Privacy Policy

Last updated: July 20, 2026

1. Data you provide

The card flow may use a display name, birth date, optional birth time, calendar type, birth region, and a charm topic selected later. Basic use does not require an account, gender, legal name, email, or identity document.

2. How input is used

Input is used to calculate and display the requested cards, maintain the current session, and support save, share, compatibility, or charm features chosen by the user.

We do not use reading questions, birth data, selected charm topics, result text, or sensitive concern categories to select personalized ads or build advertising audience lists.

3. Local storage and retention

Saved cards and preferences may be kept in browser storage on the user's device. Users can remove local data through the card vault, where available, or browser settings.

The current character-card flow does not use a database to persist birth inputs, selected charm topics, or result text. The dormant legacy deep-reading cache and its Supabase integration have been removed. Server logs or short-lived platform caches may still retain technical request information for security, debugging, delivery, and abuse prevention under the relevant provider's retention controls.

When Stripe premium checkout is enabled, Upstash Redis keeps a pseudonymous browser reference, Stripe checkout-session ID, signed entitlement token, and fulfillment time for up to 400 days so a completed purchase can be delivered and rechecked. That fulfillment record does not contain a birth date, birth time, reading question, or result text. Stripe may retain transaction records under its own legal and operational requirements.

4. Service providers

Only providers needed for an enabled feature receive the limited data required for that feature. These may include Vercel for hosting and query-free Web Analytics, Google Analytics 4 for approved public-page measurement, Google AdSense or Ad Manager for eligible advertising, Google Gemini for an explicitly requested automated generation, Stripe for checkout, and Upstash Redis for the time-limited premium-fulfillment record described above. Supabase is not used by the current service. Each provider's own terms and privacy policy also apply.

5. Analytics, Google advertising, cookies, and device data

Public editorial and catalog pages may use query-free Vercel Web Analytics and, when configured, Google Analytics 4. Arcarix removes query strings before Vercel analytics events and sends GA4 page views only from approved public content paths with a query-free page location. Input, result, charm, comparison, vault, and payment routes do not load the GA4 tag. Analytics providers may process page path, referrer origin, device, browser, approximate location, and interaction information under their own policies.

Eligible public pages may use Google AdSense, and an explicitly selected preview may use a Google Ad Manager rewarded ad. Google and other third-party vendors may use cookies or similar identifiers for delivery, measurement, fraud prevention, reward confirmation, and consent handling.

Birth details, display names, selected charm topics, result text, and saved-card contents are not sent as analytics event properties, advertising targeting values, or audience-list values. Google's use of advertising cookies is described in its advertising and privacy materials. Users can manage Google ad personalization at https://adssettings.google.com and find additional industry opt-out choices at https://www.aboutads.info.

6. Region-specific consent

For users in the European Economic Area (EEA), the UK, and Switzerland, analytics storage, ad storage, personalization, and related personal-data use are handled through a Google-certified Consent Management Platform (CMP) integrated with IAB TCF v2.3 where required. Google consent signals default to denied until the applicable consent flow updates them.

7. Your choices

Use a nickname, omit optional fields, clear local storage, decline optional ad or premium paths, and avoid sharing a card publicly. Consent controls can be used to change or withdraw eligible advertising choices. Contact us for a privacy question tied to a support message or payment issue.

8. Children and family use

Arcarix is not directed to children under 13. If an entered birth date indicates a user under 13, optional rewarded advertising is not offered. Where local law requires parental or guardian consent, the service should be used with that adult. Do not submit a child's legal name, contact details, school information, precise location, or other unnecessary identifying information.

9. Contact

Email hello.arcarix@gmail.com. Do not send identity documents, medical records, or full payment-card details unless a lawful and narrowly defined support process specifically requires them.