Privacy Policy for Vesikaa

Effective Date: May 22, 2026
Last Updated: May 22, 2026

1. Overview

Vesikaa (“Vesikaa,” “we,” “our,” or “us”) is a tarot reading and reflection application. We designed Vesikaa to be local-first: your readings, journal entries, and reflections live primarily on your device. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have. It applies to the Vesikaa mobile application and the website at vesikaa.com.

If you do not agree with this Privacy Policy, please do not use Vesikaa.

2. Who We Are and How to Contact Us

Vesikaa is operated by an independent developer. You can reach us at:

3. Information We Collect

We collect only what we need to make Vesikaa work, keep it stable, and offer the features you choose to use.

3.1 Account and Identity Data

Vesikaa requires you to create an account or sign in to use the app. You can sign in with Sign in with Apple, Google Sign-In, or an email and password. When you sign in, we collect:

Sign in with Apple allows you to share a private relay email instead of your real one; we honor that choice and never attempt to resolve the relay address.

3.2 Reading and Reflection Data

When you use Vesikaa, we store on your device — and, if you sign in, back up to our cloud database — the following:

3.3 Preferences and Settings

3.4 Device and Diagnostic Data

To debug crashes and improve stability, we collect:

3.5 Usage Analytics

We use Firebase Analytics to understand which features are used. Events we record include:

Analytics are disabled in debug builds and never include the contents of your journal entries.

3.6 Motion Sensor Data

If you enable the gyroscope reveal, Vesikaa reads your device’s accelerometer to detect a face-down/face-up gesture. This data is processed live and is never stored, logged, or transmitted off your device.

3.7 Notifications

If you opt in to daily-draw reminders, journal reminders, or Soul House reveal reminders, Vesikaa schedules local notifications on your device. We do not currently send push notifications from our servers.

3.8 Soul House (Social) Data

Soul House is an optional feature that lets a small group of friends share daily readings. If you create or join a Soul House, the following becomes visible to other members of that house:

Soul Houses are joined via invite code only and are capped at six members. Backend-managed Cloud Functions perform house create/join/leave/freeze/share/reveal actions; the invite-code lookup table is not readable by clients.

3.9 Payments and Purchases

When in-app purchases are enabled in a future release (deck purchases, the Practice subscription, the Founders Pass):

If you submit Beta feedback through TestFlight, that feedback is handled by Apple under Apple’s privacy policy.

3.10 Information We Do Not Collect

For clarity, Vesikaa does not:

4. How We Use Your Information

We use the data described above to:

We do not use your data for advertising, profiling for advertising, automated decision-making with legal effects, or training third-party AI models.

5. Journal Encryption (Cloud Backup)

Journal entries are particularly personal, so we treat them differently from the rest of your data.

6. Third-Party Services

We rely on a small number of vendors to operate Vesikaa. Each vendor receives only the data necessary to perform its function and is contractually required to protect that data.

ServiceOperatorPurposeData Shared
Firebase AuthenticationGoogle LLCAccount sign-inEmail, name, provider tokens
Cloud FirestoreGoogle LLCUser data backup, Soul House syncReading metadata, encrypted journal blobs, preferences
Firebase Cloud FunctionsGoogle LLCSoul House create/join/leave logicSoul House mutation payloads
Firebase AnalyticsGoogle LLCUsage analyticsAnonymized event names and parameters
Firebase CrashlyticsGoogle LLCCrash reportingCrash logs, anonymous user ID
SentryFunctional Software, Inc.Error trackingExceptions, breadcrumbs, anonymous user ID
Sign in with AppleApple Inc.Optional sign-inEmail (or private relay), name
Google Sign-InGoogle LLCOptional sign-inEmail, profile, identity token
Cloudflare R2Cloudflare, Inc.Deck art deliveryNone about you; deck binaries only
Apple App StoreApple Inc.In-app purchasesPayment data (handled by Apple)
RevenueCat (planned)RevenueCat, Inc.Receipt validationApp Store transaction identifiers
Google FontsGoogle LLCFont deliveryStandard HTTP request metadata

Each provider operates under its own privacy policy. We encourage you to review them:

7. Data Retention

8. Your Rights and Choices

Depending on where you live, you may have rights under the GDPR (EU/UK), CCPA/CPRA (California), or other privacy laws, including:

You can exercise the access and deletion rights directly inside Vesikaa via Settings → Data → Export Data and Settings → Data → Delete Account. For any other request, contact [email protected] and we will respond within 30 days.

California residents: we do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

9. Security

We protect your data with industry-standard measures:

No system is perfectly secure. We will notify affected users without undue delay if we discover a breach involving their personal data, in accordance with applicable law.

10. Children’s Privacy

Vesikaa is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact [email protected] and we will delete it promptly.

The App Store age rating reflects this audience. Soul House social features should not be used by anyone under 13.

11. International Users

Vesikaa is operated from the United States. If you use Vesikaa from outside the United States, your information will be transferred to and processed in the United States and other countries where our service providers operate. These countries may have different data-protection laws than your country of residence. By using Vesikaa, you consent to this transfer.

Where required by law (including for users in the EU/UK), we rely on appropriate safeguards such as Standard Contractual Clauses for these transfers.

12. Beta Testing (TestFlight)

If you are participating in the Vesikaa beta program through TestFlight, additional information may be visible to Apple under Apple’s TestFlight privacy practices, including your TestFlight email address and any crash reports or screenshots you submit through TestFlight. We may also collect anonymized feedback you send through TestFlight to improve the app. Beta participation is voluntary and can be ended at any time by removing the beta build from your device.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of Vesikaa after a change becomes effective constitutes your acceptance of the updated policy.

14. Contact

For any privacy-related question, request, or complaint:

If you are in the EU/UK and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection authority.