Privacy notice
Create something thoughtful. Keep control of your information.
You do not need an account to create or download a greeting. We process the name and design choices needed to render your requested card. Optional usage statistics require your choice. Advertising networks, Google Analytics and paid checkout are not active.
1. Who is responsible
The operator below is the controller of the personal data processed through Generate Greetings at generategreetings.com. This notice concerns the public greeting service, its support and its administration.
The service is operated from Milan, Italy. The operator’s full legal name and public contact details have not yet been supplied for this notice. Optional statistics and sponsor banners are disabled until those details are published. Advertising networks and purchases are not active.
This is an incomplete notice while these details are missing.
2. Information, purposes and legal bases
| Information | What we do with it | Legal basis under the GDPR |
|---|---|---|
| Optional recipient name; language, occasion, wording and visual choices | Generate the greeting and render the preview or downloadable image you request. Card rendering sends the name and selected design to our server. Free card content is processed in memory and is not saved in our application database. | Performance of the free service you request (Article 6(1)(b)). For a recipient’s name supplied by someone else, our legitimate interest in providing the requested personal greeting, limited to that purpose (Article 6(1)(f)). |
| Connection information, including IP address, request time, requested resource and browser technical information | Deliver pages and images, protect the service and investigate failures or abuse. Our application rate limiter uses a short-lived hash of IP address, time window and endpoint; this is pseudonymous, not anonymous. | Legitimate interests in a secure, available service (Article 6(1)(f)); legal obligations where applicable (Article 6(1)(c)). |
| Browser privacy choice, random consent receipt identifier, notice version and decision/expiry times | Apply and demonstrate your choice, including refusal or withdrawal. Consent receipts do not contain your name, email, IP address or browsing history. | Meeting consent and accountability obligations (Article 6(1)(c)); legitimate interests in recording and defending compliance (Article 6(1)(f)). The preference cookie is necessary to remember your choice. |
| Optional counts of page views, generated greetings, downloads, and sponsor impressions/clicks | Understand service use. If enabled by the operator, these counts start only after you opt in. We store daily event totals and short-lived random event identifiers to avoid double counting. We do not join these counts to your name or consent receipt, or create an advertising profile. | Your consent (Article 6(1)(a)). Rejecting or withdrawing does not prevent free card creation or download. |
| Information you send when contacting us, and administrative access information | Answer requests, handle rights or content complaints, and restrict administrative controls to the authorised operator. | Legitimate interests in responding and protecting the service; performance of a requested service or legal obligations where relevant (Articles 6(1)(f), (b) or (c)). |
The recipient name is optional: a nickname or first name is enough. Do not enter health information, identity documents, financial information or other sensitive personal data. We use a combinatorial phrase library; creating a card does not require a visitor account or a prompt to an external AI generation service.
3. What stays in your browser
The browser remembers recent background choices for the current tab session and stores a necessary cookie after you save a privacy choice. Greeting choices and image previews also exist temporarily in page memory. See the Cookie & browser storage notice for names, lifetimes and controls.
A choice applies to this browser on this device, not all your devices. Clearing storage, using private browsing or changing browser can remove it. We do not fingerprint you to reconstruct a lost choice. If we cannot verify a valid choice, optional statistics remain off.
4. Recipients and service providers
Hosting: the site uses OpenAI’s ChatGPT Sites hosting. Under the Sites Data Processing Addendum, OpenAI processes Hosted Data for the publisher. Hosting providers process connection and operational information needed to deliver and protect the site. Infrastructure and domain services may include Cloudflare. Purchasing a Cloudflare domain does not enable Google Analytics or an advertising network.
Site administration: the authorised operator can access settings and aggregate usage statistics. Administration uses ChatGPT authentication; public card creation does not. OpenAI also applies its own privacy terms to its account services.
Sharing and external links: WhatsApp and your device’s share destinations receive content only when you choose to share or open them. Their own terms and privacy policies apply. The WhatsApp fallback opens WhatsApp with the greeting text; your device downloads the image separately. Photo-credit and sponsor links open external sites when you follow them. Images and fonts used in our card editor are served from this site.
Advertising and payments: no AdSense, other advertising-network SDK, Google Analytics tag or Stripe checkout is loaded for visitors in this release. Direct sponsor links, if enabled after the operator information is complete, are labelled and use locally hosted creative images. They do not provide advertisers with a profile of you. Optional interaction counts follow your statistics choice.
We may disclose relevant information where required by law or necessary and proportionate to protect legal rights, security or people. We do not sell recipient names or greeting content.
5. International processing
Hosting and connected services can process information outside Italy or the European Economic Area. We do not represent that all data stays in the EU. For transfers of Hosted Data, the Sites DPA provides for applicable adequacy decisions or Standard Contractual Clauses and related safeguards. Further information appears in the provider’s subprocessor list. You may request information about applicable safeguards using the controller’s published contact details.
6. Retention
- Free greetings and recipient names: not saved in the application database; processed for rendering and held temporarily in page/server memory. A file you download or share is controlled by you and the chosen destination.
- Privacy cookie: 184 days from your decision, unless you replace or clear it earlier. Reading the cookie does not renew it. Consent evidence in our database is eligible for deletion after 365 days from the recorded decision, including superseded receipts.
- Rate-limit records: expire after about two minutes. Random event-deduplication keys are eligible for deletion after two days. Daily statistics and any older generation records are eligible for deletion after 90 days.
- Cleanup: the application runs cleanup during subsequent service activity, at most once an hour per running worker. Expired records are ignored for permission checks even before physical cleanup. We do not claim immediate deletion from infrastructure logs or backups controlled by hosting retention processes.
- Support and legal matters: keep only what is needed to respond and resolve the matter, or for an applicable legal retention requirement or legal claim. Provider operational/security logs follow the relevant hosting arrangements rather than the application counters’ schedule.
7. Your choices and rights
You can accept or reject optional statistics, and change or withdraw your choice through at any time. Withdrawal applies going forward and does not affect the lawfulness of processing before withdrawal. Previously aggregated totals cannot normally be linked back to you.
Where applicable, you may request access, correction, erasure, restriction or portability of your personal data; object to processing based on legitimate interests; and withdraw consent. Contact the controller above with enough information to understand the request. We normally respond within one month; if a lawful extension is necessary, we will explain it. We may ask for proportionate verification when needed, but do not need an identity document by default.
Because you do not need an account, we may be unable to identify data belonging to you. We will explain this and consider any relevant information you voluntarily provide; we do not collect extra identity information solely to make you identifiable. You may complain to the Italian Garante per la protezione dei dati personali or your competent data protection authority.
8. Children, security and changes
This service is intended for adults creating greetings for friends and family, rather than a service directed to children. Do not submit personal information about a child beyond what is appropriate and necessary for a greeting. A parent or guardian can contact the controller about a concern.
We use HTTPS, restricted administration, validation, request limits and consent checks on the server as well as in the browser. No internet service can guarantee absolute security. We do not use these service statistics for automated decisions producing legal or similarly significant effects.
We will update the date and version when practices change. New optional purposes or material consent changes will be explained before they are enabled, with a new choice where required. English is the current master notice; the short privacy controls are available in the editor’s eleven languages.