Privacy Policy
Last updated: 1 October 2026
This English version is a translation for your convenience. Only the German version is legally binding: Deutsch
FalciDilara reads coffee cups, tarot, palm lines, dreams and horoscopes. This policy describes which data that requires, how long it is kept and who besides me gets to see it. It applies to the website www.falcidilara.com, the web app at app.falcidilara.com and the apps for iOS and Android.
1. Controller
Timur Aktas Gonzalez
Dollersweg 19
44319 Dortmund
Deutschland
Email: support@timuraktasgonzalez.com
2. The website
The website www.falcidilara.com is a collection of static pages. It requires no account and uses no forms.
Hosting. The pages are hosted on Cloudflare Pages (Cloudflare, Inc., USA). When you open a page, Cloudflare processes, as technically necessary, your IP address, the address requested, the date and time, and details of your browser and operating system, in order to deliver the page and fend off attacks. The legal basis is my legitimate interest in a secure and available website (Art. 6(1)(f) GDPR).
No tracking cookies. The website uses no analytics, no advertising, no pixels and no embedded content from third parties. Fonts are loaded from our own address, not from Google. There is exactly one cookie: if you choose a language at the top right, the cookie fd_lang stores that choice for one year so that the website and web app greet you in your language. It contains only the language code and is necessary for this function, which you requested (§ 25(2) no. 2 TDDDG).
Links to the web app. Buttons such as “Sign in” or “Start in your browser” lead to the web app. Only there does the processing described in the following sections begin.
3. Your account
When you first start the app, it creates an account with a random device identifier, without a name and without an email address. This identifier links your device to your readings and your credits.
If you wish, you can secure this account with an email address and a password, with Apple or with Google. In the web app, this is the way in. I then store:
- With email: the address and your password, but never in plain text, only as an irreversible hash.
- With Apple or Google: the identifier the provider issues for you and the email address it shares. Apple allows a hidden forwarding address for this. During sign-in itself, Apple Inc. or Google Ireland Limited respectively process your data under their own terms.
With a secured account, your credits, subscription and history are the same on every device. Each reading then also records whether it was created in the app or on the web.
4. What you enter yourself
For its readings, FalciDilara needs information about you, and all of it comes from you:
- First name, so that Dilara can address you, and for the numbers derived from your name.
- Date of birth, for your zodiac sign, horoscope and numbers.
- Time and place of birth, optional. Without them there is no complete birth chart, because the Ascendant cannot be calculated.
- Form of address, for the grammatical form of the texts.
- Language and time zone, taken from your device or browser and changeable at any time.
- Information about other people, if you enter it yourself, for example for the compatibility reading (Uyum), someone else’s palm or the round at the table. Only enter what that person would tell you themselves.
5. Photos of your cup and palm
This is the part most people are interested in, so it is set out in detail here.
For a coffee cup reading you photograph the inside of your cup, for a palm reading your palms, in the app with the camera or on the web as an upload. These photos go to my server and from there to the language model, which actually looks at them and writes the reading from them. After that they are discarded. They are not stored, not filed in an image database and not used for anything else. What remains is the written text of the reading.
Even so, think about what ends up in the picture: photograph the cup and the hand, not the room and not other people.
6. What is created when you get a reading
Every reading is saved so that you can open it again later. The same applies to follow-up questions to Dilara and to conversations with Dilara Plus.
What you write to Dilara is up to you. Some people tell a fortune teller about illnesses, relationships or their faith. Such information enjoys special protection under the GDPR, and I process it only because you share it voluntarily (Art. 9(2)(a) GDPR). Write only what you want to write.
7. Purchases
In the app, you buy credits and subscriptions through the App Store or Google Play. I do not see any payment details. The store reports via RevenueCat only that a purchase has taken place, so that your credits arrive.
On the web, you pay via Stripe (Stripe Payments Europe, Ltd., Ireland). You enter your card, Apple Pay, Google Pay, PayPal or Klarna details directly with Stripe; card numbers never reach my server. From Stripe I receive what I need for crediting your account and for tax: which product, whether the payment succeeded, a customer identifier, your country and the email address for the invoice. Stripe is itself responsible for processing the payment and additionally processes data under its own privacy policy, for example to prevent fraud. If you choose PayPal or Klarna, their terms also apply.
8. Who else processes the data
The following service providers are involved, each as a processor under a contract pursuant to Art. 28 GDPR, unless they are themselves responsible as described above:
- Anthropic PBC (USA), the language model that writes the readings. The photos and the information needed for the reading in question are sent there. According to Anthropic, it does not use the content to train its models.
- Render Services, Inc. (USA), operation of the server. The server is located in Frankfurt am Main.
- MongoDB, Inc. (USA), the database. It is located in Frankfurt am Main.
- RevenueCat, Inc. (USA), handling purchases between the stores and my server.
- Stripe Payments Europe, Ltd. (Ireland), payments on the web.
- Cloudflare, Inc. (USA), hosting of the website and web app, and the address through which the app and web app reach the server.
- Open-Meteo (Germany), the place search for your place of birth. Only the place name you type is sent there.
For providers based in the USA, the transfer is based on the European Commission’s Standard Contractual Clauses and, where the provider is listed there, on the EU-US Data Privacy Framework. This cannot guarantee a level of data protection equivalent to that in the EU; that is part of the truth too.
9. Legal bases
The processing of the information in sections 3 to 7 serves to perform the contract between you and me, that is, to deliver the readings you have requested (Art. 6(1)(b) GDPR). For special categories of data that you share voluntarily, Art. 9(2)(a) GDPR also applies. I retain invoice data because tax law requires it (Art. 6(1)(c) GDPR). Hosting and security are based on Art. 6(1)(f) GDPR.
10. How long
Photos: only for the duration of the reading, then discarded. Readings, profile, sign-in details and credits: for as long as your account exists. You can delete it in the app under Me, or request deletion informally by email; your profile, sign-in details, readings and conversations are then gone. Any credits lapse with it. Invoices from purchases on the web are kept for as long as tax law requires, in Germany for up to ten years.
11. No tracking, no advertising
FalciDilara contains no advertising, no analytics tool and no advertising network, neither on the website nor in the web app nor in the apps. Your information is not sold and is not passed on for advertising purposes.
12. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future. An informal message to support@timuraktasgonzalez.com is enough.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for my place of business is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2 bis 4, 40213 Düsseldorf.
13. Age
FalciDilara is intended for people aged 13 and over. If you are younger, the service is not meant for you.
14. Changes
If features or service providers change, I will update this policy. The date of the current version is shown at the top of the page.