture if you choose to sign in with Google) and AI model services (Google Gemini) used to generate your tarot readings. Your questions and profile context are sent to Google's Gemini API to produce interpretations. Google does not use your inputs for model training under our API terms. Google Analytics also runs on this site, but only if you accept analytics cookies; see section 15.
- Neon — database hosting for your account data and reading history.
- Railway — application hosting.
- Cloudflare — delivers the site, and stores generated files such as narration audio and profile images. Cloudflare Web Analytics also counts page views without cookies and without identifying you.
- Slack — customer support. When you start a support conversation, your name, your email address and the messages you send are relayed into our support workspace so that a person can answer you.
- Sentry — error monitoring. When something breaks we receive the technical detail of the fault, including the page you were on and your IP address. Email addresses, tokens and similar values are stripped out before the report is sent.
- ElevenLabs — voice narration. If you ask to hear a reading read aloud, the text of that reading is sent to be turned into audio.
- RevenueCat — handles purchases made inside our mobile app, and tells us what you are entitled to.
6. Legal Basis for Processing
We process your personal data on the following legal grounds under Article 6(1) of the UK GDPR:
- Contract (Article 6(1)(b)): processing necessary to provide the service you have signed up for, including generating readings, managing your account, and processing payments.
- Consent (Article 6(1)(a)): for optional profile information such as your birth date, sun sign, goals, current situation, and relationship context. You can withdraw consent at any time by removing this data from your profile.
- Legitimate interest (Article 6(1)(f)): for service improvement, security monitoring, and fraud prevention.
- Legal obligation (Article 6(1)(c)): for the identity and tax details we are required to hold about independent readers, and for the records we must keep to meet reporting, accounting and tax duties. Section 9 explains what this covers and how long it lasts.
7. International Data Transfers
Some of our service providers (including AI model providers, hosting providers, and payment processors) may process your personal data outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, adequacy decisions, or the provider's participation in recognised data protection frameworks. You may contact us for further details about the safeguards we use.
8. Data Retention
Your account data is retained for as long as your account is active. If you request deletion, your personal data is anonymised immediately and permanently hard-deleted from our systems after 30 days.
Automated backup copies may persist for a limited period (up to 30 days) after deletion before they are automatically purged from backup systems.
There is one exception, and it applies only to independent readers listed with us. Some of what we hold about a reader, we are required by law to keep even after they ask us to delete it. Section 9 sets out exactly what is kept, why, and what happens to the rest.
9. Readers listed with us
Life in Cards does not list independent readers, so nothing in this section applies to anyone using it.
10. Data Security
All personally identifiable information is encrypted at rest using AES-256-GCM. Data in transit is protected using TLS encryption. We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction.
11. Your Rights Under the UK GDPR
If you are located in the United Kingdom or the European Economic Area, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to restrict processing — request that we limit how we use your data.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — withdraw consent at any time for data processed on the basis of consent, without affecting the lawfulness of processing before withdrawal.
12. Your Rights Under the CCPA
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know — request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete — request deletion of personal information we have collected from you.
- Right to opt-out of sale — we do not sell your personal information to third parties.
- Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights.
13. Right to Complain
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). You can contact the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We encourage you to contact us first so we can try to resolve your concern directly.
14. How to Exercise Your Rights
You can exercise your data rights directly from your profile page, which includes “Download My Data” and “Delete My Account” buttons.
Alternatively, you can contact us at support@lifeincards.com to make any data rights request. We will respond within 30 days.
15. Cookies
One cookie is strictly necessary and always set: the one that keeps you logged in. Beyond that we ask. If you accept analytics cookies we set Google Analytics cookies to see how the site is used; if you decline, or ignore the banner, none are set. We use no advertising cookies, no targeting cookies and no social media cookies. Cloudflare Web Analytics counts page views without setting any cookie at all. For the full list, including how long each one lasts, see our Cookie Policy.
16. Children
Life in Cards is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from someone under 18, we will take steps to delete that information promptly.
17. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email before the changes take effect. The “Effective date” at the top of this page indicates when this policy was last revised.
18. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at support@lifeincards.com.
See also: Terms of Service · Cookie Policy