Privacy Policy
Fanfare is built so that the least possible information leaves your phone. This policy describes, in plain language, what the app actually does with information today. Fanfare is published by Felix-Vita, Inc. ("Fanfare", "we", "us").
Privacy in short
- Your address book never leaves your phone. Birthdays and names are read on the device and stay there.
- To make a card, we send a small, fixed set of details about that one person to AI services: first name, age, how you know them, the notes or interests you typed, and your photo only if you attach one.
- If you dictate your notes, the audio never reaches us. Your phone's own speech recognition turns it into text; only that text is used, exactly like notes you type.
- Your photo is used once, in memory, and is not kept. It is sent to one AI provider (OpenAI) for a safety check and to draw the card, and is never written to our storage.
- Your card history is saved to your account (message text and card settings) so it can sync across your devices. The card image itself stays on your phone and is never uploaded to our servers. You can delete your history at any time by deleting your account.
- No email required. Accounts are anonymous unless you choose to sign in with an email to sync across devices.
- Payments go through Stripe (iPhone) or Google Play (Android). We never see your card number.
- No analytics or advertising SDKs. We don't sell or share personal information.
- You can delete your account and everything in it from inside the app.
1. What stays on your phone
Most of what Fanfare knows lives only on your device, in the app's private storage:
- Your contacts. If you allow access, Fanfare reads only three fields from your address book: name, first name and birthday. It uses them to build your list of people and schedule reminders. This list is stored on your phone and is never uploaded. You can also skip contacts entirely and add people by hand.
- People you add and what you write about them — names, birthdays, your relationship, notes and interests — stay on the phone. They're sent only in the limited way described in section 2 when you choose to make a card.
- Reminders. Birthday reminders are scheduled as local notifications by your phone's operating system. Fanfare uses no push-notification service and collects no push tokens.
- Your AI-consent choice (see section 3) is stored on the phone, not on our servers.
- Cards you save or share go to your Photos app or to the app you share with (for example WhatsApp or iMessage). Those apps have their own privacy policies. We never post or send anything on your behalf.
2. What we send to make a card
When you tap to make a card, the app sends our server only the following, for that one person and that one card. The server checks every request against this list and rejects anything else:
- the person's first name;
- their age as a number, if you chose to include it (their birthday date itself is not sent);
- how you know them (relationship and how close you are);
- the notes or interests you typed or dictated for them, if any (at most 500 characters);
- the tone, language, style and motifs you picked for the card, and a short text description of the artwork built from those choices — including a short excerpt of your notes as visual hints;
- your photo, only if you attached one to this card (see section 4).
Nothing else about the person is sent: not their last name, phone number, email, address, birthday, or anything from your contact list. Requests are tied to your account only so we can apply hourly limits and bill the card.
Voice notes
You can dictate your notes instead of typing them. When you tap the microphone, your phone's own speech recognition converts what you say into text — on the device itself when your phone supports it, and otherwise by Apple's or Google's speech service under their terms (Apple, Google). Fanfare never receives, records or stores the audio; it only sees the resulting text, in the field where you can still edit it. That text is then handled exactly like the notes or interests above: sent only when you choose to make a card, covered by the same AI-consent choice (section 3), and not stored on our servers except as part of the final message text in your card history (section 6). The microphone and speech-recognition permissions are asked for the first time you tap the microphone and are only used while you are dictating; you can keep typing without granting them.
