Privacy Policy
Version: 2.1.0
Last updated: October 5, 2026
1. Introduction
This Privacy Policy explains how we collect, process and protect your personal
data when you use Santa's Sack (https://santassack.app) and Gifts
(https://gifts.santassack.app). The two products share one account and one
authentication session. We are committed to protecting your privacy and
complying with the General Data Protection Regulation (GDPR).
2. Data Controller
The data controller is Tomasz Miller, the author of Santa's Sack and Gifts. You can contact us through our contact page.
3. What Data We Collect
We collect only the data needed to operate the Service:
- Email address — used to create the shared account, sign in with an e-mail code, and send service messages (invitations, reminders, list activity).
- Profile fields you save — display name, language, timezone and default currency. We do not require a legal surname, home address or phone number.
- Santa's Sack content — groups, memberships, exclusions, draws, wish lists and related settings you create.
- Gifts content — gift lists, item titles, optional links, notes and suggested prices; invitations; reservations (including purchased state); clarifying comments; and contribution declarations (amount, currency and contributor identity for the owner's private ledger).
- Sharing secrets — Gifts share-link tokens and human access phrases are stored as HMAC hashes for lookup and as AES-256-GCM ciphertext so the list owner can reveal the link and phrase again. Raw tokens and phrases are not kept in logs, analytics or e-mail preview snippets.
- Technical data for security — as described for Cloudflare Turnstile below, when you submit a contact or support form.
- Agent connections — if you connect an agent, we store the connector name, the scopes you accepted, and HMAC-SHA256 hashes of the access and refresh tokens. We do not keep the token values. Some writes are kept as a replay record on your account so the same request is not applied twice.
We do not collect payment-card data for Gifts. Transfer declarations record money moved outside the product; they are not payments through Gifts.
4. Purpose of Data Processing
We process your data to:
- Create and maintain one account for both products.
- Let you organise Secret Santa groups, draws and wish lists in Santa's Sack.
- Let you create, share and coordinate gift lists in Gifts (link + access phrase, e-mail invitations, reservations, comments and off-platform transfer records).
- Let an agent you connect read or change Santa's Sack or Gifts, only for the products and scopes you accept on the consent screen.
- Send service e-mail (sign-in codes, invitations, optional list-activity notices). List invitations are always sent; activity mail can be turned off in Settings.
- Protect the Service against spam and abuse.
- Improve the Service using anonymous usage statistics.
Legal bases:
- Consent (Article 6(1)(a) GDPR) for optional notifications you can disable, and for connecting an agent.
- Contractual necessity (Article 6(1)(b) GDPR) for the account and product features you use.
- Legitimate interest (Article 6(1)(f) GDPR) for security, abuse prevention and service improvement.
5. Gifts sharing, access phrases and contribution privacy
Every shared Gifts list uses an unguessable URL and a human access phrase. The URL alone is not enough to open the list. Recipients who unlock with the phrase can read the list; reserving a gift, declaring a transfer or posting a comment requires a signed-in, verified account. Recipients never edit list content through share access.
Contribution amounts: only the list owner sees who declared how much. Everyone else, including other givers, sees only an aggregate budget bar (fill ratio and/or remaining amount). This applies while the list is in use, not only after account deletion.
Sign-in requests started in Gifts are handled by the Santa's Sack authentication issuer. Signing in or out on either trusted product affects the current browser in both.
6. Data Storage
Data is stored on Amazon Web Services (AWS) in the eu-central-1 region (Frankfurt, Germany). We use encryption at rest and in transit.
Data is kept while the account is active. After deletion, visible sharing data is removed immediately as described in section 8; the account row may be retained for up to 30 days for billing or defence against claims unless you request earlier deletion where the law allows.
7. Anti-Spam and Bot Protection (Cloudflare Turnstile)
We use Cloudflare Turnstile on contact and support forms to prevent spam and automated abuse.
Data collected by Cloudflare: IP address; browser information (User Agent, device type, operating system); interaction patterns with the widget; technical telemetry; response time and behavioural analytics.
