Legal

Privacy Policy

Effective June 29, 2026. Issued by Spread Weaver (Pennsylvania, USA).

1. Who we are

Spread Weaver (the "Service") is operated by Spread Weaver in Pennsylvania, USA. For privacy questions or requests, reach us at support@spreadweaver.com.

2. What we collect

  • Account information. Your email address, and a password or third-party sign-in identifier (e.g. Google). If you choose to add a display name or other profile details, we store those too.
  • Your tarot content. The spreads, questions, card draws, personal notes, journal entries, and any AI-generated synthesis you choose to save.
  • Usage data. Basic technical information needed to operate the Service — IP address, browser/device type, timestamps, requested URLs, and error logs.
  • Subscription and billing data. If you upgrade to a paid tier, our payment processor handles your card details directly; we receive limited records such as plan, status, and last-four card digits.

We do not knowingly collect information from children under 16.

3. How we use it

  • To operate the Service: store your account, save your readings, and surface them when you return.
  • To generate AI interpretations when you request them, by sending the relevant content to a third-party AI provider via the Lovable AI Gateway.
  • To maintain security, prevent abuse, and debug errors.
  • To process payments and manage subscriptions.
  • To send service-related email (e.g. password resets, important changes). We do not send marketing email at this time.

We do not sell your personal information. We do not use your readings or notes to train machine-learning models, and we do not share them with advertisers.

4. Service providers (sub-processors)

We use a small number of trusted providers to run the Service. They process data on our behalf under their own security and privacy commitments:

  • Lovable Cloud — application hosting, database, authentication, and storage.
  • Lovable AI Gateway — routes AI interpretation requests to underlying large-language-model providers.
  • Email and payment providers — used as needed for transactional email and (on paid tiers) billing.

The specific list of sub-processors may change over time as the Service evolves.

5. Cookies and similar technologies

We use a small number of strictly necessary cookies and local-storage entries to keep you signed in and to remember your preferences (such as your theme choice). We do not currently use third-party advertising cookies or cross-site tracking.

6. Data retention

We keep your account data and saved readings for as long as your account is active. When you delete your account, your readings and notes are deleted from our active systems within a reasonable period; routine encrypted backups may retain residual copies for a limited additional period before being overwritten. Limited records may be kept where required for legal, tax, security, or fraud-prevention purposes.

7. How we protect your readings

In our database. Your question, your notes, the AI's response, and the cards in each reading are encrypted before they're written to our database. The key that unlocks them lives only on our servers, never in the database itself — so a database copy on its own can't be read.

Between your device and our servers. Every request to the site travels over HTTPS, which encrypts the data in transit so it can't be read by anyone watching the network between you and us. This is the same standard used by banks and email providers.

When a reading goes to the AI. Generating an interpretation means sending the reading to a third-party AI provider, routed through the Lovable AI Gateway. Per the provider's published API policy, that content isn't used to train their models and isn't kept in your account with them. They retain it briefly — typically up to 30 days — only to detect abuse, then delete it.

What we don't do. We don't sell your readings, share them with advertisers, or use them to train any model of our own. We also enforce row-level authorization in our database so that only you can read your own readings.

A couple of honest limits: nothing connected to the internet is ever 100% guaranteed, and a few fields aren't encrypted in the database (the spread layout, timestamps, your account email) because we need them to make the app work. If we become aware of a breach that materially affects you, we will notify you and the appropriate authorities as required by applicable law.

8. Your choices and rights

Depending on where you live, you may have the right to:

  • access a copy of the personal information we hold about you;
  • correct inaccurate information;
  • delete your account and associated data;
  • export your saved readings (Pro tier currently supports Markdown export from the Journal);
  • object to or restrict certain processing.

To exercise any of these rights, email support@spreadweaver.com. We will respond within a reasonable period, generally within 30 days.

9. International users

The Service is operated from the United States and is hosted on infrastructure that may process data in the United States and other countries. By using the Service, you understand that your information will be transferred to and processed in the United States.

10. Changes to this Policy

We may update this Privacy Policy at any time, without prior notice. The "Effective" date at the top of this page reflects the latest version. We encourage you to review it periodically. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy. See also our Terms of Service.

11. Contact

For any privacy question or request, email support@spreadweaver.com.