Soiree Privacy Policy
Last updated 14 September 2026 — covers "Soiree — Black Cat Tarot" for iOS and Android
"Soiree — Black Cat Tarot" ("the App") is an app in which Soiree, a black cat reader, turns tarot cards and answers your question in writing. This policy explains, in plain language, what the App keeps, where it keeps it, what it sends out, and when it is deleted.
1. The most important points (summary)
- Your question is never stored on the developer's server. It passes through on its way to the reading and is neither written to the database nor printed to logs. It stays on your device. (The one exception is a single piece of text you attach yourself when reporting a reading — see section 6.)
- Readings are written by Claude, an AI made by Anthropic PBC. Each time you draw, your question and a short set of notes made from your past readings are sent to Anthropic. Your question is also sent for the safety check, including when no reading is produced. The App explains this on a screen at first launch and starts only after you agree.
- There is no account. The App never asks for your name, email address, phone number, date of birth, or location.
- There are no ads and no advertising tracking. The advertising machinery is simply not in the App.
- Your journal stays on your device. The developer cannot read it.
- Payments are handled by the App Store and Google Play. The developer never receives your card details.
2. What stays on your device only
The following is stored on your device and is not stored on the developer's server. (For what passes through the server and what it holds, see section 3; for what is sent to the AI, see section 4.)
- Your question, and the reading that comes back (the reading alone is held on the server for up to ten minutes, so it can be delivered again if your connection drops — see section 3)
- Your journal — the cards drawn, upright or reversed, the reading text, any follow-up questions, and the date and time
- The short notes made from past readings (up to five summary cards and one profile note)
- Your Card of the Day and whether reversals are used
Deleting the App removes all of this from your device. Your device or operating system may copy it as part of a general backup, but that is an Apple or Google mechanism; the App does not send any of it to the developer.
3. What the developer's server holds
The server (Cloudflare Workers and D1 — the Cloudflare service that runs the back end, and its database) holds the minimum values needed to count readings and purchases correctly. The main ones are listed below, and none of them includes your name or contact details.
| Stored | What it is | Why it is needed |
|---|---|---|
| Device key | A hash (a value converted so that it cannot be turned back) of a random value the server issues at first launch, plus a key derived from the device attestation (App Attest on iOS, Play Integrity on Android). On Android, the per-app device identifier assigned by the operating system is also used as an ingredient (not the advertising ID). The device model and the advertising ID itself are not used | To recognise this device when it talks to the server (counts, purchases, consent, and safety records are tied to it). It is also the key for counting free draws per device (what you pay for is counted from the purchase instead). As there are no free readings at present, this key counts nothing, though the mechanism is still in place |
| Counts | Readings taken today, and subscription readings taken today (per subscription) | To keep the promise of three readings a day on the subscription, and to stop overuse |
| Purchase root | Transaction identifiers issued by the App Store or Google Play, and the state of your purchases (tickets left, subscription active or not) | To deliver what you paid for, and to avoid granting it twice |
| Consent record | The date and the version of the disclosure you agreed to. It is tied to the device key and contains no name or address | To keep a record that consent was given |
| AI usage | Token counts (the number of chunks of text the AI read and wrote) and the approximate cost, as totals only. No text is included | To keep spending under its limit |
| Safety and audit records | The type and time of events such as consent, a grant, an account deletion, or a spending limit being reached. Not one character of your question or reading is included | To investigate faults and abuse, and to answer enquiries |
A reading is held on the server for at most ten minutes so it can be delivered again if your connection drops, and is then deleted automatically. Nothing older than ten minutes remains.
To prevent abuse, the server also counts requests against your connection's address (IP address) in a hashed form, for a short period. The address itself is not stored.
4. Using a third-party AI for readings
Readings in the App are written by Claude, an AI made by Anthropic PBC, not by a person. Each time you draw, the following is sent to Anthropic:
- The question you typed (including any follow-up question)
- The cards drawn, and whether each is upright or reversed
- Short notes made from your past readings (up to five summary cards and one profile note), which is what lets Soiree say "the Tower came up last month as well"
Not sent: your name, email address, phone number, location, device identifiers, or the full text of your journal.
Your question is also sent for the safety check. The check in section 5 runs in two stages, and the second stage is performed by an AI. Your question therefore reaches Anthropic even when no reading is produced.
- This disclosure appears in four places: the screen at first launch, a permanent notice on the reading screen, the settings screen, and the store listing. No reading begins before you agree. The fact that you agreed is kept separately, as the consent record in section 3.
- You can erase the notes at any time from Settings, under "Clear memory". After that, readings no longer refer back to earlier ones.
- Anthropic handles what it receives under its own policy (anthropic.com/legal/privacy). Anthropic may retain it for a period, for example to check for abuse. Please see that policy for the details.
- The developer uses your question for nothing other than producing your reading, and does not supply it for AI training.
5. Safety messages
If your question contains wording about harming yourself or someone else, the App does not produce a reading and shows a list of helplines instead. That check runs in two stages: a wordlist match on the server, and a check by an AI, and only the fact that it fired is recorded as a count. Your question is not stored in this case either. Purchase prompts are hidden on that screen.
