StellaAi processes only the personal information needed to provide the Stellai Service.

Stellai tarot readings and AI-generated reading text are provided for entertainment, self-reflection, journaling, and reference. Users should not enter sensitive or unnecessary information such as government identification numbers, passport numbers, bank account numbers, card numbers, passwords, detailed health information, criminal or investigation-related information, or another person’s personal information.

1. Operator Information

Service: Stellai

Operator: StellaAi

Privacy contact: stellaai.labs@gmail.com

2. Scope

This Policy applies to the Stellai app, website, account features, tarot reading features, ad rewards, paid items, customer support, and Service operations.

Some features, including external payments, ads, login, app marketplaces, and AI APIs, may be processed through external providers. Their own terms and policies may also apply.

3. Information We Collect

We may process the following information to the extent needed to provide the Service.

Category Items Purpose Retention standard
Account information Email address, Firebase UID, login provider information, display name or nickname Login, account management, identity confirmation, misuse prevention Until account deletion
Reading information User question, selected cards, card orientation, reading result, language setting, user settings Generating tarot readings, showing reading history, providing the Service, quality improvement During account retention or until the user deletes it
Payment information Google Play or App Store purchase ID, receipt information, subscription status, item grant records Providing paid items, purchase verification, refund or support response, payment abuse prevention For the period needed for payment and dispute response
Ad and reward information Advertising identifier, ad viewing records, reward grant records, ad unit, transaction ID, consent status Providing ads, granting rewards, preventing invalid traffic, managing ad settings Deleted after purpose completion or retained for the necessary period
Device and log information IP address, device information, app version, access records, error logs, crash logs, security logs Service stability, error analysis, security, misuse prevention For the period needed for operations and security
Support information Email address, inquiry content, attachments, handling history Customer support, inquiry response, dispute handling For the period needed for support and dispute response

We do not request sensitive information that is unnecessary for providing the Service.

4. How We Collect Information

  1. When a user directly enters information in the app or website.
  2. When information is provided through a login provider or authentication system.
  3. When information is provided during Google Play or App Store purchase verification.
  4. When information is automatically generated through ad SDKs, server logs, analytics tools, or error records.
  5. When a user provides information during customer support inquiries.

5. How We Use Information

  1. Account creation, login, authentication, and session management.
  2. Generating tarot readings and AI reading results.
  3. Saving and retrieving reading history.
  4. Providing coins, passes, subscriptions, and paid items.
  5. Showing ads and granting ad rewards.
  6. Purchase verification, refund inquiries, and payment abuse prevention.
  7. Error analysis, performance improvement, and security checks.
  8. Preventing misuse, ad manipulation, and reward abuse.
  9. Customer support, inquiry response, and dispute handling.
  10. Service improvement and operational statistics.
  11. Notifications, notices, and event messages that the user has agreed to receive.

6. AI Reading Processing

  1. To generate tarot reading text, we may send necessary information such as the user’s question, selected cards, card orientation, language setting, and reading conditions to generative AI API providers.
  2. We try to send only the minimum information needed for AI processing.
  3. Users should not enter sensitive or unnecessary information such as government identification numbers, bank account numbers, card numbers, passwords, detailed health information, or another person’s personal information.
  4. AI responses are automatically generated and may be inaccurate, incomplete, or different from the user’s intent.
  5. AI readings are for entertainment, self-reflection, journaling, and reference, and do not provide professional diagnosis, counseling, advice, prescription, or guarantees.

7. Ads and Reward Processing

  1. The Service may show ads to provide free access or grant rewards.
  2. To provide ads and verify rewards, we may process advertising identifiers, ad viewing records, ad units, reward transaction IDs, and consent status.
  3. Personalized ad settings may be managed through app settings, operating system settings, or consent screens provided by ad networks.
  4. If a user does not consent to personalized ads, non-personalized ads may still be shown.
  5. Reward delivery may be delayed or fail depending on the ad SDK, ad network, server verification, device status, network status, invalid traffic review, or similar conditions.
  6. If a verifiable normal completion record is confirmed, we will reasonably review and address reward issues.

