Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Data Storage & Security
  5. Third-Party Services
  6. User Rights & Controls
  7. Age Requirement
  8. Your Privacy Rights by Region
  9. Changes to This Policy
  10. Contact Us

1. Introduction

Thoth: The Unknown ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application Thoth: The Unknown (the "App").

By downloading, installing, or using Thoth: The Unknown, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with our policies and practices, please do not use our App.

2. Information We Collect

2.1 Account & Authentication

To use Thoth: The Unknown, you must create an account. We collect the following:

We do not collect passwords.

2.2 Profile Information

During account setup you may provide:

2.3 Reading Data

We store the following reading-related data in our cloud backend to enable multi-device access and history:

2.4 Device Information (Automatic)

2.5 Advertising Data (Rewarded Ads — Free Tier Only)

Free-tier users may optionally choose to watch a rewarded video ad to earn a free credit. Rewarded video is the only form of advertising in the App — there are no banner or interstitial ads. If, and only if, you tap "Watch an ad for +1 credit," our advertising provider, Google AdMob, may collect:

You are always asked for consent first: users in the EEA/UK are shown a Google-provided consent form (UMP), and all users are shown Apple's App Tracking Transparency prompt before any advertising identifier is used. If you decline, ads are served non-personalised or not at all, and the rest of the App is unaffected. Users who never tap the "watch an ad" button share no advertising data.

3. How We Use Your Information

We use the information we collect to:

We do not sell your personal data, serve banner or interstitial ads, or carry out behavioural tracking you have not consented to via the App Tracking Transparency prompt.

4. Data Storage & Security

4.1 Cloud Storage

Your account data, profile, and reading history are stored in our cloud backend operated by Supabase (see Section 5). Data is hosted in the eu-central-1 (Frankfurt, Germany) region. Reading data is also cached locally on your device for offline access.

4.2 Security Measures

4.3 Data Retention

5. Third-Party Services

5.1 Analytics & Crash Reporting

We do not use third-party analytics services (e.g., Google Analytics, Firebase, Crashlytics). If you enable Crash Reporting in iOS Settings → Privacy → Analytics, Apple may collect anonymised crash logs. This is entirely optional and controlled by your iOS settings.

5.2 AI Interpretation

The App uses AI to generate written interpretations of your readings. When you request an interpretation, we send the cards you drew, their positions in the spread, the spread type, and (if you provided them) your intention/question and limited profile context to an AI provider, which returns the reading text. This request is routed through our Supabase backend (see Section 5.3).

We use Google Gemini (Google LLC) as the default AI provider. Depending on configuration, Anthropic Claude (Anthropic PBC) may be used as an alternative provider. We transmit only the data needed to produce the interpretation; we do not send your email or authentication credentials. These providers process the data to return a response and, per their terms, do not use App data submitted through their APIs to train their models.

ProviderPurposePrivacy policy
Google LLC (Gemini API)Default AI interpretation providerpolicies.google.com/privacy
Anthropic PBC (Claude API)Alternative AI interpretation provideranthropic.com/legal/privacy

5.3 Sub-Processor: Supabase

AttributeValue
ProviderSupabase Inc.
PurposeAuthentication, database (profile + readings), account management, AI request routing
Data hostedeu-central-1 (Frankfurt, Germany)
Privacy policysupabase.com/privacy

5.4 Advertising Provider: Google AdMob

We use Google AdMob (Google LLC) to serve optional rewarded video ads to free-tier users. AdMob is only invoked if you tap "Watch an ad for +1 credit"; it is never loaded otherwise. See Section 2.5 for the data involved and the consent prompts shown first.

AttributeValue
ProviderGoogle LLC (AdMob)
PurposeServing optional rewarded video ads (free tier only)
Data collectedDevice/advertising identifiers, IP address, ad-interaction and coarse device data (see Section 2.5)
ConsentEEA/UK consent form (UMP) + Apple App Tracking Transparency prompt, both shown before any ad
Privacy policypolicies.google.com/privacy

5.5 Purchases: RevenueCat & Apple

Pro subscriptions and credit packs are sold as Apple In-App Purchases and billed through your Apple ID; payment details are handled by Apple and are never seen by us. We use RevenueCat, Inc. to manage entitlements and validate purchases. RevenueCat receives your anonymised app user ID and purchase/transaction metadata (product purchased, purchase and expiry dates) — not your name, email, or payment card.

AttributeValue
ProviderRevenueCat, Inc.
PurposeSubscription & in-app purchase management and validation
Data collectedAnonymised app user ID, purchase/transaction metadata
Privacy policyrevenuecat.com/privacy

6. User Rights & Controls

6.1 Access Your Data

You can access all your reading data at any time through the App's Reading History feature.

6.2 Delete Your Account

You can permanently delete your account directly within the App:

Settings → Account → Delete My Account

This immediately revokes your session, permanently deletes your profile and all readings within 30 days, and wipes your local cache immediately. This action is irreversible. Alternatively, email privacy@codewavemobile.com to request deletion.

6.3 Correct or Update Your Data

Update your display name, birth date, birth time, and birth place at any time via Settings → Profile.

6.4 Data Portability

Export functionality is not yet available in the App. To request a copy of your data in a portable format, contact us at privacy@codewavemobile.com.

6.5 Opt-Out

7. Age Requirement

Thoth: The Unknown is designed for users aged 18 and over.

We do not knowingly collect personal information from users under 18. The App enforces an age gate during account setup — a valid date of birth confirming the user is 18 or older is required to create an account.

If we become aware that a user under 18 has created an account, we will delete that account and all associated data without notice. Parents or guardians who believe a minor has created an account should contact us immediately at privacy@codewavemobile.com.

8. Your Privacy Rights by Region

Turkey — KVKK

  • Know whether your data is processed
  • Request information about purpose and use
  • Request correction of inaccurate data
  • Request deletion or destruction of your data
  • Object to processing

Europe — GDPR

  • Access your personal data
  • Rectify inaccurate data
  • Right to erasure ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Lodge a complaint with your local DPA

California — CCPA/CPRA

  • Know what personal information is collected
  • Know if data is sold or disclosed
  • Delete personal information
  • Opt-out of sale/sharing

We do not sell your data.

To exercise any of these rights, contact us at privacy@codewavemobile.com. We will respond within 30 days.

9. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by updating the "Last Updated" date, posting the revised policy within the App, and requesting explicit consent if changes materially alter how we handle your data.

Your continued use of the App after changes become effective constitutes your acceptance of the updated Privacy Policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

We will respond to privacy requests within 30 days.