Privacy Policy

Last updated 30 August 2026

The short version. Your palm photograph is deleted from our records as soon as your reading has been written — normally within a minute or two of you sending it. We keep your reading so you can come back to your link, and your email address so we can send it to you. We do not use analytics or advertising cookies, and we never sell your data.

Who we are

Palm & Line is operated by YairTech Ltd, a company registered in England and Wales. YairTech Ltd is the data controller for the personal data described in this policy.

For anything to do with your data — questions, requests, complaints — email hello@yairtech.co.uk.

What we collect

WhatWhy
Your email addressTo send you the link to your reading, to send a sign-in code for a free reading, and to find your order if you contact us.
A first name, if you give oneOptional. It is used only to address the reading and the PDF to you. Leave it blank if you would rather not.
A photograph of your palm (one or two, depending on the package)It is the whole point of the service — the reading is written from what is visible in it. Deleted as soon as the reading is written, see below.
Your IP addressRecorded when you sign up for a free reading, so we can cap how many free accounts come from one connection. Abuse prevention only.
Payment metadataThe amount, the time of payment, and Stripe's own references for the checkout and payment. We never see or store your card number — your card details go straight to Stripe and never touch our servers.
The reading itselfKept so that your private link keeps working. It includes a written description of what was visible in your photograph, which is what the reading was built from.

We do not ask for your address, your date of birth, your phone number, or anything about your health, and we would rather you did not send them.

Your photograph is deleted

This is worth stating plainly, because it is unusual and it is the safeguard we care most about. The moment your reading has been generated, the photograph is deleted from the order record. It is not archived, not backed up to a separate store, not kept for training, and not used for anything else. What survives is the written reading and the notes the model made about what it could see in the image — words, not pictures.

One honest exception: if a reading fails — most often because the photo does not clearly show an open human palm — the photograph stays attached to the failed order so we can help you sort it out. Email us and we will delete it immediately, and we delete these as we work through failed orders in any case.

Who processes your data for us

We use a small number of established suppliers. Each acts as our processor, on our instructions, and only for the purpose listed.

We do not sell your data, share it with advertisers, or hand it to data brokers.

Sending data outside the UK

Our own storage and hosting stay in the UK. The one routine transfer outside it is to OpenAI in the United States, which is necessary to produce the reading you asked for. That transfer is covered by the standard contractual protections in OpenAI's data processing terms. If you would rather your photograph were not sent to the US, please do not order a reading — there is no way to produce one without it.

Our lawful bases

How long we keep things

Who can see your reading

Your reading lives at a private link containing a random 128-bit identifier. It is not listed, indexed, or guessable. But anyone who has the link can open it, so treat it like a password: don't post it publicly, and don't forward it to anyone you would not want reading it.

Your rights

Under UK GDPR you have the right to:

Email hello@yairtech.co.uk and we will respond within one month. There is no charge.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to put it right first.

Cookies and local storage

We use one cookie, and it is strictly necessary:

We also use your browser's local storage (a key called pl_readings) to remember the links to readings you have bought on that device, so a closed tab does not mean a lost reading. That list stays in your browser; it is not sent to us as a profile of you, and clearing your browser data removes it.

We use no analytics cookies, no advertising cookies, no tracking pixels and no third-party trackers. There is nothing here to opt out of.

One technical note for completeness: if your browser cannot open an iPhone HEIC photo by itself, the page loads a small image-conversion library from a public code CDN (cdnjs.cloudflare.com). The conversion happens inside your browser — your photograph is not sent to that CDN.

Children

This service is for adults. You must be 18 or over to use it, and we do not knowingly collect data from anyone under 18. If you believe a child has sent us a photograph, email us and we will delete it.

Security

Traffic is encrypted in transit. Data is stored in Google Cloud's London region. Session cookies are signed, verification codes are stored only as hashes, and reading links carry 128 bits of entropy. No system is perfect, and if a breach ever affects your rights we will tell you and the ICO as the law requires.

Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how we handle data you have already given us, we will email you about it.