PRIVACY POLICY

Last updated: September 2026

DATA CONTROLLER

Lucis Occulta is operated by and the data controller is:
Giulia Azzini
1 Rue de L'Encheval
75019 Paris
France
SIRET: 97830753600018

Privacy contact: cosmic.paper.archive@gmail.com

PURPOSE OF THIS POLICY

This Privacy Policy explains how personal data is processed when you visit lucisocculta.com, purchase a Personal Reading or Gift a Reading, receive or redeem a Gift, submit a tarot question, receive a generated Reading, contact Lucis Occulta or interact with a transactional email.

PERSONAL DATA COLLECTED

For a Personal Reading, the service may process an email address where required by the purchase or communication flow, your tarot question, the cards drawn and their orientations, the generated interpretation, payment and checkout identifiers, private entitlement or access identifiers, timestamps and technical status information.

For Gift a Reading, the service may process purchaser information required by checkout, the recipient’s email address, an optional sender name and personal message, a private Gift or access token, redemption status, the recipient’s tarot question, the recipient’s cards and orientations, and the generated interpretation.

If you contact Lucis Occulta, the service processes your email address, the content of the communication and any information you voluntarily provide.

Technical data is limited to information needed to operate, secure and diagnose the service, such as request and error information, payment state, service status, timestamps and private entitlement state. Lucis Occulta does not currently operate an advertising or behavioural analytics system.

PAYMENTS — STRIPE

Payments are processed by Stripe. Lucis Occulta does not receive or store complete payment-card details. The application retains transaction-related identifiers where needed to verify successful payment, create Reading or Gift entitlements, prevent duplicate processing, recover payment state and maintain appropriate transaction records.

Stripe acts as an independent payment service provider and, where applicable, a processor of payment-related information. You can read Stripe’s Privacy Policy. No third-party tracking script is embedded for this purpose.

PERSONAL READING

Your question, the selected cards and related information are processed to provide the purchased Personal Reading, generate its interpretation, allow the completed Reading to be reopened through its private access link, provide technical support or recovery, and prevent abuse or unauthorized repeated generation.

GIFT A READING

The recipient’s email address is used to deliver the private Gift invitation and allow the recipient to access the prepaid Reading. An optional sender name and personal message are used only to personalize that Gift email.

The recipient’s tarot question and completed Reading are private. They are not disclosed to the purchaser merely because that person bought the Gift.

The recipient’s email address was provided by the person purchasing Gift a Reading. Privacy information is made available when the recipient is first contacted through the Gift email, and the recipient may exercise the applicable GDPR rights described below.

OPENAI AND AI-ASSISTED PROCESSING

Lucis Occulta uses the OpenAI API to generate or assist the interpretive content of a Reading. For this purpose, relevant content is transmitted to OpenAI, including the tarot question, the selected cards, card orientations and relevant interpretive instructions or context.

OpenAI states that API and business data is not used to train its models by default. Lucis Occulta does not claim Zero Data Retention. OpenAI may retain API input and output for a limited period for service delivery and abuse monitoring in accordance with its applicable privacy and API data-retention policies.

TRANSACTIONAL EMAIL — RESEND

Resend is used to send transactional email, including Gift a Reading invitations, Personal Reading purchase or confirmation emails where enabled, and other service-related communications. Data sent to Resend may include the recipient email address, optional sender name and message, a private Gift access URL or token where needed for delivery, and transaction or service information required to compose the email.

The recipient’s tarot question and completed interpretation are not sent to the Gift purchaser. Resend states that service data may be stored in the United States and that its Data Processing Addendum provides safeguards for transfers from the EEA, including applicable Standard Contractual Clauses. See Resend’s Privacy Policy.

CLOUDFLARE AND D1

Cloudflare provides website and infrastructure services. Cloudflare D1 is used as production persistence for Reading and Gift data. Depending on the service state, D1 stores the minimum information required to operate it, including Reading and payment identifiers, entitlement status, a private access token, purchaser or recipient email, optional Gift sender name and message, redemption and completion timestamps, the selected spread and orientations, the tarot question and the completed interpretation.

The question and interpretation are retained so the user can reopen the completed Reading through the existing private access link without regenerating it. D1 does not store payment-card information, Stripe secrets, Resend secrets or OpenAI API secrets. See Cloudflare’s Privacy Policy.

PURPOSES AND LEGAL BASES

Processing needed to purchase and provide a Personal Reading, purchase and deliver Gift a Reading, verify payment, generate the purchased service and reopen it is based on performance of a contract or steps taken before entering into a contract.

Transaction information that must be kept for accounting, tax, consumer-protection or other legal requirements is processed to comply with a legal obligation.

