Privacy Policy
Last updated 30 August 2026
Who we are
Palm & Line is operated by YairTech Ltd, a company registered in England and Wales. YairTech Ltd is the data controller for the personal data described in this policy.
For anything to do with your data — questions, requests, complaints — email hello@yairtech.co.uk.
What we collect
| What | Why |
|---|---|
| Your email address | To send you the link to your reading, to send a sign-in code for a free reading, and to find your order if you contact us. |
| A first name, if you give one | Optional. It is used only to address the reading and the PDF to you. Leave it blank if you would rather not. |
| A photograph of your palm (one or two, depending on the package) | It is the whole point of the service — the reading is written from what is visible in it. Deleted as soon as the reading is written, see below. |
| Your IP address | Recorded when you sign up for a free reading, so we can cap how many free accounts come from one connection. Abuse prevention only. |
| Payment metadata | The amount, the time of payment, and Stripe's own references for the checkout and payment. We never see or store your card number — your card details go straight to Stripe and never touch our servers. |
| The reading itself | Kept so that your private link keeps working. It includes a written description of what was visible in your photograph, which is what the reading was built from. |
We do not ask for your address, your date of birth, your phone number, or anything about your health, and we would rather you did not send them.
Your photograph is deleted
This is worth stating plainly, because it is unusual and it is the safeguard we care most about. The moment your reading has been generated, the photograph is deleted from the order record. It is not archived, not backed up to a separate store, not kept for training, and not used for anything else. What survives is the written reading and the notes the model made about what it could see in the image — words, not pictures.
One honest exception: if a reading fails — most often because the photo does not clearly show an open human palm — the photograph stays attached to the failed order so we can help you sort it out. Email us and we will delete it immediately, and we delete these as we work through failed orders in any case.
Who processes your data for us
We use a small number of established suppliers. Each acts as our processor, on our instructions, and only for the purpose listed.
- OpenAI — reads your palm photograph and writes the reading. Your photograph and any first name you gave are sent to OpenAI for this. This processing takes place in the United States.
- Stripe — takes the payment. Stripe collects your card details directly; we receive only confirmation that you paid, the amount, and Stripe's reference numbers.
- Resend — sends the emails (your reading link, and sign-in codes).
- Google Cloud — hosts the service and stores our data, in Google's London region (europe-west2).
We do not sell your data, share it with advertisers, or hand it to data brokers.
Sending data outside the UK
Our own storage and hosting stay in the UK. The one routine transfer outside it is to OpenAI in the United States, which is necessary to produce the reading you asked for. That transfer is covered by the standard contractual protections in OpenAI's data processing terms. If you would rather your photograph were not sent to the US, please do not order a reading — there is no way to produce one without it.
Our lawful bases
- Performance of a contract — for everything involved in producing and delivering a reading you have bought: the photograph, your email address, your name, and the payment record.
- Legitimate interests — for keeping the service working and stopping abuse: your IP address for signup limits, and the records we need to investigate fraud or misuse. Our interest is in running a service that is not farmed by bots; the effect on you is minimal.
- Consent — where you have given it, for example when you tick the box to send us your photograph for a free reading. You can withdraw consent at any time by emailing us, though it does not undo processing already carried out.
How long we keep things
- Palm photographs — deleted as soon as the reading is written. Usually within moments.
- Your reading — kept indefinitely, so that the private link we sent you keeps working. Ask us to delete it and we will.
- Your account (email address, free-reading count, the IP you signed up from) — kept while the account exists. Ask us to close it and we delete it.
- Payment records — kept for as long as UK tax and accounting law requires, currently six years.
- Signup rate-limit counters — short-lived, held per day for abuse prevention.
Who can see your reading
Your reading lives at a private link containing a random 128-bit identifier. It is not listed, indexed, or guessable. But anyone who has the link can open it, so treat it like a password: don't post it publicly, and don't forward it to anyone you would not want reading it.
Your rights
Under UK GDPR you have the right to:
- ask what personal data we hold about you, and get a copy (access);
- have inaccurate data corrected (rectification);
- have your data deleted (erasure);
- receive your data in a portable, machine-readable form (portability);
- object to processing we carry out on the basis of legitimate interests, and ask us to restrict processing while a dispute is resolved;
- withdraw consent where we relied on it.
Email hello@yairtech.co.uk and we will respond within one month. There is no charge.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to put it right first.
Cookies and local storage
We use one cookie, and it is strictly necessary:
- pl_session — set only when you sign in for a free reading. It keeps you signed in, lasts 30 days, and is HttpOnly (your browser will not let scripts read it). Without it the free tier cannot tell who you are.
We also use your browser's local storage (a key called
pl_readings) to remember the links to readings you have bought on that
device, so a closed tab does not mean a lost reading. That list stays in your browser; it
is not sent to us as a profile of you, and clearing your browser data removes it.
We use no analytics cookies, no advertising cookies, no tracking pixels and no third-party trackers. There is nothing here to opt out of.
One technical note for completeness: if your browser cannot open an iPhone HEIC photo by itself, the page loads a small image-conversion library from a public code CDN (cdnjs.cloudflare.com). The conversion happens inside your browser — your photograph is not sent to that CDN.
Children
This service is for adults. You must be 18 or over to use it, and we do not knowingly collect data from anyone under 18. If you believe a child has sent us a photograph, email us and we will delete it.
Security
Traffic is encrypted in transit. Data is stored in Google Cloud's London region. Session cookies are signed, verification codes are stored only as hashes, and reading links carry 128 bits of entropy. No system is perfect, and if a breach ever affects your rights we will tell you and the ICO as the law requires.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle data you have already given us, we will email you about it.