Skip to content
Byrthday
  • Deutsch
  • English

Privacy policy

Last updated: October 2026

1. Controller

Silvio Lindstedt und Maik Gräfendorf GbR
Pappelweg 27, 39576 Stendal, Germany
[email protected]

This policy covers the "Byrthday" app (iOS and Android) and the website byrthday.app. We have not appointed a data protection officer because the legal requirements for one are not met.

2. In short

  • Byrthday needs no account. You give us neither your name nor your e-mail address.
  • Your occasions, reminders and settings live only on your device. We have no access to them.
  • Only when you request an AI text are a few details about the occasion sent to our server in Germany and from there to OpenAI (section 4).
  • The website uses no cookies and no analytics or tracking tools.

3. Data in the app on your device

Occasions and settings

The occasions you create (name, nickname, type of occasion, date, relationship, reminder settings), your gift ideas including what you gave in which year, your app settings and the "Done" marks for occasions you have already handled are stored in a local database (SQLite) on your device. Done marks are deleted automatically after one year. None of this is transmitted to us or to third parties. It is part of your device backup if you have set up iCloud or Google backup; Apple's or Google's privacy policies apply to that. Deleting the app removes all of this data from the device.

Contacts

If you use the contact import, the app asks once for permission to access your contacts (read only). It then reads only name, given name, nickname, birthday and other stored dates (such as anniversaries) to make suggestions. Only the suggestions you confirm are saved, together with an internal contact id so the app can recognise duplicates. All of this happens on your device; your contact list is never sent to us. The app never writes to your contacts. You can revoke the permission at any time in the system settings.

Calendar

The app accesses your calendar only after your explicit permission. It then reads birthdays and anniversaries from your calendars as suggestions; only the ones you confirm are kept. If you like, the app also creates a calendar of its own named "Byrthday" and writes your occasions into it with name and occasion; it never changes other calendars. That calendar belongs to the calendar account that holds your default calendar (for example iCloud or Google) and is treated by that account like any other calendar, so it may sync to your other devices. For this the app stores locally only the identifiers of the calendar and its entries. Calendar data is not sent to us. You can delete the "Byrthday" calendar with its entries in the app at any time; the permission is revoked in the system settings.

Reminders (notifications)

Reminders are scheduled as local notifications directly on your device. There is no push server: neither we nor a service provider learn which reminders you have set up. So that reminders keep working without opening the app, the app lets the operating system run a background refresh regularly (about once or twice a day; the system picks the exact time) that re-plans the reminders locally.

Language and sharing

The app reads your device language to show the interface and texts in English or German. When you share a greeting, the app hands the text to the app you choose (such as WhatsApp or Messages) or to the clipboard. What happens there is governed by that app's privacy policy.

4. AI greeting texts

What is transmitted

Only when you explicitly request an AI text in the app does the app send the following to our server (api.byrthday.app):

  • the name you entered for the person (first name or nickname, at most 40 characters),
  • the type of occasion (birthday, wedding anniversary, relationship anniversary) or, for custom occasions, its label,
  • the relationship to the person (e.g. family, friend) and the tone you chose (warm, funny, formal),
  • optionally the age or number of years,
  • optionally your keywords (at most 200 characters),
  • the app language and the anonymous device identifier (section 5).

Not transmitted: your contact list, phone numbers, e-mail addresses, dates of birth or other occasions. We recommend not putting sensitive information into the keywords.

Where it is processed

Our server is hosted by netcup GmbH in Germany. It validates the request, counts your quota and forwards the details above together with a fixed instruction to the language model. The generated text is returned to the app. Our server stores neither the transmitted details nor the generated text in its database and does not write them to application logs; it only stores the counter of your quota.

