Clayfold
Privacy

Privacy Policy

Last updated 11 September 2026

The short version

You can use Clayfold without an account. We do not show ads, track you across apps, or sell your personal information.

Personalized readings are optional and off by default. If you turn them on, your written question and selected cards leave your device and are processed by our cloud service and OpenAI. If you leave them off, your written question stays on your device.

Daily Reading and the card meanings always use fixed text. They are never sent to an AI service.

You decide whether to save a reading. Saved readings stay on your device and, when available, in your private iCloud database.

Who is responsible?

Clayfold is operated by Jesko von Dessauer, a sole proprietor registered in the Netherlands and trading as Luami. Jesko von Dessauer is responsible for the personal data described in this policy and is the controller in data-protection terms.

What data does Clayfold handle?

Optional personalized readings

AI personalization is off by default. If you enable it, Clayfold sends the following to our backend:

Your question is first checked by an AI moderation service. If allowed, the question and reading details are sent to an AI model to create the personalized interpretation.

We do not store your written question on our servers. So that retries and repeat readings work, we do store the reading generated from it and the safety-check response, which can include a note or a suggested rewrite of your question. Both can repeat personal details from your question. They expire 30 days after they were last used and are then deleted automatically.

For each AI request we also keep a usage measurement: the time, the feature and AI model used, the spread and app language, and token counts showing how much text was processed, together with the installation ID. These measurements never contain your question or any reading text.

Please keep identifying details out of questions. First names, initials, or phrases such as “my partner” are usually enough. Do not include full names, phone numbers, email or home addresses, account details, or other information that could identify you or someone else.

Readings you choose to save

A saved reading is stored on your device using Apple’s storage system and syncs to your private iCloud database when iCloud is available, where we cannot read it. If iCloud is unavailable, Clayfold uses local storage instead.

Daily Reading and card meanings

Daily Reading uses fixed interpretation text that ships with the app, whether or not AI personalization is on. Its reading details are never sent to an AI service. The same is true of the short card meanings you see when you browse the deck or draw a card without a question: fixed, written text, never generated for you.

To keep that text current, Clayfold downloads updated wording for your app language from our content host. Those requests contain no question, card, reading, or installation ID — they ask only for the text file for a language, and they happen whether or not you ever open a reading.

Anonymous usage statistics

Separately from the reading data described above, Clayfold records anonymous statistics about how the app is used — for example that a daily card was opened, a question was asked and which spread, or that a reading finished or failed — together with the device model, iOS version, app version, and language setting. This measures the action, not its content: it never includes the words you typed, the cards you drew, or the reading you received, and it carries no persistent identifier — only random values that exist while the app is open and are discarded when it closes — so it cannot be traced back to you or linked to the reading data above. So that we can see whether people who started in a given month keep using the app, your device remembers the month (never the date) you first opened it and includes it with these statistics. Your IP address is used only to work out which country the statistics come from and is then discarded; it is not stored. The statistics are handled by PostHog, which acts only on our behalf, uses no cookies and no cross-app tracking, and stores the data in the European Union.

Website and support

The Clayfold website measures how its pages are used, so we can tell which parts people read and which links they follow. It records page views and clicks — the action, not who you are. There is no session recording, no advertising or cross-site tracking, and no profile: we never ask it to identify you, so no visitor profile is created. This is handled by PostHog in a separate project from the app’s, and stored in the European Union.

Whether we need your permission first depends on where you are, so we ask Cloudflare which country the request arrives from. That happens at Cloudflare’s own network edge, where your request already is: nothing is sent to a third party to look you up, and the answer is not stored. Where the law requires permission — the EU and EEA, the United Kingdom, and the US states that ask for it — nothing is measured and no analytics cookie is set unless you choose Allow analytics, and declining collects nothing at all. Elsewhere, measurement is on when you arrive and a notice offers a one-click opt-out that we remember for that browser. A Global Privacy Control signal from your browser is treated as an opt-out everywhere, whether or not you have been asked.

