Privacy policy

Plain language, no legalese. Open a Gift has no accounts, so the only personal data we hold is what you put into a gift — and every gift is deleted on a fixed schedule.

Last updated 2026-09-17

Who we are

“Open a Gift” is the product at openagift.com. This policy covers that site and its gift links. Contact: [email protected].

What we collect, and why

The gift you make. Whatever you type or choose in the maker is stored so the recipient can open it:

  • your name as sender (up to 40 characters) and, optionally, the recipient's name;
  • the occasion, tone, reveal, card design and (for the gift box) wrapping style;
  • your message (up to 600 characters) and an optional P.S. line (up to 200 characters);
  • an optional photo — resized in your browser to at most 1080 pixels on its longest side before upload; JPEG, PNG or WebP up to 6 MB is accepted;
  • optional extras you turn on: an unlock time, clue questions with their answers and hints, love-coupon lines, a countdown-calendar series, a prank layer count, or the "quiet" (no confetti or chime) setting.

What happens to the gift.We record when the gift was created and when it expires; whether and when the link was first opened; when the reveal was first completed; each emoji reaction with its time; and, when a recipient makes a return gift from the end of a reveal, which gift it was a reply to. This is what powers the sender's manage page (“opened”, reactions).

How you arrived.When a gift is created, and when it is first opened, we store a coarse note of where that visit came from: the site that linked to us (grouped into “chatgpt”, “claude”, “gemini”, “other AI”, “not AI” or “unknown”, from the referrer or a utm_source parameter), whether that came from a referrer or a UTM tag, and the public landing path. Private paths are collapsed and no query string is kept. We also store the slug of the scenario page a sender came from (for example a template page). This tells us which pages bring people in; it does not identify you.

Random identifiers.Each gift gets a random gift ID (the part of the share link) and a separate random secret that forms the sender's manage link. The secret is never shown to recipients and is the only thing that can delete a gift early.

Not collected by the gift. No account, no email address, no phone number, no password, no payment details. The gift record does not contain your IP address.

Where it is stored

Gift records are stored in Google Firebase (Cloud Firestore) and photos in Google Cloud Storage for Firebase. The site itself runs on Vercel. Both providers process the data on our behalf under their own terms.

How long we keep it

  • Gifts with a photo are deleted 30 days after creation.
  • Gifts without a photo are deleted 60 days after creation.
  • The period is measured from creation, not from opening, and replaying does not extend it.
  • The link stops working at the exact expiry time. A cleanup job then runs once a day (03:00 UTC) and physically deletes expired records and their photos.
  • Early deletion: the sender can delete a gift at any time from the manage link ("Delete this gift"). The photo and the record are removed immediately and the link stops working. If you have lost the manage link, email us the gift link and we will delete it.

Who can see a gift

Anyone who has the gift link can open it, unless the sender added clue questions. Gift pages are not listed on the site and carry a “noindex” instruction; our robots.txt also asks crawlers not to index gift and manage pages. The photo can be viewed and saved by whoever opens the gift. We never send the link to anyone — sharing is entirely in the sender's hands.

Cookies and local storage

Our own code sets no cookies.It does use your browser's local storage, which stays on your device and is never sent to us:

  • "myGifts" — a list of up to 20 gifts you created in this browser (gift ID, manage secret, occasion, recipient name, creation time), so the home page can show "Your gifts" without an account. Clearing site data removes it, and with it your easy way back to those manage links.
  • "giftSound" — whether you muted reveal sounds.
  • a per-gift record of which countdown-calendar doors you have opened.
  • session storage (cleared when the tab closes): a 30-minute note of how you arrived (the same coarse platform/landing note described above) and, for "make one back", a short-lived receipt that proves you opened the original gift.

Google Analytics.The production site loads Google Analytics 4 (gtag.js), which sets its own cookies and collects the usual usage data (pages viewed, device and browser type, approximate location derived by Google) under Google's privacy policy. On top of that we send product events such as “gift created”, “gift opened” or “reaction sent” with the chosen occasion, reveal and card, the reaction emoji, and the coarse arrival note. We do not send your names, message, photo, gift ID or manage secret to Google Analytics.

Server logs

When a request to a public page (not a gift, manage or create page) declares itself as one of a short list of AI search crawlers (for example OAI-SearchBot, ChatGPT-User, GPTBot, PerplexityBot, Claude-SearchBot, Claude-User), we write a log line with the crawler name, its declared purpose and the page path. That log contains no IP address, cookies, query string or full user-agent string. Vercel and Google may keep their own infrastructure logs under their own policies.

Microphone

One reveal, “Blow Out the Candles”, offers a “Blow for real” button. Only if the recipient taps it does the browser ask for microphone access. The sound level is analysed on the device to detect a puff of breath; nothing is recorded, stored or uploaded, and the microphone is released as soon as the candles are out or the recipient stops it. Swiping across the candles works without any microphone.

We do not sell data

We do not sell, rent or trade the content of gifts or any other data. We do not show ads on gift pages. The only third parties that process data are the providers named above (Google Firebase, Vercel, Google Analytics).

Children

Open a Gift is a general-audience site and is not directed at children. We do not ask for ages and have no way to verify them. If you believe a child has put personal information into a gift, email us the gift link and we will delete it.

Your choices

  • Delete a gift you sent: use the "Delete this gift" button on your manage link.
  • Delete a gift you received or a gift whose manage link is lost: email the gift link to the address above.
  • Analytics: block the Google Analytics script with your browser or an extension; the site works without it.
  • Local storage: clear site data for openagift.com in your browser.

Changes

If this policy changes, the new version will be published here with a new “last updated” date. Questions: [email protected] or the contact page.