Privacy Policy
- Introduction
- Plain-English Summary
- App Store Privacy Label (Apple Disclosure)
- App Tracking Transparency (ATT)
- Information We Collect
- How We Use Your Information
- Legal Basis for Processing (GDPR)
- Third-Party SDKs & Service Providers
- Data Retention
- Your Rights
- Account & Data Deletion
- Children's Privacy & Photos of Minors
- Face Data (Photos of People)
- AI Processing Disclosure (EU AI Act)
- In-App Consent & Transparency
- International Data Transfers
- Security
- Changes to This Policy
- Contact Us
1. Introduction
This Privacy Policy describes how the BirthdAI iOS application ("BirthdAI", the "App", "we", "us", "our") collects, uses, and shares information when you use the App. The App is published by TRY2APP LTD, the data controller for the purposes of this Policy.
We've designed the App to collect as little personal information as possible. You do not need to create an account. We do not ask for your name, email, phone number, or any other personally identifying information.
2. Plain-English Summary
In one paragraph: We don't know who you are. When you pick a card style, upload a photo, and enter a name and age, that photo and text are sent to our AI provider over an encrypted connection to generate your personalized birthday card, and the photo itself is not kept on our servers. We keep an anonymous ID on our backend so the App remembers your credit balance and subscription status, plus a private history of the cards you've generated. We do not use your photos to train AI, we do not sell data, and we do not track you across other apps or websites.
3. App Store Privacy Label (Apple Disclosure)
Apple requires every app on the App Store to disclose its data collection practices in the "App Privacy" label shown on each app's App Store listing. The table below mirrors the exact disclosures we make to Apple under its three required categories.
Category A — Data Used to Track You
None.
BirthdAI does not link any data collected from this app with data from third-party apps or websites for advertising or tracking purposes. We do not share any data with data brokers.
Category B — Data Linked to You
The following data types are linked to your anonymous App installation (not to your real identity):
- Identifiers — User ID. A random anonymous ID generated by Firebase Authentication. Used for App Functionality (to remember your credit balance and subscription state).
- Purchases — Purchase History. The product identifiers and status of subscriptions and credit-pack purchases made through Apple. Used for App Functionality (to grant and track your card-generation credits).
- User Content — Photos. The photo you explicitly upload to generate a card, and the resulting AI-generated card image URL. Used for App Functionality only (to produce the card you asked for).
- User Content — Other User Content. The name, age, and (for certain styles) custom caption text you type in, used to personalize your generated card.
Category C — Data Not Linked to You
- Diagnostics — Crash Data, Performance Data. Aggregated crash logs and performance metrics used for App Functionality and Analytics. These are anonymized and not tied to your identity.
What we do NOT collect
For full transparency, the following data categories Apple asks about are not collected by BirthdAI at all:
- Contact Info (email, name*, phone number, physical address, other contact info) — *the "name" you type in is only the name printed on your card, not your own identity, see Section 5
- Health & Fitness
- Financial Info (payment, credit, other financial info)
- Location (precise or coarse)
- Sensitive Info (race, sexual orientation, religion, politics, etc.)
- Contacts
- Browsing History
- Search History
- Identifiers — Device ID (IDFA or similar advertising identifier)
- Usage Data — Product Interaction, Advertising Data, Other Usage Data
- Other Data Types (Customer Support messages you email us are stored by our mail provider for support purposes only)
4. App Tracking Transparency (ATT)
Apple's App Tracking Transparency framework requires apps to request user permission before tracking them across other apps and websites owned by different companies.
BirthdAI does not track you across other apps or websites. Because we do not engage in cross-app tracking, we do not present the ATT permission prompt. We do not access or use your Identifier for Advertisers (IDFA), and we do not share any data with advertisers or data brokers.
5. Information We Collect (Detailed)
Anonymous Identifier (Firebase Auth)
When you first open the App, our backend (Google Firebase Authentication) generates a random anonymous user ID for your installation. This ID is not linked to your real identity, your Apple ID, your email, or any other personal information you've shared with Apple. The ID exists so the App can sync your credit balance and subscription state across sessions on the same device.
Photos You Upload to Generate a Card
When you create a card, you select a single photo from your iOS Photo Library via Apple's standard PhotosPicker. The selected photo is uploaded to our AI provider (fal.ai) over an encrypted TLS connection so the AI model can compose it into the birthday card style you chose. The photo is used solely to generate the card you asked for.
- We do not store the original photo on our own servers.
