Privacy Policy

Effective Date: August 1, 2026 · Version: V2026.08-Legal · Jurisdiction: Global Standards

1. Introduction & Data Controller

This Privacy Policy governs how Vaticinator ("the Platform", "we", "us") collects, uses, protects, and discloses personal data in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable international privacy statutes.

We adhere to the principles of data minimization, transparency, and local-first architecture. We do not sell or monetize personal data.

2. Data Categories & Processing

  • (1) Divination & Inquiry Data (Zero-Log) — All queries, drawn cards, and personal notes reside 100% in client-side storage (LocalStorage / IndexedDB). Our servers do not maintain logs or archives of your private readings.
  • (2) Authentication Data (Registered Accounts) — For registered accounts, we collect email addresses and salted hashed credentials solely for point balance synchronization.
  • (3) Financial & Transaction Data — All billing transactions are processed by PCI-DSS compliant payment gateways. We never store or access raw card numbers or financial credentials.
  • (4) Security & Operational Logs — Temporary IP records are processed strictly for DDoS mitigation and API rate-limiting, then automatically purged.

3. Cookies & Storage Policy

We deploy strictly necessary cookies and local storage tokens for language preferences, authentication, and local PIN locks.

> ✦ Strict Guarantee: The Platform does not employ third-party advertising trackers and never sells user data to data brokers.

4. PIN Lock & Data Security

Client-side 4-digit PIN locks protect reading archives on shared devices. All data transmission is secured with TLS 1.3.

5. User Rights & Data Erasure

Under GDPR (Articles 15–22) and CCPA, users hold comprehensive data subject rights:

  • Right to Access & Portability — View, copy, or export your reading records in JSON or text format at any time.
  • Right to Erasure — Click "Clear All" to permanently purge local history; registered users may request full account deletion via ticket.
  • Right to Object — Readings are for self-reflection only and never constitute legally binding automated decisions.

6. Children's Privacy

The Platform is intended exclusively for individuals aged 18 and older. We do not knowingly collect information from minors.

7. Amendments & Contact

We reserve the right to amend this Policy in accordance with legal and operational developments. For inquiries: admin@vaticinator.net

8. Cross-Border Data Transfers & International Compliance

When using cloud LLM inference services, your inquiry text and card context are transmitted via TLS 1.3 encrypted channels to Google Gemini (Google LLC) and OpenAI (OpenAI, Inc.) for real-time interpretation. Such transfers comply with GDPR Article 46 Standard Contractual Clauses (SCCs). Providers do not retain personally identifiable content beyond the inference session. All third-party providers we engage are SOC 2 Type II certified.

9. Complete GDPR Data Subject Rights

Under GDPR Chapter III, you hold the following comprehensive data subject rights: Right of Access, Right to Rectification, Right to Erasure (Right to be Forgotten), Right to Data Portability, Right to Restriction of Processing, Right to Object, and Right not to be Subject to Automated Decision-Making.

To exercise any of the above rights, submit a request via our support system. We will respond in writing within 30 business days.

10. Policy Updates & Notification

When we make material changes to this Policy, we will update the revision date prominently on this page and, where practicable, notify registered users. Continued use of the Platform constitutes acceptance of the updated Policy. In the event of any discrepancy between the Chinese and English versions, the Chinese version shall prevail.