Privacy Policy

Last updated: May 31, 2026

1. Data We Collect

  • Account data: Name, email address, and profile image via Google OAuth
  • Reading data: Spread type, optional questions, AI interpretations, birth date/place (for astrology)
  • Payment data: Processed by Paddle, our Merchant of Record — we store only Paddle customer and subscription IDs, not card details
  • Usage data: Credit transactions, reading history, timestamps
  • Technical data: IP address (for rate limiting), browser type

2. How We Use Your Data

  • To provide and improve the Service
  • To process payments and manage your subscription
  • To generate personalized AI readings
  • To prevent fraud and abuse
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not use your reading questions to train AI models.

3. Third-Party Services

  • DeepSeek: Processes divination reading requests (tarot, astrology, Ba Zi, Zi Wei). Subject to DeepSeek's Privacy Policy.
  • Anthropic (Claude): Generates the daily horoscope. Subject to Anthropic's Privacy Policy.
  • Paddle: Acts as our Merchant of Record and processes payments. Subject to Paddle's Privacy Policy.
  • Google OAuth: Used for sign-in only. We receive only your name, email, and profile picture.
  • Neon (Database): Hosts your encrypted data in the EU/US.
  • Vercel: Hosts the application and processes server-side requests.

4. Cookies

We use essential cookies for authentication (session management). We may use analytics cookies to improve the Service — you can decline these via the cookie banner. We do not use advertising cookies.

5. Your Rights (GDPR / CCPA)

Depending on your location, you have the right to:

  • Access: Download all data associated with your account
  • Deletion: Request account deletion (data removed within 30 days)
  • Correction: Request correction of inaccurate data
  • Portability: Receive your data in a machine-readable format
  • Opt-out: Opt out of analytics (EU users may also have additional rights)

To exercise these rights, visit your account Settings or email privacy@soulrune.com.

6. Data Retention

We retain your account data for as long as your account is active. Reading history is retained for 2 years. Upon account deletion, personal data is removed within 30 days, except where required by law (e.g., financial records retained for 7 years).

7. International Transfers

Your data may be processed in the United States and other countries. We rely on Standard Contractual Clauses (SCCs) for transfers from the EU/EEA to third countries.

8. Children

Soulrune is not directed at children under 18. We do not knowingly collect data from minors.

9. Contact

For privacy inquiries, contact privacy@soulrune.com.

Privacy Policy — Soulrune | Soulrune