Privacy Policy
Last Updated: 2026-03-22
Last Updated: Aug 2, 2026
Effective Date: Aug 1, 2026
Notice of Revision: This revision introduces provisions concerning the AI consultation service
(Karuna), including the fact that the content of your consultations is transmitted to an AI provider
located in the United States (Sections 5, 6 and 7). These changes take effect upon publication of
this policy.
1. Information We Collect
Information You Provide
- Account Information: Email, nickname, profile photo (optional)
- Birth Information: Birth date, time, and place for fortune services
- Service Usage Records: Reading history, analysis results, saved results
- Payment Information: Purchase history (payment info handled by payment processor)
- AI Consultation Content: The messages you enter in the AI consultation service (Karuna) and the responses generated by the AI
Automatically Collected Information
- Device Information: Device model, operating system version, app version, device language and region settings
- Network Information: IP address, access logs, connection timestamps
- Usage Patterns: Service usage frequency, feature access records, session duration
- Device Identifiers: Push notification tokens (Firebase Cloud Messaging)
- Service Quality Statistics: Pseudonymized usage statistics such as conversation topic classifications and response types (the text of conversations is not included)
Sensitive Information That May Appear in Consultations
Because the AI consultation service accepts whatever you choose to write, your messages may contain potentially sensitive information relating to matters such as mental health, emotional state, or family and romantic relationships. SOULCARD handles such information as follows.
- In order to provide an appropriate response, your messages are automatically classified into conversation topic types (decision, relationships, self-understanding, emotion, everyday conversation, information request, and crisis signal). The classification result is retained together with the corresponding conversation record.
- Only where a consultation is combined with a fortune analysis is a separate consultation journal entry retained, consisting of the consultation topic, the opening portion of the question you entered (up to 280 characters), the opening portion of the AI response (up to 400 characters), and a direction signal. These items are not a summary or an edited version of the content: the opening portion of the input and of the response is stored verbatim, and it is used to maintain the context of the conversation in later consultations. No consultation journal entry is created for consultations classified as emotion, crisis signal, or everyday conversation, or for consultations not combined with a fortune analysis.
- Retained classification results and consultation journal entries are used only to maintain the context of the conversation in later consultations (Section 13) and to compile service quality statistics that cannot identify an individual. They are not used to select targets for advertising or marketing, to grade or profile members, or for any disclosure to third parties other than the delegated processing described in Sections 5 and 6.
- For how consultations classified as a crisis signal are handled, please refer to "Crisis Situations" in Section 13.
- Conversation content is transmitted to OpenAI in the United States for the purpose of generating a response (Sections 5 and 7). Expressions relating to self-harm, suicide, or other crisis situations are no exception.
- Conversation text, classification results, consultation journal entries, and trend summaries are each destroyed automatically once the corresponding retention period stated in Section 8 has elapsed.
- Deleting consultation data: Selecting AI consultation data under "My > Privacy Settings > Delete Data" deletes your conversation text, consultation journal entries, and trend summaries in a single step. To delete an individual conversation only, open "Consultation history" using the history icon at the top right of the AI consultation (Karuna) screen and swipe the conversation to the left in the list.
- We recommend that you do not enter particularly sensitive information such as details of your health, medical conditions, or sex life.
2. How We Collect Information
We collect personal information through the following methods:
- Direct Collection: Information provided during registration, profile setup, and service use (e.g., birth date entry for fortune analysis)
- Automatic Collection: Device information, access logs, and usage records collected automatically during service use
- Third-Party Collection: Information received through Google social login authentication
Required vs. Optional Information
| Type | Information | Purpose |
|---|
| Required | Email, birth date | Account creation, core service provision |
| Optional | Nickname, profile photo, birth time, birth place | Personalization, enhanced analysis accuracy |
Members may decline to provide optional information; however, some service features that rely on that information may be limited.
