Privacy Policy
Last updated: August 2026
0. Who we are
Roza Tarot (rozatarot.com) is run by its sole owner, a private operator based in Warsaw, Poland — the data controller for everything described below. For any privacy matter, write to roza@rozatarot.com; a person, not a system, reads that inbox. Payments are handled by Lemon Squeezy, LLC as merchant of record (see section 3).
Roza is a crafted character. Her readings are generated with the help of artificial intelligence over an honest deck, and are offered for reflection and entertainment — they are not medical, legal, financial or any other professional advice. Wherever you talk with Roza, you are talking with an AI-assisted character, and the site says so openly.
1. What we collect
During the reading we collect your first name, your answers to the quiz questions, and the question you ask the cards — this composes your reading. After the reading, if you ask Roza to send it to you, we collect your email address. We use it to deliver that reading, and — only if you also tick the consent box — to send you Roza’s later letters.
Your reading itself is stored so it can be shown to you again at a private link that only you receive. Anyone who has that exact link can open that page, so treat it like a letter — do not share it if you want it private. If you choose to leave journal lines under a reading, those are stored with it, and deleted together with the rest of your data on request.
2. Legal basis & consent (GDPR)
One email is transactional: the reading you asked Roza to send, and — if you subscribe — the readings your plan pays for. Those are the service you requested, so they do not depend on the consent box. Every other letter (the morning card, the Sunday word, gentle reminders) is sent only after you tick the consent box. Either way you can stop all letters at any moment — each one carries an unsubscribe link, and you can always write to roza@rozatarot.com to be removed immediately.
When you tick the consent box, we also record the date and the IP address of that moment — kept as proof the consent was given freely (GDPR Art. 7), and for nothing else.
3. Who processes your data
To compose your reading, the question you type, your first name and your quiz answers are sent to Anthropic PBC (USA) — the provider of the text-generation model behind Roza’s readings — under its commercial data-processing agreement, with EU Standard Contractual Clauses as the transfer safeguard. Anthropic does not use this data to train its models.
Your reading, contact and consent records themselves live in our database, hosted by Neon (serverless Postgres, USA) under its data-processing agreement, with EU Standard Contractual Clauses as the transfer safeguard.
Contacts are stored with our email service provider (Resend) and payment data with our payment provider (Lemon Squeezy), who acts as merchant of record. We never see or store your card details.
To keep the site working and honest we also use two technical services that never receive your name, email or question: PostHog (product analytics — receives a random device identifier, which pages you visit and which steps you reached, so we can see where the ritual confuses people; if you go to the checkout, the same random identifier travels with you, so a purchase can be tied to the anonymous visit that led to it) and Sentry (error monitoring — receives diagnostic details when something breaks on the server, with any email addresses masked out before they are sent).
We also use Microsoft Clarity (Microsoft Ireland Operations Ltd., with processing by Microsoft Corporation in the USA under EU Standard Contractual Clauses) to see how the pages are actually used — where people hesitate, what they never scroll to. It records the shape of a visit: taps, scrolls and the layout of the page. Everything personal is hidden from it before it ever leaves your browser — your name, your question, your email address and the whole text of your reading are replaced by grey blocks — and the private page of a saved reading is not recorded at all. It runs only while measurement is on, and the one-click switch further down turns it off together with everything else.
Once a night a complete copy of our database is made and stored as a private build artifact with GitHub, Inc. (USA), so that a failure on our side cannot erase your reading or your subscription. Each copy is kept 30 days and then deleted automatically; only the owner can reach it.
We share your data only with these named processors, only as needed to run the service. We never sell it, and we share it with no one else.
A gentle tip from Roza herself: when you whisper your question to the cards, there is no need to include full names or details that identify other people — the cards know who you mean.
4. How long we keep things
Your reading, its cards and any journal lines are kept while the service runs, so your private link keeps its promise — until you ask us to erase them. Your contact details and letter history are kept while letters may still be sent to you. If you unsubscribe, we keep the address itself on a suppression list — that is the only way to honour “I will not write again” — and the consent record (date and IP) as legal proof, for 3 years. When you ask for deletion, everything above is erased within 30 days. When you subscribe, we also store the timezone your browser reports, so morning letters follow your own calendar.
5. Your rights
Under the GDPR you may, at any time: request a copy of your data (access), correct it, have it erased, restrict or object to its processing, receive it in a portable form, and withdraw any consent you gave — withdrawing changes nothing about what happened before. Write to roza@rozatarot.com and it will be done within 30 days, free of charge. You also have the right to complain to a supervisory authority — in Poland that is the UODO (uodo.gov.pl), or the authority of your own country.
6. Cookies & local storage
By default the site sets no cookies. If you choose to sign in to an account — by a link Roza emails you — one strictly-necessary cookie is set: it holds only a signed session token (no name, no tracking) so the table knows you across your devices, and it clears when you log out. Beyond that, the site keeps a small amount of functional storage on your own device — your name, your past readings, the morning card you turned — so the table can remember you. It also keeps one random identifier (not your name or email). That identifier is sent to our analytics service, PostHog, and is also sent to our own server and stored next to your reading: it lets the table know a repeat visit within the rest window (so the cards do not answer the same heart twice), and once you give your email it becomes linked to that reading. Clearing your browser storage erases the copy on your device.
Measurement is on, and you can turn it off. To know which advertisements bring people to this table, we load the Meta (Facebook) pixel, which sets its own cookies in your browser. This runs from your first visit unless you turn it off — the switch is a little further down this page, it takes one click, and we honour it for good on this device. The same switch also stops Microsoft Clarity, described in section 3. The site works exactly the same either way.
While it is on, we send Meta a record of five moments. From your browser: a page was opened and checkout was opened. From our own server: a reading was drawn and a subscription was paid for — the payment happens on Lemon Squeezy’s own domain, where our pixel cannot see it at all. And an email address was left goes from both at once, carrying the same identifier so Meta counts it as one moment, not two.
Whatever the address bar holds, we clear anything that names you out of it before the pixel can read it — letters link back with your email in the link, and that must never travel to an advertising network. On the private page of a saved reading, whose link is itself the secret, the pixel is not loaded at all.
With those moments we send, to help Meta recognise the account they belong to: your email address and our own random identifier for you — both only as irreversible cryptographic hashes, never in readable form — together with your IP address, the identification string your browser sends about itself, and Meta’s own cookies from your browser. For the payment event we use the IP address and browser string recorded when you left your email, since the payment reaches us from Lemon Squeezy with no browser attached. We never send your name, your question, the cards, or the text of any reading. Meta is in the United States; the transfer relies on our legitimate interest in measuring our own advertising and on Meta’s standard contractual clauses.
One click stops it, here. Turning it off is as easy as it should be. It turns the pixel off, erases the advertising marks from your device, and — if you have left us your email — tells our server to stop too, erasing the marks kept there, so no later event is sent about you, not even the one about a payment. If you have never left an email, there is nothing about you on our server to stop. None of this changes what happened before; to have what was already sent deleted as well, write to roza@rozatarot.com — a person reads that inbox, and it will be done.