← Back to Vesper

Privacy Policy

Effective date: [to be set on launch] Last updated: [to be set on launch]

Vesper is a tarot reading experience guided by Melissa, designed for reflection on relationships, decisions, and the things on your mind. This policy explains what information we collect when you use vesper.cards, why we collect it, who we share it with, and the choices and rights you have over it.

We have written this in plain language wherever the law lets us. Where a term needs to be precise for legal reasons, we have kept it precise.

1. Who we are

Vesper is operated by [Vesper legal entity — to be completed before launch], a company registered in England and Wales under company number [company number], with a registered office at [registered office address] ("Vesper", "we", "us", "our"). We are the controller of your personal information for the purposes of UK data protection law.

2. Information we collect

Account information

When you sign in with Google, we receive your name and email address from Google via our authentication provider, Supabase. We do not see or store your Google password.

Profile and onboarding information

You provide this directly when you set up Melissa as your guide:

  • The name you would like Melissa to call you
  • Your star sign and date of birth (if you choose to provide it)
  • Your mood, focus area (e.g. love, career, a big decision), relationship status, and what you are hoping a reading will show you
  • Any free-text reflections you write, including custom questions or journal entries
  • Your preferred email check-in time and marketing preference

Your readings and journal

We store the tarot readings Melissa gives you and any reading you choose to save to your journal, so you can come back to them.

Approximate location

We use your IP address, via a service called ipapi.co, to estimate your country so we can show prices in the right currency (£ or $). This is an approximate, country-level estimate, not precise GPS location, and we do not use it to track your movements.

Payment information

Subscription payments are handled entirely by Stripe. We never see or store your full card number, expiry date, or CVC. Stripe holds that information, and we receive only confirmation that a payment succeeded or failed, your subscription status, and limited billing details (such as the last 4 digits of your card, for display in your account, and your billing history).

Product analytics and technical information

We collect information about how you use the app (pages visited, features used, app version, device and browser type) through PostHog and Vercel Analytics. With your consent, this may include session recordings of how you move through the app, with sensitive inputs (such as your reflections and email address) masked. This helps us understand what is working and fix what is not. See the Cookies and analytics section below.

3. How we use it

  • To generate your readings. Your profile, onboarding answers, and any question or reflection you write are sent to our AI provider to generate Melissa's response to you, personally.
  • To run your account. Authentication, saving your journal, remembering your preferences, and showing you the right subscription status.
  • To bill you. Processing your subscription, trial, and renewals through Stripe.
  • To communicate with you. Account and billing emails (transactional, since they are how we tell you about your subscription), and, only if you have opted in, daily reading reminders and other marketing emails.
  • To improve Vesper. Understanding usage patterns so we can fix bugs and build features people actually want.
  • To keep things secure and lawful. Detecting fraud or abuse, complying with legal obligations, and enforcing our Terms of Service.

4. Our legal bases (UK GDPR)

For our UK and EU users, we rely on:

  • Performance of a contract to create your account, generate your readings, and provide the subscription you have signed up for.
  • Consent for marketing emails, session recordings, and any non-essential cookies or analytics. You can withdraw this at any time.
  • Legitimate interests for core product analytics, fraud prevention, and keeping the service secure, where this does not override your own privacy interests.
  • Legal obligation for example, keeping financial records for tax purposes.

5. How Melissa's readings are generated

When Melissa gives you a reading, the relevant parts of your profile (such as your name, star sign, and focus area) and the text of your question or reflection are sent to an AI model, Claude, made by Anthropic, which we access through Amazon Web Services' Bedrock service. This is how Melissa's responses are written.

We do not use your readings, journal entries, or reflections to train AI models, and AWS Bedrock does not use your inputs to train its underlying foundation models.

