
Privacy Policy
Last updated July 18, 2026
Birthdaypage (we, us — the operator of birthdaypage.app) wrote this so it's actually readable in one sitting: what we collect, why, who we share it with, and how to control it.
What we collect
When you create a card: the names, greetings, messages, photos, voice recordings, and GIF choices you add to it. These are stored in our database (Supabase, hosted in the EU — Stockholm).
When you make an account: your email address, used only for magic-link sign-in — there's no password to leak.
When you pay:your payment goes straight to Stripe. We never see or store your card number — we only get back a status like “payment succeeded.”
When you browse: country-level location (from CDN headers, not GPS) so we can show local pricing and handle VAT, plus general usage stats via Google Analytics. If you search for a GIF while building a card, the search text is sent server-side to KLIPY to fetch results.
Card links are public
Anyone who has the link to a card can open and view it — that's how sharing works. If you want to keep a card private, add a password when you send it. Don't put anything in a card you wouldn't want a stranger with the link to see.
What we don't do
- We don't sell your data.
- We don't run ads, and we never use your card content — photos, messages, voice recordings — to target ads or for any kind of marketing.
- When birthday reminders launch: contacts you add (name and birth date) are used only to show you your own list and remind you — never to contact that person, never shared, never used for marketing. You'll be able to edit or delete each contact, and deleting your account removes this data too.
Who we share data with
These are the services (subprocessors) that help us run birthdaypage.app. None of them get access beyond what they need to do their job.
| Service | Purpose | Region |
|---|---|---|
| Supabase | Database, auth, and file storage | EU (Stockholm) |
| Stripe | Payment processing | Global |
| Netlify | Hosting and CDN | Global |
| Google Analytics | Usage analytics | Global |
| KLIPY | GIF search | Global |
| Resend | Email delivery (being introduced for reminders) | Global |
Where your data lives
Your card content and account data live in Supabase's EU region (Stockholm) wherever possible. Some of the services we rely on — Stripe, Netlify, Google Analytics, KLIPY — operate globally under their own data protection safeguards.
Your rights
You can ask for access to, correction of, deletion of, or an export of your data. Until we build self-serve tools for all of this, email torstein@vikse.dev and we'll handle it. You can already delete any card yourself from “My cards,” and deleting your account removes your account data.
If you're not happy with how we've handled your data, you can complain to your local data protection authority — in Norway, that's Datatilsynet.
How long we keep it
Cards stay around until their owner deletes them. Account data stays until you delete your account. Abandoned drafts and uploads that were never finished may be cleaned up periodically.
Contact
Questions about your data or this policy? Email torstein@vikse.dev.
Looking for the terms of service instead? Read our Terms of Service.