The fine print
Privacy Policy.
This policy explains what birthdaycards.ai collects, how we use it, and the choices you have when you make printed or digital birthday cards.
Effective September 12, 2026
Optional feedback emails
- After you create an account, try the site and stop using it, Cole may send a one-time email asking for feedback. No separate feedback-email opt-in is required. We use broad activity stages, such as saving a design or starting a card, to personalize the message. We do not put private card messages or recipient details in these emails.
- We store your email preferences, email version, delivery events, unsubscribe status, reply excerpts, and related site-return and purchase outcomes to understand which messages are useful. Resend processes delivery and replies; replies are forwarded to our support inbox. Email opens and clicks may also be recorded if tracking is enabled. These campaign records are separate from the detailed 90-day activity history and may be retained longer to maintain preferences and measure performance.
- You can turn off feedback emails in account settings or unsubscribe from an email. This does not stop receipts or reminders you requested, and it does not change your separate free birthday-card preference. Contact us to request removal of personal campaign data.
What we collect
- Account information, such as your name, email address, and sign-in provider details if you choose to create an account.
- If you opt in to a free birthday card, we store your birthday month and day, the email from your Google account (or the delivery email you later choose in settings), and when you opted in. No birth year is required. You can change or turn off this preference in account settings.
- Card and order information, including card text, generated card artwork, delivery type, recipient name, recipient email for digital cards, shipping address for physical cards, checkout email, and order status.
- Uploaded content, such as face photos, saved People photos, voice notes, prompts, custom directions, and any other content you add to a card.
- People and reminder information, such as birthdays, relationship labels, addresses, emails, notes, saved photos, reminder settings, and timezone.
- Technical information, such as device, browser, IP address, logs, and basic usage events needed to keep the service secure and working.
Site activity and cookies
- We use a first-party browser cookie to understand visits, including visits without an account. We store landing pages, referring domains, campaign (UTM) parameters, searches and results, page navigation, card clicks and placement, and action metadata such as editing, basket and checkout steps in our own database.
- If you sign in, we may associate your prior anonymous activity from that browser with your account. Signing out or switching accounts starts a separate activity identity.
- The activity timeline records field-change actions without their contents. It does not record passwords, payment details, private card messages, addresses, file contents or screen recordings. Search terms and campaign parameters are retained as entered, so avoid putting private information in search fields.
- Detailed activity history is retained for 90 days and accessible only to authorized administrators. Order and card content needed to provide the service is stored separately.
Optional AI shopping assistant
- If you choose to chat with our AI shopping assistant, we save the messages you submit, the assistant's replies and recommendations, and any helpfulness feedback in our database. We associate the conversation with your first-party visitor session and with your account if you sign in.
- We send recent chat messages, the current shopping page type, and relevant public product information to OpenAI to provide replies. We do not automatically include private card messages, recipient addresses, uploaded photos, voice notes, or payment fields. Please do not share payment details or other sensitive information in chat.
- We use conversations to help you, understand requests and confusion, and improve the site. Authorized administrators can review conversations alongside site activity. AI-generated summaries may be imperfect. We redact common email addresses, phone numbers and links from analysis inputs, but automated redaction cannot identify every piece of personal information.
- Saved conversations and derived insights expire 90 days after the conversation starts. You can delete the saved conversation and its insights using Delete saved chat in the chat panel. Closing the panel does not delete it. Site activity is retained separately under the policy above. We do not include chat transcripts in advertising events.
Advertising measurement
- We use Google's advertising tag to understand whether a Google ad led to a purchase. Google can store advertising click identifiers in browser cookies and receive technical information such as your IP address and browser details.
- For a confirmed purchase, we send Google the amount, currency, and an opaque transaction identifier to measure sales and prevent duplicate counts. We do not include names, email addresses, recipient addresses, private card messages, photos, voice recordings, or payment card details in these conversion events.
- We disable advertising personalization signals in this tag. We do not load it when your browser sends Global Privacy Control or Do Not Track. Browser privacy settings and ad blockers may also prevent measurement.
- We also use the Meta Pixel to measure visits and purchases from Facebook and Instagram ads. Meta receives technical browser information, such as IP address, browser details and advertising cookies or click identifiers. For a verified purchase, we send only its amount, currency and an opaque payment identifier. We keep private receipt URLs, card content and customer contact details out of the pixel document, and disable automatic event detection and advanced matching. Global Privacy Control and Do Not Track prevent this pixel from loading. A local browser record helps avoid reporting the same purchase again.
How we use information
- To let you design, edit, purchase, send, print, and mail birthday cards.
- To generate AI-assisted card covers, messages, templates, and other card content you request.
- To process payments, send receipts, deliver digital cards, fulfill physical card orders, and send order updates.
- To save your drafts, People list, reminders, uploaded photos, and order history when you use those features.
- To detect abuse, debug errors, improve product quality, and comply with legal obligations.
Photos, prompts, and AI generation
- When you upload photos or enter prompts for AI features, we use that content to provide the requested card generation and editing features.
- Face photos may be stored as image assets so you can use them in Studio, saved People profiles, cards, and related product flows.
- Generated content can be imperfect. You should review the final card before checkout, especially names, faces, dates, and message text.
Payments and fulfillment partners
- Stripe processes payments. We do not store full card numbers on our servers.
- Cardly or other print and mail partners may receive the information needed to print and mail physical cards, including card artwork, message content, and recipient address.
- Resend or other email providers may receive information needed to send receipts, reminder emails, status updates, and digital card delivery emails.
- Google Cloud Storage or local storage may be used for uploaded assets such as photos, generated card images, QR codes, and voice-note audio.
- OpenAI, fal.ai, or other AI providers may process prompts, images, and related inputs when you use AI features.
Sharing
- We share information with service providers as described above to run the product, process payments, send email, generate cards, store assets, fulfill orders, and measure advertising performance.
- We may disclose information if required by law, to protect users and the service, or in connection with a business transfer such as a merger, acquisition, or sale of assets.
- We do not sell your personal information.
Your choices
- You can use guest checkout, but creating an account lets you save people, photos, reminders, drafts, and order history.
- You can delete saved People photos and update People records from your account pages.
- You can unsubscribe from optional emails where an unsubscribe option is provided. Transactional emails, such as receipts and order updates, may still be sent.
- You can request access, correction, or deletion of personal information by contacting us.
Retention and security
- We keep information for as long as needed to provide the service, maintain order records, resolve disputes, improve the product, and meet legal or operational requirements.
- We use reasonable technical and organizational safeguards, but no internet service can guarantee perfect security.
Children
- birthdaycards.ai is not directed to children under 13. Do not use the service if you are under 13.
- If you upload a photo or personal information about another person, including a child, you are responsible for having the right and permission to do so.
Changes
- We may update this Privacy Policy from time to time. The effective date above shows when this version took effect.