Privacy Policy
Last updated: 2026-09-23
We built BirthdayPro because we genuinely love the moment a friend feels remembered. That only works if you trust us with the data that makes those moments possible. This policy explains what we collect, why we collect it, and the controls you have. Plain English, no hand-waving.
Who we are
BirthdayPro is a freemium web app that helps you remember the birthdays of the people who matter, pulls those birthdays in from the tools you already use, and drafts personalized wishes with AI. When this policy says "we," "us," or "BirthdayPro," we mean Pri's Ventures LLC, an Illinois limited liability company operating the service at birthdaypro.io. You can reach the humans behind it anytime at hello@birthdaypro.io.
What we collect
We only collect what we need to run the service. Specifically:
Account data. Your email address, authentication record managed by Supabase Auth (or OAuth identifier if you sign in with Google), your display name, your subscription tier, and your notification preferences. BirthdayPro does not receive or store your plaintext password.
Birthday data. The names, birth dates, relationship notes, tone preferences, and any optional context you save for each person you track. This is the heart of the product and it stays tied to your account.
Integration tokens. When you connect a contacts or calendar source that BirthdayPro offers you (iCloud today; Google and Outlook only once their provider approval is complete and the connector is switched on), we store the OAuth access and refresh tokens or the app-specific password you enter, encrypted, so we can pull in your birthdays. For CSV, vCard, and .ics imports, we process the file you upload. We only ever request the minimum read-only scopes needed for the import you start.
Browser extension imports. If you use the BirthdayPro Importer Chrome extension to import Facebook birthdays, the extension runs in your own logged-in Facebook browser session and reads the friends' birthdays Facebook shows you. It sends each friend's name, birthday date, and the Facebook identifier of that friend's entry (used only to avoid duplicates) to your BirthdayPro account, where they wait in a preview until you choose which ones to save. Birth years are kept only when Facebook provides a plausible real year; otherwise BirthdayPro stores month and day only. We do not see, store, or transmit your Facebook password, cookies, or session token. The BirthdayPro connection code is stored locally in your browser until you revoke or replace it. The full extension disclosure is in the "Chrome extension and Limited Use" section below.
Usage analytics. Basic product telemetry such as which pages you visit, which features you use, timing of reminders, and whether a message was approved or edited. We use this to improve the product. We do not sell this data and we do not run third-party advertising trackers.
AI draft reports. If you use "Report this draft" on a generated message in the BirthdayPro app, we e-mail our support inbox (hello@birthdaypro.io, delivered through Resend) a copy of the reported draft as it is saved in your message history (not edits you made afterwards), the reason you picked, the note you typed (if any), when you reported it, which platform you used, and your account, message, and birthday identifiers. Your account name and email address are not added as separate fields. The reported draft and any note are included as written and may contain names or contact details. We also record a diagnostic event in Sentry carrying the same identifiers, the reason, the platform, and the lengths of the draft and note — never their text. Nothing is sent to the person the draft is about.
Billing metadata. If you subscribe, Stripe processes your card details — we never see your card number. We receive a customer ID, subscription status, country, and the last four digits of your card for receipts.
How we use it
We use your data to deliver the service you signed up for: storing and deduplicating your contacts, sending reminder emails before a birthday, generating personalized message drafts with AI, opening a user-selected email, Messages, or WhatsApp composer with a draft for you to review and send, enforcing plan limits and rate limits, responding to support requests, reviewing the AI drafts you report so we can improve the drafting safeguards, and keeping the product secure. Reminders are delivered by email in this release. BirthdayPro does not send contact-facing messages without your final action. We do not use your birthday data, relationship notes, or contact lists for advertising, profiling, or training foundational AI models.
