Who we are.
Given is built and operated by Superbigcompany LLC, a company based in Brooklyn, New York with a working studio in Seoul. When this policy says "we," "us," or "Given," it means Superbigcompany LLC, doing business as Given. We're the data controller for the information described here. Our parent site is superbigcompany.com.
For any privacy question, write to hello@mygiven.app. A real person reads every email.
EU and UK representative.
Given is offered in the European Economic Area and the United Kingdom. Under Article 27 of the GDPR and Article 27 of the UK GDPR, we have appointed a designated representative in the EU and the UK. Until the representative's contact details are listed here, you can reach us — and have your request forwarded to the representative — at hello@mygiven.app with the subject line "EU representative" or "UK representative." We acknowledge each request within seven days.
What we collect.
We try to collect as little as possible, and only what each part of Given actually needs to work. Here's the full list, by surface.
On the website (mygiven.app).
- Gift checkout — your name, email, and the recipient's birth details (date, time, place) so we can build the gift chart. Card details go directly to Stripe; we never see or store your full card number.
- Waitlist and product updates — if you join the waitlist, ask for your archetype by email, or otherwise sign up to hear from us, we store the email address you give us in our own database so we can send you product updates and let you know when Given opens. These are sent through our email provider (Resend), and every message includes a one-click unsubscribe link; you can opt out at any time.
- App-link text message — if you ask us to text you a link to the app, we pass the phone number you enter to our SMS provider (Twilio) to send that one message. We do not store your phone number; we keep only a short-lived hashed value to prevent repeat texts, and that is not linked to your identity.
- Server logs — our host (Fly.io) processes standard request metadata such as IP address, user agent, path, response status, and timestamp for security and uptime.
In the Given app (iOS and Android).
- Account data — your name (or chosen display name), email or Apple/Google sign-in identifier, and the password reset token if applicable.
- Birth chart inputs — your date of birth, time of birth, and place of birth. These are required to calculate your saju.
- Saved people — when you add someone for a compatibility reading, we store the birth details you enter for them: their name (or label), date of birth, time of birth, sex or gender, and birth place (city, and where supplied, its longitude and time-zone offset). This is information about another person, entered by you; only add it when you have their consent. Adding someone already on Given instead links to their existing profile.
- Invites and referrals — when you invite someone to compare charts, we create an invite link with a unique token and, if you provide one, the recipient's email address to send the invitation. We record when an invite is accepted, so we can connect the two accounts.
- Profile photo — if you add an avatar, the image you upload is stored on Cloudflare R2 and linked to your profile. It's optional and you can remove it at any time.
- Blocked users — if you block another Given member, we keep a record of that choice so we can hide the two of you from each other.
- Ask and chat conversations — the questions and messages you send in Ask are saved to your account so your conversation history is there when you return, and are sent to our AI provider to generate each answer (see "How we share it").
- Reading feedback — if you tell us a reading felt accurate or off, we store that response, tied to the reading, so we can improve.
- App usage — your daily readings, your subscription status, and your preferences.
- Purchase metadata — Apple or Google sends us the receipt and product identifier for any subscription or one-time purchase. We do not see your Apple ID, Google account, or payment method.
- Push tokens — only if you turn on notifications.
- Device + diagnostics — device model, OS version, app version, language, and time zone. Crash and diagnostic events are sent to a self-hosted error-tracking service (GlitchTip) that we operate ourselves, tagged with a pseudonymized (hashed) user identifier — no name, email, or IP address is attached. Basic in-app product events (for example, screen views and purchase outcomes) are recorded as diagnostic breadcrumbs with the same pseudonymization.
Why we collect it.
Each piece of data has a reason. Where the GDPR applies, the legal basis is in parentheses.
- Birth details, account data, and purchase metadata — to provide the service you signed up for (contractual necessity).
- Your readings and Ask answers are generated using AI — your birth details and the questions you ask are processed by our AI provider to produce them (contractual necessity).
- Waitlist emails and product update emails — because you asked to hear from us (consent).
- Server logs, crash logs, and abuse-prevention signals — to keep Given fast, stable, and safe (legitimate interest).
- Topics you raise in Ask — Given may use them to personalize your Today, Years, and compatibility readings. This stays within Given and is never shown to other users (legitimate interest; you can delete your Ask history at any time).
- Tax and financial records tied to a purchase — to comply with US and Korean tax and accounting law (legal obligation).
Sensitive data.
Your birth date, time, and place are at the heart of saju. We treat them as sensitive personal information. We use them only to compute and explain your chart and the readings you ask for. We do not use them to infer health, ethnicity, religion, or any other protected characteristic, and we do not sell or share them for advertising. Under California law you have the right to limit the use of your sensitive personal information; see "Your rights" below.
How we share it.
We use a short list of service providers. Each one only sees what they need.
- OpenRouter Inc. (US) — AI processing. Your birth details and your Ask and chat conversations are sent to OpenRouter and routed to Google Gemini models to generate your readings.