6. Who we share information with

We do not sell your personal information, and we do not share it with advertisers. We share information only with the service providers ("sub-processors") who help us run Vesper, each bound by a contract limiting what they can do with it:

ProviderWhat forWhat they see
SupabaseAuthentication and database hostingYour account, profile, and journal data
StripePayments and subscription billingYour card details and billing information; we never hold your full card number
AWS Bedrock (Anthropic Claude)Generating your tarot readingsYour profile and the text of your question/reflection, for that request only
PostHogProduct analytics and session recordingUsage, device/browser information, and (with consent) masked session recordings
VercelApp hosting and web analyticsStandard hosting logs and aggregated traffic data
ipapi.coIP to currency detectionYour IP address, for that request only
ResendSending account and marketing emailsYour email address and email content

We may also share information if required by law, to protect the rights, safety, or property of Vesper or others, or in connection with a merger, acquisition, or sale of assets, in which case we would require the new owner to honour this policy.

7. International transfers

Some of our sub-processors store or process information outside the UK, for example in the United States or the EU. Where this happens, we rely on legally recognised safeguards, such as the UK's International Data Transfer Addendum or adequacy regulations, to keep your information protected to UK standards.

8. How long we keep information

  • Account and profile data: for as long as your account is active.
  • Readings and journal entries: until you delete them individually or delete your account.
  • Billing records: retained after account deletion for as long as required by tax and accounting law.
  • Analytics data: typically retained in de-identified or aggregated form after this point.

9. Your rights (UK)

If you are in the UK (or the EU), data protection law gives you the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information ("right to be forgotten")
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time, where we rely on consent
  • Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, though we would appreciate the chance to put things right first

To exercise any of these, use the in-app tools where available (see Deleting your account below) or email us at privacy@vesper.cards.

10. Your rights (US / California)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to know what personal information we have collected about you, request deletion of it, correct inaccurate information, and opt out of the sale or sharing of your personal information.

We do not sell or share your personal information for money or for cross-context behavioural advertising, so there is nothing to opt out of on that front. We extend these same rights, access, deletion, and correction, to all our US users as a matter of practice, not just where California law strictly requires it.

To exercise these rights, use the in-app delete-account tool or email privacy@vesper.cards. We will not discriminate against you for exercising any of these rights.

11. Deleting your account

You can delete your account at any time from your account settings. Doing this will:

  • Cancel any active subscription with Stripe
  • Permanently delete your profile, readings, and journal entries from our database

Some information may be retained for a limited period afterward where we are legally required to (for example, billing records for tax purposes, see How long we keep information above).

12. Marketing emails

We will only send you daily reading reminders or other marketing emails if you have explicitly opted in during onboarding or in your account settings. Every marketing email includes an unsubscribe link, and you can withdraw your consent at any time. This will not affect transactional emails about your account or billing, which we will still need to send you.

13. Cookies and analytics

We use cookies and similar technologies for a few purposes:

  • Strictly necessary keeping you signed in and remembering your session. These do not require consent.
  • Analytics and session recording understanding how Vesper is used (via PostHog and Vercel Analytics), so we can improve it.

Where analytics, session recording, or any other non-essential cookie requires consent under UK law (the Privacy and Electronic Communications Regulations, alongside UK GDPR), we ask for it through a cookie banner before any such cookie is set, with an equally clear option to reject. You can change your choice at any time from the cookie settings in the app.

14. Children

Vesper is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will delete it.

15. Security

We use industry-standard measures to protect your information, including encryption in transit and at rest (provided by our infrastructure providers, Supabase and Vercel), and access controls limiting who at Vesper can view your data. No system is completely secure, and we cannot guarantee absolute security.

16. Changes to this policy

We may update this policy from time to time. If we make material changes, we will let you know, for example by email or an in-app notice, before they take effect. The "last updated" date at the top of this page always reflects the most recent version.

17. Contact us

Questions about this policy, or want to exercise any of your rights? Email us at privacy@vesper.cards.


Entertainment disclaimer. Melissa's readings are created for entertainment and self-reflection. They are not a substitute for professional medical, legal, financial, or psychological advice. See our Terms of Service for the full disclaimer.