← Language

Sabio Tarot · Responsible readings

Privacy in a Written Tarot Reading: What to Share and What to Keep

A hand writes in a journal beside four illustrated cards and a cup of tea.
Illustrative scene of a person recording observations beside four fictional cards. Original illustrative image; it does not document a real reading or reproduce a historical deck.

A written consultation can gather a name, email address, personal narrative, questions about third parties, and photographs of a spread. Not all these data are necessary to answer. Before requesting them, the person offering the reading should know what each field is needed for, where the message will go, who will be able to see it, and when it will stop being retained. The person consulting, in turn, can choose how much context to reveal. A good reading does not require an intimate dossier.

This page offers practical criteria, not a particular privacy policy or legal advice for all countries. The applicable rules depend on the place and the service. In the European Union, the European Data Protection Board explains data minimization and privacy by design: by default, only what is necessary for each purpose should be processed. It also reminds us that an organization must clearly inform people about processing and must not retain data indefinitely in its guide for small businesses. The specific implementation of the service must be reviewed with its providers and its applicable regulations.

A Useful Question Requires Less Data Than It Seems

Compare two fictitious messages. The first includes the full name of an ex-partner, address, workplace, screenshots of conversations, and a long story. The second says: “I want to think about how to prepare a conversation about boundaries after a breakup; I prefer not to share the other person's data.” For a symbolic reading focused on what the person consulting can decide, the second message usually offers enough context. It is not necessary to know who the third party is in order to frame a respectful question.

The reader can ask for clarification if the question is too broad: “Do you want to explore how to talk, what boundary you need, or what support would help you now?” That question improves the reading without requesting names or documents. In many cases, an initial or a generic description is enough to keep the thread. If the person introduces sensitive data on their own initiative, it does not mean the service has to copy it into a permanent record.

It is also not advisable to promise that the deck will reveal the thoughts of an absent person. That promise encourages sharing more private information about third parties and, even so, does not turn the interpretation into a fact. You can frame the work from the perspective of the person consulting: “What do you need to ask or decide?” The change reduces data and improves the scope of the response.

Map the Path of a Message Before Offering the Form

A form does not end on the website. It may pass through the form provider, an email inbox, backups, and a support system. If you sell a reading on an external platform, that platform's terms also affect the exchange. Whoever administers the service should make a simple map: input → provider → people with access → storage → deletion. Do not publish a promise of “zero records” if a platform retains messages or metadata that you have not verified.

The person consulting deserves to know, before sending, what the response channel is, which data are mandatory, and where to read the privacy information. If the form asks for email in order to reply, that purpose should be clear. If files or photos are requested, it is advisable to explain their usefulness and limit. A “tell us everything” checkbox is not a neutral invitation when the service does not need so much information.

In a private journal, decide whether you need to keep the cards and your interpretation without keeping the other person's full account. A practice record can say: “Question about a schedule change, three positions, and synthesis,” with no names or identifiable details. The pedagogical usefulness of the example does not require keeping someone else's personal story. If you later want to turn it into an article or social media post, use a case created from scratch or ask for specific authorization for that different use.

Retention Period and the Possibility of Deletion

The European Data Protection Board's guide on retention reminds us that personal data are kept only while they are necessary for the corresponding purpose and that organizations must define retention policies. This does not amount to a universal number of days for every reading. There may be different obligations for support messages, transactions, and tax documents. The service must set specific periods based on its real purposes and the legislation applicable to it, and explain them in its privacy information.

The person consulting can ask: “Do you keep the text of my consultation after replying?”, “Can I ask you to delete notes you no longer need?”, or “Are my words used for examples?” The answer should distinguish what the reader controls from what an external provider retains. It should also separate an access or erasure request from an absolute promise of immediate deletion when legal retention obligations exist. A “we will always delete everything” without knowing the system can be misleading.

If the reader sends the response by email, review what appears in the subject line and notifications. “Result of your reading about medical treatment” exposes an intimate topic even on a locked screen. A neutral subject line and text that goes directly to what was agreed can reduce accidental disclosures. Share links and files only through the channel accepted by the person, and check the recipient before sending.

Privacy Also Depends on How You Phrase the Reading

A reading can intrude without collecting additional data. “I know your boss is hiding something” attributes a fact to a third party who did not participate. “This image leads me to ask whether there is a work condition that needs clarifying” preserves possibility without fabricating personal information. In a text that may be reread or forwarded, that difference matters. The person consulting could take a blunt statement as an accusation with real consequences.

Do not include details that the person asked you to omit just so the response seems more personalized. If a piece of data does not influence the question, leave it out of the reading. If it does influence it, explain why and allow the person to decide how much they want to share. In matters of health, money, or legal conflicts, a card can help organize questions, but it does not replace documents or competent advice. Nor does it justify collecting histories or evidence that the reader is not qualified to handle.

A Fictitious Case with Two Versions of the Service

Invasive version. A page requires full date of birth, partner's name, photos, screenshots, and a detailed explanation before allowing a brief question about personal organization. It does not explain who will see the data or how long they are kept. The resulting reading announces what the partner supposedly thinks. More careful version. The page asks only for a response channel and the question the person wishes to share, clarifies the use of the message, and links to real privacy information. It invites people to avoid third-party data and returns an interpretation centered on the options of the person consulting.

The second version is not automatically compliant with any law just because it asks for less. It must correspond to the real technical flow, the applicable legal bases, and people's rights. But the comparison shows an immediate editorial decision: ask only for what helps answer, not everything that could make the reading more dramatic.

A Short Checklist Before Sending or Receiving a Consultation

If you are consulting: formulate a question you can explore without identifying third parties, review which channel you use, avoid attaching sensitive documents unnecessarily, and read the service's privacy information. If you offer readings: verify the form's real path, explain the purpose of each piece of data, protect access, define retention and erasure according to the applicable standard, and use fictitious cases to show your work. The European Data Protection Board's official guide for small businesses is a good starting point for reviewing the operation, but it does not replace local advice when the processing or the service raises doubts.

A written response leaves a trace. That trace can help recall a reflection if both parties know what is kept, and it can harm trust if it accumulates by inertia. The practical criterion is simple: the question should be clear, the information should be the minimum necessary, and each piece of data should have a path you can explain honestly.