Paper Tarot Journal Privacy Policy

Last updated: September 8, 2026

This Privacy Policy explains how Paper Tarot Journal ("Paper Tarot Journal," "we," "us," or "our") handles information when you use the Paper Tarot Journal iOS app, including the journal, the board, decks and the almanac, the calendar and reminders, practice tools, account sync, sharing, and subscriptions.

Summary

  • Paper Tarot Journal is designed to be low-data. You can write in it without giving us a name or an email address.
  • We do not sell your personal data.
  • We do not collect your contacts, location, health data, camera roll, or browsing history. The microphone is used only while you record a voice note.
  • Your journal stays on your device until you sign in and sync. Synced entries, photos, voice notes and events are stored in your account on our servers. This release does not use end-to-end encryption: the service can technically access that content. We restrict access to provide and protect the service.
  • We do not send your journal to any AI service and do not use it to train models.
  • We use a small number of service providers to run the app:
    • PostHog, hosted in the EU, for product analytics and diagnostics;
    • Supabase, hosted in the EU, for accounts, account sync, and account deletion;
    • Apple, for App Store purchases and subscriptions, Sign in with Apple, Keychain, and notification permissions;
    • Google, only if you choose to sign in with Google.

Android launch waitlist

On the Paper Tarot landing page, we also measure page visits, App Store button clicks and waitlist form outcomes using PostHog. These funnel events use an anonymous browser identifier and do not include your email or form text.

If you join the Android waitlist on our website, we store the email address you submit, the signup date and the Paper Tarot Android signup source in Supabase. We use these details to send the Android launch email you requested. This list is separate from the Moira waitlist and is not linked to your journal entries. To withdraw your request or ask us to delete your email, contact us through our support page.

Information stored on your device

The readable copy of everything you make is on your device. That includes:

  • journal entries and pages: questions, notes, cards and decks, spreads, tags, dates, outcomes you record, and the stickers, papers, and other materials you place on a page;
  • photographs you attach and voice notes you record;
  • calendar occasions and the reminders you schedule;
  • your profile settings, avatar, selected deck, and app preferences;
  • sign-in session information, stored securely in the device Keychain.

You can delete entries, pages, photographs, and voice notes inside the app. Deleting the app removes its local data from that device.

Account and sign-in

You can use the journal without an account. Local-only entries are not uploaded. Sign in to sync your journal between your devices, using:

  • Sign in with Apple. We receive the identifiers and details Apple makes available, which may include a name and either your email address or an Apple private relay address.
  • Google. We receive the identifiers and account information you authorize Google to provide, usually including an email address.

Sign-in sessions and refresh tokens are stored in the device Keychain. We never receive your Apple or Google password.

If you sign in with Apple, our server also stores an Apple-issued token in a restricted table that no user account can read. Its only purpose is to revoke the app's access to your Apple identity when you delete your account, which Apple requires. It is deleted together with the account.

Your journal and sync

Your entries, pages, photographs, voice notes and calendar events are stored on your device. When you sign in and sync, a copy is uploaded to your account over an encrypted connection. Transport encryption is not end-to-end encryption: the current release stores content in a form the service can read.

Account access controls keep users from accessing each other's records. Authorized service access may be needed to operate, secure and support synchronization. We do not send journal content to analytics or AI services and do not use it to train models.

Sync is not a guarantee against data loss. Keep your own copies of important content. Deleting the app removes local app data; it does not by itself delete your server account.

What our server can see

To run accounts and sync, some information has to stay readable on the server:

  • your account identifier and the identifiers of your records;
  • the kind of entry and the date and time it belongs to;
  • calendar record dates;
  • creation, edit, sync, and deletion timestamps;
  • payload version and sync state;
  • the contents of synced journal entries and pages, attached photographs and voice files, and calendar events.

We use this information to sync records and attachments, resolve conflicts, propagate deletions and keep accounts separate. Synced content is technically readable by the service; it is not included in product analytics.

Analytics and diagnostics

Product analytics is on by default, including during local-only use. You can turn it off in Profile, under Privacy, using Help improve the app. Turning it off stops future analytics collection without affecting journal features. We rely on legitimate interests in understanding and improving the app, subject to applicable law and your right to object.

We use PostHog, configured on PostHog Cloud EU, to collect a small set of explicitly defined in-app events. Analytics helps us understand whether the app works, which features are used, and where it needs improvement.

Analytics events may include:

  • product events, such as app opened, onboarding completed, entry created, reminder scheduled or opened, continuation created, ritual started or completed, paywall shown, and plan selected;
  • bounded properties, such as the kind of entry, the name of a ritual, where the paywall was opened from, the selected plan, and yes or no flags for whether an entry has a photo, a voice note, cards, a question, or a reminder;
  • technical properties, such as app version, build, platform, environment, and whether the build is an internal one;
  • information commonly processed by analytics services, such as device type, operating system version, timestamps, a device-level identifier, and the IP address of the request.

