Last updated April 28, 2026

Privacy Policy

We take privacy seriously. This policy describes what data we collect, on which legal basis, how long we keep it, who processes it on our behalf, and how you can exercise your rights under the EU General Data Protection Regulation (Regulation 2016/679, the GDPR).

  1. 01Data controller
  2. 02What data we collect
  3. 03Legal basis for each processing purpose
  4. 04Retention periods
  5. 05Automated processing (Art. 13(2)(f) and Art. 22)
  6. 06Sub-processors and recipients
  7. 07International transfers
  8. 08Your rights under the GDPR
  9. 09Biometric data — Palmistry
  10. 10Cookies
  11. 11Data about other people
  12. 12Children
  13. 13Security
  14. 14Changes to this policy
  15. 15Contact

01Data controller

The data controller for personal data processed via karmogram.com is CyGuru Pharm SRL, registered in Romania (Trade Register registration pending, Tax ID RO52437696), with registered office at Branesti, str. Horia 33c, jud. Ilfov. General contact: hello@karmogram.com. Privacy and data-protection requests (including DPO inbox): privacy@karmogram.com. We respond to all rights requests within thirty (30) days, in line with GDPR Article 12(3).

02What data we collect

(a) Identification + reading inputs: full name, email, birth date, optional birth time and place, partner or team-member data you choose to enter, your written question or dream description. (b) Biometric data (only for Palmistry): a photograph of your palm. (c) Account/authentication: email, magic-link tokens, last sign-in timestamp. (d) Payment metadata returned by Stripe (card brand, last four digits, country, transaction ID — we never see the full card number). (e) Technical data captured for security, fraud prevention and analytics: IP address (truncated for analytics), user-agent, device class, locale, referrer, UTM parameters. (f) Communications you send us (email body, attachments).

04Retention periods

Session cookies (iron-session, signed): 30 days from last activity. Magic-link sign-in tokens: 15 minutes (single-use). Intake and reading data (your inputs and the generated reading): 3 years from delivery, then anonymised or deleted, in line with the limitation period for civil claims under Romanian law. Palm photographs: 30 days from upload (encrypted at rest, deleted by a daily prune job at 04:00 Europe/Bucharest). Email delivery logs (Resend): 30 days. Stripe transaction records and invoices: 7 years (mandated by Romanian Law 227/2015 on the Fiscal Code and Law 82/1991 on accounting). Product analytics events (PostHog, EU region): 12 months. Error events (Sentry, if enabled): 90 days. Support correspondence: up to 3 years.

05Automated processing (Art. 13(2)(f) and Art. 22)

Your reading is generated by an automated natural-language processing system (OpenAI; palm-reading uses Anthropic). The data we send to the system is the interview fields you submitted (name, birth data, your question, partner or team data if relevant) together with our editorial guidelines. Data sent to OpenAI's API is not used to train or improve any model and is retained by OpenAI for up to 30 days for abuse monitoring before deletion; palm-reading is processed by Anthropic. Generation is fully automated, but it does not produce decisions that have a legal or similarly significant effect on you (a Karmogram reading is reflective entertainment, not a legal, medical, financial, employment or insurance decision). You may at any time request human review of a delivered reading by writing to privacy@karmogram.com; we will respond within 30 days.

06Sub-processors and recipients

We share data only with the processors strictly needed to operate the service. Stripe Payments Europe (Ireland; processing servers in the United States) — payment processing. Transfer mechanism: EU Standard Contractual Clauses 2021/914 plus Stripe's adherence to the EU–US Data Privacy Framework. Resend (United States) — transactional and marketing email delivery. Transfer mechanism: SCC 2021/914 plus EU–US Data Privacy Framework. PostHog (European Union, eu.posthog.com) — product analytics; no international transfer. Sentry (United States, only when enabled) — error tracking. Transfer mechanism: SCC 2021/914 plus EU–US DPF. Vercel Inc. (United States, with EU edge regions) — application hosting. Transfer mechanism: SCC 2021/914 plus EU–US DPF. OpenAI, L.L.C. (United States) — automated natural-language generation of your reading, accessed through our backend; data sent via the OpenAI API is not used to train OpenAI's models and is retained by OpenAI for up to 30 days for abuse monitoring before deletion. Transfer mechanism: SCC 2021/914. Anthropic PBC (United States) — natural-language processing for palm-reading, accessed through our backend. Transfer mechanism: SCC 2021/914 plus EU–US DPF. If you give explicit consent to store your answers, your customer record, purchase and reading are held in a managed PostgreSQL database located in the European Union. We do not sell your data and we do not share it with advertising networks.

