VIDASTRAL

Legal

Privacy Policy

Last updated 2026-04-22

Vidastral ("we", "us") is an AI tarot reading service. This policy describes what personal data we collect, why we collect it, how long we keep it, and the rights you have over it. We operate from the European Union (Portugal) and serve users worldwide, so this policy is written to comply with the EU GDPR and the Brazilian LGPD.

1. What we collect

  • Email address — if you sign up, join the waitlist, or request a magic sign-in link.
  • Readings — the cards drawn, any optional question you typed (up to 280 characters), the reading text we generated, and a short summary used to give future readings context.
  • Anonymous session cookie — a first-party cookie we set so anonymous readings stay associated with your device for 30 days.
  • Session cookie — if you sign in, an HTTP-only first-party cookie that expires 30 days after issue.
  • Consent preference — whether you accepted or declined non-essential cookies (stored locally on your device).
  • Analytics — if you accept, we record page views and a small number of named events (reading started, reading completed, account created, waitlist signup). We do not use Google Analytics; we use a privacy-friendly analytics provider that does not build cross-site profiles.

2. Why we collect it

  • To deliver the service you asked for: generating and displaying your reading, signing you in, sending the magic-link email.
  • To give signed-in users a three-reading memory so new readings have context. This is a core product feature.
  • To understand whether the product is working (aggregate funnel numbers), gated on your consent.
  • To comply with our legal obligations.

3. How long we keep it

  • Accounts & readings: until you ask us to delete them.
  • Anonymous sessions: the cookie expires after 30 days; the server record is retained for audit but contains no personal identifier.
  • Waitlist signups: until you ask us to remove you or until the waitlist is retired.

4. Your rights

Under GDPR and LGPD you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. MVP does not yet offer self-serve deletion — to exercise any of these rights, email privacy@vidastral.com. We respond within 30 days.

5. Cookies

We use first-party cookies only. Essential cookies (your session, your anonymous session, your consent preference) are strictly necessary for the site to function and do not require consent. Non-essential cookies (analytics) are only set after you opt in via the cookie banner; you can change your mind at any time by clearing the preference in your browser.

6. Sharing

We do not sell personal data. We share it only with sub-processors we use to operate the service (hosting, email delivery, reading generation). Each sub-processor is contractually bound to handle your data per this policy.

7. Contact

Privacy questions, requests, or complaints: privacy@vidastral.com. You also have the right to lodge a complaint with your local supervisory authority (in the EU: the CNPD in Portugal; in Brazil: the ANPD).