Curating gifts...
Curating gifts...
Last reviewed: August 1, 2026
This policy describes the current HelpFindGifts source contract. It does not, by itself, prove that a production database, identity provider, email provider, analytics service, or backup policy is deployed or operating correctly. Production behavior remains unverified until a deployed environment is tested and attested.
The implemented contract does not write recipient names, private preferences, constraints, dates, notes, or outcomes to public search indexes, public pages, analytics events, or Baldwin Industries Hub projections. HelpFindGifts does not currently expose profile-sharing grants. A future collaboration feature would require a separate, purpose-limited consent and revocation contract.
Essential browser storage may be used for sign-in continuity and privacy choices. Optional analytics and advertising must remain disabled without the applicable choice. Recipient-memory fields are outside the analytics and advertising payload contract. The presence of provider configuration in source does not establish that a provider is active in production.
A governed affiliate handoff stores an opaque one-time intent and a privacy-free terminal receipt. Its source contract does not store your IP address, referrer, user agent, account identity, recipient details, search text, or session identifier in the affiliate intent or receipt. The merchant you choose to visit operates under its own privacy terms after the redirect.
Signed-in users can review and correct individual profiles, download a portable JSON export, delete outcome feedback, delete individual profiles, remove all recipient memory from the primary store, or create a structured access, export, correction, deletion, or restriction request. Deleting a profile also detaches it from future private personalization. Structured requests use a 30-elapsed-day internal service target; this is not a claim about a legal deadline.
Open the private privacy dashboardRecipient-memory rows remain in the primary store until you delete them or a later published retention rule removes them. The implemented deletion path hard-deletes the selected primary records and stops their use in future recommendations. This source does not verify the retention or expiry behavior of deployed backups or external providers, so no fixed production deletion timeline is promised here.
Minor profiles must be created and managed by the signed-in guardian. The source contract rejects adult age bands for those profiles and does not permit outcome aggregation, advertising personalization, public indexing, or Hub projection from minor profile data.
The repository includes field encryption, owner-scoped row policies, same-origin mutation checks, bounded request bodies, private no-store responses, and focused privacy tests. Those controls reduce risk; they are not a guarantee of absolute security and do not substitute for deployment verification or an independent assessment.
Use the private dashboard to create a structured request without entering free-form private details. For a question that does not fit that workflow, use the encrypted contact form. This policy explains product behavior and available controls; it is not a claim of legal certification.