- We do not access your Photo Library without you explicitly picking a photo — we rely on Apple's picker, which sandboxes selection.
- We do not use your photos to train any AI model, our own or a third party's.
Name, Age, and Caption Text
Before generating a card, you type in the name and age you'd like shown on the card, and — for certain card styles — an optional custom headline or message. This text is sent to our AI provider along with your photo so it can be woven into the card artwork as typography. We store this text, tied to your anonymous user ID, as part of your private card history so you can revisit past cards.
Generated Card Images
The AI-generated card image URL returned by our provider is shown back to you inside the App. When you tap "Save to Photos", iOS writes the image to your own Photo Library (with your permission) — we never store it on our own servers beyond the history entry described below.
Subscription, Credit-Pack, and Purchase Data
When you purchase a subscription or a one-time credit pack, Apple processes the transaction entirely. We use RevenueCat to verify and sync your purchase status. The data we receive is limited to:
- The anonymous user ID we associate with the purchase
- The product identifier you purchased (e.g.
birthdaiweekly,birthdaiyearly,birthdai50credits) - Purchase status (active, expired, refunded) and expiration date
We never see your Apple ID, credit card number, billing address, or any other payment information. That data stays with Apple.
Account Creation Timestamp
We store the date your anonymous user ID was first created in our Firestore database, tied to that identifier only.
Diagnostic & Performance Data
To keep the App stable we may receive aggregated crash logs and performance metrics (such as load times and error rates). This data is not linked to your identity and is used to diagnose issues and improve stability.
Device Signals
For debugging we may log non-identifying signals such as iOS version, device model (e.g. "iPhone 13"), and app version. We do not use the IDFA and we do not run any advertising trackers in the App.
6. How We Use Your Information
We use the limited information we collect for the following purposes only:
- To generate the personalized birthday card you requested
- To sync your credit balance and subscription state across sessions on your device
- To validate and track in-app purchases through Apple's StoreKit
- To show you your own private history of previously generated cards
- To prevent fraud, abuse, and violations of our Terms of Service
- To comply with legal obligations
- To improve App stability through aggregated, anonymous diagnostics
We do not sell your personal information. We do not share it with advertisers. We do not use your photos, names, or generated cards to train AI models.
7. Legal Basis for Processing (GDPR)
If you are in the European Union, United Kingdom, or another jurisdiction with comparable law, we process your personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — processing necessary to provide the App and fulfill purchases (anonymous ID, purchase data, photos and text you submit, generated cards).
- Legitimate interests (Art. 6(1)(f) GDPR) — processing for App stability, fraud prevention, and security, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c) GDPR) — retention of purchase records for tax and accounting.
- Consent (Art. 6(1)(a) GDPR) — for any processing that requires consent, such as sending your photo to our AI provider. You explicitly grant this consent via the in-app AI consent screen and can withdraw it at any time (see Section 15).
8. Third-Party SDKs & Service Providers
The App includes the SDKs listed below. Each publishes a privacy manifest (PrivacyInfo.xcprivacy) as required by Apple, and is bound to the purpose for which we use it.
fal.ai (AI Generation)
Purpose: AI image generation to compose your photo into the birthday card style you chose. Model: fal-ai/nano-banana-2/edit. Data sent: your uploaded photo, the name/age/caption text you entered, and generation parameters (prompt, resolution, output format).
Privacy policy: https://fal.ai/legal/privacy-policy
Google Firebase (Authentication + Firestore)
Purpose: anonymous authentication and storage of your user document containing your credit balance, account creation timestamp, and card history. Operator: Google LLC.
Privacy policy: https://firebase.google.com/support/privacy · Google Privacy Policy
RevenueCat
Purpose: subscription and consumable purchase validation, linking Apple transactions to your anonymous user ID. Data: anonymous user ID, Apple transaction identifier, purchase/subscription state.
Privacy policy: https://www.revenuecat.com/privacy
Apple
Purpose: App Store distribution, StoreKit billing, and system services. Apple processes all payments directly; we never see your payment instrument.
Privacy policy: https://www.apple.com/legal/privacy/
9. Data Retention
- Photos you upload: Not stored by us. Transmitted to our AI provider for the duration of generation only. Our provider's retention is governed by their own policy linked above.
- Generated card images: Not stored on our own servers. The URL returned by the AI provider is displayed to you in the App and saved to your private card history, tied to your anonymous user ID, until you request account deletion.
- Name/age/caption text: Retained as part of your card history entries under the same terms as generated card images.
- Anonymous user ID, credit balance, and account creation timestamp: Retained while your installation is active. Deleted on request (see Section 11).
