CalmBird

TODO — have a qualified lawyer (ideally a GDPR specialist) review and finalise this document before launch. The text below is a placeholder scaffold only.

Privacy Policy

Last updated: 2026-06-18

1. Who we are

CalmBird (“we”, “us”) operates the CalmBird service at calmbird.app. [TODO: add registered company name and address.]

We are the data controller for personal data processed through CalmBird. Questions: privacy@calmbird.app

2. Data we collect

We collect the minimum necessary to provide the service:

  • Account data — email address, name, profile image (from Google OAuth)
  • Preferences — preferred language, delivery interval, tracked X accounts, per-account toggles
  • Delivery destinations — email addresses and Telegram chat IDs you add
  • Billing data — subscription tier, billing cycle; payment details are stored by Stripe, not us
  • Usage data — which posts were delivered to you, delivery timestamps
  • Third-party content — public X posts from accounts you choose to follow; we do not store private or deleted posts

After account deletion we retain a salted one-way hash of your email address (SHA-256; plaintext is never stored) along with a boolean flag recording whether you used a free trial. This record cannot be used to identify you and is kept solely to prevent trial abuse on re-registration.

We do not sell your data. We do not use your data for advertising.

3. How we use your data

We use your data to:

  • Authenticate you and maintain your session
  • Deliver posts from tracked accounts to your chosen channels
  • Process your subscription and billing via Stripe
  • Send account-related emails (verification, billing receipts)
  • Improve the service (aggregate, anonymised analytics only)
  • Comply with legal obligations

Legal basis (GDPR): performance of contract (account, delivery, billing); legitimate interest (service improvement, security); consent (marketing emails, if any — you can withdraw at any time).

4. Subprocessors

We share data with the following third parties as necessary to provide the service. All are bound by data processing agreements.

SubprocessorPurposeLocation
twitterapi.ioFetching public X (Twitter) postsUS
StripePayment processing, subscriptions, invoicingUS (EU transfer covered by SCCs)
TelegramBot delivery channel — sends digests to your Telegram chatUAE / distributed
SendGrid (Twilio)Transactional email — verification and digest deliveryUS (EU transfer covered by SCCs)
DeepLAuto-translate post text (opt-in, paid accounts)DE (EU)
Anthropic / OpenAITopical classification of posts (paid-tracked accounts only)US (EU transfer covered by SCCs)
NeonPostgreSQL database hostingAWS us-east-1 (TODO: confirm region)
VercelWeb application hosting and edge functionsUS / EU (configurable)
SentryError monitoring and performanceUS (EU transfer covered by SCCs)

5. Data retention

We retain your personal data for as long as your account is active. Delivered-post records are retained for [TODO: define period, e.g., 90 days] then automatically purged. Billing records are retained for [TODO: 7 years] to comply with tax law.

When you delete your account via Settings → Profile, all personal data is deleted immediately. The one exception is a salted one-way hash of your email address (SHA-256) and a boolean flag indicating whether you used a free trial. This minimal record is retained indefinitely to prevent a single email address from claiming multiple free trials. It does not contain your email in any recoverable form and cannot be used to identify or contact you.

6. Your rights (GDPR)

If you are in the European Economic Area (EEA) or UK, you have the following rights:

  • Access — request a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data (“right to be forgotten”)
  • Portability — receive your data in a machine-readable format
  • Restriction — request we limit processing of your data
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — where processing is based on consent

Account deletion is available directly in the app under Settings → Profile → Delete my account. All personal data is removed immediately upon confirmation.

To exercise other rights, or to request a data export, email privacy@calmbird.app with subject line “Data request — [your email]”. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

7. Cookies & analytics

CalmBird uses two categories of cookies:

CookiePurposeExpiryConsent required
next-auth.session-tokenAuthentication — keeps you signed inSessionNo (essential)
NEXT_LOCALERemembers your preferred language1 yearNo (essential)
cb_dismissedRemembers which in-app banners you have dismissedSessionNo (essential)
cb_analyticsStores your analytics consent choice (1 = accepted, 0 = rejected)1 yearNo (preference)
PostHog (ph_*)Product analytics — helps us understand which features are used and improve the product. Only active if you accept analytics.Up to 1 yearYes (analytics)

When you first visit CalmBird, a banner lets you accept or reject analytics cookies. You can change your choice at any time via the link in the footer. Rejecting analytics has no effect on CalmBird’s functionality.

No advertising or cross-site tracking cookies are used. We do not use Google Analytics, Facebook Pixel, or any ad-network cookies.

8. Children

CalmBird is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

9. Changes to this policy

We will notify you of material changes by email or by a notice in the app at least 30 days before the change takes effect.

10. Contact

Data protection enquiries: privacy@calmbird.app
[TODO: add DPO name and address if required.]