Privacy
Last updated: October 4, 2026 · Applies to the Arcana Code website and Chrome extensionArcana Code provides question-centered AI tarot readings. This page explains the information used by the service, where it is stored, and the choices available to you. Contact: ggolem@naver.com.
Information you provide
- Google sign-in supplies an account identifier and display name. We use these to identify your account, show your name and maintain your session. Arcana Code does not receive your Google password or access your email messages.
- Cloudflare processes connection information, including IP addresses, to serve and secure requests. Arcana uses a hash of the IP address for sign-in and extension-pairing rate limits. These are not used to identify your physical location or track other websites.
- Questions, selected spread, language, drawn cards, orientations and interpretations are used to create and display readings. Credit readings and their history are stored in your Arcana account on Cloudflare D1.
- Credit balances, purchase identifiers, pack information and payment/refund status are retained to process purchases, prevent duplicate credit grants and maintain the credit ledger. Lemon Squeezy handles payment details; Arcana Code does not store card numbers.
- If you connect your own Gemini API key, the key is stored on your device, in extension local storage or website local storage. It is sent directly to Google for the model check and requested readings. It is not sent to the Arcana server, synchronized to an Arcana account or included in history exports. Own-key readings stay in device storage.
AI providers and other service providers
For credit readings, the Arcana backend sends your question, cards, spread positions and output language to Anthropic. For own-key readings, your device sends this information directly to Google's Gemini API. AI output is returned as text data for display; the extension does not download executable AI code. Avoid including information you do not want the selected provider to process.
Google may use inputs and outputs submitted through its free API tier to improve its products. Your Google API account, quota and billing conditions apply when using your own key. See Google's Gemini API terms, Anthropic's privacy policy, Cloudflare's privacy policy and Lemon Squeezy's privacy policy.
Extension permissions and browser data
The extension uses storage for local settings, keys and sessions, and access to the Arcana service origin for account, reading and credit requests. Access to the single Google Gemini API origin is optional and requested when you connect your own key. Removing that key also removes this optional access. The extension does not read other pages, browsing history, bookmarks or cookies, inject content scripts, or use advertising/visitor analytics. All executable extension code, fonts and card artwork are packaged with the extension.
Retention, deletion and your choices
Saved readings remain available until you delete the saved reading history. Completed and failed account readings can be deleted from Reading history; active readings finish or expire before deletion. Own-key history can also be deleted there. The device key can be removed in Settings. Sign out ends the current Arcana session; server sessions expire after 14 days. Removing the extension clears its local extension storage but does not delete account records.
Account records and credit/payment ledger entries remain on the service while needed to operate your account and reconcile transactions; there is no automatic deletion period for those records. Contact us to request account deletion or assistance with your information. Any records that must be kept to resolve transactions or meet applicable obligations are handled separately from deleted reading text.
Security and use limits
Requests use HTTPS. Server sessions are stored as hashes and browser sessions use Secure, HttpOnly cookies; extension sessions use session storage. A device API key is not an encrypted password vault. Arcana Code does not sell user information or use questions for advertising, lending decisions or unrelated purposes. Data is shared with the providers described above to deliver the features you request.
Arcana Code's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use information for the disclosed reading, account and credit features and their security. We do not permit people to read private questions or interpretations except with your explicit consent for specific support, as needed to investigate abuse or security, or as required by law.
We will update this page when the service's handling of information changes. Support