The short version
Your palm photo is sent to our server, analyzed once to trace your lines, and deleted within 24 hours. It is never used to identify you, never turned into a biometric template, and never used to train a model unless you separately choose to allow that. If you join the launch list, we use your email address only to tell you when PalmMuse is available in the App Store.
What we collect
- The palm photo you choose to scan. Cropped on your device before it is uploaded, and sent under a random analysis ID rather than an account identifier.
- The reading it produces — the detected line geometry and the written text — so you can reopen a reading you paid for.
- Anything you type into the app, such as an optional question you want the reading to address.
- Basic technical data needed to run the service: request timestamps, campaign tags, the referring site's host name, error logs, and rate-limit counters keyed to an IP address.
- An email address you enter on this website, if you ask us to send the App Store link when PalmMuse launches.
- Apple purchase identifiers needed to attach a purchase to the reading it unlocked, restore it on your Apple Account, and prevent one transaction from being reused.
We do not ask for your name, birthday, address, or phone number. Purchases are handled by Apple; we never see your payment details.
How long we keep it
- The original photo: deleted within 24 hours of analysis, and normally within seconds of the reading being generated. There is no archive.
- A free reading: kept for 2 hours, then expires.
- A reading waiting for Apple purchase approval: kept for up to 30 days so a delayed transaction can still open the reading it was started from. If no purchase arrives, it expires.
- A purchased reading: kept so you can reopen it, for up to one year. You can delete it sooner from inside the app.
- A launch-list email address: kept until we send the launch notice, or deleted sooner if you ask us.
- After you delete a purchased reading, or its one-year period ends: the report, line geometry, questions, and reading ID are deleted. We retain only a one-way hash of the Apple transaction ID as a consumed purchase marker, so the same receipt cannot unlock another reading. That marker cannot reopen or identify the deleted reading.
What we never do
- We never match your palm against you, against another user, or against any database.
- We never create or store a biometric identifier or authentication template from your hand.
- We never sell your data, and we never share it with advertisers or data brokers.
- We never use your photo to improve a model by default. If we ever ask, it will be a separate, clearly worded opt-in that is off until you turn it on.
Who processes your data
To generate a reading we send your cropped photo to OpenAI's API, which processes it to produce the analysis and does not retain it for training. Readings and rate-limit counters are stored with Upstash (Redis). The app and its API run on Vercel. That is the complete list.
Your choices
You can delete a stored reading and its data from inside the app at any time. You can also email us and we will delete anything associated with a reading you identify. Because we deliberately collect no account identity, we may need the reading link or ID to find it. To remove a launch-list address, email us from that address and ask to be removed.
Children
PalmMuse is not directed at children and is not intended for anyone under 13.
Changes
If this policy changes in a way that affects what we collect or how long we keep it, we will update the date at the top and describe the change in the app's release notes.