Privacy
Questions are processed transiently for safety and are not stored or logged by our application. The current reflection stays in this browser for refresh recovery. Save adds it to your latest 10 saved reflections; questions are included only with a per-reading opt-in. Anyone with access to this browser may see them. Use Local history to clear stored reflections. Shared images contain only card names, theme, and a neutral sentence. There are no accounts or external AI requests. Optional analytics are explained below. Hosting infrastructure may keep request metadata; this draft requires owner review before launch.
Optional product analytics
Draft for owner/legal review, not a claim of legal compliance. Analytics are disabled by default. In first-party mode, Allow enables anonymous product events and an HttpOnly session cookie lasting up to 30 days. We store a keyed session hash, server event time, event name, coarse device/referrer classes and constrained campaign labels. Questions, reading text, card IDs, email, full referrers, IP and user-agent values are not stored in analytics. No third-party analytics services are used. Analytics events and intent-only rows are automatically deleted after 90 days. Your consent choice is saved locally; you can change it below. Turning analytics off stops future events and requests cookie deletion, but does not immediately erase previously collected aggregate rows. Consented visitors are not total visitors. Infrastructure may retain request metadata; storage failures, blocked requests and shared browsers limit measurement. Campaign links must never contain personal information.
Analytics choice
May we measure anonymous first-party product events, such as starting a reflection or using Share? We use a 30-day session cookie, never your question or reading text. Nothing is sent before you allow this. Your choice does not change the free reflection.