Privacy
Payments and private access
Free previews run locally. At checkout we process your birthday and preferences to derive a profile, then discard the full birth date. The derived profile is stored in an encrypted essential cookie and encrypted recovery link, with expiry. Stripe receives payment details and an opaque order reference, not your birthday. Each paid request verifies the order with Stripe. Keep your access link private. Anyone holding it can use your edit. No recovery email is sent.
Sharing and downloads
A shared link includes only the month, optional type, styling choices and palette theme number. It never includes your birthday. Downloaded cards are generated locally. Sharing through another app is subject to that app’s privacy practices.
Hosting and first-party measurement
We count visits, preview generation, sample views and checkout starts using a random browser-session identifier. The identifier is stored in session storage for 30 minutes and is hashed with the UTC date on the server. We keep only event type, date, language, a broad referral category and hosting-provided country, without birthdays, report contents, full referrer URLs or raw IP addresses. Verified purchase records use a hashed order ID and amount. Test data is separate. Do Not Track is respected for browser events. Your manual language preference uses a one-year cookie. The encrypted access cookie lasts up to 32 days. Checkout preparation temporarily stores your form in session storage for cancellation recovery and clears it after successful access verification.