Policies & legal information
Last updated: 24 September 2026
Privacy Policy
Controller and scope
SomedayMade is operated by Borys Bondarenko, self-employed (autónomo), Spain. Privacy contact: borman2@ukr.net. This notice covers the website, invitations, Future Fingerprint, reveal and AI-film beta. The private beta is intended for adults 18+.
Information we process
- Gift IDs, occasion/recipient information, friends’ questionnaire answers, contributor technical/device identifiers and timestamps.
- Recipient consent records, locale/region and the recipient’s own photo when film generation starts.
- AI-generated frames, video scenes and final outputs.
- Payment status, amount, currency and transaction references; Stripe handles card details.
- Technical/security logs, IP/network information, diagnostics and support communications.
Sources
Some data comes from you. Some future-scenario information about the recipient comes from the organizer and contributors. It is subjective gift content, not a factual assessment.
Purposes and EEA/UK legal bases
| Purpose | Typical basis |
|---|---|
| Deliver gift, Future Fingerprint and paid film | Contract / requested pre-contract steps |
| Process recipient’s own photo for AI generation | Informed user action/consent where required, and contract where appropriate; not used for identification |
| Security, abuse prevention, debugging | Legitimate interests balanced against user rights |
| Tax, accounting, fraud and legal compliance | Legal obligation / legal claims where applicable |
AI and facial images
The photo is a visual reference for fictional scenes. We do not intentionally create a face-recognition template, identify/authenticate the person by face, infer race/health/emotion from the face, or build a searchable face database. If a jurisdiction treats a particular step as biometric processing, additional required notice/consent/retention rules will apply.
Providers and international transfers
Key providers include Supabase (backend/database/storage), Runway (AI media), Stripe (payments) and Netlify (hosting). Information may be processed in the EEA, UK, U.S. and other provider locations. Where required for EEA/UK transfers to non-adequate countries, SomedayMade will use an available lawful mechanism such as Standard Contractual Clauses and supplementary safeguards.
Retention
Data is kept only as reasonably necessary for delivery, security, support, accounting and law. The current architecture is designed not to intentionally persist the source selfie in the SomedayMade application database after it is forwarded to the AI provider. Provider-side retention follows provider configuration/contracts. Face-bearing intermediate scene videos are deleted as soon as the recipient's device successfully assembles the final film. If that completion signal is not received, SomedayMade runs a daily cleanup: intermediate scenes are normally deleted after 7 days and in all cases are scheduled for deletion no later than 30 days, subject only to a legal preservation obligation. The source selfie is not intentionally persisted in the SomedayMade application database after it is forwarded to the AI provider. Consent/payment records may be retained longer to demonstrate compliance or meet accounting/legal duties.
EEA/UK rights
Where GDPR/UK GDPR applies, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. In Spain the authority is the AEPD. Requests: borman2@ukr.net.
U.S. state privacy rights
We do not sell personal information or share it for cross-context behavioral advertising. Where an applicable state law grants rights, you may request access/confirmation, correction, deletion, portability, opt-out of sale/targeted advertising/certain profiling, and where applicable appeal a denied request. We do not discriminate for valid privacy requests.
California
If and when SomedayMade is subject to the CCPA, California residents may have rights to know/access, delete, correct, opt out of sale/sharing, limit certain uses of sensitive personal information, and non-discrimination. SomedayMade currently states it does not sell/share data for cross-context behavioral advertising and does not use photographs for facial recognition.
Security
We use access controls, private tokenized links, restricted database access, encrypted transport and reasonable security measures. No internet service can guarantee absolute security.
Terms of Service
SomedayMade is a personalized digital birthday-gift service. Friends answer questions and the service creates a group Future Fingerprint. After payment and required consents, the adult recipient may upload their own photo and request an AI-generated fictional future film.
Eligibility
Private beta is 18+. Do not use the film flow for a minor.
Price and payment
Current beta offer: $9.99 USD for the U.S. offer and €9.99 EUR for the EU offer. The exact total, tax treatment and payment method are shown by Stripe before payment. No auto-renewing subscription is offered in this beta.
AI content
The film is creative fiction, not a prediction, professional advice, factual profile or guarantee. AI outputs may contain imperfections. Artificial/manipulated origin is disclosed.
Photo permissions
Only the adult recipient may provide the reference photo. By uploading, the recipient confirms the right to use it and consents to processing described below. Organizers/contributors must not upload another person’s face.
Acceptable use
Do not impersonate, harass, defame or deceive; submit images without authorization; create illegal/exploitative content; violate IP/privacy/publicity rights; bypass security; or use the service for identity verification, surveillance or high-impact decisions.
Consumer rights
Mandatory consumer protections are not waived by these terms. Spanish law governs without depriving consumers of mandatory protections of their habitual-residence jurisdiction where applicable.
Legal Notice (Spain / LSSI)
Trade name: SomedayMade
Owner: Borys Bondarenko
Status: self-employed (autónomo), Spain
NIF/NIE: Y9723504S
Professional/business address: Calle Huelva 7, 06C, 29640 Fuengirola, Málaga, Spain
Email: borman2@ukr.net
If a specific public registration or prior administrative authorization becomes legally applicable to this activity, its identifying details will be added here.
Refund & Withdrawal Policy
EU/EEA distance-contract consumers generally have a 14-day withdrawal period unless a legal exception applies. For digital content supplied without a tangible medium, loss of the withdrawal right after performance begins requires, where applicable, prior express consent to begin during the withdrawal period, acknowledgement of the resulting loss of the right, and required confirmation.
SomedayMade rule: payment alone is not treated as a silent waiver. Before paid generation begins during an applicable withdrawal period, the product flow must obtain the legally required purchaser consent/acknowledgement for immediate performance. The recipient separately consents to image processing.
If a paid film cannot be generated or delivered after the permitted retry because of a service/provider technical failure, the Consensus and Future Fingerprint remain available and SomedayMade provides a full refund for the gift. During the private beta the refund may be reviewed and issued manually. The exact immediate-performance consent accepted before EU checkout is versioned and stored; after a successful purchase it is queued for confirmation to the buyer on a durable medium (email).
AI & Image Processing Notice
The adult recipient may upload their own selfie, which is sent to an AI provider as a visual reference for fictional scenes. The result may resemble the recipient and is labeled as AI-created/manipulated fictional content.
We do not intentionally use facial recognition for identification/authentication, compare faces against a database, create a searchable biometric database, or infer sensitive traits such as race, health or emotion from the face.
Before generation, the recipient confirms age 18+, right to use the photo, and consent to AI processing/provider transfer. If a biometric-specific law applies to a processing step, SomedayMade will obtain any additional notice/consent/release and apply required retention/destruction restrictions before enabling that processing.
Our current architecture is designed not to persist the source selfie in the application database after forwarding it for generation. Provider-side temporary processing/retention follows provider configuration/contracts. Generated assets may be retained for delivery/support. We do not sell facial images or biometric identifiers.
AI-generated/manipulated output is disclosed as artificial/fictional content to support applicable transparency requirements, including EU synthetic/deepfake-content rules.