This is a courtesy translation of the Spanish-language policy that governs the service. The data controller, applicable law and jurisdiction are Spanish; see the Spanish version for the original text.
1. Data controller
Controller: MUÑOZ RODRIGUEZ ARMANDO HORACIO LUIS.
Tax ID (NIF/CIF): X6668908N.
Registered/tax address: Av. Europa 195, 4º 1ª, 08907 L'Hospitalet de Llobregat, Barcelona, Spain.
Service: Oráculo (operated under the domain tutarotenlinea.es).
Legal and privacy contact: tutarotistavirtual@gmail.com.
Data Protection Officer: not appointed, as it is not mandatory for this activity at the date of this policy.
2. Purposes and data processed
Account management: email and Google ID to identify the user, sign in and link credits.
Providing the consultation: session UUID, text messages, technical voice events, cards drawn and session metadata.
Audio processing: audio sent in real time to the Google Gemini Live API for transcription, understanding and spoken response. We do not store audio recordings on our servers.
Payments and credits: customer email, order identifier, pack purchased, amount, currency, payment/refund status and credits assigned.
Security and abuse prevention: session duration, estimated cost, technical errors, usage limits and minimal logs to protect the service.
Support: data the user voluntarily provides by email to resolve issues or refunds.
Publishing testimonials (optional): if you choose to leave a review, we process the alias you pick, your rating and the text in order to publish them on the reviews page after moderation. We never publish your email or contact details.
3. Legal basis
Performance of a contract or pre-contractual steps: account, credits, tarot sessions, support and refunds.
Legal obligation: keeping proof of purchase, tax information and handling legal rights requests.
Consent: where required for non-essential processing, including the publication of testimonials (Art. 6.1.a GDPR). You can withdraw it at any time by writing to the contact address and we will remove the published testimonial. We currently do not use behavioral advertising or marketing cookies.
4. Recipients and processors
Google LLC / Google Ireland Ltd. — Google Identity Services for sign-in and the Gemini Live API for voice and AI processing. Google's policy.
Stripe Inc. — checkout and payment processing. If Stripe Tax or Stripe Managed Payments is enabled, it may also handle tax calculation/management depending on the configuration in use. Stripe's policy.
LemonSqueezy Inc. (legacy) — previous payment processor, kept as optional for compatibility.
Railway Corp. or an equivalent hosting provider — hosting for backend, database and static files.
Sentry or another monitoring provider — only if configured, for technical errors and performance, avoiding sending secrets or unnecessary content.
Resend — only if configured, to email you the text summary of your paid voice sessions (the same summary stored in your account). No audio is sent or stored.
Google Analytics 4 — only if configured and you expressly accept the analytics category in cookie preferences. It measures pages visited and basic usage-funnel steps; it does not receive questions, emails or the content of your consultations. Google's policy.
Public authorities, courts or competent bodies — only where there is a legal obligation to do so.
5. Source of the data
Data comes from the user directly, from the Google account used to sign in, from Stripe when a payment is
completed, and from technical logs generated by normal use of the service.
6. International transfers
Some providers may process data outside the European Economic Area. When this happens, we use mechanisms
recognized under the GDPR, such as adequacy decisions, the EU-U.S. Data Privacy Framework where applicable,
or Standard Contractual Clauses approved by the European Commission.
7. Retention periods
User account: while the account is active and up to 12 months after last use, unless a legal obligation or a valid deletion request applies.
Purchases and refunds: for the applicable tax, accounting and claims-defense periods.
Technical logs and session metrics: up to 12 months, unless investigating abuse, fraud or a security incident.
Audio: processed in real time; not kept as a recording on our servers.
Support requests: for as long as needed to resolve the request and document the response.
8. User rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and
portability by writing to tutarotistavirtual@gmail.com.
To protect your account we may ask for reasonable information to verify your identity.
Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness
of processing carried out before the withdrawal.
If you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data
Protection Agency (Agencia Española de Protección de Datos): www.aepd.es.
9. Automated decisions
We do not make automated decisions with legal effects or similarly significant effects on the user. AI
responses and tarot readings are for entertainment and symbolic reflection, not professional, financial,
healthcare, legal or credit-related evaluation.
10. Minimal local storage
We store in localStorage an anonymous technical browser identifier, your cookie selection, and the
temporary state of the daily free-consultation limit. The session token is stored in sessionStorage,
is removed when you close the tab, and we do not store your email, consultation history, payment data
or a persistent credit counter there. We do not use advertising profiles, remarketing or behavioral
advertising. Google Analytics 4 is optional and remains blocked until you expressly accept the analytics
category. See the Cookie Policy.
11. Security measures
Google authentication and our own session token.
WebSocket protected by authentication and credit checks when a production database is present.
Input validation, text limits and a time limit for voice consultations.
Security headers, restricted CORS in production and disabled debug endpoints.
Data minimization in the browser and cleanup of legacy local keys.
12. Minors
The service is intended for people over 18 years old. If we detect an account belonging to a minor, we may
block it and delete data not subject to legal retention requirements.
13. Changes to this policy
This policy may be updated to reflect legal, technical or provider changes. The update date shown at the
top indicates the version in force.