Privacy Policy
Privacy Policy
This Privacy Policy explains how Thoughtful Card Link collects, uses, and protects personal information when you use the website and app.
Last updated: 13 August 2026
Who we are
Thoughtful Card Link is made and operated by JMartyn Digital.
You can contact us through the contact page.
Information we collect
We may collect and store the following information:
- account details, such as your name, email address, and sign-in provider;
- card text you enter, such as recipient names, occasions, messages, inside messages, themes, style words, and from names;
- uploaded video greeting files and related video information, such as saved video URL, storage path, and upload date;
- optional reference photos you choose to upload for photo-guided artwork generation, which are sent for safety checking and artwork generation but are not saved to your card or account by our app;
- AI feature information, such as artwork generation status, generation count, saved artwork image URL, and error messages if generation fails;
- payment information needed to confirm that a card has been paid for and published;
- support messages or enquiries you send to us;
- technical information, such as basic logs needed to keep the website secure and working properly.
You should only add information you are comfortable using to create and share a greeting card. You should avoid adding unnecessary sensitive information about yourself or other people.
How we use your information
We use personal information to:
- create and manage your account;
- allow you to sign in securely;
- save and manage your draft and published cards;
- store and show uploaded video greetings for video greeting cards;
- generate greeting card artwork based on the card details you provide;
- use optional reference photos, when you choose to upload one, to help guide photo-inspired artwork generation;
- generate optional inside message suggestions when you choose to use the AI helper;
- process payments and publish paid cards;
- provide public card links after a card has been published;
- reply to support requests;
- keep the website and app secure, reliable, and working;
- help detect, investigate, prevent, or respond to misuse, abuse, security issues, legal requests, or serious harm.
Cookies and similar technologies
Thoughtful Card Link and the third-party services we use may use cookies, local storage, session storage, or similar technologies to keep the website secure, remember sign-in sessions, process payments, prevent fraud, and make the website work properly.
Cloudflare Web Analytics may use a small analytics script to collect basic website usage information, such as page views, visits, referrers, device type, browser type, and country-level location. Cloudflare Web Analytics does not track individual visitors and we do not use it for advertising or personalised marketing.
Some cookies or similar technologies are strictly necessary for the website and app to work, such as authentication, security, checkout, and fraud prevention. These cannot usually be switched off because the service may not work correctly without them.
If you choose to sign in with Google, they may set their own cookies or use similar technologies as part of their sign-in process.
Stripe may use cookies or similar technologies when you make a payment, including for checkout, fraud prevention, and payment security.
We do not currently use cookies for advertising or personalised marketing.
You can control or delete cookies through your browser settings. Blocking some cookies may affect how the website or app works.
AI features
Thoughtful Card Link uses OpenAI to generate personalised greeting card artwork and optional inside message suggestions.
For artwork generation, the AI is asked to create artwork and background only. Your exact card text is rendered by the app so that names and messages remain readable and reliable.
Card details such as recipient name, occasion, front message, theme, style words, and from name may be sent securely from our server-side function to OpenAI so the request can be checked for safety, checked for obvious protected-material artwork requests, and used to generate the artwork.
If you choose to upload an optional reference photo for photo-guided artwork, that photo may be sent securely from our server-side function to OpenAI for safety checking and artwork generation. Our app does not save the uploaded reference photo to your card or account. The generated artwork image is saved to your card if generation succeeds.
If you use the inside message helper, relevant card details and your chosen tone may be sent securely from our server-side function to OpenAI so an inside message suggestion can be generated.
You should avoid entering or uploading unnecessary sensitive information. You are responsible for checking the final card before publishing and sharing it.
Cards and public sharing
Draft cards are private to your account. Public card links only work after a card has been paid for and published.
When you publish a card, anyone with the public card link may be able to view that published card, including any written inside message or uploaded video greeting inside it.
You should only publish and share cards that you are happy for the recipient or anyone with the link to view.
