Privacy Policy
Last updated: 2026-07-30
We built BirthdayPro because we genuinely love the moment a friend feels remembered. That only works if you trust us with the data that makes those moments possible. This policy explains what we collect, why we collect it, and the controls you have. Plain English, no hand-waving.
Who we are
BirthdayPro is a freemium web app that helps you remember the birthdays of the people who matter, pulls those birthdays in from the tools you already use, and drafts personalized wishes with AI. When this policy says "we," "us," or "BirthdayPro," we mean Pri's Ventures LLC, an Illinois limited liability company operating the service at birthdaypro.io. You can reach the humans behind it anytime at hello@birthdaypro.io.
What we collect
We only collect what we need to run the service. Specifically:
Account data. Your email address, authentication record managed by Supabase Auth (or OAuth identifier if you sign in with Google), your display name, your subscription tier, and your notification preferences. BirthdayPro does not receive or store your plaintext password.
Birthday data. The names, birth dates, relationship notes, tone preferences, and any optional context you save for each person you track. This is the heart of the product and it stays tied to your account.
Integration tokens. When you connect Google Contacts, Outlook, iCloud, or optional beta integrations you explicitly enable, we store the OAuth access, refresh tokens, or app-specific credentials securely so we can pull in your birthdays. For CSV and vCard imports, we process the file you upload. We only ever request the minimum scopes needed to read contacts or the specific fields you ask us to read.
Browser extension imports. If you use the BirthdayPro Chrome extension to import Facebook birthdays, the extension runs in your own logged-in Facebook browser session and reads the friends' birthdays Facebook shows you. It sends friends' names and birthday dates to your BirthdayPro account so we can create reminders. Birth years are kept only when Facebook provides a plausible real year; otherwise BirthdayPro stores month and day only. We do not see, store, or transmit your Facebook password, cookies, or session token. The BirthdayPro connection code is stored locally in your browser until you revoke or replace it.
Usage analytics. Basic product telemetry such as which pages you visit, which features you use, timing of reminders, and whether a message was approved or edited. We use this to improve the product. We do not sell this data and we do not run third-party advertising trackers.
Billing metadata. If you subscribe, Stripe processes your card details — we never see your card number. We receive a customer ID, subscription status, country, and the last four digits of your card for receipts.
How we use it
We use your data to deliver the service you signed up for: storing and deduplicating your contacts, sending reminder emails and push notifications before a birthday, generating personalized message drafts with AI, opening a user-selected email, Messages, or WhatsApp composer with a draft for you to review and send, enforcing plan limits, responding to support requests, and keeping the product secure. BirthdayPro does not send contact-facing messages without your final action. We do not use your birthday data, relationship notes, or contact lists for advertising, profiling, or training foundational AI models.
Google API data and Limited Use
If you choose to connect Google, BirthdayPro requests only the read-only permissions needed for the import you start. Google Contacts import reads contact names, email addresses, birthday fields, and Google resource identifiers. Google Calendar import reads calendar identifiers and birthday-event titles, dates, recurrence information, event types, and Google event identifiers. We use this data only to show you an import preview, deduplicate entries, save the birthdays you select, and provide the birthday reminders and message-drafting features you request.
OAuth tokens are encrypted at rest and are used only to perform the imports you initiate. We do not sell Google user data, use it for advertising or credit decisions, or share it with data brokers. Service providers receive only the data needed to operate the user-facing feature described in this policy. Any operational diagnostics derived from Google imports are limited to aggregate counts and exclude names, email addresses, phone numbers, event titles, and other contact content.
Google user data is not used to train generalized AI or machine learning models. When you explicitly request an AI birthday-message draft, the relevant saved birthday details and notes may be sent to Google Gemini solely to generate that draft; Google API inputs are not used to train its generalized models. The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting Google revokes BirthdayPro's stored connection. You can delete imported birthdays individually, export your data, or delete your account in Settings. Account deletion follows the retention schedule described below.
