Contents
1. Introduction
Thoth: The Unknown ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application Thoth: The Unknown (the "App").
By downloading, installing, or using Thoth: The Unknown, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our App.
2. Information We Collect
2.1 Account & Authentication
To use Thoth: The Unknown, you must create an account. We collect the following:
- Email address — used to send you a magic link for sign-in; stored in our backend.
- Apple ID credential — if you choose "Sign in with Apple," we receive your anonymised Apple user ID and, optionally, your name. Apple may provide a relay email address.
We do not collect passwords.
2.2 Profile Information
During account setup you may provide:
- Display name (optional) — a nickname shown only to you within the App.
- Date of birth (required) — used to personalise tarot interpretations and to verify you meet the minimum age requirement (18+). Not shared with third parties.
- Time of birth (optional) — used for natal chart context in interpretations.
- Place of birth (optional) — free-text field; used for natal chart context in interpretations.
2.3 Reading Data
We store the following reading-related data in our cloud backend to enable multi-device access and history:
- Cards drawn during readings
- Spreads used (any of the app's eleven spread types)
- Your intention or question text for a reading (optional)
- Dates and times of readings
- Personal reflections or notes added to readings (optional)
- Favourite status of readings
2.4 Device Information (Automatic)
- Device model and type
- Operating system version
- App crash logs and performance data (only if enabled in your iOS Settings → Privacy → Analytics)
2.5 Advertising Data (Rewarded Ads — Free Tier Only)
Free-tier users may optionally choose to watch a rewarded video ad to earn a free credit. Rewarded video is the only form of advertising in the App — there are no banner or interstitial ads. If, and only if, you tap "Watch an ad for +1 credit," our advertising provider, Google AdMob, may collect:
- Device identifiers (including the Identifier for Advertisers, IDFA, only if you grant permission via the iOS App Tracking Transparency prompt)
- Coarse device and advertising data (ad interaction, IP address, general device information)
- Crash and performance data related to ad delivery
You are always asked for consent first: users in the EEA/UK are shown a Google-provided consent form (UMP), and all users are shown Apple's App Tracking Transparency prompt before any advertising identifier is used. If you decline, ads are served non-personalised or not at all, and the rest of the App is unaffected. Users who never tap the "watch an ad" button share no advertising data.
3. How We Use Your Information
We use the information we collect to:
- Authenticate you and maintain your session securely across devices
- Provide and personalise the App — deliver readings, personalise interpretations, and maintain reading history
- Generate AI interpretations — send your drawn cards, their positions, and optional intention/profile context to our AI provider to produce a reading (see Section 5.2)
- Process purchases — enable Pro subscriptions and credit packs and reconcile your entitlements (see Section 5.5)
- Serve optional rewarded ads — only if you choose to watch one to earn a credit (see Section 5.4)
- Improve the App — fix bugs, optimise performance, and develop new features
- Provide technical support — troubleshoot issues and respond to requests
- Comply with legal obligations — including age verification
We do not sell your personal data, serve banner or interstitial ads, or carry out behavioural tracking you have not consented to via the App Tracking Transparency prompt.
4. Data Storage & Security
4.1 Cloud Storage
Your account data, profile, and reading history are stored in our cloud backend operated by Supabase (see Section 5). Data is hosted in the eu-central-1 (Frankfurt, Germany) region. Reading data is also cached locally on your device for offline access.
4.2 Security Measures
- Authentication tokens are stored in the iOS Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly— they do not sync to iCloud. - All data in transit is encrypted via TLS (HTTPS).
- Row-Level Security (RLS) policies ensure each user can access only their own data.
- Sign in with Apple nonces are generated using
SecRandomCopyBytesand hashed with SHA-256.
4.3 Data Retention
- Active account: Your data is retained for as long as your account is active.
- Account deletion: All personal data is permanently deleted from our servers within 30 days of deletion. Authentication records are removed immediately.
- Device cache: Local cache is wiped immediately when you delete your account or sign out.
5. Third-Party Services
5.1 Analytics & Crash Reporting
We do not use third-party analytics services (e.g., Google Analytics, Firebase, Crashlytics). If you enable Crash Reporting in iOS Settings → Privacy → Analytics, Apple may collect anonymised crash logs. This is entirely optional and controlled by your iOS settings.
5.2 AI Interpretation
The App uses AI to generate written interpretations of your readings. When you request an interpretation, we send the cards you drew, their positions in the spread, the spread type, and (if you provided them) your intention/question and limited profile context to an AI provider, which returns the reading text. This request is routed through our Supabase backend (see Section 5.3).
