Legal
Privacy Policy
This policy explains what personal data Baba Vanga collects when you ask for a reading, why we collect it, how long we keep it, and the rights you have over it under the EU General Data Protection Regulation (GDPR).
1. Who we are
Xpacore Ltd (Експакор ЕООД), registered at Sofia, Bulgaria, ЕИК 208932439 ("we", "us"), is the data controller for your personal data in Baba Vanga. This policy applies to Baba Vanga (vanga.info) and the Baba Vanga Android app. For any privacy question, or to exercise your rights, write to office@pacod.io.
2. Data we collect
- Account data — your name, email address and password (stored hashed); or, if you use Sign in with Google, your Google account identifier, email address and name (see section 8).
- Your photos — the pictures of your coffee cup or your palms that you take for a reading.
- Your question — the optional question you type before a reading.
- Your readings — what we generate for you: the title and text of the reading, the symbols marked on your photo, the themes and timeline, and the spoken audio version.
- Usage data — when you asked for a reading, of which kind, how many photos, which AI model produced it and how much of your free allowance you have used. Which pages you view and for how long is measured by our own first-party tool only if you allow analytics cookies.
- Technical and security data — IP address, browser and device type in server logs; and, for each signed-in device, a device label, browser, IP address and sign-in times, which you can see and sign out on your account page.
- Cookies — see our Cookie Policy.
3. How and why we use your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Your account, and producing, storing and reading aloud your readings | Performance of a contract |
| Creating a share link when you ask for one | Performance of a contract |
| Enforcing the free allowance, keeping the service secure and preventing abuse | Legitimate interests |
| Support, fixing errors and improving reading quality — authorised staff can view individual readings (question, photos and result) for these purposes and to prevent abuse | Legitimate interests |
| Analytics and advertising cookies | Consent |
| Meeting legal and accounting obligations | Legal obligation |
4. How a reading is made
- Before anything is stored, our server straightens each photo, reduces it to at most 1568 pixels on its longest side and removes all embedded metadata, including GPS location. The Android app already does this on your phone before uploading.
- Our own server checks that the photos are sharp enough. No third party is involved in this step.
- Your photos and your question are sent to an AI model provider, which writes the reading. We currently use Anthropic; depending on configuration this may instead be Google (Gemini) or OpenAI.
- The text of your reading (never your photos) is sent to OpenAI to create the spoken version. If that fails, your own browser reads the text aloud instead.
We use these providers through their business APIs, under agreements that allow them to process the data only to provide the service to us.
5. How long we keep it
- Unfinished readings (abandoned, failed or never submitted) and their photos are deleted automatically once they are 24 hours old, by a clean-up that runs every day.
- Finished readings — photos, question, text and audio — are kept in your archive until you delete them, and are deleted automatically by the same daily clean-up once they are 365 days old. You can delete any reading from your archive at any time; this removes its photos and audio from our servers immediately.
- Account data is kept while your account exists and for 90 days after you close it.
- Server logs are kept for 12 months; detailed usage-analytics records for 180 days.
6. Sharing a reading
Readings are private. If you choose to share one, we create a link with a long random code. Anyone who has the link can open it and see the title and text of the reading, the symbols, the audio version and your first photo, which is also shown as the preview image when the link is posted in a messaging app. The link never shows your question, your name, your email address or your other photos.
Shared pages are not listed for search engines. You can stop sharing at any time — the old link then stops working for good — and deleting the reading removes the shared page too.
7. Sharing and processors
We do not sell your personal data. We share it only with service providers ("processors") who help us run Baba Vanga, under contracts that require them to protect it and act only on our instructions:
- a hosting and infrastructure provider, on whose servers your account, photos and readings are stored;
- an AI model provider that writes the reading (see section 4);
- OpenAI, which turns the reading text into speech;
- an email-delivery provider that sends your account emails (email verification and password reset).
Our pages load their typefaces from Google Fonts, so your browser connects to Google's servers and Google receives your IP address; no cookie is set for this.
