Back to home

Privacy

Last updated February 2026

The short version

We do not ask who you are. There is no account, no sign-up and no email address. Your palm photographs are processed in memory and are never written to disk or object storage. The text of your reading is stored temporarily behind an unguessable link, and you can delete it at any time.

Your palm photographs

When you submit two palm photographs, they are sent over HTTPS to our server, held in memory, and re-encoded to strip embedded metadata — including any GPS location your camera may have attached. They are then sent to our AI provider for analysis.

As soon as the reading is generated, the image data is overwritten in memory and discarded. We never save your photographs to a database, a file system, or a storage bucket, and we never attach them to your reading or to any card you share.

Our AI provider (OpenAI, via its API) processes the images to produce your reading. We use their API under terms that do not permit your images to be used to train models. Providers may retain API inputs briefly for abuse monitoring under their own policies; that retention window is theirs, not ours, and we do not control it. We do not send them anything that identifies you.

What we are not doing

We do not perform biometric identification. We do not create, derive or store a biometric template, faceprint, handprint, or any identifier capable of recognising you in another photograph. We do not attempt to determine your identity, and we do not match your palms against anything.

What we do store

We store the text of your reading, the three answers you gave (dominant hand, age range, reading focus), the currency your reading was priced in, and timestamps. That record is reachable only through the link in your address bar, which contains a 256-bit random identifier. There is no listing page, no search, and no way for us or anyone else to find your reading without that link.

If you pay, we store the payment identifiers our payment provider gives us — an order reference, a payment reference, the amount and the currency. We never see or store your card number, CVV or bank credentials; those go directly to Stripe and never touch our servers.

How long we keep it

An unpaid reading is deleted automatically 24 hours after it is created. A paid reading is deleted automatically 30 days after it is unlocked, unless you download it — downloading extends the window so you do not lose it while you still want it.

You can delete a reading immediately at any time using the “Delete my reading now” control on the result page. When you do, the reading text is overwritten and the record is removed shortly afterwards. This cannot be undone, and we cannot recover it for you.

Analytics

We record anonymous counters so we can tell how many readings were started, completed, and paid for. These events contain no personal information and nothing derived from your palms — no archetype, no reading text, no image data. We do not use third-party analytics, we do not set advertising cookies, and we do not build a profile of you.

To prevent abuse we rate-limit requests by IP address. The IP address is hashed with a secret before it is stored, so the stored value cannot be turned back into an address, and these records are discarded automatically.

Security

Traffic is served over HTTPS. Result links use 256-bit random identifiers, which are not practically guessable. Our database is a managed Postgres instance provided by Supabase, and access to it is restricted to our application credentials. We describe here only what we actually do — we make no additional guarantee about encryption at rest beyond what our hosting provider offers by default.

Children

Palmsaga is intended for adults aged 18 and over. We do not knowingly collect information from children.

Contact

Palmsaga is a product of Lynkx LLC. For privacy questions or a deletion request, write to support@palmsaga.com. Because we hold no account information, please include the reading link if you want a specific reading deleted.