ManTarot
Privacy Policy
How ManTarot collects, uses, retains and deletes data across the public website, Android app and ManTarot Live.
Last updated: August 2, 2026
Index
- Controller and contact
- Scope and principles
- Account, authentication, profile and preferences
- Readings, questions and history
- Artificial intelligence and possible errors
- ManTarot Live, microphone and temporary audio
- Transcripts, responses and memory
- Purchases, subscriptions and Google Play Billing
- AdMob, FCM, installation and device
- Sharing and temporary files
- Admin, audit, logs and backups
- Providers and international transfers
- Retention
- Access, correction, export and deletion
- Minors and security
- Cookies, changes and contact
Controller and contact
ManTarot is a product developed by /dev.ursus. The controller responsible for personal data processing is Gabriel Andrés Di Martino, Argentina. Contact: privacy@mantarot.app.
This policy covers the public website, Android application, ManTarot Live, account services, commercial features, transactional communications and the infrastructure required to operate ManTarot.
Scope and principles
We process data only to provide the features selected by the user, maintain security, manage the account and meet applicable obligations. We apply data minimization, purpose limitation, user control, justified retention and separation between content, history, memory and audit records.
We do not sell personal data. We do not use private user content as public material, and Admin personnel may not copy personal content unless strictly necessary for security, investigation or compliance.
Account, authentication, profile and preferences
We may process Firebase UID, email address, authentication provider and status, email verification, preferred name, country, language, time zone, plan, account status, selected deck and experience or notification preferences.
Firebase Authentication manages technical identity. ManTarot's own backend stores operational account and product information. Users should keep the information needed to access and recover their account accurate.
Readings, questions and history
To generate and restore readings, we may process questions, written context, spread type, cards, orientation, positions, deck, interpretations, advice, deeper readings, dates, execution identifiers and exact history snapshots.
History may exist in the backend and, where applicable, in local app storage. Saved readings are not regenerated when reopened; they retain the result and context that were recorded.
Artificial intelligence and possible errors
AI-assisted features run through the ManTarot backend and technical providers. To generate a response, the question, context, cards, orientation, language and minimum required instructions may be sent to a provider; the app does not contact providers directly.
Automated responses may contain errors, omissions, bias or inaccurate interpretations. ManTarot is an entertainment and reflection experience; its responses do not replace medical, psychological, legal, financial or other professional advice.
ManTarot Live, microphone and temporary audio
ManTarot Live requires microphone permission when a user chooses to start a voice conversation. Input and output audio are transmitted and processed temporarily during the session to listen, transcribe and respond.
ManTarot does not store ManTarot Live audio. Audio is processed temporarily during the session. Transcripts and responses may be retained as part of history until the user deletes them.
Transcripts, responses and memory
A Live session may retain transcripts, responses, cards, order, orientation, context, summary, final status, duration and technical metadata required for continuity, history, cost control and incident resolution.
Structured memory is separate from history. Memory retains facts or relationships useful for continuity between sessions; history retains consultations and results. Deleting memory does not automatically delete history, and deleting history does not automatically delete memory.
Purchases, subscriptions and Google Play Billing
Google Play Billing processes purchases, subscriptions, renewals, cancellations and refunds. ManTarot receives identifiers and technical or commercial status needed to validate Premium, one-off purchases, credits, entitlements, prices and reconciliation.
ManTarot does not receive the full payment card number. Minimum commercial records may be retained in de-identified form when necessary for legal or accounting obligations, fraud prevention or dispute resolution.
AdMob, FCM, installation and device
The free plan may include Google AdMob advertising, including rewarded ads. Google and its SDKs may process advertising identifiers, device signals and interaction data according to the applicable configuration and their own policies.
For notifications and security, we may process an FCM token, installation identifier, Firebase Installation ID, platform, device model, operating system and app version, language, permissions, time zone and minimum delivery or compatibility diagnostics.
Sharing and temporary files
When a user chooses to share a card or reading, the app may create a temporary raster file and pass it through the system chooser to the app selected by the user. ManTarot does not choose the final destination or control that app's later processing.
Temporary files should be limited to the time needed to create and complete the sharing action. Users are responsible for reviewing content and recipients before sending.
Admin, audit, logs and backups
Admin access is restricted by authentication, roles and operational controls. Audit records may include actor, action, date, status, reason and technical identifiers, but should not duplicate questions, transcripts, production prompts or unnecessary personal content.
Logs and backups may retain technical metadata or copies for limited windows for security, diagnostics and recovery. Deletion may complete first in active systems and reach backups through their secure rotation cycle without reintroducing deleted data into production.
Providers and international transfers
We use providers for authentication, messaging, purchases, advertising, AI, Realtime processing, infrastructure and service delivery. These may include Google Firebase, FCM, Google Play, AdMob and AI or voice providers enabled by ManTarot.
These services may process data outside Argentina. We seek to limit information to what each function requires and apply contracts, technical controls and security measures proportionate to the processing risk.
Retention
Personal data will be retained only for as long as necessary to provide the ManTarot features used by the user, maintain the account and meet duly justified legal or security obligations.
The specific period depends on the data type, enabled feature, account life, user requests, abuse prevention, commercial obligations and backup cycles. Content is not retained indefinitely without a documented purpose.
Access, correction, export and deletion
Users may request information, access, correction, updating, export or partial or total deletion. They may manage profile data, readings and history, Live sessions and transcripts, memory, all content while keeping the account, or the entire account.
Account deletion includes profile, operational name and email, readings, deeper readings, history, Live, transcripts, responses, memory, tokens, installations, Firebase Authentication and other personal content, except minimum records that must legally be retained. The web flow verifies identity and does not disclose whether an email exists.
Minors and security
ManTarot is intended exclusively for people aged 18 or older. If we detect an account belonging to a minor, we may restrict it and delete its data in accordance with applicable obligations.
We use HTTPS, access controls, service separation, protected credentials, hashed single-use verification tokens, rate limits, auditing and minimization. No system can guarantee absolute security; we will investigate and mitigate incidents according to their impact.
Cookies, changes and contact
The public website does not use its own advertising cookies. It may use local storage to remember language, and reCAPTCHA may use cookies or technical signals needed to prevent abuse. The app and AdMob use device identifiers according to enabled features.
We will publish material changes on this page and update the effective date. To exercise rights or ask a question, write to privacy@mantarot.app. Argentina's data protection authority is the Agency for Access to Public Information.