**Effective date:** [LAST_UPDATED_DATE]
**Application:** MysticPath (package: `com.magic.life.palm_reader`)
**Platform:** Android (Google Play)
> **Before publishing on Play Console:** Replace `[LEGAL_ENTITY_OR_INDIVIDUAL]`, `[PRIVACY_CONTACT_EMAIL]`, and the effective date with your real information. Host this document at a **public URL** (GitHub Pages, your website, etc.) and paste the link in **App content → Privacy policy** in Play Console.
---
MysticPath is an app for **entertainment and personal reflection** (symbolic palm reading, horoscopes, tarot, sign compatibility, and conversational guidance). We respect your privacy. This policy explains **what data** may be processed, **why**, which **third parties** are involved, and **your choices**.
The app is **not** intended for medical diagnosis, legal or financial advice, or to replace professional care.
---
- **Data controller:** [LEGAL_ENTITY_OR_INDIVIDUAL]
- **Privacy contact email:** [PRIVACY_CONTACT_EMAIL]
For privacy requests (access, deletion, questions), please email the address above.
---
| Data | Purpose |
|------|---------|
| **Date of birth** (optional) | Derive zodiac sign and personalize entertainment content (horoscope, compatibility, etc.). |
| **Sign identifier / label** | Stored in your local profile for display in the app. |
| **Language / locale** | Show the UI and content in the correct language. |
| **Content you type** (e.g. chat messages) | Sent to a third-party AI service when the feature is enabled and the device is online (see Section 4). |
| Permission / source | Purpose |
|---------------------|---------|
| **Camera** | Used only when you open the capture flow for symbolic palm reading. You may deny permission; the camera feature will not work without it. |
| **Internet** | Calls the AI provider’s API (Google) when the app is built with an API key and you use network-dependent features (AI chat, optional palm text enrichment, optional AI tarot summary). Some tarot/horoscope content may work offline depending on the feature. |
- Images are stored **temporarily** in the app’s **internal cache** on the device to support the palm-reading session and, where applicable, to be included in requests to the AI service to generate **entertainment-only** text—not medical analysis or biometric identification.
- The app **does not verify** whether the image is actually a hand.
- Cache may be cleared by the operating system or when you clear app data / uninstall.
On the device, the app may store:
- **User preferences** (DataStore): onboarding state, disclaimer acceptance, locale, date of birth, sign, daily free-chat allowance, etc.
- **In-app “credits” balance** (DataStore) used to unlock certain content or messages as designed in the current app.
- **Chat response cache** (Room database on device): keys derived from context (e.g. sign, locale, normalized question text) and **AI response text**, to reduce duplicate API calls; intended as **short-term** storage (e.g. on the order of **24 hours** per app logic).
**Note:** The current version **does not** require an email address or phone number in the app for core features.
---
When the app integrates **Google Gemini (Generative Language API)** and a **valid API key** is configured, the following flows may **transmit data over the internet to Google’s servers**:
1. **Chat:** text you send, recent conversation context (limited number of turns), sign-related information, and locale—to generate text replies.
2. **Palm reading (some text):** your sign label and the **captured image** (as a downscaled/processed bitmap on the client) may be sent to generate entertainment-oriented copy.
3. **Tarot (three-card spread):** card names, upright/reversed state, short meanings already present in the app, locale, and optional sign context—to generate a short combined reading.
Processing on Google’s side is governed by **Google’s privacy policy and terms** for the AI / API products you use. We encourage you to read the latest documentation on Google’s developer and AI sites.
We **do not sell** your personal information to third parties in the sense of commercial bulk data sales.
---
- Operate and display in-app features.
- Personalize entertainment content using date of birth / sign (if you provide them).
- Run AI-powered features when you choose to use them and the device is online.
- Improve technical experience (local caching, fewer duplicate API calls).
---
Depending on where you live, legal bases may include: **performance of a contract / provision of the service**, **consent** (when you grant permissions or submit content), and **legitimate interests** (security and proportionate service improvement). You may withdraw consent by revoking camera permission, clearing app data, or stopping use of the relevant features.
---
- Data in **DataStore / Room** on the device remains until you **clear app data**, **uninstall** the app, or use in-app reset/clear functions (if available).
- Local chat response cache may be overwritten or expire per app logic.
- Data sent to **Google** is handled under Google’s policies; we do not control Google’s servers.
---
When you use Google services, data may be processed on **servers in countries/regions** where Google operates. By using network AI features, you acknowledge cross-border transfer practices typical of cloud AI providers.
---
Where applicable law provides them, you may:
- **Access or update** personalization data (e.g. birth date, language) through in-app settings.
- **Delete local data** using in-app clear/reset or Android **Settings → Apps → MysticPath → Clear storage**.
- **Revoke Camera** permission in system settings.
- **Contact** [PRIVACY_CONTACT_EMAIL] for further assistance.
---
MysticPath is **not directed** at children under **13** (or the minimum age required in your jurisdiction). We do not knowingly collect data from children. If you are a parent and believe your child has provided data, please contact us so we can help delete it where reasonable.
---
We use reasonable technical measures (e.g. **HTTPS** to APIs, local storage on your device). No system is perfectly secure; protect your device with a lock screen and OS updates.
---
We may update this policy when we add features or when the law requires. The **Effective date** at the top will change. For material changes, we will provide reasonable notice (e.g. in the app or on the page hosting this policy).
---
Use the table below when completing **Data safety** in Play Console (adjust if you change the app):
| Data type | Collected? | Shared? | Primary purposes |
|-----------|------------|---------|------------------|
| **Personal info** — date of birth, sign-related info | Yes (optional) | Not sold; **sign/locale context** may be sent to **Google** when calling AI | Personalization, AI features |
| **Photos and videos** — camera image (hand) | Yes (when you capture) | May be sent to **Google** when using AI palm text enrichment | Palm feature / entertainment copy |
| **App activity** — chat text you enter | Yes (when you send a message) | May be sent to **Google** (Gemini) | AI chat |
| **Financial info** | Not collected in-app as described here (no card/bank details in this design) | — | — |
**Encryption in transit:** Yes (HTTPS to the API).
**Deletion requests:** Users can clear on-device data or contact support email.
---
Content in MysticPath is for **entertainment only**. It is not medical, legal, financial, or professional psychological advice.
Thanks for Reading, and contact support to : dev.fromwhere@gmail.com