Privacy Policy

Mystic Tarot — Chrome Extension

Effective date: August 24, 2026 · Document version 1.0

1. Who we are and scope of this policy

This Privacy Policy explains what data the Mystic Tarot Chrome extension ("extension", "we", "us", "the Service") and its backend API collect, use, and store when you register, request tarot readings, and make payments through the extension.

The Service is operated by CloudApi LLC. Contact details for privacy questions are listed in Section 14 ("Contact Us").

By using the extension, you agree to the collection and processing of data as described below. If you do not agree, please do not install the extension, or remove it at any time — Section 10 ("Your Rights") explains how to also request deletion of data already collected.

2. What data we collect

2.1. Data you provide directly

DataCollected whenWhy we need it
Name At registration Identifies your profile
Email address At registration Account sign-in, linking payments, contacting you if needed
4-digit PIN At registration Simple authentication in place of a password
Your question / reading topic Every time you request a reading Sent to an Server to a personalized interpretation of the cards
Selected interface language When you change language Localizes the interface and interpretation text

2.2. Data generated automatically

2.3. Data we do not collect

3. Chrome extension permissions

The extension requests the following browser permissions:

PermissionWhat it's used for
sidePanel Displays the extension's interface in Chrome's side panel
tabs Opens WayForPay's secure checkout page in a new tab when you top up your balance
host_permissions: <all_urls> Technical permission enabling network requests to our API server and to WayForPay. The extension does not read or modify the content of other websites.

4. How we use your data

We do not use your data to serve advertising, and we do not sell it to third parties.

5. Who we share data with

We share limited data with the following third-party services, only to the extent required for their specific function:

WayForPay (payment processing)

When you top up your balance, your email and order details (amount, contents) are sent to WayForPay to generate a secure checkout page. Card details are entered directly on WayForPay's page and never pass through our server. See WayForPay's Privacy Policy.

Install-analytics service (cloudapi.stream)

On install, update, or removal of the extension, its extension ID and event type are sent to cloudapi.stream — used for basic install/uninstall statistics and not linked to your email or account.

We may also disclose data where required by law, in response to a valid request from a government authority, or to protect the rights, safety, and property of the Service and its users.

6. Payments and card data

All payments are processed by WayForPay on its own secure, PCI DSS-compliant checkout page. We receive only the outcome of the transaction from WayForPay: status (approved / declined), the amount, a masked card number such as 4149****1234 (used only to verify the transaction and not stored in our database), and a service authorization code. The full card number, expiry date, and CVV/CVC are never sent to us and are never stored by us.

7. Data stored in your browser

For convenience — so you don't have to re-enter your email and PIN every time — the extension stores your email, PIN, user ID, current points balance, and selected language in your browser's localStorage. This data is stored locally on your device, is not transmitted directly to third parties from the browser, and is cleared when you select "Log out" in the extension or when you remove the extension entirely.

Because this data is stored in plain form in your browser's local storage, anyone with physical access to your device and Chrome profile could potentially read it. Avoid signing in on a shared computer without logging out afterward.

8. Data retention

9. Data security

The connection between the extension and our server is protected via HTTPS. We apply reasonable technical and organizational measures to protect data against unauthorized access, alteration, or loss. That said, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security.

10. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email kiev3381917@gmail.com, including the email address used at registration. We respond to such requests within a reasonable period, typically no later than 30 days.

11. Children's privacy

The Service is not intended for and is not directed at anyone under the age of 18, for either entertainment or informational purposes. We do not knowingly collect data from children. If you become aware that a minor has provided us with personal data, please contact us and we will delete it.

12. International data transfers

Our servers and those of our third-party providers (WayForPay) may be located in countries other than your country of residence. By using the Service, you consent to the transfer of your data to such countries, where data protection standards may differ from those in your local jurisdiction.

13. Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the "effective date" at the top of this document and, where appropriate, notify users through the extension's interface. Continued use of the Service after changes are published constitutes acceptance of the updated policy.

14. Contact us

For any questions about this Privacy Policy or how your data is handled, contact us at:

CloudApi LLC
Email: kiev3381917@gmail.com