Back to Hyperion Tarot Terms of Service

Privacy Policy

Effective Date: August 29, 2026
Last Updated: August 29, 2026

This Privacy Policy explains how Codex Dev ("we", "us", or "our"), based in the Netherlands, collects, uses, and protects your information when you use Hyperion Tarot (the "Service").

We are committed to a privacy-by-design architecture: your interactive prompts, tarot spreads, and conversational interpretations are strictly ephemeral and are never persisted on our storage systems.


1. Information We Collect

We intentionally minimize the data collected from our users:

  • Google Account Information (Authentication Data): When you sign in using Google Identity Services, Google returns an authentication ID token that includes your Google account name, email address, and profile picture. We use this authentication response only to verify your identity, and we store only your email address in our secure database for account authentication, access control, and rate-limiting enforcement. We do not use or store your Google profile name, profile picture, contacts, or other Google account metadata.
  • Ephemeral Session & Interaction Data: When you input questions, select or generate tarot spreads, and converse with the system via WebSocket, these inputs and outputs are processed temporarily in volatile system memory (RAM). We do not save, record, or log your tarot questions, spreads, or chat history to any persistent database or disk.
  • Payment Information: If you choose to make a voluntary donation, payment transactions are processed entirely by Stripe. We do not collect, process, or store your credit card numbers or banking details. Stripe handles your payment data under its own privacy policy.

2. How We Use Your Information

We process your data strictly for the following purposes:

  • To authenticate your identity and grant access to the Service.
  • To enforce fair-use rate limits and prevent abuse of our computing resources.
  • To generate real-time tarot interpretations during an active WebSocket session using our self-hosted artificial intelligence engine.
  • To comply with statutory obligations under applicable law.

3. AI Processing and Ephemeral Architecture

  • Self-Hosted AI Infrastructure: All natural language processing and tarot spread interpretations are executed on our own self-hosted open-source model infrastructure. Your inputs and prompts are never transmitted to third-party AI model providers, such as OpenAI, Anthropic, or external cloud LLMs.
  • No Model Training on User Data: We do not use your session prompts, questions, or generated answers to train, fine-tune, or improve any machine learning models.
  • Session Termination & Data Purge: The context of your conversation exists solely within the memory of your active WebSocket connection. As soon as you click "Reset", disconnect, or close your browser session, all contextual conversation data is immediately and permanently wiped from volatile memory.

4. Third-Party Services

We do not sell, rent, trade, or share your personal data with third parties, except for the following essential infrastructure providers:

  • Google Identity Services: Used to authenticate your Google Account. Google returns an authentication ID token that includes your name, email address, and profile picture; Hyperion stores only your email address.
  • Stripe: Used exclusively to process voluntary financial donations.
  • Cloudflare: Used strictly as a DNS and network routing layer to protect against distributed denial-of-service (DDoS) attacks. Cloudflare does not store your authentication credentials or conversational payloads.

5. Google API Services User Data Policy Compliance

Our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements:

  • We use Google sign-in data only to authenticate you and manage rate limits, and we store only your email address.
  • We do not transfer, sell, or disclose your Google user data to third parties, advertising platforms, data brokers, or information resellers.
  • We do not use Google user data to serve advertisements or retarget users.
  • Human personnel cannot view your session prompts, as they are not stored.

6. Legal Basis & Your Rights (GDPR)

Because Codex Dev operates within the European Union (Netherlands), we process your data under the General Data Protection Regulation (GDPR):

  • Legal Basis: Processing the Google sign-in response and storing your email address is necessary for the performance of a contract (providing the Service and managing abuse/rate limits). Processing voluntary donations is based on contract and legal compliance.
  • Your Rights: You have the right to request access to the email address and any other personal data we hold about you, request immediate deletion of your account and email address from our database, restrict or object to the processing of your data, and lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

To exercise any of these rights, email us at [email protected]. Account and email deletion requests are fulfilled within 30 days.

7. Children's Privacy

The Service is not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from minors.

8. Contact Us

If you have any questions or concerns regarding this Privacy Policy or your personal data, contact:

  • Entity: Codex Dev
  • Location: The Netherlands
  • Email: [email protected]