Privacy policy
Nireye works without sign-in. This policy explains what is processed when you use the site, save a reading, contact us, or choose to sign in.
Summary
- Sign-in is optional for tarot spreads and the daily card.
- Guest saves stay in this browser. Account saves are stored in our PostgreSQL database and linked to your Auth0 sign-in identifier.
- An optional tarot question may be processed on our servers and by a configured AI provider to generate the reading.
- Nireye does not sell personal information or use it for cross-context behavioral advertising.
- You can manage, export, or delete Nireye account data from the Account page.
Data we process, why, and for how long
Tarot questions and reading sessions
Data: optional question, spread choice, drawn cards and orientation, generated narrative, and one optional follow-up exchange. Purpose: generate and deliver the requested reading and keep the active session working. Legal basis: providing the service you request and our legitimate interest in operating it. Recipients: our hosting and PostgreSQL infrastructure and, when an AI reading is available, OpenAI or a paid Google Gemini service. Storage criterion: active sessions are kept only while needed for generation and the available follow-up, then removed during periodic cleanup; you can also delete the active session yourself. If you were signed in when the reading was drawn, deleting your Nireye data from Account also erases that session and its stored question.
Account and saved-reading data
Data: Auth0 subject identifier, optional sign-in email, saved readings, journal notes, resonance selections, and saved follow-up answers. Purpose: authenticate you and sync your private journal across devices. Legal basis: providing account features you request. Recipients: Auth0 and our hosting and database infrastructure. Storage criterion: Nireye account journal data is kept as a continuous history until you delete all Nireye account data from Account.
Feedback
Data: category, message, optional reply email, browser user-agent, and submission time. Purpose: respond when requested, diagnose problems, improve the service, and prevent abuse. Legal basis: your request and our legitimate interest in support and product security. Recipients: our hosting and database infrastructure and the people responsible for reviewing Nireye feedback. Storage criterion: kept while needed to review or resolve the submission and related safety or legal issues, then deleted when it is no longer needed.
Technical and security data
Data: IP address processed for rate limiting, hashed rate-limit keys, request time, route, error codes, and ordinary server security logs. When error tracking is configured, crash reports (stack, route path without query string, release) are also sent to Sentry. Questions, narratives, follow-up text, email, cookies, and request bodies are not included. Purpose: secure the service, prevent abuse, and diagnose failures. Legal basis: our legitimate interest in reliable and secure operation. Recipients: hosting, network, database, and security infrastructure providers, and Sentry when a DSN is configured. Storage criterion: rate-limit and log data is retained only for the operational, security, and legal period for which it is needed, according to the relevant system or provider.
Product analytics, when enabled
Data: a random pseudonymous session identifier, page and labeled-button events, coarse product milestones, dates, and app version. Questions, narratives, notes, email, and saved reading content are excluded. Purpose: understand whether the product works and where it fails. Legal basis: consent where required, otherwise our legitimate interest in measuring the service. Recipients: our hosting and PostgreSQL infrastructure. Storage criterion: events are kept only for the limited measurement period for which they are useful, then periodically removed. Analytics is disabled unless explicitly enabled in deployment configuration, and browser Do Not Track disables collection.
Data stored in your browser
Local storage may hold guest reading history, journal notes and resonance check-ins, daily-card reflections, tarot practice notes, learning-path progress, reading-merge state, and pseudonymous analytics identifiers when analytics is enabled. This data stays on that browser until you clear the site's browser storage. We cannot restore a guest-only browser copy.
Auth0 uses cookies needed to maintain an optional sign-in session. These authentication cookies are not used by Nireye for advertising.
AI providers and model improvement
Nireye does not train its own AI models on your tarot question or follow-up. Depending on deployment configuration, a reading may use OpenAI or Google Gemini. Requests are made by our server, not directly by your browser.
OpenAI states that API data is not used to train its models unless the API customer explicitly opts in. Nireye does not opt in. Google states that prompts and responses from Gemini Paid Services are not used to improve Google products. Nireye blocks tarot spread and follow-up content from Gemini unless the deployment is explicitly configured as a paid Gemini service. Provider security, abuse-prevention, and legally required processing may still apply under the provider's terms.
A spread can also use a catalog-based template without sending your question to an AI provider.
Service providers and recipients
- Auth0: optional authentication and session management.
- OpenAI or paid Google Gemini: generation of tarot narrative and follow-up text when configured.
- Hosting, network, and PostgreSQL infrastructure: serving the application, storing account and operational data, security, and backups.
- Authorities or professional advisers: only when reasonably necessary to comply with law, protect rights and safety, or address a legal claim.
Providers may act as processors or independent controllers depending on the data and service. We do not authorize them to use Nireye data for their own advertising.
International processing
Nireye and its providers may process data in the United States and in other countries where their infrastructure or personnel operate. Privacy laws in those countries may differ from those where you live. Where applicable law requires a transfer safeguard, we rely on the provider's data-processing terms and available lawful transfer mechanisms, such as adequacy decisions or Standard Contractual Clauses. The mechanism depends on the provider, service, and country from which the data is transferred.
Your privacy rights
Depending on where you live, you may have the right to ask what personal data we hold, obtain a portable copy, correct inaccurate data, delete data, restrict or object to certain processing, withdraw consent, and appeal a denied privacy request. You may also have the right to complain to your state attorney general or another privacy regulator. We will not discriminate against you for exercising an applicable privacy right.
Use the Account page to export or delete all Nireye account data, and History to correct journal notes and check-ins. For Auth0 identity deletion, feedback records, questions about technical data, or an appeal, send a request to support.nireye@gmail.com or through the feedback page. We may need to verify that the request concerns your data. Some records may be retained when required for security, fraud prevention, legal compliance, or legal claims.
Nireye does not sell personal information, share it for cross-context behavioral advertising, or use automated decision-making that creates legal or similarly significant effects.
Children
Nireye is intended only for people age 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us through Feedback so we can review and delete it.
Changes and contact
We may update this policy as the product or law changes. Material changes will appear on this page with a new updated date.
For privacy questions or requests, email support.nireye@gmail.com or use our feedback page.
Nireye is for reflection and entertainment. It is not medical, legal, financial, or mental health advice.