6. Reporting a reading
If a reading is upsetting, you can report it from the reading screen. This meets Google Play's requirement for apps whose core feature is generative AI.
- By default the report does not include the text. Only the reason you selected is sent.
- There is a checkbox to attach the question and the reading. Only when you tick it yourself does the developer receive that one piece of text. This is the single exception to the rule that questions are not stored on the server.
- Attached text is deleted after 90 days; only the fact of the report and its reason remain.
7. Purchases
- Everything is sold as an in-app purchase through the App Store or Google Play. Apple and Google process the payment; the developer never receives card details.
- There is no free trial of the AI readings. Soiree's Tarot Reading is bought as a ticket or on the subscription (the Card of the Day is free every day and uses up nothing). A subscription never starts on its own.
- You can cancel a subscription from your App Store or Google Play account settings. The App's settings screen links straight there.
- "Restore purchases" in Settings brings back your remaining tickets and subscription on a new device. You need to be signed in with the same Apple Account or Google account you bought with.
- Family Sharing and the Google Play family library are not supported. Purchases work on the buying account only, so that draws and entitlements are counted correctly per subscription.
8. Deleting your data
| What you want gone | How | What is deleted |
|---|---|---|
| The memory notes | Settings → Clear memory | Summary cards and the profile note. Later readings stop referring back |
| A journal entry | Delete it in the journal screen | That entry |
| Everything | Settings → Delete account | All data on the device, plus a request to delete the server-side rows |
After you delete your account, the main things the server still keeps are:
- Today's reading count and today's subscription seat count — numbers only. This stops the daily limits from being recreated by deleting and reinstalling. Both disappear after 24 hours. They are only a key and a number: not one character of your question, journal, or reading is included. That "key", however, may contain a transaction identifier issued by the store, because daily counts and subscription seats are counted per subscription.
- A copy of the device key, and its counts. It is the tally for free draws and has no expiry (deleting your account does not remove it). What stays there is the device key itself (section 3) and numbers — no name and no text of yours. As there are no free readings at present, nothing is being counted, though the mechanism is still in place.
- The purchase ledger rows. The value that linked them to you (the device key) is removed, but the rows stay, because they are needed for refunds and to prevent double grants. Restoring purchases from the same account brings your remaining tickets and subscription back on a new device.
- Safety and audit records (section 3), in a form that is not linked to any person.
- The fact that a report was made, and its reason (section 6). Any attached text is deleted.
- The record of several purchases having been joined into one. It is kept in a form that is not linked to any person, so that the joining cannot be undone.
- The date and the spread of each reading, also in a form that is not linked to any person. It contains neither the cards drawn nor your question.
- Cost totals, in a form that is not linked to any person.
If you have an active subscription, please cancel it with Apple or Google before deleting your account. Removing the App does not stop the billing.
9. Who else receives anything
| Party | Role | What reaches them |
|---|---|---|
| Anthropic PBC | Writes the reading | Your question, the cards drawn, and the short memory notes (section 4) |
| Cloudflare, Inc. | Server and database | The values in section 3, and traffic in transit (questions are not stored) |
| Apple (App Store) | Distribution, payments, device attestation | Whether a purchase exists, and its transaction identifier (payment stays inside Apple) |
| Google (Google Play) | Distribution, payments, device attestation | Whether a purchase exists, and its purchase token (payment stays inside Google) |
All four are companies headquartered in the United States, so the information above goes to recipients outside Japan. Nothing is provided or sold to anyone else. No advertising or analytics company receives anything, because none is built into the App. See the policies of Anthropic, Cloudflare, Apple, and Google.
10. Age rating
The App is rated 13+. It is not intended for children under 13, and no information is collected from them.
Users aged 13 to 17 should go through this page with a parent or guardian.
11. What a reading is
Readings are text written by an AI, based on traditional ways of reading tarot. They do not predict future events. The App gives no medical, legal, or financial advice. For anything concerning your health, money, or legal position, please consult a professional.
12. If you need someone to talk to
These helplines operate in Japan. Numbers were checked against their official sites on 13 September 2026.
- Yorisoi Hotline 0120-279-338 (from Fukushima Prefecture, 0120-279-226) — 24 hours
- #Inochi SOS 0120-061-338 — 24 hours, every day
- Inochi no Denwa (toll free) 0120-783-556 — daily 16:00–21:00; on the 10th of each month, 8:00 to 8:00 the next morning
- Childline (up to age 18) 0120-99-7777 — daily 16:00–21:00, closed 29 December to 3 January
- DV Consultation Plus (DV Soudan Plus) 0120-279-889 — phone line open 24 hours
- 24-hour Children's SOS Line 0120-0-78310 — 24 hours
- For a sudden medical emergency, call 119. At night, or when it feels like an overreaction, it is still fine to call.
13. Changes to this policy
This policy may be revised as the App changes. Significant changes will be announced through an App update and by changing the "last updated" date on this page. If a change would add a recipient or add to what is sent, this policy is updated first, and consent is requested again where needed.
14. Contact
- Provider: Takuto (independent developer)
- Email: iguchi.apps@gmail.com
- For the rules of use, see the Soiree terms of use.
- For how to use the App, see Soiree Support.