Privacy Policy
Privacy Policy — Roda do Destino
Last updated: 30 July 2026
1. Introduction
This Privacy Policy explains how the Roda do Destino mobile application, developed and made available by [NAME OF THE RESPONSIBLE PERSON OR COMPANY], collects, uses, stores, protects and shares information relating to its users.
Roda do Destino is a tarot application intended for entertainment, personal reflection and self-knowledge. The readings provided by the application do not constitute medical, psychological, legal, financial or professional advice.
By using the application, the user confirms that they have read and understood this Privacy Policy.
2. Data controller
The controller responsible for the processing of personal data is:
Name or entity: [FULL NAME OR COMPANY NAME]
Trading name: Mystic Wheel Studio
Country: Portugal
Address: [BUSINESS OR REGISTERED ADDRESS, WHERE APPLICABLE]
Privacy and support email: [SUPPORT EMAIL]
Website: [WEBSITE ADDRESS]
For questions relating to privacy, the exercise of rights or account deletion, the user may contact us using the email address provided above.
3. Data we may process
Depending on how the user uses the application, we may process the following categories of data.
3.1. Google account data
When the user chooses to sign in with Google, we may receive:
the name associated with the Google account;
email address;
profile picture, where provided;
unique account identifier provided by Google;
information required to authenticate and recover the account within the application.
Roda do Destino does not receive or store the password for the user’s Google account.
This data is used to identify the user, maintain the account, recover credits and usage limits, and allow access following a reinstallation or change of device.
3.2. Tarot questions and readings
The application may process:
questions entered by the user;
the theme selected for the question;
the chosen response type;
cards drawn;
generated interpretations and responses;
date and time of the reading;
selected language;
reading history, when this feature is active.
Questions entered by the user may contain personal information voluntarily provided by the user. We recommend that users do not enter full names, addresses, identification numbers, banking information, detailed medical information or other unnecessary data.
3.3. Usage and credit data
We may process information such as:
number of free readings used;
date of last use;
available in-depth reading credits;
credits used;
type of reading requested;
purchase confirmations;
technical transaction identifiers;
payment status.
We do not directly receive or store full bank card details. Payments are processed by Google Play through the Google Play Billing system.
3.4. Advertising data
The application may display advertisements, including rewarded advertisements, through Google Mobile Ads.
Depending on the user’s settings, applicable consent and the configuration of the services, the following data may be processed:
device advertising identifier;
IP address;
approximate device information;
operating system version;
language;
interaction with advertisements;
data required for measurement, fraud prevention and advertising delivery.
Google explains that applications using its advertising services may share technical information, including the application name and identifiers used for advertising, measurement and abuse prevention.
3.5. Technical and security data
We may receive or record:
device model;
operating system and version;
application version;
language and region;
IP address;
date and time of access;
error logs;
application crash information;
technical data required for security and fraud prevention.
This data may be processed directly by us or by technology providers integrated into the application.
3.6. Support communications
When the user contacts us, we may process:
name;
email address;
message content;
screenshots or files voluntarily submitted;
information required to respond to the request.
4. Purposes of processing
Data may be used to:
create and authenticate the account;
enable sign-in with Google;
recover the account following a reinstallation or change of device;
provide free and paid readings;
process questions and generate interpretations;
apply the daily free-reading limit;
manage purchased credits;
process and validate purchases made through Google Play;
display advertisements and grant associated rewards;
store reading history, where applicable;
provide user support;
detect errors and improve stability;
prevent fraud, abuse or misuse;
comply with legal obligations;
exercise or defend legal rights;
improve the application and its services.
5. Legal bases for processing
Where the General Data Protection Regulation applies, processing may be based on the following legal grounds.
5.1. Performance of a contract
Processing is necessary to provide the application and the features requested by the user, including:
account creation and management;
authentication;
tarot readings;
credit management;
purchases and restoration of access.
5.2. Consent
Consent may be used for:
personalised advertising, where applicable;
storage of or access to identifiers that require consent;
certain optional features;
promotional communications, should these be introduced.
The user may withdraw consent at any time, without affecting the lawfulness of processing carried out before consent was withdrawn.
5.3. Legitimate interests
We may process certain data to:
ensure the security of the application;
prevent fraud;
correct errors;
protect our systems;
analyse the general operation of the service;
respond to requests and complaints.
When relying on this legal basis, we assess our interests against the rights and expectations of the user.
5.4. Compliance with legal obligations
Certain data may be stored or processed where necessary to comply with legal, tax, accounting, regulatory or judicial obligations.
The GDPR establishes, among other matters, transparency duties and rights of access, rectification, erasure, restriction and objection.
6. Service providers and data recipients
We may use the following service providers.
6.1. Google
We use Google services for:
Google account sign-in;
application distribution;
purchase processing;
advertisement display;
measurement and security.
Data processed by Google is subject to Google’s own policies and terms.
6.2. Supabase
We use Supabase for backend services, which may include:
authentication;
database services;
user management;
recording readings and limits;
credit management;
server functions;
security and access control.
6.3. Artificial intelligence provider
Questions, selected cards, language, theme and other information required for a reading may be sent to the artificial intelligence provider used by the application, currently DeepSeek, to generate the requested interpretation.
The user should not enter sensitive or unnecessary personal information in their questions.
The artificial intelligence provider may process data through infrastructure located outside the European Economic Area.
6.4. Google Play Billing
Purchases are processed through Google Play. We may receive information such as:
purchased product;
purchase identifier or token;
transaction status;
payment confirmation;
data required to validate the purchase.
