Privacy notice
Effective September 21, 2026 · Version 2026-09-21-ouro-2
What is saved
OURO saves your question, the three reading angles, actual cards and orientations, discussion and generated text so your reading survives a refresh. A secure browser session identifies your saved readings without a login screen. If you choose email recovery, we save your verified email and link it to your readings and purchases. Submitted text is not anonymous to the service. Avoid full names, contact details, account numbers and identifying information about other people.
AI processing
Your question, relevant reading context and generated responses are sent to OpenAI for generation and safety checks. We send a secret-derived anonymous session identifier for provider safety monitoring, not your email or raw IP address. We request that responses are not stored as application state in the Responses API. This does not eliminate provider security or abuse-monitoring retention. OpenAI does not train on API inputs or outputs by default; account sharing settings and applicable provider terms govern exceptions. The local demo uses sample responses and sends no AI requests.
Hosting, email and payments
The configured hosting and database providers process reading data to operate the service. Railway is the intended production host; the test build can run locally. If you request email recovery, a transactional email provider processes the address and recovery link to deliver it. Stripe processes payment details on its hosted checkout. We store payment references and reading access, not full payment-card details.
Usage and abuse prevention
We record funnel events and safety decision categories/versions with opaque reading IDs and source labels, never question or chat text in these event logs. Rejected generated responses are not saved in your reading. Safety categories may themselves reveal sensitive information; they are kept with the same access protections as saved reading data. We use a secret-derived IP identifier for temporary rate limits, not raw IP addresses in these counters. Hosting and authentication systems may separately keep technical access data. Counters are removed after their expiration and cleanup delay. Browser sessions can last up to 90 days and may renew while used.
Human checks
When repeated anonymous session creation suggests abuse, OURO may use Cloudflare Turnstile to check that a visitor is human. The server verifies the challenge before issuing another session. Cloudflare may process browser and network signals for this check under its own privacy terms; normal reading use does not require a challenge.
Agreement record
We store the policy version, time and your confirmation that you are at least 18 when you accept the Terms. This acknowledgment does not collect a date of birth and is an age declaration, not identity verification.
Sharing and advertising
Reading pages require your session. Saving or sharing an image is your choice, and your personal question is excluded unless you choose to include it. Check the image before sharing it. The current app does not sell your submitted text, use it for targeted ads, or load advertising pixels.
Retention and requests
Saved readings, discussion, agreement records and payment references currently remain in the service until removed by the operator. This version does not implement automatic 30-day or self-service deletion. Clearing cookies does not delete server records. Before you link a verified email, clearing cookies can remove your access; afterward you can request an email sign-in link to recover it. Contact support for access, correction or deletion requests. We may need proportionate verification and may retain records that applicable law requires.
Changes
We will update this notice before materially changing these practices and obtain consent where required. The applicable Terms and disclosure version is shown below; updates can require another acknowledgment.
For support, a refund request or a privacy request, email support@ouro.cards.