Last updated: 10 August 2026
This notice explains what data Mago Lucas collects, why we collect it and what you can do to control it. It is written to be read: if anything is unclear, write to us and we will explain.
It covers magolucas.com and every service on it: tarot readings, horoscopes, natal charts, rising sign and couple compatibility.
Who processes your data
The data controller is [RAGIONE SOCIALE], registered office at [INDIRIZZO], VAT number [P.IVA].
For anything concerning your personal data, write to [EMAIL PRIVACY].
Data protection officer (DPO): [DPO].
What data we collect
Data you give us for an account
First name, last name, email address and a password. The password is never stored in readable form: we keep only a cryptographic hash of it (bcrypt), from which the original password cannot be recovered.
With your account we also store your preferred language, the tarot deck you chose, the invite code you signed up with, if any, and your email preference.
Data you give us to use the services
For tarot readings: the text of the question you ask. That is all.
For astrology services: date, time and place of birth, sex, and the name you want to appear in the text. Couple compatibility needs the same details for the second person too.
Data generated by using the site
- The texts generated for you (readings, horoscopes, natal charts) and the cards drawn.
- Your credit ledger: how many credits you received, bought and spent, and on which service.
- Your login sessions, with the date, the IP address and the browser you connected from. These keep you signed in and let you spot a suspicious login.
- The likes you give to public content.
Payment data
We never see your card details. Payments are handled entirely by Stripe, an authorised payment institution. We only keep a Stripe customer identifier plus the amount and date of the purchase, which we need for invoicing and to credit your account.
What we do not do
We do not use Google Analytics or any other statistics or tracking system. We do not use advertising pixels. We do not profile visitors. We do not sell or share your data with anyone for marketing purposes.
Why we process it, and on what legal basis
To provide the service — creating and managing your account, generating the readings and horoscopes you ask for, keeping track of credits, sending you service emails (address verification, password reset, purchase confirmation).
Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
For special category data you volunteer in your questions — if your tarot question mentions your health, your love or sex life, your religious beliefs or your personal financial situation, you are providing what the GDPR calls "special categories of personal data".
Legal basis: your explicit consent, Art. 9(2)(a) GDPR, given by voluntarily writing that text after reading this notice. You can withdraw it at any time by asking us to delete the reading.
Please read the section Be careful what you write in your questions below: our advice is not to include such data at all.
To keep the site secure — detecting and blocking unauthorised access attempts, abuse, credit fraud and automated use of the service.
Legal basis: our legitimate interest, Art. 6(1)(f) GDPR. The interest is protecting the service and its other users; for this purpose we process only technical data, and only for short periods.
To meet accounting and tax obligations — issuing and keeping sales records.
Legal basis: legal obligation, Art. 6(1)(c) GDPR.
To send you messages that are not necessary to the service — if and when we do, it will only be with your consent, which you can withdraw at any time.
Legal basis: consent, Art. 6(1)(a) GDPR.
Artificial intelligence: what happens to your text
The readings, horoscopes and interpretations you read on this site are written by an artificial intelligence language model, not by a person. We have a whole page about this: AI transparency.
Here we cover the part that concerns your data.
What reaches the model provider
To generate a tarot reading we send the model provider:
- the text of your question, exactly as you wrote it;
- the cards drawn and their meanings;
- the language you want the answer in.
For astrology services we send the name you entered, the reference date and the planetary positions already calculated on our server.
We never send your email address, your last name, your password, your payment details or your IP address. The provider has no way of linking the request to your identity.
Who the provider is and in what role
The model is supplied by a third-party company (currently OpenAI; we may change provider, and we will update this page if we do). The provider acts as a data processor under Art. 28 GDPR, under an agreement that prohibits it from using the data for its own purposes.
Your text does not train the models
We use the provider's paid programming interface (API). Under the contractual terms the provider applies to this mode of use, data sent through the API is not used to train or improve its models. The provider may retain it for a limited period solely to detect abuse and policy violations, after which it is deleted.
This depends on the provider's contractual terms, which are outside our control. We review them periodically and will tell you if they change.
Transfers outside the European Union
The model provider is based in the United States and requests may be processed there. The transfer relies on the safeguards set out in Chapter V of the GDPR: the Standard Contractual Clauses approved by the European Commission and, where applicable, the provider's participation in the EU-U.S. Data Privacy Framework.
In the United States, public authorities may in certain cases access data under powers different from those in Europe. We tell you this so that you know it before writing anything sensitive.
Be careful what you write in your questions
This is the most important part of this notice. Please read it.
Do not write in your questions:
- data about your health or anyone else's (diagnoses, treatments, illnesses, pregnancies, addictions);
- data about your sex life or sexual orientation;
- religious beliefs, political opinions, trade union membership, ethnic origin;
- criminal offence data, yours or anyone else's;
- the name, surname or any detail that makes a person other than you identifiable.
A question works perfectly well without any of that. "How will things go with the person I am seeing?" gets exactly the same reading as a question full of names and details, and leaves nothing sensitive behind.
What happens if you do it anyway. The text is stored in our database and sent to the model provider like any other question. If it contains special category data, you are providing it voluntarily and the processing rests on the explicit consent described above. An automated check flags questions touching sensitive areas (requests for medical diagnoses, serious legal advice, matters concerning identifiable third parties); in those cases the answer is generated more cautiously and the reading is marked for review. But it is an automated filter: it is not infallible, and it cannot unwrite what you have already written.
If you realise you wrote something you did not mean to, write to [EMAIL PRIVACY] with the address of the reading and we will remove it.
Tarot readings are public
We say this plainly, because it is a feature of the service and not a technical detail.
