B-DAY is a local-first birthday organizer for iPhone and Apple Watch. Your information is stored on your device, and — only if you choose — in your own private iCloud. We do not use analytics, advertising, or tracking, and we include no third-party SDKs. We never receive your birthdays, contacts, photos, or notes. There is exactly one exception, and only if you choose to use it: greeting cards you send as a link (see section 13). Nothing else ever leaves your device. This Privacy Policy is provided by Aleksandr Pavlov.
1. Who this applies to
This policy covers the B-DAY iPhone app, its widgets, and the Apple Watch app. Information about other people that you add (names, birthdays, etc.) is entered by you; you are responsible for having a reasonable basis to store it.
2. Information the app handles
Depending on how you use B-DAY, the app stores: names, birthdays (and whether the year is known), optional photos, phone numbers, email addresses, social handles (Instagram/Telegram/Facebook), relationship type, notes, gift ideas, favorite status, reminder preferences, and app settings. This information is used only to provide the app's features.
3. Where your data is stored (local-first)
App data is stored locally on your device using Apple's on-device storage. It is protected by your device passcode and iOS encryption. We do not add separate encryption on top of iOS.
4. Contacts import (optional)
If you choose to import from Contacts, the app asks for Contacts permission and lets you select which contacts to import. For the contacts you pick, it copies their name, birthday, phone, email, social handles, and photo thumbnail into the app. The app does not read your contact notes, does not change or delete your contacts, and does not send your contacts to us. You can use the app without granting Contacts access by adding people manually.
5. iCloud sync (optional, off by default)
B-DAY includes an optional iCloud Sync that is turned off by default. If you turn it on, your birthday records sync through your own private iCloud account (Apple's CloudKit private database). This data is tied to your Apple ID and handled by Apple's infrastructure; we have no access to your private iCloud data. Sync requires that you are signed in to iCloud. You can turn sync off at any time.
6. Notifications (local only)
Reminders are local notifications scheduled on your device. There is no push service and no server involved; we receive nothing. Notification previews can show a person's name, age, and birthday date on your screen, including the Lock Screen. You can hide previews in iOS Settings and disable reminders in the app.
7. Widgets
Home Screen and Lock Screen widgets read birthday information (names, dates, a small photo thumbnail, favorite status) from a shared on-device container so they can display upcoming birthdays. Widgets make no network connections.
8. Apple Watch
The Apple Watch app and widgets receive only the birthday information needed to display their features — names, dates, a small photo, and reminder summaries. Phone numbers and email addresses are not sent to or stored on the watch. Data moves only between your iPhone and your paired Apple Watch using Apple's WatchConnectivity, and a minimal copy is cached on the watch so it can work on its own. Nothing is sent to any server from the watch.
9. Purchases
B-DAY offers a one-time Full Version purchase (not a subscription). Purchases are processed by Apple through the App Store; we do not receive your payment details. The app stores only a local flag indicating whether the Full Version is unlocked. Restoring purchases is handled through Apple.
10. Analytics, advertising, tracking
B-DAY contains no analytics, no advertising, and no tracking. There is no IDFA, no ad SDKs, and no third-party analytics. We do not build user profiles and do not sell data.
11. Third-party services
The app includes no third-party SDKs. It uses Apple services only: iCloud/CloudKit (if you enable sync), StoreKit (purchases), and Apple Speech (only if you use voice search). When you tap an action like "message" or "open Instagram," iOS opens the relevant app; the phone number or handle is handed to that app by iOS, not to us.
12. Voice search (optional)
If you use voice search, the app uses the microphone and Apple's Speech Recognition to turn speech into text. Depending on your device and language, Apple may process the audio to recognize it. The recognized text is used only to fill the search field; it is not stored or sent to us.
13. Greeting cards sent as a link (optional)
This is the only feature that sends anything to a server we run.
If you choose Send as a card, the greeting you wrote is sent to our service so that the person you send it to can open it in a browser. What we receive: the heading, the lines of the greeting, the signature, the sender name you type, the language, and — if you set one — the moment the card should unlock. We do not receive the recipient's name, birthday, phone number, email, photo, notes, or anything else from your list.
The card address is 12 randomly generated characters (for example `/g/K7XQ2M9TVB4P`). It is never derived from anybody's name, so it cannot be guessed from one.
Photos, audio, and files cannot be attached to a card at all — the service accepts text only, and any web links inside that text are removed.
A card is deleted automatically 14 days after it was last opened (the countdown starts when the card unlocks, not when it was created). You can delete it earlier at any time from Settings → Greetings → My cards; the link stops working immediately.
The service runs on Cloudflare (Pages, D1). No account is required and we do not store an identifier for you: to check that your purchase is valid, we keep only a one-way hash of the Apple transaction, which cannot be turned back into your Apple ID.
If you never use this feature, nothing is ever sent to our server.
14. The recipient's side (microphone)
The card page asks the recipient's browser for microphone access so the candles can be blown out. The audio is analysed inside their browser only, is never recorded, and never reaches us or you. Blowing can be skipped entirely with a tap. The app itself never asks for microphone access for this feature.
17. Data sharing
We do not sell or share your personal data. Your data stays on your device and, if you enable sync, in your own iCloud — except for a greeting card you deliberately send as a link (section 13). Apple may process data when you use iCloud, the App Store, or Speech, under Apple's terms.
16. Retention and deletion
Your data remains as long as it is on your device or, if sync is enabled, in your iCloud. You can delete a single person, delete all local data, or delete local and iCloud data from within the app. Deleting local data removes only the on-device copy. Delete local and iCloud data permanently removes your data from the device and from your private iCloud database — this works whether or not iCloud Sync is turned on, but it requires that you are signed in to iCloud and connected to the internet, and the app confirms completion only after the iCloud deletion succeeds (if it can't reach iCloud, your local data is kept so you can try again). Uninstalling the app removes on-device data but does not delete data stored in your iCloud.
17. Export / backup
You can export your data to a JSON file and share it through iOS. Once you share or save it, that file is under your control; manage or delete it like any other file.
18. Security
We rely on iOS and iCloud security and your device passcode. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
19. Children
B-DAY is a general-purpose organizer. It can store information you enter about other people, which may include family members. Only add information you have a reasonable basis to store.
20. International processing
If you enable iCloud or use Apple services, Apple may process data through its infrastructure in accordance with Apple's terms and privacy practices. Feature availability can vary by region and Apple account.
21. Changes
We may update this policy when the app or legal requirements change. The "Last updated" date reflects the latest revision.
22. Contact
Questions about privacy: alexblessingx@gmail.com.
