Effective 2026-09-28
Mumu Tarot (mustar.vip, "the site") does one thing: it takes the cards you drew and the question you wrote, sends them to a language model, and returns a reading meant for you alone. This page explains which machines your words pass through and what is left behind.
1. Information you give us
Signing up needs only an email and a password. A nickname is optional. We never ask for a phone number, your legal name, an address or an ID document.
If you use the chart tools you may save birth data (date, time, place or coordinates). It is used for calculation and is visible only to you while signed in.
The question and background you write, the cards you draw and the reading generated from them are stored as history so you can return to them.
Your credit balance, deduction and top-up ledger, and redemption records.
2. What we do not collect
There is no payment integration on the site, so we never see or store card numbers or payment accounts — top-ups happen off-site and arrive as redemption codes.
No advertising, no third-party advertising or cross-site tracking cookies, no profiling. We do not sell or rent any of your information.
3. Technical data recorded automatically
To know whether the service is working and whether it is being farmed by scripts, each request logs: time, duration, success or failure, language, number of cards, and a one-way hash of your IP address.
This exists for statistics and abuse prevention and is designed so that it cannot be traced back to a person. It is stored separately from your account.
4. Sign-in state and local storage
Your browser keeps two things in localStorage: the session token and your language choice. Clearing browser data removes both and you will need to sign in again.
5. Who else handles your data
Supabase — database, authentication, verification email delivery.
Vercel — hosting and static asset delivery.
AI generation providers — they receive the question, background and cards you supplied and return the reading text. This is the core of the product and cannot be avoided.
Each of them processes your data only as far as needed for that function. Nothing goes anywhere else.
6. How long we keep it, and how to delete it
Until you ask otherwise: individual readings can be deleted from Account → Reading history.
Deleting your account lives in Account → Security & account and requires typing your own email as confirmation. Your profiles, saved spreads, reading history and credit ledger are removed with it.
Two things remain: the audit log and the AI usage statistics. The first keeps only a technical identifier that can no longer be traced back to your email; the second is what lets us spot re-registered farming accounts. Neither is shown publicly.
7. How we protect it
HTTPS everywhere. Passwords are salt-hashed by the authentication service — we cannot read them either.
Credit deduction and balance checks happen on the server; numbers sent by the browser are never trusted.
The admin area is role-gated. Only the operator account can see customer data, and every change it makes is written to the audit log.
8. Minors
The site is intended for adults. If you are under 18, use it only with a guardian informed and consenting.
9. Changes
The effective date at the top of this page is the current version. Any change that affects your rights will be announced in the site.
10. Contact
For any request about your personal data — access, correction, export, deletion — write to support@mustar.vip and include your 8-digit account id (visible on the Account page).