If we believe a card, uploaded video greeting, account, or public link is being misused, we may disable access, remove content, preserve relevant information, or share information where required by law or where needed to respond to serious abuse or security issues.
How long we keep information
We keep account, card, artwork, video greeting, and payment information for as long as needed to provide the service, manage payments, keep records, and meet legal or accounting requirements.
In future, published cards may have expiry or cleanup rules so that old card data, artwork files, and video files can be removed after a period of time.
If you ask us to delete your account or card data, we will delete or anonymise personal information where we no longer need to keep it.
Security
We use reasonable technical and organisational measures to protect personal information. No online service can be guaranteed to be completely secure, but we take steps to protect the data used by the app.
Changes to this policy
We may update this Privacy Policy from time to time. If we make important changes, we will update the date on this page.
Done-for-you card orders
You may order a personalised digital greeting card without creating an account by using our done-for-you card service.
You may provide the information needed to create your card through an agreed communication method, such as Facebook Messenger or email.
The information we receive may include your name, email address, social media profile details, recipient name, occasion, card messages, artwork ideas, style preferences, from name, optional reference photos, optional video greetings, and any other information you choose to provide.
We use this information to discuss your order, create the card, send you a preview, make agreed changes, request payment where applicable, publish the finished card, provide its shareable link, respond to support questions, and keep appropriate business and payment records.
Our lawful basis for processing information needed to prepare and complete your order is normally that the processing is necessary to take steps at your request before entering into a contract and to perform our contract with you.
We may also process limited information where necessary to comply with legal, tax, accounting, fraud-prevention, security, or record-keeping obligations.
Messages and attachments sent through Facebook Messenger, email, or another communication service may remain stored by that provider under its own privacy and retention policies.
Photos, videos, or other files sent to us may sometimes need to be temporarily downloaded to our local computer so that we can prepare, upload, and check your card.
Separate local working copies are deleted once they are no longer needed to create and check the card. This does not remove copies stored by the communication provider you used to send the file or files that have been uploaded as part of the finished published card.
We do not intentionally save a separate permanent local copy of an optional reference photo after it is no longer needed to create the card.
A reference photo may be sent securely to OpenAI through its API for safety checking and photo-guided artwork generation. If generation succeeds, the generated artwork may be saved as part of the finished card.
The original reference photo is not published as part of the card unless you separately ask us to include it and we agree to do so.
If you provide a video greeting, the video may be uploaded and stored as part of the published card so that it can be played by anyone who has access to the card link.
Relevant card details may also be sent securely to OpenAI if you ask us to use AI to help generate an inside message for your card.
Order messages and related details may be retained for as long as reasonably needed to complete the order, provide support, resolve disputes, protect the service, and meet legal, tax, accounting, or record-keeping requirements.
You should avoid sending unnecessary sensitive personal information about yourself, the recipient, or anyone else.
How long we keep information
We keep personal information only for as long as reasonably needed for the purpose it was collected, including providing the service, supporting customers, protecting the service, resolving disputes, and meeting legal, tax, accounting, or record-keeping requirements.
Published cards do not currently have a fixed expiry date and may remain available for an extended period while they continue to be hosted as part of the service.
We periodically review older or inactive card data and may delete a published card and its associated generated artwork or uploaded video where we no longer reasonably need to keep it, or where deletion is reasonably necessary for storage, security, technical, legal, or operational reasons.
You may request deletion of a card or your personal information at any time. We will delete or anonymise information where we no longer need to keep it, subject to information that must be retained for legal, tax, accounting, fraud-prevention, security, dispute-resolution, or record-keeping purposes.
Account and payment records may need to be retained separately from the published card where they are still needed for legitimate business, security, legal, tax, accounting, or record-keeping purposes.
Services we use
We use trusted third-party services to run Thoughtful Card Link. These may process personal information for us when needed.
- Firebase - used for authentication, storing card data, storing generated artwork files, and storing uploaded video greeting files.
