Privacy Policy
Last Updated: April 5, 2026
1. Introduction
This Privacy Policy describes how Gathering Gifts Foundation Inc. ("we," "us," or "our") collects, uses, and protects your personal information when you use our web application (the "Service"). We are committed to protecting your privacy and handling your data with transparency and care.
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, first name, last name, and password (encrypted)
- Profile Information: Your Gift Statement, Key Word, and Noble Purpose generated through our discovery process
- Chat Transcripts: Your responses to reflection questions and conversations with our AI assistant
- Feedback: Ratings and comments you provide about your experience
2.2 Automatically Collected Information
- Usage Data: Session IDs, timestamps, and interaction patterns
- Technical Data: IP address, browser type, device information (collected by our hosting provider)
2.3 Information We Do NOT Collect
- We do not use tracking cookies or analytics beyond basic server logs
- We do not sell or share your data with third parties for marketing purposes
- We do not collect payment information (the Service is currently free)
3. How We Use Your Information
We use your information to:
- Provide and improve the Gift Discovery Service
- Generate your personalized Gift Statement, Key Word, and Noble Purpose using AI
- Save your progress and allow you to access your profile across sessions
- Respond to your support requests
- Improve our service and AI models, including using your chat conversations and generated Gift Statements for quality evaluation and service improvement
- Analyze usage patterns using anonymized, aggregated data
- Comply with legal obligations
Important: Your conversations are processed by Anthropic's Claude language models. Anthropic does not use API data to train their models by default.
4. Third-Party Services
We use the following third-party services to operate the Service:
- Supabase: Database and authentication provider. Data is encrypted at rest and in transit. Supabase Privacy Policy
- Anthropic: AI language model provider for generating Gift Statements and facilitating conversations. Your chat transcripts are sent to Anthropic for processing. Anthropic does not use API data to train their models by default. Anthropic Privacy Policy
- Vercel/Netlify: Hosting provider. Vercel Privacy Policy
5. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit using HTTPS/TLS
- Database is encrypted at rest
- Passwords are hashed using bcrypt
- Row-level security policies ensure users can only access their own data
- Access to production data is restricted to authorized administrators only
However, no method of transmission over the Internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you without undue delay and within 45 days of discovering the breach, as required by California law. Notification will be sent to the email address associated with your account and will include:
- A description of the breach and the types of information affected
- Steps we are taking to address the breach
- Recommended actions you can take to protect yourself
- Contact information for further questions
6. Your Rights
You have the following rights regarding your personal data:
- Access: You can view your profile and chat history at any time while logged in
- Correction: You can edit your profile information from your dashboard
- Deletion: You can request deletion of your account and all associated data by contacting us at [contact email]
- Export: You can request a copy of your data in a portable format
- Withdraw Consent: You can stop using the Service at any time
For EU/EEA users: You have additional rights under GDPR, including the right to object to processing and the right to lodge a complaint with a supervisory authority.
For California users: You have rights under CCPA, including the right to know what personal information is collected and the right to opt-out of sale (though we do not sell your data).
7. Data Retention
- Active Accounts: We retain your data as long as your account is active
- Deleted Accounts: When you delete your account, we permanently delete all your personal data within 30 days
- Anonymous Sessions: Chat sessions from non-logged-in users are retained for up to 90 days for service improvement, then deleted
- Backups: Deleted data may persist in encrypted backups for up to 90 days before permanent deletion
8. Children's Privacy
The Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. By using the Service, you consent to such transfers.
Our third-party service providers (Supabase, Anthropic, and Vercel/Netlify) may process your data internationally and maintain their own compliance programs, including:
- Standard Contractual Clauses (SCCs): Our providers use EU-approved SCCs for international data transfers
- Data Processing Agreements: We maintain agreements with all processors handling your data
- Security Certifications: Our providers maintain SOC 2, ISO 27001, and other security certifications
We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable data protection laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. California Privacy Rights
If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA).
Your California Rights
California residents have the right to:
- Know: Request information about the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business purpose for collecting it, and the categories of third parties with whom we shared it
- Delete: Request deletion of your personal information, subject to certain exceptions
- Opt-Out of Sale: We do not sell your personal information
- Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your privacy rights
Exercising Your Rights
To exercise your California privacy rights, please contact us at corequest@earthlink.net. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf by providing written authorization.
Minors Under 18
If you are a California resident under 18 years old and have posted content on our Service, you may request removal of such content by contacting us at corequest@earthlink.net. Please note that removal does not ensure complete deletion if the content has been shared or reposted by others.
Shine the Light Law
California's "Shine the Light" law permits California residents to request information about our disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:
Gathering Gifts Foundation Inc.
13202 La Jolla Cir Unit B
La Mirada, CA 90638
Email: corequest@earthlink.net