3. The AI services we use
Fanfare does not run its own AI models. It sends the details above to third-party AI providers that write the message and draw the card. The app asks for your agreement before the first card, and you can review or withdraw it under Wallet → Legal & support → AI & your data. If you decline, nothing is sent.
| Provider | What it does for Fanfare | What it receives |
|---|---|---|
| OpenAI | Runs an automated safety check on every card request (the text, and your photo if attached). Draws the card artwork (first choice) and, if you attached a photo, composites it into the artwork. Writes the message only if Google and Anthropic are unavailable. | The card details in section 2. The only provider that ever receives your photo. |
| Google (Gemini, Imagen) | Writes the message options (first choice). Draws the artwork only if OpenAI is unavailable. | The card details in section 2. Never your photo. |
| Anthropic (Claude) | Writes the message options if Google is unavailable. | The card details in section 2. Never your photo. |
Which provider answers depends on availability: the server tries them in a fixed order and moves to the next if one fails. Each provider processes this data under its own API terms. We use their paid business APIs (OpenAI, Google, Anthropic). Under those terms, the providers do not use the data we send to train or improve their models; they may keep it for a limited time to detect abuse, as their terms describe.
Safety check. Before any card is drawn or written, the text (and the photo, if any) goes through OpenAI's automated moderation. If it is flagged, the card is not made and nothing goes to the writing or drawing services. If the safety check itself cannot be completed and a photo is attached, the card is not made either. The check runs on every version of a card, including each change you ask for.
4. Your photos
- Attaching a photo is optional. When you do, it is used for that one card only.
- The photo is sent only to OpenAI: first for the safety check, and, if that passes, to composite it into the artwork. It is never sent to Google, Anthropic or anyone else.
- On our side the photo exists only in memory for the duration of that request. It is never written to a database or a storage bucket, so there is nothing of it to retain or delete afterwards.
- The finished artwork, which may include the person from your photo, is kept only on your phone (and wherever you choose to save or share it). It is never uploaded to our servers.
- Many cards are for children. You are responsible for having permission to use a photo of someone else, and for a child, their parent or guardian's permission. We never store a flag saying whether a card is for a child; the app only adjusts its wording by the age you chose to include.
Video cards, which would involve recording and uploading a video, are not available in this version of the app. No video is recorded, uploaded or processed.
5. Your account
- Anonymous by default. The first time you open Fanfare, the app creates an anonymous account with a random identifier. It has no name, email or phone number attached.
- Optional email sign-in. If you want your card history and preferences to sync across devices, you can sign in with an email. We use your email to send you a 6-digit sign-in code and to recognize your account. We don't send marketing email. Signing in upgrades your anonymous account in place, so your wallet and cards are kept.
- What the account stores on our servers: the account identifier; your signature line; your default card language and app language; your wallet balance, remaining free cards and total amount loaded; hourly request counters (used to limit abuse); your card history (section 6); any reports you submit (section 8); and your payment ledger (section 7).
6. Your card history
Each finished card is saved to your account so it can be shown again and synced to another device if you sign in. For each card we store: the year, its status, the format, the final message text, language, tone, style and motifs, and when it was created. We do not store the card image: it stays on the phone where you made it, so a card synced to another device shows its message without the picture.
By design, the server never stores who the card was for: no name, no birthday, no link to your contacts. On your phone the card is linked to the person; on our servers it is not.
7. Payments and your wallet
Fanfare uses a prepaid wallet in US dollars. We never receive or store your card number.
- On iPhone, adding money opens Stripe Checkout in your browser. We give Stripe your account identifier and the amount; Stripe collects your payment details on its own page and may ask for an email for the receipt. Stripe then tells us the payment succeeded and we credit your wallet. Stripe's handling of your data is governed by Stripe's privacy policy.
- On Android, adding money goes through Google Play Billing. Google handles the payment. We receive the purchase confirmation (an order identifier and a hashed form of your account identifier) to verify the purchase with Google and credit your wallet. Google's handling of your data is governed by Google's privacy policy. Stripe is never used on Android.
- What we keep: your balance, and a ledger of every credit and debit with its date, amount, reason and the Stripe or Google reference, which we need for accounting and to resolve disputes.
8. Reporting a card
You can report a card the AI produced from inside the app. A report contains: the reason you chose, your optional comment, the AI-written message text, which AI provider and model produced it, your account identifier and the time. The card image is never included in a report, because it may depict a child. Reports can't be read back or edited from the app; we review them ourselves. They are deleted with your account.