3. How We Use Information
- Service Provision: Personalized fortune analysis and results
- Service Improvement: Improving service quality through usage pattern analysis
- Customer Support: Responding to inquiries and resolving issues
- Fraud Prevention: Detecting and preventing unauthorized access, abuse, and fraudulent activity
- AI Consultation: Generating conversational responses to the questions you raise and maintaining the context of the conversation
- Statistical Analysis: Compiling service usage statistics using anonymized or pseudonymized data (pseudonymized information is processed for statistical and scientific research purposes in accordance with Article 28-2 of the Personal Information Protection Act of the Republic of Korea, and we make no attempt of any kind to re-identify members)
- Legal Obligations: Compliance with applicable laws, regulations, and legal proceedings
4. Information Sharing
Member personal information is not shared with third parties except:
- With explicit member consent
- When required for legal compliance
- When using external services essential for service provision
SOULCARD does not sell or share your personal information with third parties for advertising or cross-context behavioral advertising purposes.
For specific third-party recipients and data transfers, please refer to the "Third-Party Data Sharing," "Data Processing Delegation," and "International Data Transfers" sections below.
5. Third-Party Data Sharing
SOULCARD shares personal information with the following third parties for service provision:
- Supabase (USA): User authentication, profile and service data storage
- Firebase/Google (USA): Push notifications, app analytics
- Fortune API Server (South Korea): Fortune analysis processing (birth date, time, and place transmitted)
- OpenAI (USA): Generation of AI consultation responses. The information transmitted consists of the consultation content you enter (the recent flow of the conversation) together with the context required for the consultation, namely your name, date of birth and age, gender, personality type (MBTI, where you have provided it), summaries of previous consultations (consultation topic, an excerpt of the opening portion of the question, and a direction signal), and the gist of fortune analysis results (including any cards or hexagrams you drew yourself). Your account identifiers (email address and member number), time of birth, birthplace coordinates, and the raw birth details of any other person are not transmitted to OpenAI. In addition, where a conversation is classified as a crisis signal relating to self-harm or suicide, personal details such as name and date of birth and summaries of previous consultations are not transmitted; only the conversation content is sent. The company does not consent to member consultations being used to train the AI provider's models, and does not take part in any separate data-sharing program that would permit such training. The AI provider may nonetheless retain transmitted data under its own policies for purposes such as abuse detection for a limited period (up to 30 days, based on the API data usage policy published by OpenAI) before deleting it, and this period is separate from the SOULCARD retention periods set out in Section 8. The specific processing carried out by the provider is governed by that provider's terms of use and data processing policies. Regarding a change of AI provider, please refer to Section 6.
- Google (Google Play): In-app purchase processing
Each recipient receives only the minimum information necessary for service provision and manages data in accordance with their respective privacy policies.
6. Data Processing Delegation
SOULCARD delegates processing of personal information to the following service providers:
| Service Provider | Delegated Tasks | Information Processed |
|---|
| Supabase (USA) | Cloud database hosting, user authentication | Account information, service data |
| Google/Firebase (USA) | Push notification delivery, app analytics | Device tokens, usage statistics |
| OpenAI, L.L.C. (USA) | Generation of AI consultation responses | Consultation content, name, date of birth and age, gender, personality type (MBTI), summaries of previous consultations, gist of fortune analysis results |
| Google Play (USA) | In-app purchase processing | Purchase transaction data |
Each delegated processor is contractually bound to process personal information only for the specified purposes and to implement appropriate security measures. Delegation agreements expressly provide for compliance with personal data protection laws, confidentiality of personal information, restrictions on further sub-delegation, and liability in the event of an incident.
Changes to the Provider Generating AI Consultation Responses
The provider that generates AI consultation responses may change depending on response quality, cost, and availability. Where the company changes the provider, it proceeds as follows.
- Where the delegated processor or the country to which personal information is transferred (Section 7) changes, the company will first reflect the change in Sections 5, 6 and 7 of this policy and give advance notice in accordance with the procedure set out in Section 16, and only then transmit consultation content to the new provider. The provider will not be replaced ahead of that notice.
- Consultation content is never transmitted to a provider that is not named in this policy. Where a response cannot be generated because of an outage or maintenance at the provider, the request is not automatically re-routed to another provider; instead, we inform you of a temporary connection problem and stop generating that response.