We do not receive full payment method details.
6.5. Google Mobile Ads
Google Mobile Ads may process technical and advertising data to display advertisements, measure results, limit repetition and prevent fraud.
6.6. Technical service providers
We may also use providers of:
hosting;
domain and website services;
technical support;
error monitoring;
security;
accounting;
legal advice.
We only share data to the extent necessary for the provision of the relevant services.
7. International transfers
Some providers may process data outside Portugal or the European Economic Area.
Where required by applicable law, we seek to use recognised mechanisms for international transfers, such as:
adequacy decisions;
standard contractual clauses;
other legally permitted safeguards.
The availability and exact location of processing may depend on the infrastructure used by each provider.
8. Data retention
We retain data only for as long as necessary for the purposes for which it was collected, without prejudice to legal obligations.
In general:
Account data: for as long as the account remains active;
Daily limits and usage records: for the period necessary to apply limits and prevent abuse;
Reading history: until deleted by the user or until the account is deleted, unless legal retention is required;
Purchase and transaction data: for the period required by tax, accounting or fraud-prevention obligations;
Support requests: for the period necessary to resolve the request and retain a record of the response;
Security logs: for a reasonable period necessary to protect the systems;
Data subject to a valid deletion request: deleted or anonymised, unless retention is legally required.
After the applicable retention period expires, the data will be deleted or anonymised.
9. Account and data deletion
The user may request the deletion of their account and associated data:
through the Delete account option, which should be available in the application settings; or
through the public page:
[https://YOUR-DOMAIN.com/account-deletion]
The user may also submit a request to:
[PRIVACY EMAIL]
The request may require verification of the user’s identity and account ownership.
Once validated, data associated with the account will be deleted, including, where applicable:
user profile;
reading history;
saved questions;
available credits;
usage records associated with the account.
Some information may be retained where necessary to comply with legal obligations, prevent fraud, resolve disputes or maintain accounting records.
Deleting the account may result in the permanent loss of unused credits. This consequence must be clearly presented to the user before confirmation.
Google Play requires applications that allow users to create accounts to provide both an in-app account deletion method and a webpage where users can request deletion of their account and associated data.
10. User rights
Under applicable law, the user may have the right to:
obtain information about the processing of their data;
request access to their data;
request correction of inaccurate data;
request deletion;
request restriction of processing;
object to certain processing activities;
withdraw consent;
receive their data in a structured format, where applicable;
lodge a complaint with a supervisory authority.
In Portugal, the user may contact the Portuguese Data Protection Authority, the Comissão Nacional de Proteção de Dados — CNPD.
The exercise of these rights is generally free of charge, although manifestly unfounded or excessive requests may be handled in accordance with applicable law.
To exercise a right, contact:
[PRIVACY EMAIL]
We may request reasonable information to verify the identity of the person making the request.
11. Security
We adopt technical and organisational measures intended to protect data, including, where applicable:
user authentication;
encrypted connections;
access controls;
database security policies;
restriction of access to data by user;
server-side request validation;
monitoring of errors and abuse;
updating dependencies and services.
No system is completely immune to failures, unauthorised access or incidents. We therefore cannot guarantee absolute security.
12. Special categories of data
The application is not designed to deliberately collect health data, religious beliefs, sexual orientation, political opinions or other special categories of personal data.
However, the user may voluntarily enter this type of information in a tarot question. We recommend that users do not do so.
Where a question concerns health, legal matters, finances or other important decisions, the reading must be understood only as entertainment and reflection, and not as professional advice.
13. Children and minors
The application is not intended for children below the minimum age required by applicable law or Google Play requirements.
We do not knowingly collect data from children without valid permission from a parent or legal guardian.
If we become aware that a child’s data has been improperly processed, we will take reasonable steps to delete it.
Note: Before publication, a specific minimum age, such as 16 years, must be selected and stated, and the application’s target audience settings on Google Play must be configured consistently.
14. Advertising and preferences
Depending on the user’s location, age, consent and settings, advertisements may be:
personalised;
non-personalised;
restricted according to age or region.
Where legally required, a mechanism will be provided to collect or manage consent before data is used for personalised advertising.
The user may also manage certain preferences through their Google account and device settings.
15. Purchases, credits and refunds
Purchases are made through Google Play and are also subject to Google Play’s applicable terms.
Purchased credits:
are associated with the account used in the application;
are intended exclusively for readings within Roda do Destino;
do not represent money, electronic currency or transferable value;
cannot be sold or transferred between users;
may be lost when the account is deleted.
Refund requests are handled in accordance with Google Play rules and applicable law.
16. Third-party links and services
The application or website may contain links to third-party services.
We do not control the privacy practices of those third parties. We recommend reading their respective policies before using their services.
17. Changes to this Policy
This Policy may be updated to reflect:
changes to the application;
new service providers;
legal changes;
new types of data;
changes to the purposes of processing.
The date of the latest update will be shown at the beginning of this page.
Where a change is significant, we may display a notice within the application or request new consent, where legally required.
18. Contact details
For questions about this Policy, privacy requests or account deletion:
Responsible person or entity: [NAME OR ENTITY]
Email: [PRIVACY EMAIL]
Website: [WEBSITE]
Country: Portugal
19. Supervisory authority
Without prejudice to any other administrative or judicial remedy, the user may lodge a complaint with the competent data protection authority.
In Portugal:
Comissão Nacional de Proteção de Dados — CNPD