Cookies set by Cloudflare: cf_clearance (1 year); __cf_bm (30
minutes).
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Data may be transferred to the USA with GDPR-appropriate safeguards.
More information: Cloudflare Privacy Policy
Objecting to this processing may prevent you from submitting contact forms.
8. Account deletion
Deleting the account from Santa's Sack or Gifts signs the browser out of both products. Gifts share links and invitations stop working immediately. Memberships are removed. Unpurchased reservations are released; purchased gifts stay claimed without the deleted person's name. Contribution amounts remain on the owner's private ledger without the giver's identity. Comment text remains with an anonymised author label. Owned lists are kept and return as private lists if the user later signs in again (account restore). Santa's Sack groups you own remain subject to the 30-day retention in section 6. Deleting the account also revokes every connected agent. Signing in again does not restore those connections.
9. Data Sharing
We do not sell your personal data. We share it only as required by law or as needed to provide the Service (for example AWS infrastructure providers bound to confidentiality, and Cloudflare for form protection). If you connect an agent, tool results are sent to that agent's host, as described in section 10.
Gifts list content is shown to people the owner invites or who unlock a share with the access phrase, under the redaction rules in section 5.
10. Connecting an agent
You can connect an agent, such as ChatGPT, Claude, or Grok, with OAuth 2.1
on Santa's Sack (https://santassack.app). The agent calls POST /mcp on
that site. Gifts (https://gifts.santassack.app) does not host /mcp.
We do not offer this connection in a public app directory. You add the
server address yourself in the agent you already use.
On the consent screen you choose Santa's Sack, Gifts, or both. The grant
is limited to the scopes that client asked for: sack:read and
sack:write for Santa's Sack, and gifts:read and gifts:write for
Gifts. openid, email, and offline_access are included only when the
client requested them and you accept at least one product. openid lets
the client receive your account id. email also lets it receive your
e-mail address and whether that address is verified. Neither scope is
access to lists or draws. A write scope does not include reading.
The access token is an opaque value. We store an HMAC-SHA256 hash of it,
not the token itself. It expires after 15 minutes and is accepted only at
the /mcp address of the Santa's Sack site that issued it. When you grant
offline_access, the client also receives a refresh token that expires
after 30 days. Using it issues a new refresh token and the previous one
stops working. The agent does not receive your browser sign-in cookie.
With the scopes you accepted, the agent can read and change groups, personal wish lists, and draws, and gift lists you own or belong to, including reserving a gift and marking it bought. It sees the same information you would see on the website for your role. After a draw is closed, a result can include the exchange pairs as display names. Before the draw is closed, a result includes your own assignment only when the website would show it to you. This version cannot start or close a draw, and it cannot send invitations or handle share links, access phrases, contribution amounts, comments, exclusions, or friends.
Tool results, which may include list contents and those closed-draw pairs, are returned to the third-party host of the agent you connected. That host processes them on its own systems and under its own terms. We do not control that host.
You can disconnect an agent in Santa's Sack settings, under Connected agents. Revoke removes that client's consent and its access and refresh tokens. Gifts settings links to the same list. Deleting the account on either product revokes every agent grant. Signing out of the website does not. A connected client can also revoke its own token.
Legal basis: your consent when you allow the selected access (Article 6(1)(a) GDPR).
11. Your Rights
Under GDPR you may request access, rectification, erasure, restriction of processing, data portability, and object to certain processing. Contact us through the contact page.
12. Data Security
We implement appropriate technical and organisational measures, including HMAC hashing and AES-256-GCM encryption of share tokens and access phrases. No method of transmission over the internet is 100% secure.
13. Liability Disclaimer
Tomasz Miller assumes no responsibility for content that users store on their accounts. Users are responsible for that content and for complying with applicable law.
14. Changes to this Privacy Policy
We may update this policy. We will notify you of changes via an in-app notice or e-mail.
15. Contact
If you have questions about this Privacy Policy, contact us through the contact page.
Thank you for your trust and for using Santa's Sack and Gifts.