- This policy is distributed as part of the app, and revisions can therefore be viewed once you have updated the app to the latest version. The version currently in force is identified by the "Last Updated" date shown at the top of this policy.
7. International Data Transfers
Your personal information may be transferred to the following countries for service provision:
- United States: Supabase (database), Firebase (notifications/analytics), OpenAI (generation of AI consultation responses)
- South Korea: Fortune API (fortune analysis server, AI consultation orchestration)
Information transferred: Account information, birth date information, service usage records, AI consultation content
Purpose of transfer: Service operation and provision
Protective measures: SSL/TLS encryption, access control management, compliance with the terms of use and data processing policies of each processor
8. Data Retention
- Account Information: Retained 30 days after account deletion, then permanently destroyed
- Service Usage Records: Retained per member settings (default 1 year)
- Payment Records: Retained 5 years pursuant to Article 6 of the Act on the Consumer Protection in
Electronic Commerce of the Republic of Korea. Where an account is deleted, the records are retained
with user identifying information removed (anonymized).
- Access Logs: Retained 3 months per applicable telecommunications regulations
- AI Consultation Text: Destroyed automatically 1 day after the conversation is created for members without a subscription, and 7 days after creation for subscribing members (destruction is carried out in a single batch once a day, so processing may be delayed by up to 24 hours)
- AI Consultation Journal Entries (consultation topic, excerpt of the opening portion of the question, insight summary, direction signal): Destroyed automatically 7 days after creation for members without a subscription, and 90 days after creation for subscribing members
- AI Consultation Trend Summaries (self-pattern cards): Destroyed automatically after 7 days for members without a subscription, and after 90 days for subscribing members
- Service Quality Statistics (pseudonymized): Destroyed 30 days after collection
- Service Quality Statistics (aggregated): Retained without a time limit in the form of daily aggregate figures (counts and processing times by language, conversation type, and response type) that contain neither member identifiers nor conversation text
- Operational Logs (error diagnostics and API call records): Destroyed after 90 days
Upon expiration of the retention period, personal information is permanently destroyed within 5 business days. Information that must be retained under applicable law is stored separately and securely until the legal retention period expires.
If you request deletion of your account, the account is permanently deleted after a 30-day grace period, in line with the retention period for Account Information above, and any AI consultation text, consultation journal entries, and trend summaries still remaining at that point are destroyed together with the account. Information whose retention period listed above expires earlier is destroyed at that earlier point, even during the grace period. If you cancel the deletion request within the grace period, information that has not yet been destroyed remains available to you.
- Service quality statistics contain no member identifier and cannot be linked to an individual account. They are therefore processed in accordance with the periods stated above (30 days for pseudonymized statistics; no time limit for aggregated statistics), regardless of whether the account has been deleted.
9. Your Rights
- Access: Request access to collected personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion (except legal retention requirements)
- Portability: Request download of personal information
- Consent Withdrawal: Withdraw consent for collection and use of personal information at any time
How to Exercise Your Rights
- In-App: Under "My > Privacy Settings" you can manage consent for each category of information collected, edit your information, download your data, delete reading history, partner profiles and AI consultation data, configure retention periods, and delete your account yourself
- AI Consultation Conversations: Individual conversations can be deleted by opening the history icon at the top right of the AI consultation (Karuna) screen, selecting "Consultation history", and swiping the conversation to the left. Selecting "Delete all" deletes your conversation text, consultation journal entries, and trend summaries together
- Email: Submit requests to privacy@soulcard.app; requests will be processed within 30 days following verification of your identity
- Consent Withdrawal: Specific consent items (e.g., marketing, optional data collection) can be withdrawn individually through in-app settings or by email request
- Legal Representative: Rights may be exercised through an authorized legal representative with proper verification documentation
The company will not impose any disadvantage on members who exercise their rights. If a request cannot be fulfilled (e.g., legal retention requirements), the reason will be communicated in writing.
