Last updated: 4 September 2026
BirthBrief is operated by Matteo Rigo, an individual trader, ul. Popieluszki 2a/190, 80-864 Gdańsk, Poland. Contact: [email protected].
This policy explains what personal data we collect when you use birthbrief.com, why we collect it, and your rights under the General Data Protection Regulation (GDPR, EU 2016/679).
When you purchase or generate a natal chart report, we collect:
We also log a one-way hash of your IP address for rate-limiting and fraud prevention. The hash cannot be reversed to identify you.
Legal basis (GDPR Art. 6(1)(b)): All data above is processed to perform the contract — i.e. to generate and deliver the natal chart report you purchased or requested. We do not use this data for advertising or sell it to third parties.
To deliver the service we share your data with the following processors, each bound by data processing agreements:
Most processors are based in the United States; Meta and Google are contracted through their Irish entities, which transfer onward to the United States. Data transfers outside the EEA are covered by Standard Contractual Clauses and, for the US recipients, by the EU–US Data Privacy Framework where the recipient is certified.
BirthBrief uses a cookie consent banner (cc.js, self-hosted — no external scripts). On your first visit, you can choose to accept or reject analytics and marketing cookies. Your choice is stored in a cookie called bb_cc.
We set one functional cookie (bb_gate_passed) that does not require consent — it records that you completed the free report email gate. We also use browser localStorage for the gate status (bb_teaser_gate) and, if you accept analytics, an anonymous GA4 client ID (bb_ga4_cid).
Analytics (optional, consent required): If you accept analytics, we send page view events to Google Analytics 4 via a server-side proxy on our own domain. No Google cookies are set in your browser, and no gtag.js or other Google script runs in it. The proxy forwards usage data to Google's Measurement Protocol under a random identifier we generate; it never carries your name, your email address, your birth data or your report.
Separately, when a purchase completes, our server sends Google a purchase event carrying the order reference, the amount and the currency — only if you accepted marketing. It is not linked to your browsing session and carries no name or email address.
Marketing (optional, consent required): If you accept marketing cookies, the Meta Pixel (Facebook/Instagram) loads in your browser and reports page views, and we also send matching events to Meta directly from our own servers (Meta's Conversions API). The server-side events are the same actions — viewing a brief, requesting a free one, starting a checkout, completing a purchase — sent a second way so that ad measurement still works when a browser blocks the pixel. They carry your IP address, your browser's user-agent string and Meta's own _fbp / click identifiers. On a completed purchase they also carry your email address, irreversibly hashed (SHA-256) — Meta uses it to match the sale to an account on its own platforms so that ad measurement works; we never send the address itself.
Both paths run only if you accept marketing: with no consent, the pixel never loads and the server sends nothing. You can withdraw consent at any time via the cookie preferences link in our footer, and we stop immediately. We never send Meta the contents of your brief, your birth data, or your birth time.
Our fonts are self-hosted — no requests are made to Google Fonts or any font CDN. See our Cookie Policy for a complete table of all cookies.
Product analytics on our own servers (optional, consent required): If you accept analytics, we record how you use BirthBrief so we can make the writing better. This data stays on our own infrastructure and is never sold, shared or used for advertising. We record a fixed, published list of events — nothing outside this list is collected:
We do not record your mouse movements, your keystrokes, your screen, or the content of your brief. We do not use fingerprinting, and we do not track you across other websites.
Each reading session gets a random identifier stored in your browser's
sessionStorage (bb_s), which disappears when you close the tab, plus a
counter of how many times you have opened your own brief (bb_open_… in
localStorage). Legal basis: your consent (GDPR Art. 6(1)(a)), which you can
withdraw at any time via the cookie preferences link in our footer — after
which we stop collecting immediately.
Audience counting (no consent asked — here is why): Separately from the product analytics above, we keep a simple count of page views so we know whether anyone is visiting at all. For each view we store the page type (home, teaser or report), the country from our network edge, which channel sent you — chosen from a fixed published list (direct, card, meta, tiktok, instagram, facebook, youtube, reddit, x, pinterest, google, bing, email, newsletter, other) — and, if the link carried them, a campaign and creative label limited to plain lowercase identifiers. Anything that does not match that list or that format is discarded rather than stored, so a link cannot be crafted to push arbitrary text into our records.
We do not store your IP address. To avoid counting the same person twice within half an hour we store a truncated, salted one-way hash of it, which cannot be reversed back to an address. This counter sets nothing on your device — no cookie, no localStorage — so it does not require consent under the ePrivacy rules. Legal basis: our legitimate interest (GDPR Art. 6(1)(f)) in knowing our own audience size. It does not profile you, does not follow you across other sites, and is never used for advertising. These records are deleted after 90 days, and you can object at any time by writing to us.
Your report and birth data are retained for 12 months from the date of generation, then automatically deleted from our database.
Order records are kept longer, and we keep them ourselves. When you buy, we store an order record in our own database containing your email address, the amount, the currency and the payment reference. We are required to retain these as accounting records, so they are not deleted after 12 months and are not removed when you ask us to erase your data (GDPR Art. 17(3)(b)). Everything else about you — your birth data, your chart, your report and your usage events — is deleted. Stripe separately retains its own payment records under its own policies.
Usage events are kept for 90 days and then deleted automatically. After that we retain only aggregate counts, which cannot be traced back to any individual. If you ask us to erase your data, your usage events go with it.
Under GDPR you have the right to:
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Personal reports are generated automatically by an AI language model from computed astronomical data, and are delivered to you without human review. Nobody reads your report before you do. Automated quality checks run on every report, but they do not block delivery.
The public Celebrity Library pages are generated the same way and are published under the editorial responsibility of Matteo Rigo / BirthBrief.
We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes. Continued use of the service after a change constitutes acceptance of the updated policy.
Matteo Rigo
ul. Popieluszki 2a/190, 80-864 Gdańsk, Poland
[email protected]