Personal Data Policy | Твой таролог
Last updated: May 10, 2026
This Personal Data Policy sets out how the personal data of users of «Твой таролог» at https://my-tarot.one is processed and protected.
This Policy was prepared in accordance with Federal Law No. 152-FZ of July 27, 2006, “On Personal Data”, and applies to all users, including guests, registered users and users with paid Tarot+ access.
1. Personal data controller
The personal data controller is:
Стромов Борис Александрович
Taxpayer Identification Number (INN): 683202564919
Status: an individual applying the special tax regime “Tax on Professional Income”
Email for personal data inquiries and support: borisstromov@yandex.ru
Service website: https://my-tarot.one
The Operator independently organizes personal data processing for users of «Твой таролог», determines its purposes, the data to be processed and the processing operations.
2. Purpose of the service
«Твой таролог» provides automated AI interpretations of readings, user questions, continued conversations, in-depth analyses and special spreads.
Responses are generated using artificial intelligence on the Operator’s server infrastructure located in the Russian Federation.
The service’s responses are for information and entertainment purposes. They do not constitute medical, legal, financial, investment, psychological or other professional advice. Users assess the relevance of the information for themselves and take responsibility for their own decisions.
The service is not intended for diagnosis, treatment, emergency assistance, legally significant decisions, financial advice or as a substitute for consulting qualified specialists.
3. Definitions
This Policy uses the following terms:
Personal data: any information relating directly or indirectly to an identified or identifiable user.
Personal data processing: any operation involving personal data, including collection, recording, organization, accumulation, storage, updating, use, transfer, anonymization, blocking, deletion and destruction.
User: a person who uses «Твой таролог», including a guest, a registered user or a user with paid access.
Guest: a person who uses the service without registering.
Account: the User’s account with the service.
Reading: the result of the User’s interaction with the service, including the question, cards, interpretation, follow-up messages, continued conversation and related technical data.
Tarot+: paid access to additional service features for a fixed period, without automatic renewal.
4. Personal data processing principles
The Operator processes personal data according to these principles:
lawful and fair processing;
limiting processing to specific, predetermined and lawful purposes;
processing only the amount of data appropriate to the stated purposes;
avoiding the processing of excessive data;
ensuring data is accurate and up to date where needed for the processing purposes;
retaining data no longer than required by the processing purposes, service terms or the law;
taking measures to protect personal data against unauthorized access, alteration, disclosure, destruction or other unlawful actions.
5. Personal data processed
The Operator may process the following categories of data.
5.1. Account data
Registration, sign-in and account use may involve processing:
username;
display name;
interface language;
profile settings;
account status information;
information about paid Tarot+ access;
account creation date;
technical user identifiers.
If the User registers with an email address and password, the password is stored as a technical hash rather than in plain text.
5.2. Third-party sign-in data
When the User signs in through Google, Яндекс, VK, Telegram or other authentication providers, the service may receive and store:
the authentication provider’s name;
the User’s identifier at the provider;
display name, if supplied by the provider;
email address, if supplied by the provider and used by the service;
the date of the most recent sign-in.
VK and Telegram may not supply an email address, and it may not be required to use the service.
Third-party authentication providers process users’ data under their own rules and policies. «Твой таролог» uses the data received only for sign-in, account creation, account linking and access protection.
5.3. Guest access data
Use of the service without registration may involve processing:
a technical guest user identifier;
a cookie verifying ownership of a guest reading;
technical browser data;
information needed to continue a guest session and protect readings against access by third parties.
Guest access allows Users to start using the service without registering and later link a reading to an account if they wish.
5.4. Reading and conversation data
Creating and continuing a reading may involve processing:
the User’s question;
the User’s follow-up answers;
selected cards;
AI interpretations;
continued conversations;
in-depth analyses;
special spreads;
suggested follow-up questions;
technical reading data;
information about the selected mode, language, spread type and related settings.
The service may store reading data as soon as a reading is created, as part of providing the service. Selecting “Save”, registering or signing in after guest use links the reading and conversation history to the User’s account for later access.
Selecting “Save” is not the only point at which data is stored: some data is created and stored when the reading is generated.
5.5. Paid access and payment data
Once payments are enabled, the service may process:
the selected Tarot+ plan;
the access period;
the payment amount;
the payment currency;
the payment status;
the payment identifier at the payment provider;
the payment date;
refund information;
technical data needed to verify payment and provide access.