Google API data and Limited Use
If you choose to connect Google, BirthdayPro requests only the read-only permissions needed for the import you start. Google Contacts import reads contact names, email addresses, birthday fields, and Google resource identifiers. Google Calendar import reads calendar identifiers and birthday-event titles, dates, recurrence information, event types, and Google event identifiers. We use this data only to show you an import preview, deduplicate entries, save the birthdays you select, and provide the birthday reminders and message-drafting features you request.
OAuth tokens are encrypted at rest and are used only to perform the imports you initiate. We do not sell Google user data, use it for advertising or credit decisions, or share it with data brokers. Service providers receive only the data needed to operate the user-facing feature described in this policy. Any operational diagnostics derived from Google imports are limited to aggregate counts and exclude names, email addresses, phone numbers, event titles, and other contact content.
Google user data is not used to train generalized AI or machine learning models. When you explicitly request an AI birthday-message draft, the relevant saved birthday details, notes, and your earlier drafts for that person may be sent to Google Gemini solely to generate that draft; Google API inputs are not used to train its generalized models. The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google revokes BirthdayPro's stored connection. You can delete imported birthdays individually, export your data, or delete your account in Settings. Account deletion follows the retention schedule described below.
Chrome extension and Limited Use
The BirthdayPro Importer Chrome extension has a single purpose: importing the birthdays of your Facebook friends into your BirthdayPro account so you can be reminded of them. It runs only when you start an import, from the BirthdayPro website or from the extension's own popup, and only on facebook.com pages in your own logged-in browser session. It collects nothing until you start an import, does not read other websites, and requests only the storage and scripting permissions plus access to facebook.com and birthdaypro.io that this import needs.
The extension reads the friends' names, birthday dates, and Facebook entry identifiers that Facebook shows you, and sends them to BirthdayPro over HTTPS using a connection code tied to your account (created in Settings, or automatically when you start the import from the website). Your Facebook password, cookies, and session token stay in your browser; BirthdayPro never receives them. Imported entries are staged as a preview for 30 minutes and are saved to your account only for the entries you select in that preview; entries you do not select are discarded. Saved entries become ordinary birthday records in your account, used for the reminders and optional message drafts described in this policy, and can be deleted or exported like any other record.
Data received through the extension is used only to provide this import and the birthday reminders and drafts you request. It is not sold, not used for advertising, not transferred to data brokers, and not used for credit or lending decisions; it is transferred to the service providers named below only as needed to operate the service, or when required by law. BirthdayPro's use of information received through the BirthdayPro Importer extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
How we protect your data
BirthdayPro uses HTTPS/TLS to protect data in transit between your browser or mobile device, BirthdayPro, and connected providers such as Google. Google OAuth access and refresh tokens, along with other integration credentials, are encrypted before database storage using authenticated AES-256-GCM encryption with a unique random initialization vector. The encryption key is held separately in server-side environment configuration and is not sent to the browser or mobile app.
User-owned records are protected by authenticated database row-level security policies that restrict access to the owning account. Privileged service credentials stay on the server and are used only by narrowly scoped operations after the requesting user, signed link, API key, webhook, or scheduled job has been verified. Google imports request read-only scopes and do not create, edit, or delete data in your Google account.
We minimize sensitive data in operational logs, restrict diagnostics derived from Google imports to non-content counts, monitor service errors, and keep production secrets out of client-side code. No online service can guarantee absolute security; if a breach affects your personal data, we will investigate, contain it, and notify affected users and regulators when required by law.
Who we share it with
We work with a small set of infrastructure providers who process data on our behalf under strict contracts. We do not sell your personal data to anyone, ever.
Supabase hosts our Postgres database and handles authentication. Your account and birthday records live here.
Render hosts the web app and its API routes.
Stripe processes payments for paid plans. They act as an independent controller for payment data under their own privacy policy.
Resend delivers reminder emails and transactional messages like password resets, and carries the AI draft reports described above to our support inbox.