Service security, fraud and abuse prevention, technical reliability, and protection against duplicate or unauthorized entitlement use may be based on Lucis Occulta’s legitimate interests, balanced against the rights of the people concerned.

Consent is used only where a particular activity genuinely relies on consent. The consumer-law request for immediate performance of a digital service and acknowledgement concerning withdrawal rights is not treated as GDPR consent.

REQUIRED AND OPTIONAL INFORMATION

Information needed to complete payment and provide the service is required. Without a tarot question, a personalized Reading cannot be generated. Without a recipient email address, Gift a Reading cannot be delivered. A Gift sender name and personal message are optional.

DATA RETENTION

Completed Personal and Gift Readings are retained for 12 months from the Reading completion date. During that period, the tarot question, generated interpretation, drawn cards and orientations, private access token, and Reading status or completion information may be retained so the completed Reading can be reopened. After 12 months, private access expires and the Reading content is deleted or irreversibly anonymized as appropriate.

An unused or unredeemed Gift a Reading entitlement expires 12 months after purchase. After expiry, the Gift cannot be redeemed and its private token no longer authorizes generation. Unnecessary Gift personal data is removed in accordance with this schedule.

Operational Reading and Gift entitlement information is normally retained for up to 12 months where needed for service delivery, entitlement recovery, duplicate-payment prevention, technical support, and fraud or abuse prevention. Private tokens remain valid only for the associated Reading’s 12-month accessibility period.

Support communications are normally retained for 12 months after the enquiry is closed. They may be kept longer where necessary to comply with a legal obligation, handle a dispute, or establish, exercise or defend legal claims.

Payment, accounting and transaction records may be retained for longer where applicable tax, accounting, consumer-protection or other legal obligations require it. Expiry of Reading content does not require the premature deletion of those separate records.

DATA RECIPIENTS

Personal data is shared only as needed with relevant service providers: Stripe for payment processing, Resend for transactional email, OpenAI for AI-assisted Reading generation, and Cloudflare for hosting, infrastructure and D1 persistence. Personal data is not sold.

INTERNATIONAL DATA TRANSFERS

Some service providers may process personal data outside the European Economic Area. Where applicable, transfers rely on safeguards made available by the relevant provider, such as adequacy decisions, the EU–U.S. Data Privacy Framework where applicable, Standard Contractual Clauses or other lawful transfer mechanisms. Lucis Occulta does not claim that all data remains exclusively in France or the European Union.

COOKIES AND FUNCTIONAL STORAGE

The site currently uses first-party localStorage and sessionStorage for functional purposes, including theme preference, cart state, the current tarot draw, temporary checkout state and preservation of a Reading question during the service flow.

No Google Analytics, Meta Pixel, Mixpanel, Segment, PostHog or equivalent advertising or analytics tracking system is currently implemented, and no non-essential marketing-cookie system is currently used. A consent banner is therefore not displayed solely for essential functional storage. This position must be reassessed if analytics, advertising trackers, embedded third-party media or other non-essential tracking technologies are introduced.

AI-GENERATED CONTENT

Artificial intelligence is used to generate the interpretive content of a Reading. The Reading is provided for personal reflection and entertainment. It does not make legal or similarly significant automated decisions about you and does not determine your legal rights.

SECURITY

Lucis Occulta uses reasonable technical and organizational safeguards appropriate to the service. These include encrypted transport in production, server-side payment verification, private unpredictable access tokens, single-use Gift generation entitlements, restricted server-side credentials and access controls. No online service can guarantee absolute security.

PRIVATE LINKS

Private Reading and Gift URLs should be treated as confidential. They are excluded from the public sitemap and are protected from search indexing through robots and noindex controls. Private identifiers are not intended for public pages or analytics event names.

YOUR GDPR RIGHTS

Subject to the conditions of applicable law, you may request access to your personal data, rectification, erasure, restriction of processing, portability, or object to processing. Where processing genuinely relies on consent, you may withdraw that consent without affecting processing already carried out lawfully.

Requests may be sent to cosmic.paper.archive@gmail.com. Reasonable identity verification may be requested where necessary to protect personal data.

COMPLAINTS

You may lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL). Visit the official CNIL website.

CHILDREN

The service is not intentionally designed to collect personal data from children. If you believe a child has provided personal data through the service, contact Lucis Occulta so the situation can be reviewed and appropriate action taken.

CHANGES TO THIS POLICY

Material changes will be reflected by updating this policy and its “Last updated” date. Additional notice will be provided where required by law.

PRIVACY CONTACT

No Data Protection Officer has been appointed. For privacy enquiries, contact cosmic.paper.archive@gmail.com.

Last updated: September 2026