Privacy policy
Written to be read rather than survived. If any of it stops being true, this page changes before the app does.
Last updated 10 September 2026
Journal entries, saved readings, Patterns and remembered context all live in on-device storage. There is no account, no login, and no copy of your journal on any server. The only backup is the file you choose to save into Files or your own iCloud Drive, which lives in your Apple account and not ours.
Three actions send text off the device. Each goes to our Cloudflare Worker, which passes it to Anthropic's API to be interpreted. Neither we nor the Worker keeps any of it once the response comes back.
| When | What is sent | Where it goes |
|---|---|---|
| You request a reading | The question you typed, the cards drawn, and which deck they came from. If you have entered a preferred name or pronouns, those go too, so the reading is written to you correctly. If you have turned on History in readings, a small, related slice of your past questions may go with it; that setting is off by default. | Cloudflare Worker → Anthropic API. Not stored. |
| You open the Patterns tab | Up to 60 of your recent entries — journal note titles with their full text, plus your saved readings' questions and anything you wrote under “what you noticed.” This runs when the tab opens and your entries have changed since the last check, not on every visit. | Cloudflare Worker → Anthropic API. Not stored. |
| You select a pattern | That pattern's name, up to 40 of the questions you filed under it, and the names of cards that recurred across them. | Cloudflare Worker → Anthropic API. Not stored. |
To stop a single device from exhausting the service, the Worker counts requests. Those counters are keyed to your IP address and a device identifier, and they hold nothing but a number — never anything you wrote.
They delete themselves after two days. That is the whole of what is retained.
Ads. Free readings are supported by a single interstitial from Google AdMob, which uses a device identifier and advertising data. iOS asks your permission before any tracking, and declining is a real option that costs you nothing in the app.
Subscriptions. TareOh Plus is handled by RevenueCat and the App Store. They hold your subscription status and an anonymous identifier — never your name, never your journal.
Your own API key. If you supply one, it is stored on the device outside the app's backup namespace, sent with each request, and never retained by us.
Settings → Manage local data erases every entry, reading and pattern on the device. Because there is no server-side copy, that is the end of it — with one exception. A backup you chose to save is your own file, held in Files or your iCloud Drive, and neither deleting the app nor Manage local data reaches it. That is what a backup is for; it also means deleting the app is not by itself a way to erase what you wrote.
TareOh is not directed at children and collects nothing that would identify one. We don't knowingly gather data from anyone under 13.
If what the app sends ever changes, this page changes first, with the date above updated. No silent expansions.
Write to support@tareoh.com and a person will answer.