- Subscription and purchase records: Retained for the duration of your subscription plus the period required by tax, accounting, and consumer-protection law (typically up to 7 years depending on jurisdiction).
- Crash/diagnostic data: Retained in aggregated form for up to 90 days.
10. Your Rights
European Union and United Kingdom (GDPR / UK GDPR)
- Right to access the personal data we hold about you
- Right to rectification of inaccurate data
- Right to erasure (the "right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to solely automated decision-making
- Right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Right to lodge a complaint with a supervisory authority (e.g. ICO in the UK, your national DPA in the EU)
California, USA (CCPA / CPRA)
- Right to know what personal information is collected
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell or share)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your privacy rights
Other Jurisdictions
Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), and other jurisdictions provide similar rights. You may exercise them through the contact address in Section 19.
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected] with the subject line "Privacy Request — BirthdAI". Because we use anonymous identifiers, please include your anonymous user ID (found at the bottom of the Settings screen in the App) so we can locate your data. We will respond within the timeframe required by applicable law (typically within 30 days under GDPR/CCPA).
11. Account and Data Deletion
You can delete your anonymous account and all associated data at any time. Because the App does not require an email or real-name account, deletion is handled via email:
- Email [email protected] with the subject "BirthdAI — Delete my data", including the anonymous user ID shown at the bottom of the Settings screen.
- We confirm receipt within 2 business days and complete deletion within 30 days.
- If you have purchased items, we may retain the minimal purchase-history records required by tax and consumer-protection law, in anonymized form.
Deleted data includes your Firestore user document, card history, credit balance, and subscription sync state. Apple retains purchase records it is legally required to keep; these are outside our control.
Uninstalling the App alone does not delete server-side data. To have everything removed from our backend, you must email us.
12. Children's Privacy & Photos of Minors
BirthdAI is a tool for creating birthday cards for people of any age — including babies and children — but the App itself is not directed to or marketed at children, and the App user (the person operating the device, entering text, and making purchases) must be an adult or otherwise meet the eligibility requirements in our Terms of Service. We do not knowingly collect personal information directly from children under 13 through App-account creation, because the App has no account system at all — only an anonymous device identifier.
Uploading a photo of a child. If the photo you upload to generate a card depicts a child, by uploading it you confirm that you are that child's parent or legal guardian, or that you have the express permission of a parent or legal guardian to upload and use that photo for this purpose — the same standard that applies to any family photo book, greeting card, or print service. We do not perform facial recognition or attempt to identify who is depicted in any photo (see Section 13).
If you are a parent or guardian and believe your child has independently used the App to submit personal information without your consent, please contact us at [email protected] and we will delete it promptly.
The App's content rating in the App Store is set in accordance with Apple's age rating guidelines.
13. Face Data (Photos of People)
BirthdAI's core purpose is to compose a photo of a person into a stylized birthday card — so nearly every photo processed by the App contains a face. This section explains in detail how we treat images that include faces.
What face data we collect
The App processes your photo as a single image — a collection of pixels. It does not perform any of the following on faces in your photo:
- No facial recognition or face identification
- No biometric face data, face embeddings, or faceprints
- No attempts to link a face to a real-world identity
- No extraction of demographic, emotion, age, or identity signals from faces
- No creation or storage of face templates
The AI model we use (fal-ai/nano-banana-2/edit at fal.ai) treats your photo holistically as an image to compose into the chosen card design. It does not output biometric data, does not cross-match faces, and does not maintain any face database. The model is instructed to preserve the photographed person's identity, facial features, and likeness exactly — it composes and stylizes the scene around them, it does not replace or reshape who is in the photo.
All planned uses of face data
The only purpose for which a photo containing a face is processed is to produce the personalized birthday card you explicitly requested by uploading it and tapping Generate. No other use is made of the face pixels — not for training, not for analytics, not for advertising, not for demographic profiling.
Sharing with third parties
The photo — which will typically contain a face — is transmitted once, over an encrypted TLS connection, to our AI processing provider fal.ai (operated by Features & Labels, Inc.) to generate the card. It is not shared with any other third party. fal.ai is contractually bound not to train on user input and not to retain the photo beyond what is technically necessary to serve the request. Our list of subprocessors is in Section 8.
Storage and retention of face data
- We do not store the original photo on our own servers.
- fal.ai processes the photo in memory to produce the output and retains it only for the time technically required to serve that individual request. fal.ai does not use input photos as training data.