Google Gemini generates the AI birthday message drafts. When you ask for a draft, we send the relevant person's name, relationship, your notes, your tone preference, and your earlier drafts for that person to Google's API so the new draft does not repeat them. Your account name and email address, and your other birthdays, are not added on their own; everything in that person's notes and in those earlier drafts is sent exactly as you wrote it, including any names or contact details you put there. Google has committed to not using API inputs to train its models.
Sentry captures error traces and stack information so we can fix bugs quickly, and records one diagnostic event for each AI draft report: your account identifier, the report, message, and birthday identifiers, the reason, the platform, and the lengths of the draft and note — never the draft or note text. We scrub email addresses and personal names from stack traces where possible.
Upstash stores short-lived request counters keyed by your account identifier so we can enforce per-user rate limits, and holds the Chrome-extension import preview (the names, birthday dates, and Facebook entry identifiers waiting for your selection) for up to 30 minutes, until you confirm your selection or the preview expires. No other birthday content is stored there.
Gift links. Gift ideas open the retailer's own site (Amazon, or a ShopMy affiliate link when one is configured) in a new tab. BirthdayPro may earn a commission on qualifying purchases and does not send your account or birthday data to those retailers; once you are on their site, their privacy policy applies.
Where your data lives
Our primary database and application servers run in the United States. If you access BirthdayPro from outside the US, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses with our sub-processors where applicable to protect international transfers.
How long we keep it
We hold onto your account data and the birthdays you've added for as long as your account is active. If you delete your account from /settings, we remove your personal data from our production database within 7 days and from encrypted backups within 30 days. Server logs that contain IP addresses and request metadata roll off after 30 days. Billing records are retained for 7 years to meet tax and accounting obligations.
AI draft reports live outside that database: the e-mail copy is delivered through Resend to our support mailbox, and the diagnostic event is held by Sentry. Deleting your account does not by itself remove either copy. We do not promise a fixed retention period for them; how long each copy is kept follows the support mailbox's and Sentry's own retention settings. The reference the app shows you (the first characters of the report identifier) identifies a report if you contact us about it.
Your rights and controls
You have the right to access, correct, export, and delete your personal data. Most of these controls live directly in /settings — you can export your birthdays as CSV, disconnect any integration, revoke OAuth tokens, or delete your account with a single click. If you'd rather have a human help, email hello@birthdaypro.io and we'll respond within 7 days.
Cookies
We set a small number of essential cookies to keep you signed in and remember your subscription tier during a session. We do not use Google Analytics, Facebook Pixel, advertising cookies, or any third-party tracking pixels. For the full story, see our Cookie Notice.
GDPR (for visitors in the EEA and UK)
Our lawful basis for processing your personal data is the performance of the contract you entered into by signing up (Article 6(1)(b)) for core features, and our legitimate interest (Article 6(1)(f)) for product improvement, fraud prevention, and security. For marketing emails beyond transactional messages, we rely on your consent, which you can withdraw at any time.
Under the GDPR and UK GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. You can exercise these rights at /settings or by emailing hello@birthdaypro.io. We do not have a statutorily required Data Protection Officer, but privacy questions go to the same address and are handled by a named person on our team. If you believe we've mishandled your data, you have the right to lodge a complaint with your local supervisory authority.
CCPA (for California residents)
Under the California Consumer Privacy Act, you have the right to know what personal information we collect, to delete it, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under the CCPA, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit. We will not discriminate against you for exercising any of these rights.
Children's privacy
BirthdayPro is built for adults and older teens. You must be at least 13 years old to create an account. We do not knowingly collect personal data from children under 13. If you believe a child has signed up, email us and we will delete the account.
Changes to this policy
If we make material changes, we'll email active users at least 14 days before the new policy takes effect. Smaller edits get a new "Last updated" date at the top of this page.
Contact us
Privacy questions, requests, or concerns? Email hello@birthdaypro.io and a real human on our team will get back to you within 7 days.
Postal mail: Pri's Ventures LLC · 2501 Chatham Rd, Suite N · Springfield, IL 62704, US.