- Google Sign-In - used when you choose to sign in with your Google account.
- OpenAI - used to check and generate greeting card artwork, optional photo-guided artwork, and optional inside message suggestions from the card details and optional reference photos you provide.
- Stripe - used to process one-off card payments, payment confirmations, and receipts.
- Cloudflare - used for privacy-focused website analytics, such as page views, visits, and referrers.
- Netlify - used to host the website and run server-side functions.
Google sign-in
If you sign in using Google, Google may share basic account information with Firebase, such as your name, email address, and profile image. We use this to create and manage your account.
You can read more in the Google Privacy Policy.
Payments and billing
Paid card publishing, artwork credit purchases, and done-for-you card payments are handled by Stripe.
Done-for-you card payments may be collected through a reusable Stripe-hosted Payment Link after you have reviewed and approved your card preview.
Stripe may process your name, email address, payment details, billing details, payment confirmations, receipts, device information, and information needed to prevent fraud and complete the payment.
We may receive and retain payment information such as your name, email address, Stripe checkout session or payment identifiers, product purchased, amount paid, currency, payment status, receipt details, and relevant payment dates.
We use this information to confirm payment, identify the related order, provide the purchased service, respond to payment questions, prevent fraud, resolve disputes, and meet legal, tax, accounting, and record-keeping obligations.
We do not store your full payment card number, card security code, or full payment card details on our own systems.
OpenAI and AI features
Thoughtful Card Link uses OpenAI to help check artwork requests, generate greeting card artwork, and generate optional inside message suggestions.
When artwork is generated, card information such as recipient name, occasion, message, theme, style words, from name, artwork description, and other relevant card details may be sent securely from our server-side function to OpenAI so the request can be checked and the artwork can be created.
This applies to artwork created directly by a user through the app and artwork created by us for a done-for-you card order.
If an optional reference photo is provided for photo-guided artwork, the photo may be sent securely from our server-side function to OpenAI for safety checking and artwork generation.
Our app does not save uploaded reference photos to a card or account. For done-for-you orders, we do not intentionally keep a separate permanent local copy of the reference photo after it is no longer needed to create the card.
The communication service used to send a done-for-you reference photo, such as Facebook Messenger or email, may retain the original message or attachment according to that provider's own policies.
If you use the inside message helper, or ask us to generate an inside message for a done-for-you card, relevant information such as the recipient name, occasion, relationship, tone, existing message ideas, and other details needed to create the suggestion may be sent securely to OpenAI.
OpenAI states that information sent through its API is not used to train or improve its models unless the API customer explicitly opts in. OpenAI may retain API abuse-monitoring logs containing prompts, images, responses, or related metadata for up to 30 days by default, unless longer retention is required for legal or safety reasons.
If artwork generation succeeds, the generated artwork image may be saved to the card. The original reference photo is not published as part of the card unless this has been separately requested and agreed.
The generated image is intended to be artwork or a card background. The exact card text is normally rendered separately by the app on top of the artwork.
You should avoid entering or providing unnecessary sensitive information. You should check the final card before approving, paying, publishing, or sharing it.
You can read more in the OpenAI Privacy Policy.
Your rights
Depending on your location and the circumstances, you may have the right to:
- ask for a copy of the personal information we hold about you;
- ask us to correct inaccurate or incomplete information;
- ask us to delete your personal information;
- ask us to restrict certain uses of your personal information;
- object to certain uses of your personal information;
- receive certain information in a portable format where the right to data portability applies;
- withdraw consent where processing is based on consent;
- complain to the Information Commissioner’s Office if you believe your personal information has been handled unlawfully.
These rights may apply to information held in your app account and to information connected with a done-for-you card order, including relevant messages, payment records, and order details.
Some information may need to be retained where required for legal, tax, accounting, fraud-prevention, dispute-resolution, or record-keeping purposes.
You can ask about your personal information, request account deletion, or make another privacy request by contacting us through the contact page.
