✦
← Back

Privacy Policy

Effective date: September 6, 2026

TeamCat (the "Company") treats your personal information with care and processes only the minimum necessary. This Policy has been prepared in compliance with the Personal Information Protection Act of the Republic of Korea (PIPA), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA), and the Act on the Protection of Personal Information of Japan (APPI). The Service has no sign-up and no login. It does not collect your name, email address, telephone number, date of birth, or payment details, and it creates no account that identifies you. What follows describes only the information the Company actually processes on that basis.

Article 1 (Data Controller)

Responsibility and authority for the processing of personal information in the Service rest with the following business.

Data controller: TeamCat

Representative: Hyungjun Park

Business registration number: 705-17-02663

Mail-order sales registration number: Not yet registered

Place of business: 4F, 443-98 Beon-dong, Gangbuk-gu, Seoul, Republic of Korea

Privacy officer and contact: admin@taro.teamcat.app

Service domain: taro.teamcat.app

Where no separate privacy officer has been designated under applicable law, the representative serves in that role.

Article 2 (Information Collected)

The following is the entirety of what the Company processes.

1. Information you enter yourself

Your question: a sentence you may optionally enter when beginning a reading. It is not required, and a reading proceeds normally if you leave it blank. Where you request an AI in-depth reading, this sentence is transmitted to an external AI inference provider.

The Company advises against entering personal information in your question. Do not write real names, contact details, addresses, national identification numbers, health conditions, financial circumstances, or information about other people. The Company is under no obligation to screen or filter what you enter.

2. Information stored in your browser

Language preference cookie: a single cookie that remembers the display language you chose. Its value is a language code (e.g. ko, en) and nothing that identifies you.

3. Information generated automatically when you connect

Server and network logs: IP address, time of access, requested path, browser and operating system, and response status. These are generated to keep the Service running, to diagnose errors, and to block malicious requests.

4. Information the Company does not collect

The Company does not collect names, email addresses, telephone numbers, dates of birth, gender, postal addresses, payment details, location data, contact lists, or device identifiers. Only where you write to the Company directly does it process your email address and the content of your message.

Article 3 (Purposes of Processing and Legal Bases)

The Company processes the information collected only for the purposes below. The legal basis under Article 6 of the GDPR is given in parentheses.

Providing readings and interpretations: generating and delivering the interpretation of the card layout you requested, including the AI in-depth reading. (Article 6(1)(b) β€” performance of a contract)

Maintaining your display language: presenting the Service in the language you chose. (Article 6(1)(b) β€” performance of a contract)

Operating and securing the Service: diagnosing errors, responding to incidents, blocking automated abuse, and protecting server resources. (Article 6(1)(f) β€” legitimate interests)

Responding to enquiries: answering messages and requests to exercise rights. (Article 6(1)(f) β€” legitimate interests)

Complying with legal obligations: retention required by law and response to lawful requests from authorities. (Article 6(1)(c) β€” legal obligation)

The Company does not process your information for advertising, profiling, or targeted marketing. It carries out no automated decision-making producing legal effects concerning you or similarly significantly affecting you. Generating an interpretation is content creation you requested yourself; it is not a procedure that evaluates or classifies you.

Article 4 (Storage of Generated Interpretations)

To avoid generating the same interpretation twice for an identical request, the Company stores generated interpretations on its server. What is stored is the text of the interpretation, the language used, the type of spread, and the time of generation.

Stored interpretations are not linked to the User who requested them. The Company does not store IP addresses, cookie values, or any other identifying information alongside them, and maintains no means of tracing a stored interpretation back to an individual.

If you write something identifying about yourself in your question, that content may be reflected in the interpretation and stored with it. This is precisely why Article 2 advises against putting personal information in your question.

Article 5 (Processors and Disclosure to Third Parties)

The Company does not sell your information and does not share it for marketing purposes. It entrusts processing to the following, to the minimum extent necessary to provide the Service.

External AI inference provider: only where you request an AI in-depth reading, the fixed cards, positions, and orientations, your question, and the requested language are transmitted to that provider, which generates the interpretation. The Company does not send your IP address, cookies, or any other identifier with the request. The provider's servers may be located outside the Republic of Korea, and the provider's own data handling policy applies. If you do not request an AI in-depth reading, nothing is transmitted outside and you receive the base interpretation only.

Network and security infrastructure provider: the Service passes through an external provider's edge infrastructure for distributed denial-of-service protection and secure (TLS) connections. That provider processes connection metadata such as IP addresses for routing and security inspection, and does not persistently retain the content of the Service.

The Company's application servers and its store of generated interpretations run on infrastructure under the Company's control located in Seoul, Republic of Korea.

The Company may disclose information to investigative or supervisory authorities only where they follow the lawful procedures prescribed by law.

