Brutal Tarot

Trust & privacy

Brutal honesty includes being honest about how this works.

What we collect

Your name, age, gender, email, timezone, the questions you ask, and the readings we generate for you. Optionally your birth date, if you add it to enrich readings. That's the working material of a personal reading — nothing more.

Payments

Billing runs entirely through Whop, our merchant of record. Your card details go to Whop's PCI-compliant checkout and never touch our servers or our database. Plan changes, card updates, and cancellation happen in Whop's self-serve portal.

Private reading links

Every reading lives behind a private link containing a long random access token. Links are yours alone, work without a password, and can be revisited any time. We never expose readings by ID — no token, no reading.

Email

Readings and daily cards are delivered by Resend from our verified notifications subdomain. We record delivery and engagement events (delivered, opened, clicked) to make sure readings actually arrive. Every daily-card email has a one-click opt-out.

Where your data lives

Application data is stored in Supabase (Postgres) with row-level security: your rows are readable by you and by no other member. Readings are composed by our reading engine, which runs on infrastructure from Anthropic; your question and profile context are processed there under Anthropic's API data policies and are never used to identify you publicly.

Retention & deletion

Your readings and journal stay in your archive for as long as you keep your account. To delete your account and everything in it, email contact@brutaltruthtarot.com from your account address — we complete deletion requests within 30 days.

Security contact

Found something that worries you? Write to contact@brutaltruthtarot.com — security reports go to the top of the pile.