BD Birth Date Report

Privacy Notice

Version 2026-09-24.1 · Birth Date Report

This notice explains what personal data Birth Date Report collects, why, what we rely on to process it, who it is shared with, how long it is kept, and the rights you have over it. It is written to the standard of the EU and UK General Data Protection Regulation, which we apply to everyone regardless of where you are.

1. Who we are

Birth Date Report is the controller of the personal data described here. The service generates a personal insight report from your birth details.

A contact address for privacy requests has not been published yet. Until it is, use the same channel you contacted us through to buy or ask about a report, and we will act on the request.

2. Data we collect

  • To write the report: full name, gender, date of birth, time of birth, place of birth, and the report language you choose.
  • To reach you: email address and phone number.
  • If you pay: the payer's name and email, the amount, and the payment status, as reported to us by Stripe. Card and bank details go directly to Stripe and never pass through or get stored by this service.
  • If you open an account: email address, password (stored only as a hash, never in readable form), display name, and — if you sign in with Google — the name and email address on your Google profile.
  • Technical and operational: your IP address (to limit abuse of the free preview), session cookies, and a record of what each report cost us to generate in AI model usage.

We do not ask for, and do not knowingly collect, special category data such as health information, religious or philosophical beliefs, political opinions, or anything about your sex life or sexual orientation. The report is for personal insight. It is not medical, financial, legal or psychological advice, and nothing in it should be relied on as such.

3. Where the data comes from

All of it is provided directly by you through the forms on this site — except for batch reports, where a CSV file is uploaded by someone who is responsible for having obtained the consent of every person listed in it. If you were included in such a batch and did not agree to it, contact us and we will delete your data.

4. What we do with it, and what allows us to

Under GDPR Art. 6 each purpose needs its own lawful basis, and they are not interchangeable. Ours are:

  • Calculating your birth profile, writing your report, and keeping it available in your account — performance of a contract (Art. 6(1)(b)). This is what you asked us to do; we cannot do it without the birth details.
  • Taking payment and confirming a report has been paid for — performance of a contract (Art. 6(1)(b)).
  • Contacting you if something goes wrong with your report or your payment — performance of a contract (Art. 6(1)(b)).
  • Preventing abuse of the free preview, keeping the service secure, and analysing what it costs us to run — our legitimate interests (Art. 6(1)(f)). We use the minimum data needed for it, and you may object (see section 8).
  • Sending you marketing about Birth Date Report — your consent, and only your consent (Art. 6(1)(a)). Asked for separately, never required, and withdrawable at any time.
  • Keeping payment and tax records — compliance with a legal obligation (Art. 6(1)(c)).

The report is written by an automated system, but it produces a document for you to read. It makes no decision about you that has legal effect or similarly significant consequences, so it is not automated decision-making of the kind GDPR Art. 22 restricts.

5. Who else sees it

We do not sell your data, and we do not share it for anyone else's advertising. It is disclosed only to the providers who operate parts of this service for us, each under a contract that limits them to our instructions:

  • Anthropic (United States) — the AI model that writes the report. It receives your name, gender and birth details. Your email address and phone number are not sent to it.
  • Supabase, Railway, Cloudflare — database, file storage, hosting and delivery. They hold your submission, your report and your account.
  • Stripe — payment processing. It receives the payer's name and email, and handles the card details we never see. Stripe is an independent controller for its own fraud-prevention and regulatory purposes.
  • Open-Meteo — geocoding. It receives the place name you typed and nothing else: not your name, not your date of birth.
  • Resend (United States) — email delivery. It receives your name, your email address and the contents of your report, including your birth details, in order to send you (a) a copy of your free preview with a link to resume it, and (b) if you buy, the full report as an attachment with a link to read it online.

International transfers. Several of the providers above are outside the EU and UK, principally in the United States. Where a transfer is not covered by an adequacy decision, it is made under the European Commission's Standard Contractual Clauses (GDPR Art. 46(2)(c)) or the UK equivalent. You may ask us for details of the safeguards that apply.

6. What is required and what is genuinely optional

Required: your name, gender and birth details, because the report cannot be produced without them; and your email address and phone number, because they are how we reach you if the report or the payment fails.

Required to use the service: accepting this notice. That is not a consent to marketing — it is you confirming you have been told what happens to your data before you hand it over.

Genuinely optional: marketing. It is a separate tick box, unticked by default, and leaving it unticked costs you nothing: the free preview runs, the report generates, and the purchase completes exactly the same either way. We separate the two deliberately, because consent bundled into a condition of service is not freely given and is therefore not valid consent (GDPR Art. 7(4)).

Opening an account is also optional. You can buy and download a report without one; an account exists so you can reopen a report later.

7. How long we keep it

  • Two hours, then gone: the answers held mid-way through the form, the text of an unpaid free preview, and a payment that was started but never completed. These live in the server's memory only, and a restart clears them sooner.
  • Kept: the details you submitted for every report that was actually generated — including a free preview you never paid for, because generating it cost us real money and we keep the record of that — together with your contact details and consent record, and any paid report in your account. We hold these until you ask us to delete them, or until they are no longer needed for the purposes in section 4.
  • Kept as long as the law requires: payment and tax records, typically six to seven years depending on jurisdiction.

8. Your rights

Wherever you are, you may ask us to:

  • Give you access to the personal data we hold about you, and a copy of it (Art. 15).
  • Correct anything inaccurate or incomplete (Art. 16).
  • Delete it (Art. 17). We will, except where we must keep a payment record to comply with tax law.
  • Restrict what we do with it while a dispute about it is resolved (Art. 18).
  • Port it — receive it in a machine-readable format, or have it sent to another provider where that is technically feasible (Art. 20).
  • Object to processing we base on legitimate interests (Art. 21), and to stop any direct marketing, which we will do without asking why.
  • Withdraw consent to marketing at any time (Art. 7(3)). It is as easy to withdraw as it was to give, and withdrawing it does not affect a report you have already bought or the lawfulness of anything done before you withdrew.

To exercise any of these: A contact address for privacy requests has not been published yet. Until it is, use the same channel you contacted us through to buy or ask about a report, and we will act on the request. We will verify who you are before acting — otherwise the access right becomes a way to read a stranger's data — and reply within one month, as Art. 12(3) requires.

If you are in the EU or the UK and you think we have got this wrong, you may complain to your national data protection authority. In the UK that is the Information Commissioner's Office. Complaining to them does not require you to raise it with us first, though we would rather you did.

9. Security

All connections are encrypted in transit (HTTPS). Reports are held in private storage that carries no public URL; a link to your own report is signed and expires. The database is reachable only by our server — your browser is never given direct access to it. Card details never enter our systems. Passwords are stored as hashes, so we cannot read yours and will never ask for it. If a breach occurs that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk to you is high (Art. 33 and 34).

10. Children

This service is not intended for anyone under 16, and we do not knowingly collect their data. A report can legitimately be generated about a child by a parent or guardian; the contact details we hold in that case are the adult's. If you believe a child has given us their own data, tell us and we will delete it.

11. Changes to this notice

We may update this notice. The version number at the top changes whenever the content changes materially, and your consent is stored alongside the version you were shown — so what you agreed to remains answerable later, rather than being quietly replaced by whatever the page says today. A report costs $19.99; nothing in this notice changes with the price.

Privacy Notice