9. Service providers and hosting
- Supabase hosts our database, sign-in, storage and server functions, in the US West region (Northern California). Access rules ensure each account can read only its own rows.
- OpenAI, Google and Anthropic — AI generation and safety checks, as described in section 3.
- Stripe (iPhone) and Google Play (Android) — payments, section 7.
- Apple App Store and Google Play distribute the app and handle installs under their own policies.
- Cloudflare hosts this website (myfanfare.app) and forwards email sent to our support address. Like any web host, it processes your IP address and browser information to deliver pages and protect against attacks. The website uses no cookies, analytics or trackers.
- Expo (EAS Update) delivers small app updates. When the app checks for updates it contacts Expo's update server with basic app information (platform, app version and update channel) and a random install identifier that Expo's update library creates on your phone. That identifier is not derived from your device hardware, is not linked to your Fanfare account, and is used only to deliver updates.
We use no analytics, crash-reporting or advertising SDKs. Our video-rendering service (used only for video cards) is not active in this version, since video cards are not offered; if we enable them we will update this policy first.
All data is processed in the United States. Fanfare is offered in the United States only.
10. How long we keep information
| Information | Kept for |
|---|---|
| Contacts, people, notes, reminders (on your phone) | Until you remove them or delete the app or your account. |
| Your photo | Not kept. It exists only in memory while that one card is made. |
| Card history (message text and card settings — no images) | Until you delete your account. |
| Account, preferences, wallet balance | Until you delete your account. |
| Reports | Until you delete your account. |
| Hourly request counters | Rolling one-hour windows; deleted with your account. |
| Payment ledger | Kept after account deletion, with your account identifier removed, for accounting and dispute handling. Stripe and Google keep their own records under their policies. |
| Operational server logs | Kept by our hosting provider (Supabase) for no more than 7 days, for security and troubleshooting. They can include IP address, device type and request time — never your photo. |
11. Deleting your account
Open Fanfare, go to Wallet → Legal & support → Delete account, and confirm. This removes your account, sign-in, wallet, card history and reports from our servers, and everything Fanfare stored on that phone. Any remaining balance is forfeited. Full details, and the email alternative, are on the Delete your account page.
12. Security
All traffic between the app and our servers is encrypted (HTTPS). Database access rules limit every account to its own data; wallet balances can only be changed by our server, never by the app. Photos are never written to storage. Our AI and payment keys live only on the server. No system is perfectly secure, so we also keep the amount of personal data we hold as small as we can.
13. Your rights, including California rights
Wherever you live, you can ask us to access, correct or delete the personal information we hold about you, or to get a copy of it. If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:
- know what personal information we collect, use and disclose, and why (this policy is that notice);
- delete your personal information (use the in-app deletion, or email us);
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information — we do not sell or share personal information, and we do not knowingly sell or share the personal information of anyone under 16;
- limit the use of sensitive personal information — the only sensitive information we process is a photo you choose to attach, and we use it only to make the card you asked for;
- not be discriminated against for exercising these rights.
To exercise a right, use the app or email support@myfanfare.app. Because most accounts are anonymous, we may ask you to act from inside the app or from the email address you signed in with, so we can be sure we're acting on the right account. You may use an authorized agent; we will ask for proof of their authority. We respond within the time the law requires (45 days in California, extendable once).
We do not use personal information to make automated decisions with legal or similarly significant effects. We do not currently respond to browser "Do Not Track" signals, because our app has no web tracking to turn off.
14. Children
Fanfare is for adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, email us and we will delete it.
Cards are often about children. The adult user provides a first name, an optional age and optional notes; the server never stores whether a card is for a child, and if a photo is attached it is processed once and never stored (section 4). If you want information about a child removed, contact us.
15. Changes to this policy
If we make a material change — for example adding a provider, or storing something new — we will update this page, change the date at the top, and ask for your agreement again inside the app where the change affects what leaves your phone.
16. Contact
Felix-Vita, Inc.
Email: support@myfanfare.app