Confetti

Confetti iPhone app compliance page

Confetti Privacy Policy

Privacy policy for the Confetti iPhone app. Effective August 17, 2026; also covers the owner-only Messages service.

Who we are and what this covers

Confetti is operated by Keith Kakadia, doing business as Confetti. This policy applies to the Confetti iPhone app, its Messages and Widget extensions, the owner-only Messages service, controlled-access start pages, and the public support and compliance pages at birthdayconfetti.app. Confetti does not offer a browser account product.

Confetti is a private birthday assistant that starts in Messages. It serves the account owner and does not autonomously contact birthday recipients, send owner drafts to other people, buy gifts, or complete merchant checkout.

The controlled-access start and public compliance pages support the native service; they are not a browser account product.

Information you provide

Depending on the features you use, Confetti stores birthdays, names, relationship labels, interests, avoidances, budgets, gift preferences, saved gift identifiers, reminder choices, birthday decisions, message drafts, and feedback you intentionally submit. You are responsible for having an appropriate reason to add information about another person.

Contacts access is optional and starts only after you choose the import flow. Confetti imports only the contacts you select and does not sync recipient phone numbers or your full address book to the backend.

During controlled Messages access, an invited tester may submit their own mobile number with explicit consent so Sendblue can register and, when necessary, verify it. Confetti retains keyed one-way hashes of the private invite and submitted number plus status, attempt, capacity, time, verification, and last-four-digit metadata for access control and anti-reuse. The private start page does not create a browser account.

After the owner sends the first text, Confetti receives owner message text and verified sender information from Sendblue. Message text is processed to understand and answer the request, but Confetti's durable account store excludes raw message transcripts, AI prompts, and AI outputs. The owner's delivery number is retained inside the encrypted production account so Confetti can reply and deliver reminders the owner has enabled; APIs, exports, and logs expose only a redacted suffix. Email sign-in, when enabled, retains hashes and a redacted suffix rather than the raw address.

Information collected automatically

Confetti may collect account-scoped identifiers, an opaque device-enrollment identifier, app and service events, reminder and delivery status, affiliate handoff events, diagnostics, bounded AI decision and cost metadata, and ordinary server security logs. The device-enrollment secret is sent to the enrollment endpoint to derive an opaque account identifier, remains in device Keychain for the app, and is not returned or persisted by the backend.

The current product does not use third-party advertising SDKs, sell personal information, or share personal information for cross-context behavioral advertising. When Shopify commerce is enabled, Confetti may retain account-scoped cart and checkout identifiers plus redacted order and fulfillment status. Confetti does not store payment card data, buyer addresses, Shop passwords, raw App Store receipts, recipient conversation transcripts, or the full Contacts address book in its backend.

How we use information

We use information to remember birthdays, maintain your private account, answer owner Messages requests, prepare owner-approved reminders and drafts, suggest gifts, preserve your choices, provide export and deletion controls, manage the controlled beta, prevent abuse, secure the service, troubleshoot problems, and measure reliability.

We do not use information about birthday recipients to contact them. Confetti may send service replies and enabled reminders only to the verified owner through the owner's Messages conversation.

Service providers and merchant handoffs

Confetti uses Apple for app distribution and platform services; Vercel and a hosted database provider for backend infrastructure; Sendblue for controlled registration and the owner-only Messages service; OpenRouter and selected model providers for bounded interpretation; and Shopify for gift discovery, optional Shop account linking, owner-requested carts, merchant checkout handoff, and order status. Providers process information under their own terms and privacy practices for the functions Confetti requests.

For ordinary owner messages, Confetti sends the minimum redacted structured context needed for interpretation and requests zero-data-retention routing where supported. Model providers still process the request under their own service terms. The model can propose an intent but cannot directly write data, contact a recipient, purchase, approve reminders, link an account, or claim an external result.

When you choose a merchant or affiliate handoff, the destination receives the ordinary information associated with opening its link. For supported Shopify gifts, Confetti may prepare a cart and merchant-hosted checkout after your tap. You review and complete payment with the merchant; Confetti never submits payment or completes the purchase. Confetti may record redacted checkout, order-status, click, or conversion metadata and may earn a disclosed commission.

Retention and security

Core account, birthday, gift, and reminder data is kept until you delete it or Confetti adopts and discloses an inactivity policy. Operational audit events are normally retained for up to 365 days and 1,000 events per account; messaging delivery, AI decision metadata, and redacted Shopify order status for up to 90 days; beta feedback for up to 365 days and 250 entries per account; expired pairing codes with a seven-day cleanup grace; and encrypted recovery backups for up to 30 days after deletion. Controlled-access invite records are retained while needed to enforce beta capacity and one-time use; a separate automatic deletion period is not yet configured. Financial or legal records may be kept longer when required or under an approved policy.

Confetti uses account scoping, application-level encryption at rest for production sync records, encrypted local storage, Keychain-backed device secrets, HTTPS, access controls, redaction, and bounded logs. No service can guarantee absolute security.

Your choices and rights

The iPhone app includes local and backend export and deletion controls. You can edit or delete birthdays, disable proactive reminders, opt individual birthdays out, and reply STOP to pause owner messaging or START to resume. Deleting an active Confetti account clears its active account bucket promptly; a redacted deletion receipt and encrypted recovery copies may remain for the periods described above.

Depending on where you live, law may provide rights to know, access, correct, delete, or receive a copy of personal information, and to appeal certain decisions. Confetti does not discriminate for exercising applicable privacy rights. We may verify your identity before acting on a request.

For privacy, access, correction, export, or deletion help, contact support@birthdayconfetti.app.

Children and geography

Confetti is not directed to children under 13, and we do not knowingly create accounts for them. Users between 13 and the age of majority should use Confetti only with permission from a parent or guardian. An adult account owner may store a family member's birthday when the owner has an appropriate personal or legal basis to do so.

The initial public App Store launch is intended for the United States. Controlled testing may be offered by private invitation in other technically supported locations. Confetti is operated from the United States, and providers may process information in the United States and other locations where they operate.

Changes and contact

We may update this policy as Confetti changes. Material changes will be posted here with a new effective date and, when appropriate, communicated in the app or Messages service.

Questions may be sent to support@birthdayconfetti.app.