8. Payment and Subscription Processing

  1. Paid item purchases are processed through Google Play, Apple App Store, or another payment method connected by the Company.
  2. We do not store direct payment method information such as card numbers, CVC codes, or bank account passwords.
  3. We may process purchase IDs, receipt information, subscription status, and grant records to provide paid features, verify purchases, confirm subscription status, respond to refund inquiries, and prevent payment abuse.
  4. Purchase cancellation, refunds, and subscription cancellation are generally handled through the app marketplace or payment provider used for the purchase.

9. Processors and External Providers

We may use external providers to operate the Service.

Provider Purpose
Google / FirebaseAuthentication, database, server functions, hosting, Remote Config, App Check, analytics, error checks, security
Google AdMobAd display, ad revenue measurement, rewarded ads
Google User Messaging PlatformAd consent management
Google PlayAndroid app payments, purchase verification, subscription status confirmation
Apple App StoreiOS app payments, purchase verification, subscription status confirmation
Generative AI API providersGenerating reading text based on user questions and card information
Analytics and error-checking toolsApp stability, performance, error, and crash analysis
Email or customer support toolsInquiry response and notices

We try to provide external providers only the information needed to provide the Service.

10. International Processing

Cloud, advertising, payment, and AI API providers used to operate the Service may be located outside the user’s country or may use servers in other countries. As a result, account information, log information, ad and reward information, payment verification information, and minimum information needed for reading generation may be processed internationally.

  1. Sending only necessary information.
  2. Using encryption during transmission where appropriate.
  3. Limiting access permissions.
  4. Restricting use to Service-related purposes.
  5. Reviewing external providers’ security practices where practical.

If you do not want international processing, some features may be limited.

11. Retention and Deletion

  1. Account information is deleted when the account is deleted.
  2. Reading history and user settings are deleted when the account is deleted or when the user requests deletion.
  3. Ad reward records are retained for the period needed to confirm reward delivery and prevent misuse.
  4. Payment and subscription records are retained for the period needed for refunds, disputes, payment abuse prevention, and accounting.
  5. Security logs and error logs are retained for the period needed for Service stability and misuse prevention.
  6. Inquiry records are retained for the period needed for inquiry handling and dispute response.
  7. When the retention purpose ends, information is deleted or processed so that it can no longer identify an individual.

12. Account Deletion

You may request account deletion at any time.

Delete in the app

If you cannot access the app

Information deleted after account deletion

Information that may be retained for a necessary period

This information is retained only to the extent needed for payments, refunds, disputes, security, and misuse prevention. After account deletion, previous reading history, settings, coins, passes, rewards, and subscription-related information may not be recoverable.

13. User Choices and Rights

  1. Request access to personal information.
  2. Request correction of inaccurate information.
  3. Request deletion of personal information.
  4. Request restriction or stopping of processing.
  5. Change personalized ad settings.
  6. Withdraw consent.
  7. Delete the account.

Requests can be submitted through app settings or by email. We may confirm account ownership when needed to process a request.

14. Managing Ad Settings

  1. Privacy or ad settings within the app.
  2. Android advertising ID settings.
  3. iOS tracking permission settings.
  4. Ad network consent screens.
  5. Browser or device settings.

Limiting ad settings may reduce personalized ads, and some ad-supported free features or reward features may be limited.

15. Cookies and Local Storage

The website may use cookies or local storage to keep users logged in, store language settings, save basic settings, and stabilize the Service.

You can limit or delete cookies in your browser settings. If you do, login persistence, language settings, or some web features may not work properly.

16. Children and Minors

Stellai is not intended for children. We do not knowingly collect personal information from children. If we learn that a child has provided personal information without appropriate guardian involvement, we will review the matter and take necessary steps.

If a minor purchases paid items or uses the Service, guardian consent may be required.

17. Security Measures

  1. Limiting access permissions to necessary personnel.
  2. Using encryption during transmission where appropriate.
  3. Managing server and database access.
  4. Reviewing error and security logs.
  5. Detecting misuse.
  6. Managing backup and recovery.
  7. Minimizing unnecessary data collection.

18. Security Incident Response

If we learn of a personal information leak or security incident, we will review the cause and take steps to reduce harm. When needed, we will inform users of the incident, its potential impact, and available steps.

19. Contact

Questions about privacy, account deletion, data deletion, ad settings, reward issues, or payment-related matters may be sent to the email address below.

20. Updates

We may update this Policy when Service features, collected information, external providers, payment methods, advertising methods, or AI processing methods change.

For material changes, we will provide notice through the app, website, email, notice screen, or another reasonable method.