Home › Privacy Policy
Privacy Policy
Last updated: August 20, 2026
This document is the privacy policy of Mistera AI ("Mistera", "we") for the app and website, prepared in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK").
Data controller: Ahmet Taha Berberoğlu (operator of Mistera AI). For any question or request, write to app.mistera@gmail.com.
What data do we collect?
- Account data: your e-mail address, display name (if any) and an irreversible hash of your password. Your password is never stored in plain text.
- Social sign-in: if you sign in with Google, the authentication token and e-mail address provided by Google.
- Reading content: the questions you ask, the cards you pick or that are recognized from a photo, the generated interpretations and any notes you add. When this feature is enabled, numeric summaries (embeddings) may be derived from this content so your history can be searched meaningfully.
- Astrology profile: birth date, optional birth time, birth place, latitude, longitude, and time zone. The calculated birth chart is stored with your account. AI-generated astrology readings (the birth-chart reading and the "today’s sky" reading) are saved to your astrology history; a relationship-compatibility reading is stored only if you choose to save it. Sky and transit calculations shown without an AI reading are not stored.
- Relationship compatibility: birth dates, times, and locations entered temporarily for a comparison are used only while processing the request and are not stored permanently. If you explicitly choose to save, names, your focus, the deterministic score, and the generated reading—which may contain planetary placements—may be stored with your account.
- Card photos: an uploaded photo is processed only to recognize the card names and is deleted from the server as soon as processing finishes; it is not stored permanently.
- Device and connection data: a randomly generated device ID, your IP address and basic request logs (for rate limiting and abuse prevention).
- Credit and transaction records: your credit balance and every balance movement (spend, refund, regeneration, purchase).
- Daily card: the card drawn for each day, the short reading generated for it, and your consecutive-use streak.
- Invite code record: the record linking the closed-beta invite code you used to your account.
- Content reports: if you report an AI output you find inappropriate, a copy of that text, the category you selected, any explanatory note you add, and the related question.
- Age and consent record: an audit record of your 18+ declaration, international AI-transfer preference, the notice version shown, and date and time.
Cookies and local storage
A first-party "mistera_session" cookie keeps you signed in. Preferences such as theme, language, onboarding state and ad frequency are kept in your browser's local storage. If you are signed in, a copy of your reading history is also cached in local storage for fast display; it is cleared from your device when you sign out or delete your account. We do not use third-party tracking cookies for advertising or analytics.
Why and on what legal basis do we process your data?
- Generating tarot and astrology readings, keeping the results you choose in history, and managing your account — performance of a contract (KVKK art. 5/2-c).
- E-mail verification, password reset and account security notices — performance of a contract and legitimate interest (KVKK art. 5/2-f).
- Rate limiting, fraud and abuse prevention — legitimate interest (KVKK art. 5/2-f).
- Providing a safe experience: before your messages are sent to the AI, they are automatically scanned for signals such as self-harm/crisis and statements of being under 18. This scan may surface a special-category signal such as health; that signal is not stored permanently and is used only to steer the immediate response (e.g. showing a support prompt) — legal obligation and the vital/fundamental interests of the data subject (KVKK art. 5/2-ç, art. 6).
- Reviewing content reports and preventing abuse — legitimate interest and legal obligation (KVKK art. 5/2-f, art. 5/2-ç).
- Compliance with legal obligations — KVKK art. 5/2-ç.
Who is your data shared with? (International transfers)
Mistera’s application server, database, error-tracking system, and e-mail infrastructure are hosted in Türkiye (Istanbul); your persistent data — including your account, reading history, and birth information — is not transferred abroad. International transfers are limited to the AI providers below that generate the readings, and are carried out under the applicable transfer condition and safeguards in KVKK art. 9. Separate explicit consent is requested before AI features and can be withdrawn in Settings; the consent record does not replace the data controller’s other obligations and safeguards under KVKK art. 9.
- Vulut Bilişim Teknolojileri (Türkiye, Istanbul): hosting of the application server, database, and e-mail infrastructure. This is domestic hosting, not an international transfer; your IP address is processed to serve the connection.
- OpenAI (US): tarot, chat, and astrology AI readings are generated with an OpenAI model by default. For this, your questions, the cards you pick or that are recognized from a photo, calculated planetary placements, your focus, or the message you send to the assistant are processed; card photos may be processed to recognize cards. Raw birth dates, locations, and coordinates entered temporarily for relationship compatibility are not sent. In addition, hard identifiers that may appear in your questions — phone numbers, e-mail addresses, national ID numbers, IBANs, and card numbers — are automatically masked before being sent to the AI.
- Groq (US): acts as a fallback/technical-failure provider when OpenAI is unavailable and processes the same AI inputs on some requests; card photos may be processed to recognize cards. The identifier masking above and the exclusion of raw compatibility data also apply to this provider.
- Google: authentication only if you sign in with Google.
Application error and crash logs are kept in our own error-tracking system on our own server, without being sent to any third party; request bodies and identity information are not written to these logs.
We do not sell your personal data to third parties and do not build advertising profiles. We may use anonymized or aggregated data that does not identify you for statistics and service improvement. If in the future we want to share your personal data with third parties for their own purposes, we will notify you in advance and, where required, obtain your separate explicit consent.
How long is your data kept?
Your account data, birth profile, calculated charts, and saved tarot/astrology readings are kept until you delete your account. A compatibility result you do not save is not written to persistent storage after the request. You can permanently delete your account at any time via Settings → Account → Delete account. In guest mode, data is linked only to a device ID. Records subject to legal obligations (e.g. transaction records) may be retained for the periods required by law. Internet access (traffic) logs are retained with integrity protection for the period required by Law No. 5651 and destroyed at the end of that period.
Content reports you submit are kept as a moderation record to prevent abuse. When you delete your account, these reports are anonymized so they can no longer be linked to you (your identity fields and free-text fields are removed); the content and category may continue to be retained for moderation purposes. Resolved reports are automatically deleted after a period of time.
Your rights under KVKK
Under KVKK art. 11 you have the right to:
- Learn whether your personal data is processed and request information about it.
- Learn the purpose of processing and whether it is used accordingly.
- Know the third parties to whom your data is transferred, in Türkiye or abroad.
- Request correction of incomplete or inaccurate data.
- Request erasure or destruction of your data.
- Object to a result produced against you exclusively by automated systems.
- Claim compensation if you suffer damage due to unlawful processing.
Send your requests to app.mistera@gmail.com; they are answered within 30 days at the latest.
Children's privacy
Mistera is intended for users aged 18 and over; we do not knowingly collect data from anyone under 18.
Changes
This policy may be updated from time to time. Significant changes are announced in the app; the current version is always published on this page.
The in-app version of this text: Open in the app