Cake Day Gifts
Privacy Policy
Effective date: 17 July 2026
Cake Day Gifts helps account holders remember celebrations, prepare messages, and keep private relationship notes. We collect only what is needed to provide those features, secure the service, support purchases, enforce fair-use limits, and understand whether the product is useful. We do not sell personal data, show third-party advertising, or use app data for advertising or cross-app tracking.
Information We Collect
- Account information such as your name, email address, sign-in provider, and profile photo if you add one.
- Information you choose to save about other people, including names, celebration dates, relationship labels, gift preferences, notes, phone numbers, email addresses, reminder times, photos, and message details.
- Purchase and subscription status, product identifiers, renewal or expiry state, and related billing-event records handled through Apple and RevenueCat.
- Optional AI request fields needed to generate a suggestion, such as a recipient name, relationship, occasion, tone, locale, suggestion count, and your optional brief.
- When you create a Celebration Brief, the app may send only the selected intent, normalized relationship group, occasion kind, age band, timing band, budget band, currency, up to three interest categories, gathering choices, selected constraints, locale, and optional context you approve. It does not send a saved person's name, exact date, contact details, photo, notes, or Cake Day record identifier for this feature.
- Privacy-safe product analytics, including contracted event names, Pro status, a saved-count band, locale, app version, and the Supabase profile identifier used as the analytics distinct ID.
- Operational information needed to protect the service and enforce AI limits, including authentication identifiers, request logs, error information, and per-user usage counters.
How We Use Information
- To create and secure your account.
- To store celebrations, reminders, notes, photos, and gift preferences you add.
- To schedule local reminders when you request them.
- To generate optional AI message suggestions and structured Celebration Briefs through our secure backend.
- To verify subscriptions, restore purchases, enforce per-tier AI limits, and prevent abuse.
- To measure activation, feature use, purchases, and return use so we can improve the product.
- To provide data export and account deletion, respond to support, and investigate reliability or security problems.
Information About Other People And Children
Cake Day Gifts is designed for an adult account holder, but you may choose to save information about family members, including a child's name, birthday, photo, preferences, or notes. Only add information you are authorised to use, keep it proportionate to the reminder or celebration purpose, and avoid unnecessary sensitive details. The app is not directed to children under 13 and does not invite children to create accounts. The account holder can export or delete saved family information at any time.
Third-Party Services
- Firebase Authentication verifies sign-in while the authentication migration to Supabase is completed.
- Supabase stores profiles, saved celebrations, subscription entitlements, and AI usage counters.
- Apple App Store and RevenueCat process purchases and provide subscription and entitlement status. Cake Day Gifts does not receive your full payment-card details.
- Anthropic Claude processes the minimum fields required when you explicitly request an AI message suggestion or provider-enhanced Celebration Brief.
- PostHog EU Cloud receives the contracted product events described below. Session replay, interaction autocapture, surveys, advertising features, and automatic error capture are disabled.
- Google Cloud Run hosts the Cake Day Gifts backend. Sentry may process backend error diagnostics when enabled; saved-person content is not intentionally attached to diagnostic events.
Product Analytics And Your Choice
Analytics collection is on by default and can be turned off at any time in Settings. Turning it off stops future PostHog product-event collection from the app. We identify signed-in analytics only with the Supabase profile UUID. Analytics properties are restricted to the reviewed event contract and must not contain a saved person's name, contact details, birthday, relationship, notes, message or prompt text, photo, file, URL, or idea contents. We do not attach email, phone number, Firebase UID, or PostHog person properties.
Device Permissions
The app may ask for contacts, notifications, or photo-library access. You can deny or change these permissions in iOS Settings. Contact and photo-library access is used only for features you choose, such as selecting or importing contacts, adding profile photos, or adding memory images.
AI Features
When you request AI suggestions, Cake Day Gifts sends only the fields needed for that request to our backend and then to Anthropic Claude, a third-party AI provider. Those fields may include recipient name, relationship, tone, locale, suggestion count, and your optional brief or occasion. We do not intentionally store AI prompts or responses in the app database. We do not send phone number, email, photos, gift notes, or your full contact record for this AI message feature. Do not submit sensitive information you do not want processed for that purpose. We do not use AI prompts to sell advertising.
Celebration Concierge uses normalized, non-identifying categories for relationship, occasion, age range, timing, budget, interests, gathering choices, and selected constraints. Optional context is length-limited and screened for obvious email addresses, phone numbers, links, and control characters before provider processing. Suggestions may be incomplete or unsuitable, so review them and independently check age labels, allergies, supervision needs, accessibility, venue rules, availability, delivery, and professional guidance where relevant.
Plans Saved On This Device
Celebration Concierge drafts and completed briefs are stored locally on your device in a bounded, versioned store. They are included in the in-app local privacy export and can be deleted individually or cleared from Privacy & Data. They are also cleared by the app's account-deletion and guest-data-reset flows. These plans are not synced to Supabase in this release.
Optional Retailer Links
If Cake Day later shows a verified physical-product link, the app displays an affiliate disclosure before the link. Cake Day may earn a commission from an eligible purchase. Retailer information must come from the current retailer service, not from generated suggestions. Price, availability, delivery, suitability, and retailer coverage are never guaranteed. Retailer links are hidden when a compliant provider is unavailable.
Purchases
RevenueCat helps us verify purchase status, restore purchases, and check whether Cake Day Pro is active. We may set limited purchase-flow attributes, such as the screen that showed the upgrade prompt, to improve app functionality. These attributes should not contain names, emails, phone numbers, or message content.
Data Retention And Deletion
We keep account and saved-person data while your account is active. PostHog product events are retained for up to 12 months under the current Cake Day Gifts plan. AI prompts and generated responses are not intentionally stored in the Cake Day Gifts database. Operational logs and provider records are kept only as needed for security, reliability, fraud prevention, legal obligations, and billing. Provider backups may retain deleted records for a limited backup cycle, during which they are not used as active app data.
You can delete your account inside the app. The deletion flow removes the Firebase account and Cake Day Gifts records in Supabase, including the profile, saved celebrations, entitlement rows, and user-specific AI usage counters. The app also resets its PostHog identity. Apple, RevenueCat, and other processors may retain limited transaction, fraud-prevention, security, or legal records under their own obligations. Deleting your Cake Day account does not cancel an active Apple subscription; manage or cancel subscriptions in your Apple ID subscription settings.
Data Export
The in-app export includes Cake Day Gifts server-held account and profile fields, every saved celebration record, RevenueCat entitlement records persisted by Cake Day Gifts, user-specific AI usage counters, and local Celebration Concierge plans stored on that device. Guest exports include celebrations and local concierge plans stored on that device. PostHog analytics events, Apple purchase receipts, and records held only by third-party providers are not part of the Cake Day Gifts export; contact support if you need help making a provider-specific access or deletion request.
Your Choices
- Export Cake Day data held by our service from the app's Privacy & Data screen. PostHog analytics events and Apple or RevenueCat records held only by those providers are not included in this file; contact support if you need help making a provider-specific access or deletion request.
- Delete your account from the app's Privacy & Data screen.
- Turn privacy-safe usage analytics on or off in Settings.
- Turn permissions on or off in iOS Settings.
- Contact us to ask privacy questions.
Security And International Processing
We use access controls, encrypted transport, service-role separation, and provider security features to protect data. No system is completely secure. Our providers may process data in countries other than yours; where required, that processing is governed by their contractual and legal safeguards.
Changes To This Policy
We may update this policy when the product, providers, or legal requirements change. We will update the effective date and provide additional notice when a change materially affects your choices.
Contact
Email: hello@cakedaygifts.com