Privacy Policy

Effective date: September 24, 2026

This policy explains how BirthMinder handles information when you use the BirthMinder mobile application and website.

1. Who controls your data

BirthMinder is the controller of personal data described in this policy. You can contact us at support@birthminder.app.

2. Information we process

3. Contacts and notifications

BirthMinder accesses device contacts only after you grant permission, and reads only names and birthday dates. Phone numbers, email addresses and photos are never read. The scan itself runs on your device and shows you import candidates. Only the people you choose to import are saved, and because they become part of your account they are stored on our servers so your reminders survive a lost or changed phone. Contacts you skip are never uploaded. We use notification permission to schedule reminders on your device. You can revoke either permission in system settings.

4. Google Contacts, Google Calendar and Google Tasks

If you choose to import from a Google account, BirthMinder asks Google for read-only access to the one source you picked: contacts.readonly for Google Contacts, calendar.calendarlist.readonly and calendar.events.readonly for Google Calendar, and tasks.readonly for Google Tasks. The app never adds, changes or deletes anything in your Google account.

From Google Contacts the app reads only names, birthdays and other dated events of your contacts. From Google Calendar it reads the names and colors of your calendars and the events in the calendar and date range you choose. From Google Tasks it reads the names of your task lists and the tasks in the list you choose. It also reads your Google account name to label your main calendar.

This data is read directly from Google by the app on your device and shown to you as a preview. Only the entries you select are saved. They become people and events in BirthMinder and are stored and synchronized like everything else you add (see sections 3 and 5). Entries you do not select are discarded. Our servers never connect to your Google account. We do not store Google access tokens, and the app signs out of Google when the import ends. You can remove BirthMinder's access at any time at myaccount.google.com/connections.

We use Google user data only to provide the import feature you see in the app. We do not sell it, use it for advertising, or use it to train generalized artificial intelligence or machine learning models. BirthMinder's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Local storage and account sync

Core app data is stored locally on your device. If you sign in and enable account-backed functionality, your people, events, chat messages, and preferences may be synchronized with our cloud backend so they can be restored and used across sessions. Supabase provides authentication, database, storage, and server functions.

6. Why we use information

7. Service providers

We may share only the information needed to operate the service with providers such as Supabase (backend and authentication), OpenAI (wish text generation), RevenueCat and Apple or Google (subscriptions and purchases), Sentry (error diagnostics), Resend (service email delivery), and Cloudflare (website delivery). These providers process information under their own terms and privacy commitments.

When you generate or refine wishes in the app, the context needed to write them is sent to OpenAI and processed to produce the suggestion. This can include the person's first name, relationship, the occasion, notes you saved about that person, and the instructions you type in the wishes chat. The same applies to the birthday email we send you on your own birthday: your first name, age, and the people you saved are processed by OpenAI to compose the wishes, and the email is delivered through Resend. The content is used only to generate the text; under OpenAI's API terms it is not used to train OpenAI's models.

To decide whether a service email is needed and when to send it, we keep a small engagement summary in Supabase: notification permission status, the number of saved people and events, app language, timezone, and when the app was last opened.

Diagnostic events are configured to exclude free-form app content, request bodies, breadcrumbs, email addresses, names, notes, and chat content. We do not sell personal data.

8. Retention and deletion

We keep information while your account is active and as needed to provide the service. You can clear local data from the app. You can also request or use account deletion; this removes your account and associated cloud data, subject to information we must retain by law or limited records that are anonymized to preserve service integrity.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent. In the EEA and UK you may also complain to your local data protection authority. Contact us to exercise these rights.

10. Security and international processing

We use reasonable technical and organizational safeguards. No system is completely secure. Our providers may process data in countries other than yours using appropriate transfer safeguards where required.

11. Children

BirthMinder is not directed to children under 13, or a higher minimum age where local law requires it. Contact us if you believe a child provided personal data without appropriate permission.

12. Cookies on our website

The website itself works without cookies. We remember your language choice and your cookie decision in your browser's local storage, and that information stays on your device.

The only cookies we use are for advertising measurement. When you allow them, we load the Meta and TikTok pixels, which set cookies to tell us whether our ads bring people to the site and to the app stores, and to build audiences for our ads. Meta Platforms and TikTok process this data under their own privacy policies and may combine it with data they hold about you. Where the law requires opt-in consent, such as in the EU, the United Kingdom, and Switzerland, we ask on the cookie banner and load nothing before you agree. Elsewhere the pixels load by default; we honor the Global Privacy Control signal by asking first, and you can always block cookies in your browser.

You can withdraw your consent at any time by clearing this site's data in your browser; the banner will then ask again on your next visit.

13. Advertising measurement in the app

When app measurement is enabled, Meta and TikTok receive installation and app-activity signals, including the start of a trial or subscription. Their SDKs also process technical information such as device identifiers, IP address and app version. Our explicit purchase events do not include store transaction IDs, receipts, names, contact details or birthday records. Apple Ads attribution is queried separately to identify eligible ad-driven installations.

You can turn measurement off in the app settings. Where applicable rules allow an opt-out model, we show a notice before enabling it; otherwise it stays off until you enable it. Your manual choice takes precedence. On iOS, Meta and TikTok tracking additionally requires the system tracking permission. We use our Cloudflare-hosted service to determine an initial regional setting from connection metadata; the app receives only the setting, not the IP address or location. Disabling measurement stops new app-submitted events and applies the SDK controls available to us. It does not recall data already sent or guarantee deletion of provider-managed queues.

14. Changes

We may update this policy as the app changes. We will publish the revised version here and change the effective date.

Questions or privacy requests: support@birthminder.app