10. Children's Privacy
SOULCARD does not knowingly collect personal information from children under 14 years of age (or the minimum age for digital services as required by the laws of your country of residence). If we become aware that we have collected personal information from a child under 14 years of age (or the minimum age for digital services as required by the laws of your country of residence), we will take steps to delete such information promptly.
11. Regional Privacy Rights
This service operates globally, and additional privacy rights may apply depending on your region of residence.
California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You may request details about the categories and specific pieces of personal information we collect.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: SOULCARD does not sell or share your personal information with third parties for cross-context behavioral advertising purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
EU/EEA Residents (GDPR)
Under the General Data Protection Regulation (GDPR):
- Right to Object (Art. 21): You may object to the processing of your personal data in certain circumstances.
- Right to Restriction of Processing (Art. 18): You may request restriction of the processing of your personal data.
- Legal Basis for Processing (Art. 6): Processing of your data is based on your consent (Art. 6.1.a), which you may withdraw at any time.
- Right to Lodge a Complaint: You may file a complaint with the data protection supervisory authority in your country.
EU Residents (EU AI Act)
The following disclosures are made pursuant to Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689):
- Notice of interaction with an AI system (Art. 50(1)): The AI consultation service (Karuna) is an artificial intelligence system, and you are interacting with an AI rather than with a human being. This is stated both in the app interface and in this policy.
- The AI consultation service is neither an emotion recognition system nor a biometric categorisation system (Art. 50(3) does not apply).
- You have the right to request an explanation of a response generated by the AI and to request human intervention.
Japanese Residents (APPI)
Under Japan's Act on the Protection of Personal Information (APPI):
- Consent is obtained for third-party data sharing in accordance with Article 27.
- For provision of personal information to third parties in foreign countries, information about the personal data protection systems of those countries is provided in accordance with Article 28.
- The United States (Supabase, Firebase, OpenAI) does not have a comprehensive federal personal information protection law, but each service provider meets security standards such as SOC 2 certification.
CIS Region Residents
SOULCARD is designed for Russian-speaking users outside the Russian Federation, including users in Commonwealth of Independent States (CIS) countries. Personal data is stored on or transmitted to servers in the United States (Supabase, OpenAI) and South Korea (Fortune API). If your country of residence has data localization requirements, please consider this when using the service.
To exercise any of these rights, contact privacy@soulcard.app.
12. Data Breach Notification
In the event of a personal data breach, SOULCARD will respond as follows:
- Notify affected members via email or in-app notification within 72 hours of becoming aware
- Provide details of the breached data, timing, circumstances, and response measures
- Report to relevant regulatory authorities without delay
- Implement immediate technical measures to minimize damage
13. Automated Decision-Making and Notice of AI Use
SOULCARD uses AI-based algorithms to generate fortune analysis results and consultation responses.
Notice of AI Use
- You are speaking with an AI, not with a person. Every response given by the AI consultation service (Karuna) is generated automatically.
- This is also indicated in the app interface.
Automated Processing
- Fortune analysis: All fortune services, including tarot interpretation, Four Pillars (Saju) analysis, astrology charts, and compatibility analysis
- AI consultation (Karuna): Generation of conversational consultation responses based on the messages you enter
Processing Method
The AI analyses the information you provide, such as your birth date, time and place, together with the content of the conversation, in order to generate a result. The AI consultation service may take the context of earlier conversations into account when responding.
Important Notice — Not a Substitute for Medical or Professional Advice
- All results are for entertainment and reference purposes only and do not replace professional advice.
- The AI consultation service is not a medical service, psychotherapy, psychiatric diagnosis, legal advice, or investment advice. For decisions concerning your health, legal position, or finances, please consult a qualified professional in the relevant field.
- The AI may generate responses that are inaccurate or inappropriate.
Crisis Situations
Where a crisis signal relating to self-harm or suicide is detected in a conversation, the AI does not lead with a fortune analysis or with advice. It continues the conversation in a way that attends first to how you are feeling, and at the same time provides contact details for professional support services.
- The contact details offered are selected on the basis of the app language you have set, and not on the basis of your actual country of residence or mobile carrier. You may therefore be given a number for a country in which you do not live, and that number may not connect from your country of residence.