07International transfers

Where personal data leaves the European Economic Area (Stripe, Resend, Sentry, Vercel, OpenAI, Anthropic) the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, by the recipient's certification under the EU–US Data Privacy Framework. You may obtain a copy of the safeguards by writing to privacy@karmogram.com.

08Your rights under the GDPR

You have the right of access (Art. 15), rectification (Art. 16), erasure / right to be forgotten (Art. 17), restriction of processing (Art. 18), data portability (Art. 20 — you can ask for your data in a structured, machine-readable JSON file), and objection (Art. 21). Where processing is based on consent (Art. 6(1)(a) or Art. 9(2)(a)), you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing. To exercise any right, use the form at /privacy/erase or email privacy@karmogram.com. We respond within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro) or with the supervisory authority of your habitual residence.

09Biometric data — Palmistry

Palm photographs uploaded for the Palmistry reading are biometric data within the meaning of GDPR Art. 4(14) and Art. 9. We process them solely under your explicit consent (Art. 9(2)(a)) and only for the purpose of generating your Palmistry reading. We strip EXIF and location metadata from your image both client-side (in the browser, before upload) and server-side (defense-in-depth). Files are encrypted at rest with AES-256, never exposed via public URLs, accessed by the reading engine only via short-lived signed URLs (≤ 5 minutes), and deleted within 30 days by a daily prune job. You can request immediate deletion at /privacy/erase or by emailing privacy@karmogram.com.

10Cookies

By default we set only strictly-necessary cookies (the iron-session cookie, the CSRF token, the cookie-consent flag itself). Analytics cookies (PostHog) load only if you opt in via the cookie banner. We do not use third-party advertising cookies.

11Data about other people

If you submit personal data about another person (a partner for a Compatibility reading, founders, team members for a Team Compatibility reading, or anyone named in your question), you confirm that you have informed that person of the processing and that you have a lawful basis to share their data with us. We will, on request from such a person, exercise their GDPR rights under Article 14 in the same way as for our direct users.

12Children

Karmogram is intended exclusively for adults aged 18 or older. We do not knowingly process the personal data of minors. If you believe a minor has submitted data through the service, please report it immediately to privacy@karmogram.com and we will erase the data promptly.

13Security

Data in transit is protected by TLS 1.2+. The application runs on Vercel's infrastructure; where we store customer records and readings, they are held in a managed PostgreSQL database in the European Union, encrypted in transit. Secrets are managed through the hosting platform's encrypted environment and never committed to source control. Access to production data is restricted to named personnel and logged. We notify the supervisory authority and affected users within 72 hours of becoming aware of a personal-data breach, in line with GDPR Art. 33–34.

14Changes to this policy

When we make material changes to this policy we notify all account holders and recent customers by email at least fifteen (15) days before the changes take effect. Non-material changes are published with an updated revision date at the top of this page. The current version is dated April 28, 2026.

15Contact

Data controller: CyGuru Pharm SRL, Branesti, str. Horia 33c, jud. Ilfov. General inbox: hello@karmogram.com. Data protection inbox (DPO): privacy@karmogram.com. Romanian supervisory authority: ANSPDCP, dataprotection.ro.

Operated by CyGuru Pharm SRL (registration pending, CUI RO52437696), Branesti, str. Horia 33c, jud. Ilfov. Contract nr. 1/17.04.2026.