Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how Wishmori, operated by Fendaro ("we", "us"), collects, uses, and protects information when you use the Wishmori website, create an account, and build birthday experience pages (together, the "Service").
1. Information we collect
- Account information. When you sign in with Google, we receive your name, email address, and profile picture from Google to create your Wishmori account. We do not receive or store your Google password.
- Your Gemini API key. If you connect your own Google Gemini API key to generate birthday emails, it is encrypted before storage, is never displayed again after you save it, and is used only to generate content for your own birthday experiences.
- Birthday experience content. Recipient names, nicknames, birthday dates, written messages, gift content, theme selections, and uploaded photographs you supply when creating a birthday page.
- Recipient email addresses. Collected only when you enable email delivery for a specific birthday experience, for the sole purpose of sending that birthday email.
- Generated email content. Inputs you supply for AI email generation (relationship, tone, personal message, and any memories provided) and the resulting drafted subject, heading, and body.
- Technical and log data. Standard request logs (timestamps, IP address, user agent) and email delivery events (queued, sent, delivered, bounced, failed, complained) reported by our email provider.
- Essential cookies/storage. Session data required to keep you signed in. We do not use advertising or third-party tracking cookies on birthday pages.
2. How we use information
We use collected information to:
- Authenticate you and maintain your account;
- Render the birthday experience pages you create and publish;
- Generate personalized birthday email drafts using your connected Gemini API key, from the details you supply;
- Deliver approved birthday emails via Resend and track delivery status;
- Automatically delete birthday experiences and their related data one week after creation (see Section 5);
- Operate, secure, and improve the Service, including detecting abuse and enforcing rate limits and account limits;
- Respond to support requests sent to the contact address below.
3. Who can access a published birthday page
A published birthday page is accessible to anyone who has its unique link. Birthday pages are excluded from search engine indexing by default (noindex); you may explicitly opt a specific page into indexing. Unpublished (draft) pages are not accessible at their public link. Wishmori accounts are private to each user — you can only view and manage the birthday experiences your own account created.
4. Third-party service providers
We rely on the following third-party providers to operate the Service. Information relevant to each provider's function is shared with it as described:
- Google Sign-In. Used to authenticate your account, per Google's own terms and privacy practices.
- Google Gemini API. If you connect your own Gemini API key, details you supply for email generation (recipient name, relationship, tone, personal message, memories) are sent to Google's Gemini API — under your own Google account and API terms — to draft email content.
- Resend. Recipient email address and the approved email content are sent to Resend to deliver birthday emails and report delivery status.
- Database and hosting infrastructure. Birthday experience content, uploaded photographs, and account data are stored in our PostgreSQL database and file storage, hosted with our infrastructure providers.
We do not sell personal information, and we do not use birthday page content for advertising.
5. Data retention and automatic deletion
Each birthday experience automatically expires and is permanently deleted — including its photographs, gallery data, email drafts, and delivery records — one week after it is created. You may also delete a birthday experience yourself at any time, which deletes the same data immediately. Your account itself (Google sign-in details and your encrypted Gemini key, if connected) persists until you ask us to delete it.
6. Security
Your Gemini API key is encrypted at rest and never returned by any part of the Service after you save it. Access to your birthday experiences requires an authenticated session scoped to your account, uploaded files are validated for type and size, and webhook requests from our email provider are verified using signed request headers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or delete personal information we hold about you, or to object to certain processing. To exercise these rights, or with any privacy question, contact us at support@fendaro.online.
8. Children's birthdays
Wishmori is intended for use by adults creating birthday experiences for others. If you are creating a page featuring a child's name, photographs, or details, you are responsible for having the appropriate authority and consent to do so under applicable law.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above when we do.
10. Contact
Fendaro
[Your registered business address]
Governing jurisdiction: [Your jurisdiction - e.g. State/Country of incorporation]
Email: support@fendaro.online