PRIVACY POLICY

Privacy Policy

This Policy explains what information NTTarot handles and where it is stored.

01

Scope

This Policy applies to the public NTTarot website and web application (together, the “Service”) provided by the NTTarot administration office (the “Operator”). Information handled within services provided by Cloudflare, Microsoft, Dropbox, Google and other third parties is also subject to each provider's terms and privacy policy.

02

Information we handle and why

Data you create

The web app handles your Tarot questions and themes, selected cards and their upright or reversed orientation, reading history and notes, edits to decks and spreads, AI prompt settings, and storage and synchronization settings in order to provide, save and synchronize the app's features.

This data is processed in your browser and in cloud storage that you choose. Unless you send it to the Operator yourself, for example in an inquiry, the Operator does not collect, store or view your reading content, notes, decks, spreads or other saved data.

Account information used for cloud connections

If you connect OneDrive, Dropbox or Google Drive, the browser handles a display name, email address or username, account identifier and authentication tokens so that it can display the connected account and access the app-specific storage area. The Operator does not obtain the password for any of these accounts.

Information in inquiries

We use email addresses, names or display names, inquiry content and other information included in a message to review and answer the inquiry, verify identity, prevent misuse and keep a record of our response. Inquiry email is received and stored using Google's Gmail service.

03

Where information is stored

Storage on your device

Reading and other data is first stored in the storage area of the browser you are using, regardless of the storage method you select. If you choose “Do not sync (local only),” this data is not sent to the Operator's server. It may be impossible to recover the data if you delete browser data or can no longer use the device.

Cloud synchronization

If you choose OneDrive, Dropbox or Google Drive, data is saved and synchronized in the provider's app-specific storage area. Cloud data is managed under your own account and is transferred directly between your browser and the connected service, without passing through the Operator's server.

04

Connections to external services

For OneDrive, the Service uses Microsoft authentication and the Microsoft Graph API; for Dropbox, Dropbox authentication and APIs; and for Google Drive, Google Identity Services and the Google Drive API. Each is used only to the extent necessary to display the connected account and work with files in the app-specific storage area. These connections are optional, and the Service remains available with local storage if you do not use them.

The Service has no direct connection to an AI service and does not automatically submit the prompt it creates. When you choose “Discuss with AI,” you can either copy the prompt to your device's clipboard or open the sharing interface through the browser's Web Share API. Copied information becomes subject to the destination service's handling of information when you select a destination and paste it there. If you share the prompt, the destination service's handling of information applies when you choose that destination and pass the prompt to it. Canceling the sharing interface does not share the prompt and returns you to the method-selection screen. If the prompt contains personal or confidential information, review the destination's policy and remove anything unnecessary before pasting or sharing it.

05

Browser storage and cookies

The Service stores app settings, file data, encryption keys, sign-in state and information needed for authentication in IndexedDB, localStorage or sessionStorage. Microsoft's authentication cache is stored in same-origin localStorage. Dropbox and Google Drive access tokens are stored in sessionStorage.

For analytics and monitoring through Cloudflare, the Service uses a first-party cookie that associates page views and events within the same session. A session using this cookie remains valid for 60 minutes.

Google AdSense is not currently enabled, and the Service does not currently use third-party advertising cookies. If you disable or clear browser storage, you may be signed out, saved data may be lost, and some or all of the Service may become unavailable.

06

Delivery and analytics through Cloudflare

The Service is delivered through Cloudflare. Cloudflare Web Analytics and Cloudflare Zaraz let us review aggregate information such as page views, referrers, pages viewed, browser, operating system, country or region, page-display performance and the number of times reading features are used. Zaraz advanced monitoring also associates the history of page views and events within one session to produce user timelines, funnels and other monitoring reports.

This information is sent to systems managed by Cloudflare, Inc. and is used by the Operator to understand usage, improve display performance, investigate failures and protect against unauthorized access, and by Cloudflare to provide, maintain and secure its services. Analytics do not include your questions, cards, notes or any other reading content.

