Privacy policy

What leaves your phone,
and what doesn't.

Written to be read rather than survived. If any of it stops being true, this page changes before the app does.

Last updated 10 September 2026

Everything stays on your phone by default

Journal entries, saved readings, Patterns and remembered context all live in on-device storage. There is no account, no login, and no copy of your journal on any server. The only backup is the file you choose to save into Files or your own iCloud Drive, which lives in your Apple account and not ours.

What leaves, and exactly when

Three actions send text off the device. Each goes to our Cloudflare Worker, which passes it to Anthropic's API to be interpreted. Neither we nor the Worker keeps any of it once the response comes back.

WhenWhat is sentWhere it goes
You request a reading The question you typed, the cards drawn, and which deck they came from. If you have entered a preferred name or pronouns, those go too, so the reading is written to you correctly. If you have turned on History in readings, a small, related slice of your past questions may go with it; that setting is off by default. Cloudflare Worker → Anthropic API. Not stored.
You open the Patterns tab Up to 60 of your recent entries — journal note titles with their full text, plus your saved readings' questions and anything you wrote under “what you noticed.” This runs when the tab opens and your entries have changed since the last check, not on every visit. Cloudflare Worker → Anthropic API. Not stored.
You select a pattern That pattern's name, up to 40 of the questions you filed under it, and the names of cards that recurred across them. Cloudflare Worker → Anthropic API. Not stored.

The one thing the server keeps

To stop a single device from exhausting the service, the Worker counts requests. Those counters are keyed to your IP address and a device identifier, and they hold nothing but a number — never anything you wrote.

They delete themselves after two days. That is the whole of what is retained.

Ads, subscriptions, your own key

Ads. Free readings are supported by a single interstitial from Google AdMob, which uses a device identifier and advertising data. iOS asks your permission before any tracking, and declining is a real option that costs you nothing in the app.

Subscriptions. TareOh Plus is handled by RevenueCat and the App Store. They hold your subscription status and an anonymous identifier — never your name, never your journal.

Your own API key. If you supply one, it is stored on the device outside the app's backup namespace, sent with each request, and never retained by us.

Your side of it

Deleting everything

Settings → Manage local data erases every entry, reading and pattern on the device. Because there is no server-side copy, that is the end of it — with one exception. A backup you chose to save is your own file, held in Files or your iCloud Drive, and neither deleting the app nor Manage local data reaches it. That is what a backup is for; it also means deleting the app is not by itself a way to erase what you wrote.

Children

TareOh is not directed at children and collects nothing that would identify one. We don't knowingly gather data from anyone under 13.

Changes

If what the app sends ever changes, this page changes first, with the date above updated. No silent expansions.

Questions

Write to support@tareoh.com and a person will answer.