How we protect your data
BirthdayPro uses HTTPS/TLS to protect data in transit between your browser or mobile device, BirthdayPro, and connected providers such as Google. Google OAuth access and refresh tokens, along with other integration credentials, are encrypted before database storage using authenticated AES-256-GCM encryption with a unique random initialization vector. The encryption key is held separately in server-side environment configuration and is not sent to the browser or mobile app.
User-owned records are protected by authenticated database row-level security policies that restrict access to the owning account. Privileged service credentials stay on the server and are used only by narrowly scoped operations after the requesting user, signed link, API key, webhook, or scheduled job has been verified. Google imports request read-only scopes and do not create, edit, or delete data in your Google account.
We minimize sensitive data in operational logs, restrict diagnostics derived from Google imports to non-content counts, monitor service errors, and keep production secrets out of client-side code. No online service can guarantee absolute security; if a breach affects your personal data, we will investigate, contain it, and notify affected users and regulators when required by law.
Who we share it with
We work with a small set of infrastructure providers who process data on our behalf under strict contracts. We do not sell your personal data to anyone, ever.
Supabase hosts our Postgres database and handles authentication. Your account and birthday records live here.
Render hosts the web app and its API routes.
Stripe processes payments for paid plans. They act as an independent controller for payment data under their own privacy policy.
Resend delivers reminder emails and transactional messages like password resets.
Google Gemini generates the AI birthday message drafts. When you ask for a draft, we send the relevant person's name, your relationship notes, and your tone preference to Google's API. Google has committed to not using API inputs to train its models.
Sentry captures error traces and stack information so we can fix bugs quickly. We scrub email addresses and personal names from stack traces where possible.
Where your data lives
Our primary database and serverless functions run in the United States. If you access BirthdayPro from outside the US, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses with our sub-processors where applicable to protect international transfers.
How long we keep it
We hold onto your account data and the birthdays you've added for as long as your account is active. If you delete your account from /settings, we remove your personal data from our production database within 7 days and from encrypted backups within 30 days. Server logs that contain IP addresses and request metadata roll off after 30 days. Billing records are retained for 7 years to meet tax and accounting obligations.
Your rights and controls
You have the right to access, correct, export, and delete your personal data. Most of these controls live directly in /settings — you can export your birthdays as CSV, disconnect any integration, revoke OAuth tokens, or delete your account with a single click. If you'd rather have a human help, email hello@birthdaypro.io and we'll respond within 7 days.
Cookies
We set a small number of essential cookies to keep you signed in and remember your subscription tier during a session. We do not use Google Analytics, Facebook Pixel, advertising cookies, or any third-party tracking pixels. For the full story, see our Cookie Notice.
GDPR (for visitors in the EEA and UK)
Our lawful basis for processing your personal data is the performance of the contract you entered into by signing up (Article 6(1)(b)) for core features, and our legitimate interest (Article 6(1)(f)) for product improvement, fraud prevention, and security. For marketing emails beyond transactional messages, we rely on your consent, which you can withdraw at any time.
Under the GDPR and UK GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. You can exercise these rights at /settings or by emailing hello@birthdaypro.io. We do not have a statutorily required Data Protection Officer, but privacy questions go to the same address and are handled by a named person on our team. If you believe we've mishandled your data, you have the right to lodge a complaint with your local supervisory authority.
CCPA (for California residents)
Under the California Consumer Privacy Act, you have the right to know what personal information we collect, to delete it, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under the CCPA, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit. We will not discriminate against you for exercising any of these rights.
Children's privacy
BirthdayPro is built for adults and older teens. You must be at least 13 years old to create an account. We do not knowingly collect personal data from children under 13. If you believe a child has signed up, email us and we will delete the account.
Changes to this policy
If we make material changes, we'll email active users at least 14 days before the new policy takes effect. Smaller edits get a new "Last updated" date at the top of this page.
Contact us
Privacy questions, requests, or concerns? Email hello@birthdaypro.io and a real human on our team will get back to you within 7 days.
Postal mail: Pri's Ventures LLC · 2501 Chatham Rd, Suite N · Springfield, IL 62704, US.