Privacy Policy
Ryoma Services LLC ("we," "us," or "our") operates Arcana Solitaire at arcanasolitaire.com. This Privacy Policy explains what information we collect, how we use it, and your rights.
1. Information We Collect
1.1 Information You Provide: Account info (name, email, Google profile picture via Google OAuth). Optional Threads of Fate inputs: a name, a free-text intention, and a life-area choice. You can leave all of these blank. Support communications if you email us. If you buy without an account, Stripe collects an email address at checkout so the receipt and the purchase can be tied to that payment. You do not need an Arcana account to buy. Section 3 describes which of these inputs are sent to Anthropic.
1.2 Automatically Collected: Gameplay data (game outcomes, move counts, session duration, Sanity Vials used, Essence scores, game seed for CS reconstruction). Vial activation events (move number, sanity before/after, remaining vials — retained for CS dispute resolution only). Usage analytics via PostHog (events transmitted through arcanasolitaire.com/ingest proxy). Anonymized session-replay and heatmap data via Microsoft Clarity (on-screen interactions during play, with sensitive input fields masked). Ad-conversion measurement via Microsoft Advertising (Bing), the Meta (Facebook/Instagram) Pixel, and the TikTok Pixel when you arrive from — or to measure the performance of — one of our ads. These pixels send limited event data (for example, that a game was started) to those platforms so we can measure how our ads perform; the platforms may also use this data to optimize delivery of our ads on their services. Standard web server logs (IP address, browser type — used for security only, not advertising).
1.3 Payment Information: We do not collect or store payment card details. Stripe handles all payment processing, including the email address it collects when you check out without an account. We receive transaction confirmation, SKU, amount, and Stripe payment ID. We do not copy that guest email into our own database. When you buy a continue for the round in progress, we send Stripe the anonymous analytics id, the game seed, and any UTM tags from the visit, as Checkout metadata, so the payment can be matched to that round. We do not send your name, your intention, or your card number to Stripe as metadata.
2. How We Use Your Information
To operate the Game and your Account; process purchases and credit Sanity Vials or a paid continue in the round you bought it for; investigate and resolve CS disputes; detect and prevent fraud; send transactional communications; analyze aggregate usage to improve the Game; comply with legal obligations.
We do NOT sell or rent your personal information for money, and we do NOT let third parties use your information for their own independent marketing. To measure and improve our own advertising, we share limited event data (for example, that a visitor started a game) with our ad platforms — Microsoft (Bing), Meta, and TikTok — through their measurement pixels; those platforms may also use this data to optimize delivery of our ads. Under some privacy laws (such as California's CCPA/CPRA) this pixel-based sharing may be considered "sharing" for cross-context behavioral advertising.3. Third-Party Services
| Service | Purpose |
|---|---|
| Google OAuth | Account sign-in |
| Stripe | Payment processing |
| Supabase | Game data storage (US servers) |
| PostHog | Usage analytics |
| Microsoft Clarity | Anonymized session replay and heatmaps to improve gameplay (no personal info; sensitive content masked) |
| Microsoft Advertising (Bing) | Conversion measurement for our ads (counts how many visitors start a game or purchase — used to measure ad performance, not to target you) |
| Meta (Facebook/Instagram) Pixel | Conversion measurement and delivery optimization for our ads on Meta (shares limited event data such as that a game was started; Meta may use it to optimize delivery of our ads) |
| TikTok Pixel | Conversion measurement and delivery optimization for our ads on TikTok (shares limited event data such as that a game was started; TikTok may use it to optimize delivery of our ads) |
| Vercel | Website hosting |
| Anthropic (Claude API) | Writes the in-game end-of-game Oracle text from the round you just played (details below) |
When a game ends, our server sends Anthropic one prompt for the sole purpose of writing that Oracle text. The prompt contains:
Card themes. The keyword meanings of your three fate cards, in past, present, and future order. Each meaning is a short theme phrase tied to that card, such as "hope, faith, rejuvenation, spiritual healing."
How the round ended. A short phrase the game itself writes, describing how the round ended.
Your question. If you type an intention, we send that text. Choosing a life area — Love, Career, Health, Money, Family, Change, Shadow, or Purpose — fills the intention with a set phrase for that area, and we send that phrase together with the life-area label. On the full Threads of Fate screen, the intention box may already contain the question shown above it; we send whatever you leave in the box. If the intention is empty and you chose no life area, we send the focus question the game selected for the round (the line shown on the Threads of Fate screen). If that question is empty, we send the line "What does the universe hold for me?"
A name, when the name field has one. You may type a name. If you are signed in with Google and you open the full Threads of Fate screen, we place your Google account name in that field when it is empty. We send the name still in the field when the game ends. "Read without a name," or an empty field, means the prompt includes no name.
The name, the intention, and the life-area choice are optional. You can play, and still receive the Oracle text, without providing any of them.
Do not enter sensitive personal information in the name or intention fields. That includes health details, government identification numbers, and financial account numbers.
5. Children's Privacy
The Game is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact support@arcanasolitaire.com if you believe a child under 13 has used the Game.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until deletion requested |
| Game session records | 2 years |
| Vial activation events | 2 years |
| Purchase records | 7 years (tax/accounting) |
| Support correspondence | 2 years from resolution |
| Analytics data (PostHog) | ~1 year |
7. Data Security
We implement reasonable security measures including HTTPS, JWT authentication, and database access controls. No method of internet transmission is 100% secure.
8. Your Rights
8.1 All Users: Request a copy of your data; request correction; request deletion. Email support@arcanasolitaire.com. We respond within 30 days.
8.2 California Residents (CCPA): Right to Know, Right to Delete, Right to Opt Out of Sale (we do not sell data), Right to Non-Discrimination. Submit CCPA requests to support@arcanasolitaire.com with subject "CCPA Request."
9. Data Transfers
We are based in the United States. Data from users outside the US is transferred to and processed in the US.
10. Changes to This Policy
We may update this policy periodically. The "Last updated" date above reflects the most recent revision.
11. Contact
Email: support@arcanasolitaire.com | Operator: Ryoma Services LLC | arcanasolitaire.com/privacy