- Clerk — authentication: your name, email, and sign-in identity.
- Neon — Postgres database hosting.
- Fly.io — application hosting and Redis.
- Cloudflare R2 — profile photo storage.
- Expo — push notification delivery.
- Stripe — card payment for gift purchases on the website.
- Resend — email delivery, both transactional messages (such as gift receipts) and the product-update emails you sign up to receive.
- Twilio — sending the one-time app-link text message when you ask for it.
- Apple and Google — in-app purchases on iOS and Android.
We may also disclose information when we're legally required to (a valid subpoena, court order, or similar), to protect Given or its users, or in connection with a merger or acquisition. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
What other users can see.
Given has social features, and two of them are on by default. Both can be turned off at any time in the app under Settings → Privacy, and turning either off takes effect immediately.
- Profile discovery — other Given users can find you by searching your @handle or display name. A search result shows your display name, handle, profile photo (unless you've hidden it), and your day-master and archetype labels. It never shows your birth date or birth time.
- Anonymous compatibility readings — a user who finds your profile can generate a compatibility reading with you without being connected to you and without asking you first. They see only the reading Given writes about the pairing — never your birth date, birth time, or the underlying chart data. You may receive a notification that someone checked their compatibility with you. Users you've blocked can't find you or run readings with you.
Tracking and analytics.
Given does not engage in "tracking" as defined by Apple's App Tracking Transparency framework. We do not link your data with data from other companies' apps or websites for advertising or measurement, and we do not present the App Tracking Transparency prompt. The marketing site does not run Google Analytics, Meta Pixel, or any third-party advertising or analytics SDK.
Cookies and local storage.
The marketing site does not set advertising or analytics cookies. We use the minimum browser storage needed to keep the gift checkout working and to remember that you've dismissed a banner. The app stores your account session and your preferences locally on your device.
Children.
Given is built for adults. You must be at least 13 to use it (16 if you're in the European Economic Area or the United Kingdom). We do not knowingly collect personal information directly from children under those ages, and we do not run the Apple Kids Category.
If you enter a birth chart for a child — for example, a parent gifting Given to a kid, or a chart drawn for a young family member — that data is treated as your information about a third party. We do not create an account for the minor and we do not use the chart to profile them. If you're a parent or guardian and you believe a child has given us personal information directly, email hello@mygiven.app and we will delete it.
How long we keep it.
- Account and chart data — for as long as you have a Given account, then deleted within 30 days of account deletion.
- Waitlist and product-update email — stored until you unsubscribe or ask us to remove it, after which we delete it from our database.
- App-link phone number — not stored. The short-lived hashed value used to prevent repeat texts expires on its own shortly after the message is sent.
- Gift checkout records — for as long as needed to fulfill the gift, then trimmed.
- Receipts, invoices, and tax records — up to seven years, as required by US and Korean tax law, even after your account is deleted.
- Server logs — typically 30 days.
Security.
We encrypt traffic in transit with TLS and encrypt our databases at rest. Access to production systems is limited to Given's operator on hardware-backed keys. No system is unbreakable, but we treat your chart with the care it deserves and we tell you promptly if anything material happens.
International transfers.
Given's servers are in the United States. If you use Given from the European Economic Area, the United Kingdom, or another region, your data is transferred to and processed in the US. We rely on the European Commission's Standard Contractual Clauses with our processors that operate in the US, and we accept the protections of the EU–US Data Privacy Framework where our processors are self-certified.
Your rights.
Wherever you live, you can ask us to:
- tell you what we hold about you;
- correct it;
- delete it;
- export it in a portable form;
- stop using it for marketing;
- limit how we use sensitive parts of it.
To exercise any of these, email hello@mygiven.app. We respond within 45 days. We will never charge you or retaliate against you for asking.
If you live in California, the CCPA/CPRA gives you specific rights to know, delete, correct, opt out of sale or sharing (we do neither), and limit the use of sensitive personal information. We have not sold or shared personal information for cross-context behavioral advertising in the past twelve months.
If you live in the EEA, the UK, or Switzerland, the GDPR and UK GDPR give you the rights above plus the right to object, withdraw consent at any time, and lodge a complaint with your data protection authority.
Other US states — Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others with comprehensive privacy laws give you similar rights, and we honor them on the same email channel above.
Account and data deletion.
In the Given app, open Settings → Account → Delete account. Confirm the prompt and we kick off deletion immediately. You can also email hello@mygiven.app from the address on your account to request deletion.
When you delete your account, we purge your name, email, birth chart inputs, saved questions, readings, and push tokens from our active systems within 30 days. Receipts and tax records are retained for the legal periods listed above. Backups roll off within 90 days.
Changes to this policy.
When something material changes, we update this page and bump the effective date at the top. For larger changes — new categories of data, new processors, a new way the app behaves — we'll also tell you in-app or by email before the change takes effect.
Contact.
Questions, requests, or concerns: hello@mygiven.app. Postal mail can reach us at Superbigcompany LLC, Brooklyn, NY.