Analytics and advertising providers — Google, Yandex, Microsoft, Meta, TikTok, X, Pinterest and LinkedIn — receive data only if you allow the corresponding optional cookie category; until then their scripts are never loaded. See the Cookie Policy. How Google uses the data its tags collect is explained in How Google uses information from sites or apps that use our services.
8. Sign in with Google (Google user data)
You can create an account and sign in to Baba Vanga (vanga.info) and the Baba Vanga Android app with your Google account ("Sign in with Google"). In the Android app, sign-in opens Google's page in your browser and then returns you to the app. This section explains exactly what we receive from Google, what we do with it and how you can remove it.
- What we request — only Google's basic sign-in permissions:
openid,emailandprofile. We do not request access to Gmail, Google Drive, Google Photos, Calendar, Contacts or any other Google service or data. - What we receive and keep — your Google account identifier, your email address and whether Google has verified it, and your name. We store the identifier and email address to recognise you when you sign in again, and your name as your display name. We do not store your Google profile picture.
- Google tokens — the short-lived access token Google issues during sign-in is used once, to read the details above, and is then discarded. We keep no Google access or refresh token, so we cannot access your Google account afterwards.
- How we use it — only to create your account, sign you in, keep your account secure (we link Google to an existing account with the same email address only when Google has verified that address), and send you emails about your account.
- What we never do with it — we do not sell Google user data; do not use or transfer it for advertising, retargeting or personalised ads; do not use it to determine creditworthiness or for lending; and do not use it to develop, improve or train artificial-intelligence or machine-learning models. Google account data is never sent to our AI model providers.
- Who can see it — Google user data is shared only with the hosting and email-delivery providers that store it or send your account emails on our behalf, where required by law, or as part of a merger or acquisition, with notice to you. Our staff do not read it except with your consent, where necessary for security or to comply with the law, or in aggregated and anonymised form.
- How we protect it — it is transmitted only over encrypted connections (TLS), stored on access-controlled servers, and accessible only to authorised personnel who need it to operate the service.
- Retention and deletion — we keep it as long as your account exists and delete it together with your account. You can stop our access at any time at myaccount.google.com/permissions — this ends Sign in with Google but does not delete your account. To delete your account and all associated data, see section 12.
9. The Android app
- The app asks only for camera and internet access. Photos stay in the app's memory until you send them for a reading; they are not saved to your gallery.
- Hand detection, which helps you frame your palm, runs entirely on your phone (Google MediaPipe, used offline); nothing is sent anywhere for this step.
- The app stores your sign-in session and your language choice in its private storage on the phone. This data is excluded from cloud backup and device transfer. The app may also keep a temporary cache of your reading images. Uninstalling the app removes all of it.
- The app contains no analytics, advertising or crash-reporting libraries.
10. International transfers
Our AI model and speech providers are based in the United States. Where a provider is outside the European Economic Area, we rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data ("right to be forgotten");
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with your supervisory authority — in Bulgaria, the Commission for Personal Data Protection (CPDP / КЗЛД).
To exercise any of these rights, email office@pacod.io. We respond within one month.
12. Deleting your account
You can delete individual readings yourself at any time. To delete your whole account — whether you use the website or the Android app, and including an account created with Google — email office@pacod.io from the address registered to it with the subject "Delete my account". We then delete your account, all your readings, photos and audio, any share links and your Google account data, and confirm within one month.
13. Security
We protect your data with encryption in transit, hashed passwords, and access controls. Your photos are never publicly accessible: they can be opened only by you, through your share link if you create one, and by authorised staff who need to for support, abuse prevention or quality review. No system is perfectly secure, but we work continuously to reduce risk.
14. Age limit
Baba Vanga is intended only for adults (18 or older). We do not knowingly collect data from anyone younger; if you believe a minor has used the service, contact us and we will delete their data.
15. Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the "Last updated" date; significant changes will be communicated directly where appropriate.