You can change your choice at any time with Website privacy choices at the bottom of any page.

Like most websites, its hosting provider may receive technical request data such as your IP address, browser, device type, and request time. If you email us, we receive your email address and anything you include in the message.

Why do we use this data?

For people covered by the GDPR or similar laws, our legal bases are: performing the service you request; your consent for optional AI personalization, including your explicit consent to process special-category details you choose to include in a question; our legitimate interests in security, misuse prevention, reliable operation, understanding usage and costs, and support; your consent for website analytics wherever consent is required for them; and compliance with legal obligations where required.

You can withdraw your permission at any time by turning off Enable AI readings in the app’s settings. This stops any new question or reading data leaving your device. It does not undo processing that already happened, and it does not cancel your subscription, which stays active until you cancel it with Apple. Because withdrawing clears your permission, turning AI back on asks for it again. To also remove data that was already processed, use Delete Server Reading Data in the app’s settings.

Your choice about website analytics is separate from this and is changed with Website privacy choices at the bottom of any page. Turning it off stops any further measurement in that browser and clears the analytics cookies it had set.

Where does the data go?

Google Cloud / Firebase, OpenAI, Cloudflare and PostHog process data on our behalf under data processing agreements that require them to give it the same or equal protection that this policy describes. Saved readings stay in your own iCloud account under Apple’s terms. Some processing may take place outside your country or the European Economic Area. Where required, those transfers use recognized safeguards such as adequacy decisions or standard contractual clauses; PostHog Inc. is also certified under the EU-U.S. Data Privacy Framework. We may also disclose data if the law requires it or to protect people, rights, and service security.

How long is data kept?

Expired records are not used or returned by Clayfold.

Deleting your data

You can delete an individual saved reading inside Clayfold. This removes the local record and its iCloud copy through Apple’s sync system.

To remove server reading data linked to this installation, open Settings → Delete Server Reading Data. This removes the installation’s links to question-based AI readings, deletes cached readings that are not shared with another installation, and deletes older usage records. Current-day limit counts are reduced to the minimum needed so that deleting data cannot reset that day’s limits; they expire at the end of the day.

The same action removes the installation ID from stored usage measurements, leaving only anonymous totals. Measurements recorded in the hours just before your request may keep the installation ID; they are deleted on the schedule above in any case.

The anonymous usage statistics described above contain nothing that could identify you or your installation, so they are not affected by these actions.

We do not store the written question itself. A cached safety-check response may contain a note or suggested rewrite that echoes details from it. Data used to enforce daily limits may link that response to this installation until the end of the UTC day. Choosing Delete Server Reading Data removes the link immediately but keeps the request count needed to preserve that day’s limit. It does not delete the response itself because another installation may use the same cached response; it is deleted automatically after 30 days. Because Clayfold has no account system and these responses use protected identifiers, we may not be able to identify a particular response as yours.

For help, or to make a broader privacy request, email . Because Clayfold has no account system, we may need information from your installation to locate the right records, and we may be unable to connect some pseudonymous records to you.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain uses. You may also withdraw consent and complain to your local data-protection authority. We will not treat you differently for exercising a privacy right.

Clayfold does not sell personal information or share it for cross-context behavioural advertising. It does not use your data for targeted advertising.

Security and children

We limit server database access to the backend, use encrypted network connections in production, and use app-and-device attestation to reject requests that do not come from an authentic Clayfold app instance. We also use providers with technical and organisational security measures. No system is perfectly secure, so please avoid putting sensitive or identifying information in a question.

Clayfold is offered for ages 16 and up and is not directed at children. If you believe someone under 16 has provided personal data, contact us so we can review and delete what we can identify.

Changes and contact

We will update this page when Clayfold’s data practices or service providers materially change and will change the date at the top.

Questions, concerns, or privacy requests are welcome at .