- The generated result URL is displayed to you in the App. If you save the result to your own Photo Library, iOS handles that storage — we do not keep a copy on our servers.
- In our Firestore database we store, for your private card history, only the URL of the finished card and its associated name/age/caption text and a timestamp, tied to your anonymous user ID.
- On request (see Section 11) we will delete all data associated with your anonymous user ID within 30 days.
Where in this policy face data is addressed
Face data (as part of the broader category of photos that may contain faces) is addressed in:
- Section 3 — "App Store Privacy Label" (disclosed as User Content — Photos)
- Section 5 — "Photos You Upload to Generate a Card" and "Generated Card Images"
- Section 12 — Children's Privacy & Photos of Minors
- This Section 13 — Face Data
- Section 9 — Data Retention
- Section 14 — AI Processing Disclosure
In-app consent before any face-bearing photo is sent
Before the App transmits your first photo to fal.ai, the App displays a dedicated in-app consent screen that names fal.ai as the third-party AI processor, explains that photos will typically contain faces, confirms that no biometric face analysis is performed, and requires you to check a confirmation box and tap Agree to proceed. You can revoke consent at any time by uninstalling the App. No photo is transmitted before you explicitly complete this step and tap Generate.
14. AI Processing Disclosure (EU AI Act Compliance)
In compliance with Regulation (EU) 2024/1689 (the "EU AI Act") and global best practices for transparent AI, we disclose:
- The App uses generative artificial intelligence to compose a user-supplied photo into a stylized birthday card design — incorporating the uploaded photo, the name and age you provide, and (for some styles) a custom caption — while preserving the photographed person's identity, facial features, and likeness. The output is synthetic content generated by an AI system.
- The AI model is
fal-ai/nano-banana-2/edit, provided by fal.ai. - AI generation is initiated only by your explicit action (uploading a photo, entering details, and tapping "Generate Now"). The App does not generate content automatically.
- Generated images may include provenance markers embedded by the AI provider.
- You are responsible for the lawful use of any content generated by the App. Use to deceive, create non-consensual manipulated imagery, or otherwise violate applicable law is prohibited by our Terms.
15. In-App Consent & Transparency
Apple's App Review guidelines (5.1.1(i) and 5.1.2(i)) require that, before any personal data is shared with a third-party AI service, the App disclose what data is sent, identify who the data is sent to, and obtain the user's permission. BirthdAI complies with these requirements through the following in-app mechanisms:
- First-run AI consent screen. Before any photo is ever sent for AI processing, the App presents a dedicated consent screen that: (a) names the third party receiving the data — fal.ai (operated by Features & Labels, Inc.); (b) explains that the single photo the user selected, and only that photo, is transmitted; (c) confirms that no facial recognition or biometric analysis is performed; (d) confirms that the photo is not used to train AI models; and (e) links to this Privacy Policy. The user must check a confirmation box and tap Agree and Continue to proceed. Tapping Cancel keeps the App usable but prevents any photo from being sent.
- Explicit user action required. The App never transmits a photo automatically. A transmission only occurs when the user has (a) manually selected a photo through Apple's standard Photo Library picker, (b) entered a name and age, and (c) tapped the Generate button.
- Revocability. Consent can be withdrawn by uninstalling the App or by contacting us at [email protected]. On data deletion request we remove all records associated with the user's anonymous identifier within 30 days.
16. International Data Transfers
Our backend services (Google Firebase, RevenueCat, fal.ai) operate from data centers in the United States and the European Union. By using the App, you consent to the transfer of your information to these regions for processing.
For transfers of personal data from the European Union or United Kingdom to countries outside the EEA, we and our processors rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards (Art. 46 GDPR).
17. Security
We protect the limited information we collect using industry-standard measures:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest provided by Google Cloud and our other infrastructure providers
- Anonymous identifiers — no real-name linkage
- Firestore security rules that restrict access to each user's own documents
- Limited backend access restricted to authorized personnel
- Regular security review of third-party providers and their privacy manifests
No system is perfectly secure. If you become aware of a security incident affecting your data, please contact us immediately at [email protected]. For incidents that affect personal data of EU/UK users, we will notify the relevant supervisory authority as required by law.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Update the "Last updated" date at the top of this policy
- Notify users via in-app message where appropriate
- For significant changes, provide a plain-language summary of what changed
Continued use of the App after changes are posted constitutes acceptance of the updated policy.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Email: [email protected]
Subject: BirthdAI — Privacy Inquiry
Data controller: TRY2APP LTD
We typically respond within 7 business days.