- Support services available in your country of residence can be found through the international helpline directory findahelpline.com.
- This detection is automatic and not exhaustive. It may miss a genuine warning sign, and it may treat an expression that carries no risk as a crisis.
- In an emergency, please contact the emergency number for your country of residence immediately.
- Any contact details stated in this policy are current as at the effective date and may change at the discretion of the organisations concerned.
- SOULCARD is not an emergency service. It does not report on your behalf or notify any third party. Where your safety requires it, please seek help directly.
Your Rights
You may request an explanation of automated decision-making or request human intervention. Please contact privacy@soulcard.app.
14. Cookies and Local Storage
SOULCARD is a mobile application and does not use web browser cookies. However, the app utilizes the following local storage mechanisms:
- Secure Storage: Authentication tokens such as login tokens and session information are stored in the device's secure storage for maintaining login sessions
- Shared Preferences: Language settings, consent records, notification preferences, date and time of birth, name, birthplace (city, country and coordinates), gender, and MBTI are stored locally on the device
- Local Cache: Temporary data for improving app performance (e.g., cached images, recent results)
All locally stored data is deleted when the app is uninstalled from the device. Members may also clear app data through their device settings at any time.
15. Data Security
SOULCARD implements the following measures to protect member information.
- Encryption in transit: Communications between the app and our servers are encrypted using SSL/TLS.
- Encryption at rest: Personal information and AI consultation content are held in an environment to which the database provider (Supabase) applies storage-level encryption at rest. Field-level encryption is not applied to individual items, so the minimum number of personnel holding database operating privileges are able to view that information.
- Access control: Row Level Security is applied to the database so that a member account can, as a matter of principle, access only its own data, and internal server-to-server calls require a separate authentication key. Access rights for personnel handling personal information are limited to the minimum number required for their duties.
- Retention minimisation: Potentially sensitive information such as AI consultation text is destroyed automatically once the retention period stated in Section 8 has elapsed.
- Diagnostic logs: Error diagnostic logs record request metadata only, so that consultation content is not included, and they are destroyed once the retention period stated in Section 8 has elapsed.
- Safeguards for pseudonymized information: Where information is pseudonymized for service quality statistics, the additional information that would allow it to be restored to its original state (the pseudonymization key) is held separately from the statistics database and access is limited to the minimum number of personnel. Any attempt to combine pseudonymized information with other information in order to identify a particular individual is prohibited by internal rules.
- Information stored on your device: Authentication information such as login tokens is, as a rule, stored in the device's secure storage (Android EncryptedSharedPreferences). On some devices, however, where secure storage cannot be initialised, it may be stored in the app's private storage area. Profile information needed to use the service, such as your date of birth, name, and birthplace, is by contrast stored in the app's private storage area on the device without separate encryption. We therefore recommend that you use a device lock, and that you uninstall the app before transferring or disposing of your device.
16. Changes to Privacy Policy
- For general changes, at least 7 days advance notice will be provided via in-app notification before the effective date.
- For changes that materially reduce member privacy rights or expand the scope of information collection/use, at least 30 days advance notice will be provided via both in-app notification and email.
- The revised policy becomes effective from the posted effective date.
- Members who do not agree with the changes may request account deletion.
17. Complaints and Remedies
Data Protection Officer
| Item | Details |
|---|
| Name | Lucide Seo |
| Email | privacy@soulcard.app |
| Responsibility | Oversight of all personal information processing, handling of member inquiries and complaints |
Filing Complaints
Members who believe their personal information rights have been violated may seek assistance from the following organizations:
For users in all jurisdictions:
- Contact your local data protection authority for guidance on your rights under applicable local law.
- SOULCARD Data Protection Officer: privacy@soulcard.app
For users in South Korea:
- Korea Internet & Security Agency (KISA) Privacy Center: 118 (no area code), privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee (KOPICO): 1833-6972, kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Division: 1301, spo.go.kr
- National Police Agency Cyber Bureau: 182, cyberbureau.police.go.kr
Privacy Inquiries: privacy@soulcard.app
Data Protection Officer: Lucide Seo