Policies & legal information

Last updated: 24 September 2026

Privacy Policy

Summary. SomedayMade is an adult-only private beta. Friends answer questions about a recipient’s possible future. The recipient — not the organizer — uploads their own photo if they choose the AI film. We do not sell personal information or use it for cross-context behavioral advertising.

Controller and scope

SomedayMade is operated by Borys Bondarenko, self-employed (autónomo), Spain. Privacy contact: borman2@ukr.net. This notice covers the website, invitations, Future Fingerprint, reveal and AI-film beta. The private beta is intended for adults 18+.

Information we process

  • Gift IDs, occasion/recipient information, friends’ questionnaire answers, contributor technical/device identifiers and timestamps.
  • Recipient consent records, locale/region and the recipient’s own photo when film generation starts.
  • AI-generated frames, video scenes and final outputs.
  • Payment status, amount, currency and transaction references; Stripe handles card details.
  • Technical/security logs, IP/network information, diagnostics and support communications.

Sources

Some data comes from you. Some future-scenario information about the recipient comes from the organizer and contributors. It is subjective gift content, not a factual assessment.

Purposes and EEA/UK legal bases

PurposeTypical basis
Deliver gift, Future Fingerprint and paid filmContract / requested pre-contract steps
Process recipient’s own photo for AI generationInformed user action/consent where required, and contract where appropriate; not used for identification
Security, abuse prevention, debuggingLegitimate interests balanced against user rights
Tax, accounting, fraud and legal complianceLegal obligation / legal claims where applicable

AI and facial images

The photo is a visual reference for fictional scenes. We do not intentionally create a face-recognition template, identify/authenticate the person by face, infer race/health/emotion from the face, or build a searchable face database. If a jurisdiction treats a particular step as biometric processing, additional required notice/consent/retention rules will apply.

Providers and international transfers

Key providers include Supabase (backend/database/storage), Runway (AI media), Stripe (payments) and Netlify (hosting). Information may be processed in the EEA, UK, U.S. and other provider locations. Where required for EEA/UK transfers to non-adequate countries, SomedayMade will use an available lawful mechanism such as Standard Contractual Clauses and supplementary safeguards.

Retention

Data is kept only as reasonably necessary for delivery, security, support, accounting and law. The current architecture is designed not to intentionally persist the source selfie in the SomedayMade application database after it is forwarded to the AI provider. Provider-side retention follows provider configuration/contracts. Face-bearing intermediate scene videos are deleted as soon as the recipient's device successfully assembles the final film. If that completion signal is not received, SomedayMade runs a daily cleanup: intermediate scenes are normally deleted after 7 days and in all cases are scheduled for deletion no later than 30 days, subject only to a legal preservation obligation. The source selfie is not intentionally persisted in the SomedayMade application database after it is forwarded to the AI provider. Consent/payment records may be retained longer to demonstrate compliance or meet accounting/legal duties.

EEA/UK rights

Where GDPR/UK GDPR applies, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. In Spain the authority is the AEPD. Requests: borman2@ukr.net.

U.S. state privacy rights

We do not sell personal information or share it for cross-context behavioral advertising. Where an applicable state law grants rights, you may request access/confirmation, correction, deletion, portability, opt-out of sale/targeted advertising/certain profiling, and where applicable appeal a denied request. We do not discriminate for valid privacy requests.

California

If and when SomedayMade is subject to the CCPA, California residents may have rights to know/access, delete, correct, opt out of sale/sharing, limit certain uses of sensitive personal information, and non-discrimination. SomedayMade currently states it does not sell/share data for cross-context behavioral advertising and does not use photographs for facial recognition.

Security

We use access controls, private tokenized links, restricted database access, encrypted transport and reasonable security measures. No internet service can guarantee absolute security.

Terms of Service

SomedayMade is a personalized digital birthday-gift service. Friends answer questions and the service creates a group Future Fingerprint. After payment and required consents, the adult recipient may upload their own photo and request an AI-generated fictional future film.

Eligibility

Private beta is 18+. Do not use the film flow for a minor.

Price and payment

Current beta offer: $9.99 USD for the U.S. offer and €9.99 EUR for the EU offer. The exact total, tax treatment and payment method are shown by Stripe before payment. No auto-renewing subscription is offered in this beta.

AI content

The film is creative fiction, not a prediction, professional advice, factual profile or guarantee. AI outputs may contain imperfections. Artificial/manipulated origin is disclosed.

Photo permissions

Only the adult recipient may provide the reference photo. By uploading, the recipient confirms the right to use it and consents to processing described below. Organizers/contributors must not upload another person’s face.

Acceptable use

Do not impersonate, harass, defame or deceive; submit images without authorization; create illegal/exploitative content; violate IP/privacy/publicity rights; bypass security; or use the service for identity verification, surveillance or high-impact decisions.

Consumer rights

Mandatory consumer protections are not waived by these terms. Spanish law governs without depriving consumers of mandatory protections of their habitual-residence jurisdiction where applicable.

Refund & Withdrawal Policy

EU/EEA distance-contract consumers generally have a 14-day withdrawal period unless a legal exception applies. For digital content supplied without a tangible medium, loss of the withdrawal right after performance begins requires, where applicable, prior express consent to begin during the withdrawal period, acknowledgement of the resulting loss of the right, and required confirmation.

SomedayMade rule: payment alone is not treated as a silent waiver. Before paid generation begins during an applicable withdrawal period, the product flow must obtain the legally required purchaser consent/acknowledgement for immediate performance. The recipient separately consents to image processing.

If a paid film cannot be generated or delivered after the permitted retry because of a service/provider technical failure, the Consensus and Future Fingerprint remain available and SomedayMade provides a full refund for the gift. During the private beta the refund may be reviewed and issued manually. The exact immediate-performance consent accepted before EU checkout is versioned and stored; after a successful purchase it is queued for confirmation to the buyer on a durable medium (email).

AI & Image Processing Notice

The adult recipient may upload their own selfie, which is sent to an AI provider as a visual reference for fictional scenes. The result may resemble the recipient and is labeled as AI-created/manipulated fictional content.

We do not intentionally use facial recognition for identification/authentication, compare faces against a database, create a searchable biometric database, or infer sensitive traits such as race, health or emotion from the face.

Before generation, the recipient confirms age 18+, right to use the photo, and consent to AI processing/provider transfer. If a biometric-specific law applies to a processing step, SomedayMade will obtain any additional notice/consent/release and apply required retention/destruction restrictions before enabling that processing.

Our current architecture is designed not to persist the source selfie in the application database after forwarding it for generation. Provider-side temporary processing/retention follows provider configuration/contracts. Generated assets may be retained for delivery/support. We do not sell facial images or biometric identifiers.

AI-generated/manipulated output is disclosed as artificial/fictional content to support applicable transparency requirements, including EU synthetic/deepfake-content rules.

Cookie Notice

The current landing page does not intentionally set advertising cookies, cross-site behavioral trackers or optional audience-analytics cookies. Hosting/infrastructure providers may process ordinary server request logs for security and delivery. External providers such as Stripe may use their own cookies under their own policies.

If non-essential analytics/advertising technology is added later, this notice will be updated and consent controls will be added before activation where EU/UK law requires consent.