Tarot readings are published on the site by default. They go into the public archive, anyone who knows their address can open them, and search engines index them. The site holds around 6,000 public readings imported from the previous version of Mago Lucas.
What a public reading shows: the question as it was written, the cards drawn, the generated text, the date and the category.
What it does not show: your first name, your last name, your email, your IP address. Nothing publicly connects a reading to you. But if your question itself contains something that identifies you, that stays visible: you control what goes into the text.
How to ask for removal. Write to [EMAIL PRIVACY] with the address of the reading (the last part of the URL). We will make it private or delete it, as you prefer. It costs nothing and we will not ask you to justify the request.
Astrology content is not public. Personal horoscopes, natal charts, rising sign and couple compatibility do not appear in the archive and are not indexed by search engines: only someone with the exact address can open them. The exception is the daily horoscope by sign, which is generic and about no one in particular.
Cookies
We use two cookies, both strictly technical, and neither profiles you. They are described in detail in our Cookie policy.
Who we share data with
- The artificial intelligence model provider, to generate the texts (see above).
- Stripe, to handle payments. Stripe acts as an independent controller for anti-money-laundering and fraud prevention.
- Our email service provider, to deliver service emails.
- Our hosting provider, which runs the site and the database.
- Our accountant and advisers, for tax compliance.
- Public authorities, only where the law requires it.
We have an Art. 28 GDPR agreement in place with every supplier that processes data on our behalf. An up-to-date list of processors is available on request from [EMAIL PRIVACY].
How long we keep data
- Account data (name, email, preferences): for as long as your account is active. When you delete it, this data goes.
- Login sessions (IP, browser): 12 months from login, or less if you sign out sooner.
- Readings and horoscopes linked to your account: for as long as your account is active. When you delete the account they are detached from you (see below).
- Anonymous public readings: they stay online indefinitely, because they are part of the site archive and contain no identifying data. You can ask for their removal at any time.
- Credit ledger: for as long as your account is active, and in any case for as long as we may need to answer a dispute.
- Tax documents and billing data: 10 years, as Italian law requires.
- Technical and security logs: 12 months.
If you delete your account
You can delete your account yourself, from your profile page, without asking our permission. It takes your password and a typed confirmation, because it cannot be undone.
Exactly what happens:
- Deleted: your first name, last name, email, password hash, preferences, sessions, credit ledger (including any unspent credits, which are lost) and your likes.
- Anonymised: the readings and horoscopes you generated. The link to your account is set to null and the texts stay online with no reference to you left.
Why not delete them outright? Because public readings have addresses that search engines have indexed for years, and deleting them would break the site archive — while, once detached, they no longer contain any personal data. If you want the texts deleted and not merely anonymised, write to [EMAIL PRIVACY] before deleting your account, or afterwards giving us the addresses of the readings: we will do it.
Your rights
The GDPR gives you rights. They are not boilerplate: they work, and you can use them.
- Access — find out what data we hold about you and get a copy.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted, in the cases the law provides for.
- Restriction — ask us to freeze a processing operation while a question is being settled.
- Portability — receive the data you gave us in a machine-readable format, or have it sent to another provider.
- Objection — object to processing based on our legitimate interest.
- Withdrawal of consent — take back a consent you gave, at any time, without affecting what was done before.
How to use them, in practice
On your own, on the site, without asking anyone:
- correct your name, surname, language and deck: profile page;
- change your email address: profile page, with confirmation on the new address;
- change your password: profile page;
- stop receiving non-essential emails: the preference in your profile, or the link at the bottom of every email;
- delete your account and everything attached to it: profile page, section at the bottom.
By writing to [EMAIL PRIVACY] for everything else: a copy of your data, portability, removal of a single reading, objection, or simply to ask a question.
We reply within one month, as Art. 12 GDPR requires. If the request is complex we may take two more months, but we will tell you within the first month. We do not charge, except for manifestly unfounded or repetitive requests.
Complaining to a supervisory authority
If you think we are handling your data improperly, you can complain to the Italian data protection authority, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy, www.garanteprivacy.it. You may also complain to the supervisory authority of the EU member state where you live or work, or go to court.
We would be grateful if you tried us first: it is almost always sorted out in two emails.
No automated decision-making about you
Under Art. 22 GDPR: we do not take automated decisions that produce legal effects concerning you or similarly significantly affect you.
Readings, horoscopes and natal charts are entertainment content. They do not assess your creditworthiness, your suitability for a job, your health or anything else that could affect your rights. We do not profile your personality and we do not use what you write to make decisions about you.
The only automated check we run is the one described above: a classification of the question, used to choose the card spread and to flag sensitive topics. It has no effect on you as a person.
Minors
The service is for people aged 18 or over. We do not knowingly collect data from minors. If we find that an account belongs to a minor we close it and delete the data. If you are a parent or guardian and believe a minor has given us their data, write to [EMAIL PRIVACY] and we will act immediately.
Security
Passwords are protected with bcrypt. Traffic to the site is encrypted over HTTPS. Session cookies cannot be read by JavaScript and are limited to our domain. Database access is restricted to the application.
No system is invulnerable. If a breach occurs that poses a risk to your rights, we will tell you and notify the supervisory authority within the legal deadlines (Arts. 33 and 34 GDPR).
Changes to this notice
If we change something substantial — a new supplier, a new purpose, a change in how we handle your texts — we update this page and change the date at the top. If the change affects you materially, we will email you.
Contact
Controller: [RAGIONE SOCIALE], [INDIRIZZO], VAT [P.IVA].
Email for personal data matters: [EMAIL PRIVACY].
General email: [EMAIL TITOLARE].
See also: Terms of use · Cookie policy · AI transparency