Birthday Calendar Extractor

Privacy Policy

Draft for owner review. This text is not approved for publication. Bracketed fields remain blank at the owner's request.

Effective date: [Effective date]

Operator: [Legal operator name]
Postal address: [Postal address and country]
Contact: [email protected]

Birthday data on your device

Birthday Calendar Extractor reads available birthday information from Facebook when you start a scan. It uses your existing Facebook session in your browser. You can also add contacts yourself.

Birthday data stays in the extension. Contact names, Facebook profile identifiers, birthdates, and contact settings are stored in your browser's local extension storage. They are not sent to our API, Supabase, Stripe metadata, or server logs.

ICS and CSV files are created on your device. You decide where to save or import them. When you import a file into a calendar or spreadsheet service, that service handles the imported data under its own terms and privacy policy. Opening a contact link sends your browser to Facebook.

Premium accounts and payments

Free scans, calendar preview, ICS export, and delete-ICS export do not require a Premium account. CSV export is the only paid feature.

When you sign in to Premium, our API and Supabase process your email address, sign-in request details, hashed confirmation and session tokens, and their validity times. The extension stores your Premium session and access status locally. Your extension version is sent when you request a sign-in link.

Stripe handles checkout, subscriptions, and the billing portal. We send your account email and the product or plan identifiers needed for billing. Our backend stores Stripe customer and subscription identifiers, subscription status, billing-period information, and your Premium access status. Payment details entered on Stripe's pages are handled by Stripe; our extension and API do not collect your full payment-card details.

Extension usage analytics

The extension sends usage events to Google Analytics. Events include a random client identifier stored in local extension storage, a session identifier, extension page paths and query strings, page and button names, usage counts, scan duration, export type, and engagement time.

These events measure use of the extension. They do not include contact names, profile identifiers, birthdates, or the time until a contact's birthday. The current extension sends events automatically and has no analytics switch. Disabling or removing the extension stops future extension events.

Owner decision: [Approved analytics legal basis, user choice or consent mechanism, and retention settings]

Service providers and technical information

These services receive network information, such as an IP address, when your browser contacts them. Our API records request paths, methods, status codes, timing, and operational identifiers for diagnostics. Email, authentication secrets, and payment payloads are redacted from application log fields.

The public landing and legal pages contain no analytics scripts and set no application cookies. This does not describe the separate pages operated by Facebook, Stripe, or other providers.

[Provider regions and approved safeguards for international data transfers]

Purposes and legal bases

Account and payment records support sign-in, paid access, billing, and support. Operational records help diagnose failures and protect the service. Usage events help us understand extension use.

[Approved legal bases for account services, billing, support, security logs, and analytics; applicable obligations and legitimate interests]

[Approved Chrome Web Store Limited Use disclosure, including permitted data uses, transfers, advertising restrictions, and human access]

Retention and deletion

Local contact records remain until you clear the extension's data or remove the extension. Files you downloaded and events you imported into other services remain in those locations until you delete them there.

Signing out clears the session from the extension and requests revocation on the server. If that request fails, the server session can remain valid until it expires. Signing out does not delete your account or cancel a subscription. Removing the extension also does not cancel a subscription. Use the Premium page's billing controls to manage a subscription.

[Approved retention periods or criteria for account records, expired sign-in and session records, analytics, email-delivery records, support messages, logs, and backups]

To request account or personal-data deletion, email [email protected]. Do not include birthday exports or payment-card details. We may need to verify control of the account email before acting.

[Approved deletion response process and response time; records retained for accounting or other legal obligations, including Stripe records]

Your rights and questions

Depending on the law that applies to you, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, object to processing, or withdraw consent where processing relies on consent. You may also have a right to complain to a data-protection authority.

Contact [email protected] about privacy requests. [Applicable authority and any required representative or data-protection officer details]

[Approved policy-change notice process]