The Oracle's Purpose
Tarot Oracle exists to bridge the gap between ancient wisdom and modern seekers. In a world of noise and distraction, the tarot offers a moment of stillness—a mirror reflecting not fortune or fate, but the deeper currents of your own psyche.
🎴 The Rider-Waite Tradition
We use the Rider-Waite-Smith deck, created in 1909 by Arthur Edward Waite and illustrated by Pamela Colman Smith. This deck revolutionized tarot by giving each of the 78 cards its own symbolic scene—making the cards speak through imagery as much as tradition.
The deck comprises 22 Major Arcana cards representing life's great archetypal journeys, and 56 Minor Arcana cards divided into four suits: Wands (fire, passion), Cups (water, emotion), Swords (air, intellect), and Pentacles (earth, material).
✚ The Celtic Cross Spread
We focus exclusively on the Celtic Cross—the most comprehensive and respected spread in tarot tradition. Its ten positions create a complete picture of your situation: the present, obstacles, influences, past, future, and the forces both within and around you.
Rather than offering many shallow spreads, we believe in depth over breadth. A single Celtic Cross reading, properly interpreted, reveals more than a dozen simpler spreads combined.
🔒 Your Privacy, Our Promise
Your tarot reading is a personal, sacred experience. We never ask what question you bring to the Oracle—your intentions remain yours alone. Your readings are stored securely so you can revisit them in your Sanctum, but the meaning you find in them is entirely your own.
The Card Mirror and Cosmic Mirror features process your images transiently—they are analyzed in memory and never stored on our servers. The only copy exists in your browser's local storage, where you control it.
📬 Reaching the Oracle
Should you need guidance beyond the cards, two paths await:
General Inquiries — For matters of account, payment, or technical assistance, write to info@tarot-oracle.com. We aim to respond within 48 hours.
Reading Consultations — Seek deeper understanding of your spread by writing to oracle@tarot-oracle.com. Your first consultation is offered freely; subsequent guidance requires 150 fortune per reply.
Our Philosophy
🤫 Why We Never Ask Your Question
Most online tarot services begin with a text box: "Type your question here." We find this approach fundamentally misaligned with the nature of divination.
When you articulate a question in words, you've already constrained the answer. You've decided what the reading should be about. But the cards often speak to what you need to hear, not what you think you're asking. A question about career might reveal truths about self-worth. A question about love might illuminate patterns of fear.
By offering tarot readings without asking your question, we preserve the Oracle's ability to surprise you. Your intention matters—hold it in your mind as you approach the cards—but it belongs to you alone. We have no business knowing your hopes, fears, or midnight worries. That's between you and the cards.
This approach also means complete privacy. There's no database of questions to breach, no intimate thoughts stored on servers, no AI analyzing your deepest concerns. You receive a question-free tarot experience where your private intentions stay private.
🪞 The Mirror's Wisdom
We believe your face tells a story—but perhaps not the story you expect.
The Card Mirror is our dark comedy feature. Two cards await you: Death will roast you about your mortality, while The Fool will mock the absurdity of consulting cardboard for life guidance. Both use facial analysis not to divine your future, but to prove they actually saw you—weaving specific observations about your appearance into their brutal honesty. "A bearded gentleman past his prime looking surprisingly cheerful—guess ignorance really is bliss about the sands running out." That kind of thing.
Why would a serious tarot service include this? Because divination without humor is just superstition with better marketing. The cards have always been mirrors. We just made ours literal—and gave them a comedian's timing.
The Cosmic Mirror takes a different approach, weaving your physical presence into a genuine interpretation of your spread. Your face becomes part of the Oracle's canvas, another symbolic layer in the tapestry of meaning.
Both features operate on transient image processing: your photograph exists only in the moment of analysis, passes through memory, yields its insights, and vanishes. No facial data persists on our servers. The only copy lives in your browser's local storage, under your control.
🔐 Zero-Knowledge Divination
In an age of data harvesting, we've built something deliberately different: a tarot service that knows as little about you as possible while still serving you effectively.
We don't know your question. We don't store your face. We don't track which cards you lingered over or how many times you revisited a troubling interpretation. What happens between you and the cards is yours.
This isn't just privacy as a feature—it's privacy as philosophy. The zero-knowledge tarot approach means we cannot betray what we do not possess. No breach can expose your secrets because we never held them. No subpoena can reveal your readings' contexts because we never asked.
Some might call this a limitation. We call it respect. The Oracle speaks to whoever approaches with sincere intention. It doesn't need to know your name, your question, or your face to offer wisdom. Private tarot readings aren't a premium feature here—they're the only kind we offer.
Technical Methodology
System Architecture
Tarot Oracle operates on a serverless distributed architecture utilizing AWS Lambda for computation, DynamoDB for persistence, and WebSocket API Gateway for real-time bidirectional communication. This design achieves sub-second reading delivery latency while maintaining horizontal scalability.
Cryptographic Implementation
Session identifiers and authentication tokens are generated using crypto.randomUUID() conforming to RFC 4122 for cryptographically secure randomization. Magic link authentication employs HMAC-SHA256 signatures with base64url encoding, featuring 15-minute token freshness windows and one-time-use validation to prevent replay attacks.
Card Selection & Spread Logic
The Oracle draws from the complete 78-card Rider-Waite-Smith deck: 22 Major Arcana representing archetypal life journeys, plus 56 Minor Arcana across four suits (Wands, Cups, Swords, Pentacles). The Celtic Cross spread assigns cards to 10 distinct positional meanings without weighting—each position carries equal interpretive significance.
Multi-Language Generation
Interpretations are generated across 5 regional variants: English, Mexican Spanish (tú form), Castilian Spanish (tú form), Brazilian Portuguese (você form), and French (literary register). Each variant incorporates culturally-specific mystical vocabulary and regional spiritual traditions via dedicated AI guidance parameters.
Zero-Knowledge Image Processing
The Card Mirror and Cosmic Mirror features implement transient image analysis—photographs are processed entirely in-memory via AWS Rekognition facial analysis, with immediate buffer disposal post-interpretation. No images, facial data, or intermediate results persist on backend infrastructure. Client-side storage uses browser localStorage exclusively, under user control.
Fortune Token Economy
The platform operates a deterministic token economy: card reveals consume 25 fortune tokens uniformly across all positions. Initial grants provide 100 tokens to new users, with a one-time +70 token bonus available via email verification (7-day claim window). Token signatures use HMAC-SHA256 with cryptographic expiry validation.
Security Measures
Bot mitigation employs reCAPTCHA v3 with a minimum score threshold of 0.5 and 2-minute token freshness validation. Database operations use Query-only patterns (no Scan operations) ensuring O(1) performance at scale. IP-based rate limiting implements 24-hour automatic blocks for anomalous activity patterns.
About the Developer
Tarot Oracle was created by Robert Campbell, a cybersecurity professional based in Gladstone, Queensland, Australia. The platform serves as a demonstration of security best practices in production—implementing defense-in-depth principles, zero-knowledge privacy patterns, and cryptographically secure session management. For cybersecurity consulting services, visit robertcampbell.com.au.