Article 6 (Cross-Border Transfers)

The Company's main servers are in Seoul, Republic of Korea. Requests and connection information from Users outside Korea are therefore transferred to Korea for processing.

Residents of the EU and the UK: in December 2021 the European Commission granted the Republic of Korea an adequacy decision under the GDPR. Personal data of European residents may therefore be transferred lawfully to Korea without separate standard contractual clauses, and the Company complies with the supplementary rules issued by the Personal Information Protection Commission of Korea.

Residents of Japan: Japan and Korea recognize each other's adequacy, and the transfer is made on the basis of your agreement to this Policy in accordance with the cross-border provisions of the APPI.

When using AI in-depth readings: as described in Article 5, your question and card layout may be transmitted to an AI inference provider that may be located outside Korea. You can avoid this transfer by not requesting an AI in-depth reading; the base interpretation is still provided in full.

Article 7 (Retention and Deletion)

The Company deletes information without delay once the purpose of processing has been achieved. Retention periods by category are as follows.

Your question: used only for the one-off processing needed to generate an interpretation, and not separately stored on the Company's servers. Its substance may nonetheless remain reflected in the stored interpretation under Article 4.

Generated interpretations: retained to avoid regenerating them, and deleted when they are no longer needed operationally or when the interpretive method changes.

Language preference cookie: stored in your browser for up to one year. You may delete it at any time from your browser settings.

Server and network access logs: retained for up to 90 days for incident response and error analysis, then deleted. Where the Protection of Communications Secrets Act or other applicable law prescribes a longer period, that period applies.

Email enquiry records: retained for three years after the enquiry is closed, then deleted.

Electronic records are erased by technical means that make recovery impossible; any printed material is shredded.

Article 8 (Your Rights and How to Exercise Them)

Regardless of where you live, you have the right of access, the right to rectification, the right to erasure, the right to restrict or object to processing, the right to data portability, and the right to withdraw consent.

You may exercise these rights by writing to admin@taro.teamcat.app. The Company will inform you of the outcome within one month (EU standard), 45 days (California standard), or 10 days (Korean standard) of receiving your request.

Because the Service keeps no accounts, however, the Company holds no means of connecting a particular requester to the records remaining on its servers. When requesting access or erasure, please include information that identifies the target β€” the time of access and the IP address used, for example. Without it the Company may be unable to identify your records and therefore unable to act on the request. This is a consequence of the Company not tracking you.

The fastest way to remove the language preference cookie is to delete it yourself in your browser.

You have the right to lodge a complaint about the Company's processing with the Personal Information Protection Commission of Korea, the Korea Internet & Security Agency privacy report center (privacy.kisa.or.kr), or the supervisory authority in your country of residence.

Article 9 (Additional Notice for California Residents)

Residents of California are given the following additional notice under the CCPA and CPRA.

No sale, no sharing: the Company has not sold your personal information for monetary or other valuable consideration in the preceding 12 months, nor shared it for cross-context behavioral advertising, and has no plans to do so.

Sensitive personal information: the Company does not collect statutory sensitive information such as race, ethnicity, religion, sexual orientation, genetic data, or precise geolocation. If you write such content into your question yourself, it is processed solely to generate the interpretation you requested and is never used to profile you.

Non-discrimination: the Company will not degrade the quality of the Service or restrict your use of it because you exercised a privacy right.

Article 10 (Children's Personal Information)

The Service is not directed at children under 14 (or under 13 or 16, in certain jurisdictions including parts of the EU), and the Company does not knowingly collect their personal information.

If the Company learns that a child's personal information is being processed without the consent of a legal guardian, it will delete that information without delay. A guardian may contact the address above to confirm and request deletion.

Article 11 (Cookies and Similar Technologies)

The Company uses a single strictly necessary cookie, which remembers your display language. It exists so that the Service can operate in your language and serves no advertising or analytics purpose.

The Company uses no third-party advertising cookies, web beacons, pixels, advertising identifiers, or cross-site tracking technologies, and embeds no external analytics tools in the Service.

You may refuse or delete cookies in your browser settings. The Service remains fully usable if you refuse the language cookie; your display language will simply be determined afresh from your browser settings on each visit.

Article 12 (Security Measures and Changes to This Policy)

The Company protects the information it processes by encrypting all traffic between your browser and its servers with HTTPS/TLS, restricting access to servers and stores to the minimum number of people whose work requires it, and minimizing the categories of information collected in the first place, which structurally lowers the risk of any breach.

This Policy may be revised as the law or the Service changes. The Company will announce any change on the Service at least 7 days before it takes effect, and at least 30 days in advance where the change materially affects your rights.

In the event of a data breach, the Company will notify affected data subjects and the competent supervisory authority without delay as required by law.

Contact

Please send privacy enquiries and requests to exercise your rights to the address below.

admin@taro.teamcat.app