We use Google Gemini (Google LLC) as the default AI provider. Depending on configuration, Anthropic Claude (Anthropic PBC) may be used as an alternative provider. We transmit only the data needed to produce the interpretation; we do not send your email or authentication credentials. These providers process the data to return a response and, per their terms, do not use App data submitted through their APIs to train their models.
| Provider | Purpose | Privacy policy |
|---|---|---|
| Google LLC (Gemini API) | Default AI interpretation provider | policies.google.com/privacy |
| Anthropic PBC (Claude API) | Alternative AI interpretation provider | anthropic.com/legal/privacy |
5.3 Sub-Processor: Supabase
| Attribute | Value |
|---|---|
| Provider | Supabase Inc. |
| Purpose | Authentication, database (profile + readings), account management, AI request routing |
| Data hosted | eu-central-1 (Frankfurt, Germany) |
| Privacy policy | supabase.com/privacy |
5.4 Advertising Provider: Google AdMob
We use Google AdMob (Google LLC) to serve optional rewarded video ads to free-tier users. AdMob is only invoked if you tap "Watch an ad for +1 credit"; it is never loaded otherwise. See Section 2.5 for the data involved and the consent prompts shown first.
| Attribute | Value |
|---|---|
| Provider | Google LLC (AdMob) |
| Purpose | Serving optional rewarded video ads (free tier only) |
| Data collected | Device/advertising identifiers, IP address, ad-interaction and coarse device data (see Section 2.5) |
| Consent | EEA/UK consent form (UMP) + Apple App Tracking Transparency prompt, both shown before any ad |
| Privacy policy | policies.google.com/privacy |
5.5 Purchases: RevenueCat & Apple
Pro subscriptions and credit packs are sold as Apple In-App Purchases and billed through your Apple ID; payment details are handled by Apple and are never seen by us. We use RevenueCat, Inc. to manage entitlements and validate purchases. RevenueCat receives your anonymised app user ID and purchase/transaction metadata (product purchased, purchase and expiry dates) — not your name, email, or payment card.
| Attribute | Value |
|---|---|
| Provider | RevenueCat, Inc. |
| Purpose | Subscription & in-app purchase management and validation |
| Data collected | Anonymised app user ID, purchase/transaction metadata |
| Privacy policy | revenuecat.com/privacy |
6. User Rights & Controls
6.1 Access Your Data
You can access all your reading data at any time through the App's Reading History feature.
6.2 Delete Your Account
You can permanently delete your account directly within the App:
Settings → Account → Delete My Account
This immediately revokes your session, permanently deletes your profile and all readings within 30 days, and wipes your local cache immediately. This action is irreversible. Alternatively, email privacy@codewavemobile.com to request deletion.
6.3 Correct or Update Your Data
Update your display name, birth date, birth time, and birth place at any time via Settings → Profile.
6.4 Data Portability
Export functionality is not yet available in the App. To request a copy of your data in a portable format, contact us at privacy@codewavemobile.com.
6.5 Opt-Out
- Advertising & tracking: Rewarded ads are always optional — simply never tap "Watch an ad for +1 credit" and no ad data is collected. You can also revoke the App Tracking Transparency permission any time via Settings → Privacy & Security → Tracking.
- Crash Reporting: Disable in Settings → Privacy → Analytics
- Location Services: Thoth: The Unknown does not request location access
7. Age Requirement
Thoth: The Unknown is designed for users aged 18 and over.
We do not knowingly collect personal information from users under 18. The App enforces an age gate during account setup — a valid date of birth confirming the user is 18 or older is required to create an account.
If we become aware that a user under 18 has created an account, we will delete that account and all associated data without notice. Parents or guardians who believe a minor has created an account should contact us immediately at privacy@codewavemobile.com.
8. Your Privacy Rights by Region
Turkey — KVKK
- Know whether your data is processed
- Request information about purpose and use
- Request correction of inaccurate data
- Request deletion or destruction of your data
- Object to processing
Europe — GDPR
- Access your personal data
- Rectify inaccurate data
- Right to erasure ("right to be forgotten")
- Restrict processing
- Data portability
- Lodge a complaint with your local DPA
California — CCPA/CPRA
- Know what personal information is collected
- Know if data is sold or disclosed
- Delete personal information
- Opt-out of sale/sharing
We do not sell your data.
To exercise any of these rights, contact us at privacy@codewavemobile.com. We will respond within 30 days.
9. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by updating the "Last Updated" date, posting the revised policy within the App, and requesting explicit consent if changes materially alter how we handle your data.
Your continued use of the App after changes become effective constitutes your acceptance of the updated Privacy Policy.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
- Email: privacy@codewavemobile.com
- Mailing Address: Thoth: The Unknown Support, Istanbul, Turkey
We will respond to privacy requests within 30 days.