Bank card details are processed by the payment provider. «Твой таролог» does not store users’ bank card details.
At the time this version of the Policy was prepared, payment integration may still have been in progress. Payment and refund conditions apply once payment functionality is enabled.
5.6. Technical data
Use of the service may involve processing:
IP address;
browser type;
device information;
the date and time of requests;
technical service logs;
security events;
error information;
information about the use of service features;
localStorage and sessionStorage data.
This data is used to operate the service, diagnose errors, maintain security, prevent abuse and improve product quality.
5.7. Cookies, localStorage and sessionStorage
The service may use cookies, localStorage and sessionStorage to:
authenticate users;
protect sessions;
provide guest access;
verify ownership of guest readings;
protect OAuth sign-in;
retain a temporary intention to save a reading after registration or sign-in;
save interface preferences;
save the selected tarot reader persona;
continue a previous reading;
ensure the interface works correctly.
Users can restrict cookies through browser settings, but this may cause some service features to work incorrectly or become unavailable.
5.8. Analytics data
The service may use web analytics tools, including Яндекс.Метрика, to analyze visits, improve the interface, diagnose errors and develop the service.
Once these tools are enabled, anonymized or technical data about visits, actions on the website, device and browser parameters and referral sources may be processed.
6. Purposes of personal data processing
The Operator processes personal data for the following purposes:
user registration;
account sign-in;
providing guest access;
creating readings;
generating AI responses;
continuing conversations;
saving readings and history in the User’s account;
linking guest readings to accounts;
providing paid Tarot+ access;
processing payments and refunds once payments are enabled;
user support;
restoring access;
maintaining account security;
preventing abuse;
preventing unauthorized access to other people’s readings;
diagnosing errors;
improving service quality;
analyzing interface performance;
complying with Russian law;
protecting the rights and legitimate interests of the Operator and Users.
7. Legal bases for processing
The Operator processes personal data on the following bases:
the User’s consent to personal data processing;
the need to process data to provide service features;
performance of the user agreement or public offer;
fulfillment of obligations under Russian law;
protection of the rights and legitimate interests of the Operator and Users;
maintaining service security.
If the User does not provide data needed to register, sign in, create a reading, save history or pay for access, the corresponding feature may be unavailable.
8. Processing readings and AI responses
The User understands that their question, follow-up messages, reading data, AI responses and related technical information may be processed and stored to provide the service.
Readings can be created as a guest or through an account. Access to guest readings is protected by technical verification of guest session ownership. When registering or signing in, Users can link a guest reading to their account.
Once a reading has been linked to an account, another account cannot access or claim it without a lawful basis and technical verification of ownership.
9. Protecting reading data
The Operator takes technical and organizational measures to protect users’ private readings.
Access to private readings is provided to:
the account owner;
a user with verified guest access;
others where provided for by law.
The service’s administrative interfaces are not intended for viewing users’ private reading text. Access to data is restricted through technical and organizational measures.
New sensitive text data in readings, messages and in-depth analyses is protected with server-side encryption at rest.
The service does not use end-to-end encryption or a “zero-knowledge” system. The server decrypts data to display it to the User, continue conversations, operate service features, diagnose issues and fulfill statutory obligations.
Older technical records created before encryption was introduced may remain in their original format until deletion, expiry of their retention period or processing during maintenance.
10. Special categories of personal data
The service is not intended to deliberately process special categories of personal data, including information about health, intimate life, political views or religious or philosophical beliefs.
Users should not include information in questions or messages that is unnecessary for an entertainment or informational AI interpretation.
If a User voluntarily includes such information in a question or message, the service may technically process it only within the scope of that request and the service feature being provided.
11. Automated processing
The service uses automated data processing and artificial intelligence to generate responses.
The service does not make decisions that in themselves have legal consequences for the User or otherwise affect their rights and legitimate interests through legally significant decisions based solely on automated processing.
AI responses are not binding, do not replace professional advice and are used at the User’s discretion.
12. Data processing and storage location
Users’ personal data is processed and stored in the Russian Federation.
Responses are generated on the Operator’s server infrastructure located in the Russian Federation.
