Legal
Privacy Policy
Effective 8 August 2026 ยท Applies to join.taparcana.com and to the AI Jewelry Assistant on WhatsApp and Telegram.
The short version
- We collect everything you send the bot. Every message, every photo you upload, every image the bot generates, and the settings you configure are stored on our servers.
- Our team can read all of it. There is an internal dashboard that shows full conversation history, images and AI prompts for every user.
- We keep it indefinitely, and there is no way to delete it. The Service is free and offers no data deletion or export.
- Your photos are sent to OpenAI to produce the results you asked for.
- Access is at our discretion and can be revoked at any time, for any reason, without notice.
This summary is for convenience. The full terms below govern.
Contents
1. Who this is from
The AI Jewelry Assistant ("the bot", "the Service") is operated by Tap Arcana ("we", "us", "our"). This policy covers the signup site at join.taparcana.com and the bot as delivered over WhatsApp and Telegram.
It does not cover WhatsApp or Telegram themselves, which are operated by Meta and Telegram FZ-LLC respectively under their own privacy policies.
The Service is provided free of charge and on an unsupported basis. We do not operate a support desk, a published contact address, or a data request process โ see section 8.
2. What we collect
We collect all data you provide to or generate through the Service. We do not limit collection to a narrow subset โ assume that anything you type, send or upload to the bot is recorded. In detail:
2.1 Account data (at signup)
- The name you enter.
- The email address you enter.
- The access key issued to you, and when it was created.
- Your IP address, recorded at the time of signup and used to rate-limit key creation.
- The fact that you accepted these terms.
2.2 Channel identity (when you redeem your key)
- Your WhatsApp phone number, in the form the platform provides it, and/or your Telegram chat ID.
- Which channel each identity is on and when it was bound to your key.
2.3 Conversation data (everything, both directions)
- Every message you send the bot, in full text, including messages sent before you redeemed a key and messages the bot did not understand.
- Every message the bot sends you.
- Every image you upload โ jewelry photos, and any model or personal photo you choose to send for a try-on. Images are written to disk on our server, not just referenced.
- Every image the bot generates for you, stored the same way.
- Which feature (generate, try-on, price, settings) each message belonged to, and a timestamp.
2.4 AI generation data
- The full prompt text sent to the AI model on your behalf.
- The input and output images for each generation.
- Extracted results โ for example the metal, weight and stone specifications the model reads off a photo in the price flow.
- The model used, its parameters, whether the call succeeded or failed, any error message, how long it took, token counts and the cost of the call.
2.5 Configuration data
- Your pricing settings: currency, gold markup, making charge, stone markup, natural and lab diamond rates, and any flat charge. These are your commercial margins โ they are stored on our servers and are visible to our team.
2.6 Technical data
- Standard web and application server logs: IP address, request time, path, and error output.
The signup site does not use cookies, analytics or third-party trackers.
3. Why we collect it
| Purpose | Data used |
|---|---|
| Delivering the feature you asked for | Messages, uploaded images, prompts, settings |
| Deciding whether you are allowed to use the bot | Access key, channel identity, name, email |
| Safety, and investigating misuse of the Service | Conversation logs, uploaded images, generation logs |
| Debugging faults and investigating failures | Conversation logs, generation logs, error output, technical logs |
| Measuring and controlling AI cost | Token counts, per-call cost, model and parameters |
| Preventing abuse of a free service | IP address, signup rate, conversation content |
| Improving the Service and its prompts | Conversation and generation history |
| Enforcing our Terms of Service | All of the above |
Where a legal basis is required, we rely on your consent (given when you created your key and each time you send the bot content) and on our legitimate interest in operating, securing and improving the Service.
4. Who can see your data
Our team can see everything described in section 2. We operate an internal dashboard that displays, for any user: the full conversation transcript, every image sent and received, every AI prompt, the extracted specifications, and per-user spend. It is used to support users, keep the Service safe, diagnose faults, control cost and enforce these terms.
There is no "private mode" in the bot. If you would not want a member of our team to see something, do not send it to the bot.
We may also disclose data:
- to service providers who host or process it on our behalf (section 5);
- where required by law, court order or a valid request from a public authority;
- to establish, exercise or defend legal claims;
- to a successor entity in connection with a merger, acquisition or sale of assets.
We do not sell your personal data.
5. Third parties and AI processing
| Provider | What it receives | Why |
|---|---|---|
| OpenAI | Your prompts, uploaded photos (including any photo of a person you send for a try-on), and generated images | Generating images, reading specifications off photos, classifying jewelry type |
| WhatsApp (Meta) / Telegram | Message delivery โ they carry every message either way | The transport the bot runs on |
| GoldAPI.io | Metal symbol and currency only โ no personal data | Live gold and platinum rates |
| Our hosting provider | All stored data, as the operator of the servers it sits on | Running the servers and database |
These providers operate under their own terms and may process data outside your country of residence. By using the Service you accept that your content is transferred to and processed by them.
6. How long we keep it
Indefinitely. Conversation logs, stored images, generation records, settings and account data are retained for as long as we operate the Service, including after your access is revoked or you stop using the bot. We keep records after revocation so we can investigate abuse and enforce these terms.
We do not offer deletion. There is no process to have your messages, photos, generated images or account data removed, and nothing in the bot will erase them. Once you send something to the Service, treat it as permanently retained. This is a condition of using a free, unsupported Service โ if it is not acceptable to you, do not use the bot.
7. Security
Traffic to this site and to our internal dashboard is encrypted in transit with HTTPS. The dashboard is password-protected and is not part of this public site. Access keys are long random strings and are shown only once, on screen, at signup.
No system is perfectly secure. Message content and images are stored unencrypted at rest on our server so that they can be reviewed by our team โ this is by design, and you should factor it into what you choose to send.
8. Your choices
The Service does not provide data access, correction, export or deletion, and there is no contact channel for making such a request. It is a free, unsupported tool operated on a take-it-or-leave-it basis. Do not use it if you need any of those things.
Your control over your data is exercised before you send it, not after. In practice that means two choices, and they are the only two:
- Choose what you send. Anything you do not send is never collected. The bot does not need photographs of identifiable people to work โ you can use the built-in model photos instead of your own, and you should.
- Choose whether to use it at all. Stopping means nothing further is collected. It does not remove what was collected already.
Some jurisdictions grant residents statutory data rights that cannot be signed away by a policy like this one. Nothing here is intended to override a right you hold under a law that applies to you. If you are relying on such a right, be aware that we have no process built to service it, and you should not use the Service.
9. Revoking access
Access to the Service is at our discretion. We may revoke any access key at any time, for any reason or no reason, with or without notice. A revoked key stops working immediately on both WhatsApp and Telegram. We may revoke access to protect the Service, control cost, or investigate suspected misuse. Revocation does not delete data already collected โ see section 6. See also the Terms of Service.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If we become aware that a child has used the Service, we will revoke the access key. Because we operate no deletion process (section 6), data already collected is retained.
11. Changes to this policy
We may update this policy. The current version always lives at this URL with the effective date at the top. Material changes will be announced through the bot. Continuing to use the Service after a change means you accept the updated policy.