Privacy Policy
Last updated: February 2026
The short version. We don't sell or broker your data and we use no advertising SDKs or cross-app tracking. Void Tarot needs no account and keeps everything on your device or in your own iCloud — we never receive your readings. Simorgh is a marketplace, so it does need an account and a profile to connect you with other people; Section 2 covers what that involves.
This Privacy Policy explains how Wild Honey on The Porch LLC ("Wild Honey on The Porch," "we," "us," or "our") handles information in connection with our websites and mobile applications, including Void Tarot and Simorgh (each, an "App," and together with this website, the "Services").
Our Apps differ significantly in how much information they involve, so Sections 1 and 2 describe each one separately.
1. Void Tarot
No account, no server
Void Tarot has no sign-in, collects no email address, and sends no readings to us. On first open it asks for a display name and birth date. These are stored on your device, used only to personalize readings, and editable or removable in Settings. Birth time and birthplace are optional; if you provide a birthplace, it is resolved through Apple's MapKit search that you type yourself. The App does not request your current device location.
Readings are generated on your device
Interpretations are produced locally using Apple's on-device Foundation Models. Your questions, drawn cards, and journal entries are not transmitted to us or to any third-party AI service. The reading generator receives only derived labels — never your raw birth date, birth time, place, coordinates, or time zone.
Sync uses your iCloud, not our database
If you are signed in to iCloud, your readings, journal entries, and settings sync through your own private CloudKit database. That data lives in your Apple account under Apple's privacy terms. We cannot access, read, or recover it. Disabling iCloud for the App keeps everything local to the device.
Purchases
Paid spreads are sold through Apple's In-App Purchase system using StoreKit. Apple processes the transaction and we never see your payment details. We receive only the verified entitlement status needed to unlock what you bought.
2. Simorgh
Account and profile
Simorgh connects nomads with community hosts, which requires an account. We collect your email address and password credentials through our authentication provider, plus the profile information you choose to enter — display name, photos, skills, description, and role. Information you publish to your profile or a listing is visible to other users of the platform, by design.
Listings, requests, and messages
We store the communities, project calls, stay requests, availability, and messages you create so the marketplace can function. Messages are visible to the participants in that conversation and, where a report is filed, to authorized moderators.
Location
Communities and project listings have locations because that is what people are searching for; a host chooses what to publish. Beyond that, Simorgh requests your device location only when you actively use a feature that needs it, and only with your explicit permission.
The optional safety help feature shares only approximate location, with a specific limited audience, for a two-hour window, and you can cancel or revoke it at any time. It is opt-in and off unless you start it.
Trust and moderation
Reviews you write after a completed stay are visible to the platform. Reports you file are private and are visible only to authorized moderators — not to the person you reported. Blocks are private to you.
Notifications
If you enable push notifications, we store a device push token so we can deliver them. You can turn notifications off in the App or in your device settings at any time.
3. Information Collected Automatically
- Crash and diagnostic data. If you have enabled sharing of diagnostics with developers in your device settings, Apple or Google may provide us with aggregated, non-identifying crash reports and performance data. You control this in your operating system settings.
- Basic server logs. Where an App communicates with our servers, standard request logs (IP address, timestamp, request path) may be retained briefly for security and reliability, then discarded.
What we don't collect
- We do not sell, rent, or broker personal information.
- We do not use advertising networks, ad identifiers, or cross-app tracking.
- We do not build advertising or behavioral profiles.
- We have no copy of your Void Tarot readings or journal.
4. How We Use Information
We use the limited information described above only to:
- Provide, operate, and maintain the Services;
- Respond to your support requests;
- Diagnose crashes and fix bugs;
- Protect against fraud, abuse, and security threats; and
- Comply with applicable law.
We do not use your information for advertising, and we do not sell it.
5. Local-First Storage
Where an App can work without a server, we build it that way. In Void Tarot, content you create — readings, journal entries, and preferences — is stored on your device and, if you use iCloud, in your own private CloudKit database. Deleting the App deletes its local data, and we cannot recover it for you, because we never had it.
Simorgh is a marketplace and therefore necessarily server-backed: listings, requests, messages, and reviews have to be stored for other people to see them. Section 2 describes what that involves, and Section 10 covers how to request deletion.
If you have enabled your device's own backup service (such as iCloud Backup or Google Backup), App content may be included in backups controlled by you and governed by that provider's privacy policy, not ours.
6. Sharing and Disclosure
We do not sell or rent personal information. We share information only:
- With service providers who host or operate parts of the Services on our behalf, bound by confidentiality obligations and permitted to use the information only to provide services to us;
- With other users, where you have deliberately chosen to share something — for example, publishing a profile within Simorgh;
- For legal reasons, if we are required to do so by valid legal process, or where necessary to protect the rights, safety, or property of our users, the public, or us; and
- In a business transfer, if we are involved in a merger, acquisition, or sale of assets, in which case we will provide notice before personal information becomes subject to a different privacy policy.
7. Data Retention
We retain information only as long as needed for the purposes described in this policy. Locally stored content persists on your device until you delete it or remove the App. Support correspondence is retained for a reasonable period to maintain continuity of support and then deleted. Server logs, where they exist, are retained for a short period for security and reliability.
8. Security
We use reasonable technical and organizational measures appropriate to the limited data we handle, including encryption in transit for any network communication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our best security control is that we collect very little in the first place.
9. Children's Privacy
Our Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Because most of our data lives on your device, you can exercise many of these rights directly by editing or deleting content within the App.
For anything held by us, send us a privacy request and we will respond within the time required by applicable law.
California residents
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve months. California residents may exercise their CCPA rights using the contact address above, and we will not discriminate against you for doing so.
EEA, UK, and Swiss residents
Where the GDPR or UK GDPR applies, our legal bases for processing are the performance of a contract (providing the Services you request), our legitimate interests (security, reliability, and support), your consent (where requested, such as for optional permissions), and compliance with legal obligations. You have the right to lodge a complaint with your local supervisory authority.
11. International Transfers
We operate from the United States. Where information is transferred internationally, we take steps to ensure it receives an appropriate level of protection consistent with applicable law.
12. Third-Party Links and Services
Our Services may link to third-party sites, such as GitHub or the App Store. Those services are governed by their own privacy policies, and we are not responsible for their practices.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be highlighted within the affected App or on this page before taking effect.
14. Contact Us
Wild Honey on The Porch LLC