Privacy Police
1. Data controller
The controller responsible for the processing of personal data on this website is:
Syscel Solutions S.L.
Calle Cervantes 19, 2º 2G
03550 Sant Joan d'Alacant (Alicante), Spain
E-mail: support@tarotsi.net
This policy explains, in accordance with Regulation (EU) 2016/679 (GDPR), which data are processed during your visit to Tarotsi.net, for which purposes, and what your rights are. In short: this site has no accounts, no contact forms, no newsletter and no tracking analytics. Only what is needed for operation, for advertising (with your consent) and for abuse protection is processed.
2. Hosting and server logs
On every visit, our hosting provider automatically processes technical access data: IP address, date and time, requested page, browser type and operating system. These logs serve to deliver the site, to guarantee its stability and security (for example, defence against attacks) and are deleted automatically after a short period. Legal basis: our legitimate interest in secure operation (Art. 6(1)(f) GDPR). No cross-referencing with other data takes place.
3. Cookies and consent
The site itself sets no cookies. Cookies appear in two places only: in Google AdSense advertising (only after your consent in the banner, see section 4) and in the Tarot Chat (a technical session cookie, see section 5). Details are in the cookie policy.
4. Advertising: Google AdSense
This site is financed by Google AdSense ads, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
On your first visit, a Google consent banner (Privacy & Messaging) asks for your permission. Google only shows personalised advertising — with cookies and similar technologies — if you consent (Art. 6(1)(a) GDPR). Without consent, only non-personalised ads may be shown. You can revoke your consent at any time with effect for the future, in the banner settings or at adssettings.google.com.
While ads are being served, data may be transferred to Google servers in the United States. Google LLC is certified under the EU-US Data Privacy Framework; the transfer rests on the adequacy decision of the European Commission (Art. 45 GDPR). What Google processes, and for how long, is described at policies.google.com/privacy and policies.google.com/technologies/partner-sites.
5. Tarot Chat (artificial intelligence)
The chat section lets you talk with a virtual tarot reader generated by
artificial intelligence. For it to work, your messages, the first name you
may give, your IP address, the times of use and a technical device identifier
are stored temporarily on our server and deleted automatically within 7 days.
The conversation is kept by a session cookie (ctrw_uid, lifetime
2 days), while a second technical cookie (ctrw_dev, lifetime 90
days) applies the consultation limit. The answers are generated on our own infrastructure; your
messages are neither passed on to external providers nor used for
advertising. Legal basis: the performance of the service you requested
(Art. 6(1)(b) GDPR). Please do not enter sensitive personal data in the
chat (health, financial data or identifiable data of third parties): the
answers are entertainment and do not constitute professional advice.
6. AI-assisted card readings
Some readings answer a free question with an AI-generated interpretation. These answers are also produced on our own infrastructure; your question is kept briefly together with your IP address, solely to enforce the usage limits, and then deleted. For the predefined interpretations of the fixed questions (for example "Yes or No"), we partly rely on OpenAI — in that case only the drawn cards and the fixed question text are transmitted, never any visitor data. The calculators (numerology and the like) run entirely in your browser: your date of birth never leaves your device.
In “Interpret your tarot spread”, we record your question, cards, their positions and orientations, the interpretation and, if requested, your follow-up question and its clarification. Clarifications are linked to the original spread and can only be requested from the same browser. These records and their technical data are retained for 90 days, with gradual removal, to provide and manage the service. IP and browser identifiers are stored as hashes. Any copy you choose to save in “My readings” remains separately in your browser.
In “Practice your tarot interpretation”, we record the fictional case, level, cards, text you write, generated feedback and technical request data. Records are retained for 90 days, with gradual removal of older entries, to provide the service and enforce its limits. IP and browser identifiers are stored as hashes. By default, the tutor uses our own AI infrastructure. Any copy you choose to save in “My readings” remains separately in your browser until you delete it.
In “The Counsel of the Three Oracles”, we record the question, drawn symbols, answer, status and consultation attempts. Records are kept for 90 days, then deleted gradually. IP and browser identifiers are stored as keyed hashes to manage usage and retrieve an answer without generating it again. The configured AI provider receives the question and symbols for interpretation. A copy saved in My Readings stays in your browser until you delete it.
In “Your Custom Tarot Spread”, we record the question, designed positions, drawn cards, interpretation, status and attempts at each stage. Records are kept for 90 days and then deleted gradually. IP and browser identifiers are stored as keyed hashes to control usage and retrieve a consultation without repeating it. The configured AI provider receives the question to create the layout, then the question, positions and cards to interpret the spread. Saved layouts stay only in this browser, up to eight; saving another replaces the oldest. You can remove them in the app. Copies saved in My Readings remain in your browser until you delete them.
7. Abuse protection
Daily usage limits apply to the free AI services. For this purpose we keep the IP address of the requests for a short time; in case of repeated abuse an IP address may be blocked. Legal basis: our legitimate interest in keeping the services available for everyone (Art. 6(1)(f) GDPR).
8. Your rights
Towards the controller you have the right of access to your data (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and portability (Art. 20), as well as the right to object to processing based on legitimate interest (Art. 21). Consent once given can be withdrawn at any time; the withdrawal does not affect the lawfulness of the processing carried out until then. You also have the right to lodge a complaint with a supervisory authority — the authority competent for the controller is the Spanish Agencia Española de Protección de Datos (aepd.es), or the data protection authority of your own country of residence.
To exercise your rights, a simple e-mail to the address above is enough.
9. Currency of this policy
This policy is updated when the site or the legal framework changes. The version published here is the one that applies.