Analytics never include your journal text, questions, page content, outcomes, tags, searches, card names or identifiers, your name, your email address, your account or record identifiers, filenames, file contents, or encrypted data. Properties that are not on our allowlist are dropped before the analytics service sees them. Session replay, screen recording, tap tracking, surveys, advertising profiles, and automatic error capture are switched off.

Device permissions

Paper Tarot Journal asks for access only when you use the feature that needs it:

  • the microphone, while you record a voice note;
  • photos you select, to attach a picture or to save a rendered card to your photos;
  • notifications, to deliver reminders and calendar alerts as local notifications on your device;

You can change any of these in iOS Settings. Turning one off stops the related feature and nothing else.

Paper Tarot Journal does not ask for or collect your location. Moon phases and calendar events are calculated on your device from the date and your device's time zone.

Sharing to other apps

You can turn a reading or a page into a picture and send it to another app, such as a messaging or social app, or to the iOS share sheet. When you do that, you are publishing that picture yourself, outside the app. The app you send it to handles it under its own terms and privacy policy, and we cannot recall or delete that copy.

To show only buttons that lead somewhere real, the app checks whether a fixed list of messaging and social apps is installed on your device. That check happens on the device, the result is not sent anywhere, and it is not used for profiling or advertising.

Payments and subscriptions

Paper Tarot Journal may offer paid features as subscriptions. Payments are handled by Apple through the App Store.

Apple processes payment information, billing details, transaction history, refunds, taxes, and subscription management under its own terms and privacy policy. We receive purchase and entitlement status from StoreKit so the app can unlock paid features. We do not receive or store your card number. Analytics record only where the paywall was opened from and which plan was selected.

You can manage or cancel subscriptions in your Apple ID subscription settings.

Support and feedback

If you write to us, we receive your message and whatever contact details you choose to include, and we use them to answer you, look into the problem, and keep a reasonable record of the response.

Service providers

  • PostHog — product analytics and diagnostics, on PostHog Cloud EU. posthog.com/privacy
  • Supabase — accounts and authentication, EU-hosted database, journal sync, file storage, and the account-deletion function. supabase.com/privacy
  • Apple — App Store distribution, purchases and subscriptions, Sign in with Apple, Keychain, local notifications, and permission controls. apple.com/legal/privacy
  • Google — only if you sign in with Google. policies.google.com/privacy

These providers process information on our behalf or as independent providers under their own terms. We use them to run the app, keep your journal in sync, process purchases, find problems, and keep things secure.

Data sharing

We do not sell personal data.

We share information only in these limited cases:

  • with the service providers listed above, to run the app;
  • with an app you choose to send a picture to;
  • if required by law, regulation, legal process, or a valid government request;
  • to protect the rights, safety, and integrity of the app, its users, or others;
  • in connection with a merger, acquisition, financing, reorganization, or sale of assets, if the app or related assets are transferred.

If legally required, we may disclose account information and synced content available to us. We assess requests under applicable law and limit disclosure to what is required.

Data retention

Local data stays on your device until you delete it in the app or remove the app. Apple-controlled backups follow your own Apple and iCloud settings.

Account data, readable sync information, and your synced journal are kept while your account exists. When you delete an entry, the synced content is removed and a small deletion marker may remain long enough to carry the deletion to your other devices.

Analytics, authentication, and diagnostic records are kept only as long as reasonably needed to run the app, deliver sync, debug problems, understand usage, meet legal obligations, resolve disputes, and maintain security. Retention is also affected by our configuration and the service terms of PostHog, Supabase, and Apple.

Your choices and controls

  • Delete entries, pages, photographs, and voice notes in the app.
  • Change microphone, photo, and notification permissions in iOS Settings.
  • Delete your account in Profile. This deletes the account and associated journal data from our servers, and erases journal entries, photos, voice notes and events on the iPhone where you perform deletion. If you signed in with Apple, we also revoke the app's access to your Apple identity. This does not cancel an App Store subscription. Copies you shared or kept on other devices are not remotely erased by this action.
  • Delete the app to remove its local data from that device.
  • Manage or cancel subscriptions through Apple.

You can contact us to ask about access, correction, or deletion of information associated with you. Because the app can be used without an account, we may need details to find the relevant records. If you live in the EEA or the UK, you may also complain to your local data protection authority.

International data processing

Our analytics and database projects are configured in the European Union. Our providers and their subprocessors may still process information in other countries for support, security, or infrastructure. Where information is transferred internationally, we rely on the safeguards required by applicable law.

Children's privacy

Paper Tarot Journal is not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact us and we will take appropriate action.

Security

We use encrypted transport, account-based database and storage access controls, a restricted table for Apple tokens, and the Apple Keychain for sign-in material. The current release does not provide end-to-end encryption of journal content. No storage or transmission method is completely secure. Keep your device and sign-in accounts secure.

Changes to this policy

We may update this Privacy Policy as the app changes. If we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice.

Contact

For privacy questions or requests, contact:

Left Hand Studio
Paper Tarot Journal by Maksim Grachev
Email: hi@left-hand.studio

See also our Terms of Use.