For text generation we use the API of OpenAI (OpenAI, L.L.C., San Francisco, USA) as a processor. The request is routed through the Cloudflare AI Gateway(Cloudflare, Inc., San Francisco, USA), which enforces spend caps and rate limits for us and logs requests and responses for a limited period. Processing in the USA is possible. The transfer is based on the European Commission's adequacy decision for the EU-US Data Privacy Framework, under which both providers are certified, and additionally on standard contractual clauses. Under OpenAI's API terms, inputs are not used to train models and are retained only for a limited time for abuse monitoring.

The connection to api.byrthday.app also passes through Cloudflare's network (proxy), which protects the connection and in doing so technically processes your IP address and connection data.

Legal basis and retention

The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR): the processing only takes place when you actively use the feature. Quota and rate limiting are based on our legitimate interest in a stable, cost-controlled service (Art. 6(1)(f) GDPR). To limit device registrations the server briefly stores a hash (SHA-256) of your IP address, never the plain IP address; these counters are deleted automatically within a few days.

5. Anonymous device identifier

On your first AI text our server generates a random access token, which the app stores in your device's secure storage (Keychain or Keystore). The server keeps only a hash (SHA-256) of this token together with the counter of free AI texts and the creation time. The token contains no information about you or your device; we cannot link it to a person. On iOS the token may survive a reinstall of the app. This record is kept for as long as we operate the service; since it is not personal data to us, we cannot delete it selectively without the token (Art. 11 GDPR).

6. In-app purchases (Byrthday Plus)

Byrthday Plus is not available in the current version yet. Once we offer it, the following applies; we will let you know in the app beforehand.

You buy Byrthday Plus through the Apple App Store or Google Play. Payment processing, invoices and refunds are handled solely by Apple or Google; we receive no payment details. To manage purchases we use RevenueCat (RevenueCat, Inc., San Francisco, USA). This processes a random, anonymous user id, the store's purchase receipts and the status of your subscription or purchase (active, expiry date). Our server stores this anonymous id and the status to unlock the Plus features. The legal basis is contract performance (Art. 6(1)(b) GDPR); the transfer to the USA is based on the EU-US Data Privacy Framework or standard contractual clauses. More information:revenuecat.com/privacy.

7. Advertising in the free version

The current version shows no ads. Should the free version include ad banners in the future, the following applies; we will let you know in the app beforehand.

Where the free version of the app shows ad banners, they are delivered throughGoogle AdMob (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Before the first ad we ask for your consent through the Google User Messaging Platform (UMP); you can change it at any time in the app settings. Without consent, and by default, only non-personalised ads are shown. Google processes technical data such as IP address, device type and the time of the impression, among other things for frequency capping and fraud prevention. Personalised advertising and matching through your device's advertising id happen only if you explicitly agree (on iOS additionally through the App Tracking Transparency prompt). The legal basis is your consent (Art. 6(1)(a) GDPR). With Byrthday Plus no ads are shown. Information on Google's data processing:policies.google.com/privacyandpolicies.google.com/technologies/ads.

8. This website

The website byrthday.app is served through Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; EU establishment: Cloudflare Germany GmbH, Munich). When you visit, Cloudflare processes technically necessary connection data (IP address, time, page requested, browser identifier) to deliver the site and fend off attacks; this data is kept only briefly in server logs. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). The website uses no cookies, no analytics or tracking tools and no third-party fonts or scripts.

9. Your rights

You have the right to:

  • access the data we hold about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on legitimate interests (Art. 21 GDPR).

You can withdraw consent at any time with effect for the future. Because we store no data in the app that would let us identify you, we may need additional information from you to answer an access or erasure request (Art. 11 GDPR). You delete the data on your device yourself by deleting the app. You also have the right to lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection of Saxony-Anhalt (Landesbeauftragter für den Datenschutz Sachsen-Anhalt).

10. Changes

We update this policy when the app or the law changes. The current version is always available at byrthday.app/en/privacy.

© 2026 Silvio Lindstedt und Maik Gräfendorf GbR

  • Privacy
  • Terms
  • Imprint
  • Deutsch
  • English