Privacy Policy
Last updated: May 31, 2026
1. Data We Collect
- Account data: Name, email address, and profile image via Google OAuth
- Reading data: Spread type, optional questions, AI interpretations, birth date/place (for astrology)
- Payment data: Processed by Paddle, our Merchant of Record — we store only Paddle customer and subscription IDs, not card details
- Usage data: Credit transactions, reading history, timestamps
- Technical data: IP address (for rate limiting), browser type
2. How We Use Your Data
- To provide and improve the Service
- To process payments and manage your subscription
- To generate personalized AI readings
- To prevent fraud and abuse
- To comply with legal obligations
We do not sell your personal data to third parties. We do not use your reading questions to train AI models.
3. Third-Party Services
- DeepSeek: Processes divination reading requests (tarot, astrology, Ba Zi, Zi Wei). Subject to DeepSeek's Privacy Policy.
- Anthropic (Claude): Generates the daily horoscope. Subject to Anthropic's Privacy Policy.
- Paddle: Acts as our Merchant of Record and processes payments. Subject to Paddle's Privacy Policy.
- Google OAuth: Used for sign-in only. We receive only your name, email, and profile picture.
- Neon (Database): Hosts your encrypted data in the EU/US.
- Vercel: Hosts the application and processes server-side requests.
4. Cookies
We use essential cookies for authentication (session management). We may use analytics cookies to improve the Service — you can decline these via the cookie banner. We do not use advertising cookies.
5. Your Rights (GDPR / CCPA)
Depending on your location, you have the right to:
- Access: Download all data associated with your account
- Deletion: Request account deletion (data removed within 30 days)
- Correction: Request correction of inaccurate data
- Portability: Receive your data in a machine-readable format
- Opt-out: Opt out of analytics (EU users may also have additional rights)
To exercise these rights, visit your account Settings or email privacy@soulrune.com.
6. Data Retention
We retain your account data for as long as your account is active. Reading history is retained for 2 years. Upon account deletion, personal data is removed within 30 days, except where required by law (e.g., financial records retained for 7 years).
7. International Transfers
Your data may be processed in the United States and other countries. We rely on Standard Contractual Clauses (SCCs) for transfers from the EU/EEA to third countries.
8. Children
Soulrune is not directed at children under 18. We do not knowingly collect data from minors.
9. Contact
For privacy inquiries, contact privacy@soulrune.com.