13. Transfer of data to third parties
The Operator may transfer personal data to third parties where necessary for:
hosting and server infrastructure;
service maintenance;
third-party authentication;
payment processing;
analytics once the relevant tools are enabled;
user support;
compliance with legal requirements;
protection of the rights and legitimate interests of the Operator and Users.
Only the data necessary for the relevant purpose is transferred.
Bank card payment data is processed by the payment provider. «Твой таролог» does not store users’ bank card details.
14. Confidentiality and security measures
The Operator takes the necessary legal, organizational and technical measures to protect personal data against unlawful or accidental access, destruction, alteration, blocking, copying, provision, dissemination and other unlawful actions.
These measures may include:
restricting data access;
user authentication;
verifying guest reading ownership;
protecting authentication cookies;
protecting OAuth processes;
server-side encryption of new sensitive text data at rest;
maintaining technical security logs without storing private reading text in those logs;
restricting administrative access to private readings;
filtering and redacting sensitive technical data in logs;
backups and recovery measures;
updating technical and organizational measures as the service develops.
15. Retention periods
Personal data is retained for as long as needed to fulfill processing purposes, operate accounts, provide access to saved readings, meet obligations to Users, maintain security and comply with Russian law.
Account data may be retained until the User deletes the account or the service closes, unless longer retention is required by law or to protect the Operator’s rights.
Reading data may be retained to provide access to history, continue conversations, diagnose technical errors and comply with legal requirements.
Deleting an individual reading may mean restricting access to it through the interface. Some technical records, security logs, activity information, payment and refund information and other data may be retained for the applicable period where needed to comply with the law, maintain service security, resolve disputes or protect the rights of the Operator and Users.
16. Deleting, blocking and updating data
Users may ask the Operator to:
provide information about personal data processing;
update data;
delete data;
restrict processing;
withdraw consent to personal data processing.
Send requests to borisstromov@yandex.ru.
The Operator reviews requests and takes action in accordance with Russian law.
The User understands that deleting data or withdrawing consent may prevent them from using their account, saved readings, paid access and other service features.
17. User rights
Users have the right to:
receive information about the processing of their personal data;
request that data be updated, blocked or deleted if it is incomplete, outdated, inaccurate, unlawfully obtained or unnecessary for the stated processing purpose;
withdraw consent to personal data processing;
contact the Operator about data processing;
appeal the Operator’s actions or failure to act to the competent authority or a court.
18. Processing minors’ data
The service is intended for users who can independently decide whether to use online services and provide personal data.
If applicable law requires a legal representative’s consent to process a minor’s personal data, that consent must be obtained before using the service.
The Operator does not deliberately collect children’s personal data.
19. Paid Tarot+ access
Tarot+ is purchased as one-time access for the selected period:
1 month;
3 months;
6 months;
12 months.
Access does not renew automatically. At the end of the paid period, access expires unless the User purchases another period.
Current prices are shown on the Tarot+ page before payment. As of the last update of this Policy, the following options are planned:
1 month: ₽790;
3 months: ₽1,990;
6 months: ₽3,490;
12 months: ₽5,990.
Once payments are enabled, payments may be processed by a payment provider, including Robokassa. Payment features may be unavailable until payment functionality is enabled.
20. Refunds
Users may request a refund in cases of:
duplicate payment;
a technical error;
failure to activate paid access;
inability to provide the paid service;
other justified requests.
Refund requests may be submitted:
through the User’s account, if that feature is available;
by emailing support at borisstromov@yandex.ru.
Refunds are handled in accordance with the service’s rules, the payment provider’s rules and Russian law.
21. Withdrawing consent
Users may withdraw consent to personal data processing by emailing borisstromov@yandex.ru.
After receiving a withdrawal of consent, the Operator stops processing data unless there are other lawful grounds to continue.
Withdrawing consent may prevent the User from using their account, saved readings, paid access, conversation history and other service features.
22. Changes to this Policy
The Operator may amend this Policy.
A new version takes effect upon publication at https://my-tarot.one, unless that version specifies otherwise.
Users are responsible for reading the current version of this Policy. Continued use of the service after a new version is published constitutes acceptance of the updated terms, unless otherwise provided by law.
23. Contact details
For questions about personal data processing, the service, data deletion, refunds or support, Users can contact us by email:
Operator: Стромов Борис Александрович
Taxpayer Identification Number (INN): 683202564919
Website: https://my-tarot.one
Last updated: May 10, 2026