Plain-language data notice
Privacy
You Are a Gift does not ask for or store a recipient email address. A sender creates a link and chooses how to share it.
What the service stores
A note stores its recipient display name, message and animation choices, optional processed photos or custom music, optional sender display name, opening and expiry times, status, report state, and an operator-only view count. A blank sender name appears as “Someone who cares.” Uploaded originals are not retained: photo metadata is removed before responsive WebP copies are stored and an operator-controlled classifier checks the image. Audio metadata is removed before one normalized Opus copy is stored. These processed files are deleted with the gift or when it expires.
Pseudonymized accountability data
On creation and reporting, the service stores keyed HMAC values derived separately from the network address and browser user-agent, together with the note ID, event type, and timestamp. These values are pseudonymized rather than anonymous: they support abuse correlation and rate limits but are not shown to recipients.
Gift passwords
An optional gift password is stored only as a salted scrypt digest, never in a form anyone can read back. It cannot be recovered, reset, or looked up by the operator. Failed attempts are recorded as the same keyed HMAC of the network address used elsewhere, together with the note ID and a timestamp, purely to slow down guessing. They are deleted within 24 hours and go with the gift when it is deleted.
Functional cookies
The service sets two kinds of cookie on this host, each holding an opaque token for one single gift. Unlocking a password-protected gift sets the unlock cookie, which expires within 12 hours. Opening a gift that can be opened only once sets an open receipt, so that reloading the page while you are still watching does not lock you out. If you collect several gifts, this browser holds at most 8 cookies of each kind at a time, and the oldest are expired to stay under that cap. Neither kind contains any note text, and neither is sent to another site. The open receipt expires within one hour, or as soon as you finish the gift. The composer stores its language preference only in this browser's local storage.
Retention
New gifts last for 1, 7, or 30 days, or until they are opened once. At expiry the note and its processed photos stop opening and are deleted by the scheduled cleanup. Pseudonymous accountability events follow a separate 30-day limit. Explicit operator deletion removes linked events immediately.
Legal disclosure
The operator can be required to disclose available records under a valid court or authority order, including a disclosure process under §21 TDDDG. The service never promises technical anonymity from lawful process and never sells sender-reveal access.
Optional feedback
After creating a gift, an optional questionnaire may send four answers directly from your browser to Google Forms. The application does not attach the gift link, note ID, names, message, or contact fields. Free text is sent exactly as you enter it, and Google receives normal network metadata such as an IP address and browser information. A local submitted marker prevents the same form from being offered again.
Usage analytics
The service uses a self-hosted, privacy-friendly analytics tool (Plausible) to count visits. It sets no cookies and does not track you across sites or build a profile of you. It records only aggregate, anonymous figures such as page paths, referrers, and general device type. It never receives your note content, names, message, or the gift link.
Questions and erasure
To ask about data or request erasure, contact [email protected] and include the note ID when possible. Because HMAC values are one-way pseudonyms, a note ID is the practical way to locate the related record.