Cloudflare's Web Analytics beacon temporarily receives the source IP address while a request is in transit. According to Cloudflare, the address is discarded at the nearest data center and is not stored in its core analytics database or logs. See Cloudflare's explanation of its RUM beacon for details.

If you disable or delete the cookie used by Zaraz advanced monitoring, you will be treated as a new session and some monitoring reports may not be created correctly. Reading, saving and the other main functions of the Service will remain available. For information about how Zaraz and Cloudflare handle data, see the Cloudflare Zaraz Monitoring documentation and Cloudflare Privacy Policy.

07

Advertising and development support

Google AdSense (planned after approval)

The Service plans to introduce Google's advertising service, Google AdSense. Google AdSense advertising is not currently being served.

After Google AdSense is introduced, Google and other third-party advertising providers may use cookies, local storage, web beacons, IP addresses and other identifiers to serve advertisements based on your previous visits to this Service or other websites. Google's use of advertising cookies may allow Google and its partners to display advertisements based on your visits to this Service and other websites.

You can manage or disable personalized advertising in Google Ads Settings. You may also be able to disable personalized advertising from some third-party providers through the YourAdChoices opt-out page.

For information on how Google uses information collected from sites and apps that use Google services, see How Google uses information from sites or apps that use our services.

Consent management for advertising

When Google AdSense advertising begins, users in the European Economic Area (EEA), the United Kingdom, Switzerland and other regions where consent is required will be provided with a consent-management interface that complies with Google's policies and applicable law. Through that interface, users can choose whether cookies and similar technologies may be used for advertising and whether they receive personalized advertisements.

Development support through Square

We accept optional development-support tips for the free Service and its content through Square's checkout page. Selecting a “Support NTTarot” link on this site or in the web app takes you to Square's site; Square then collects and processes the payment information.

Square may handle the name, email address, phone number, card details and other payment information a payer enters on its checkout page, as well as the payment date and time, amount, currency, method and information about the device and browser. The Operator may receive from Square the amount, currency, payment date and time, status and transaction identifier, as well as contact information the payer enters or provides to receive a receipt. The Operator does not directly obtain or store the complete card number or security code.

Information received by the Operator is used to confirm payments, process refunds, answer inquiries, prevent fraud and meet accounting and legal obligations. It is retained for the period necessary for those purposes or required by law. See Square's Buyer Privacy Notice for information about how Square handles data.

08

Access information

To deliver the Service, operate it reliably, investigate incidents and protect against unauthorized access, Cloudflare and the origin server may record ordinary communication and security logs, including IP addresses, access times, requested resources and information about browsers and devices. Each provider manages these under its own policies, separately from aggregate Web Analytics information.

09

Security

The Service uses encrypted communications, authorization provided by external services and mechanisms that limit access to app-specific storage areas. Saved reading history is encrypted using AES-256-GCM. These measures cannot, however, guarantee complete security in every circumstance.

The Operator works to take necessary and appropriate measures to prevent unauthorized access to, disclosure of, loss of or damage to the information it handles, and otherwise to manage information securely.

10

Your controls

You can delete relevant data in the app and clear this Service's saved data and cookies through your browser settings. Data synchronized to the cloud can be deleted from the connected app-specific storage area. You can also revoke the Service's access through your OneDrive, Dropbox or Google Account settings.

To request access to, correction of or deletion of inquiry email, or to discuss another concern, contact us below. We will respond under applicable law after verifying that the request comes from the person concerned.

11

Changes to this Policy

This Policy may be revised in response to changes in features, delivery methods or applicable law. Material changes will be announced clearly on this site. A revised Policy applies from the time it is posted on this page.

12

Operator and contact

Operator
NTTarot administration office

See the contact page for contact methods and precautions when sending information.

The Operator's legal name and address will be disclosed without undue delay after a legally valid request and necessary identity verification.