What Cake Day collects
Workspace-level data- Workspace ID and workspace name
- Bot tokens (encrypted at rest using application-level encryption — never stored in plaintext)
- Settings: celebration channel, post time, timezone, and custom AI tone prompt (Pro only)
- Slack user ID and display name
- Birth month and day (never the year)
- Work start date — year, month, and day (if provided)
- Opt-in / opt-out status
- Stripe customer ID, subscription tier, and usage count
- Stripe stores all card data directly — Cake Day never sees or stores card numbers
- Records of which shoutouts were posted or skipped, used for usage tracking and audit purposes
What Cake Day does NOT collect
- Your birth year
- Email addresses
- Message content or conversation history
- Profile photos
- Any data beyond what you explicitly provide
Data retention
AI and Google Gemini
Each shoutout is generated via a stateless call to the Google Gemini API — there is no persistent session and no shared context across workspaces. What Cake Day sends to Gemini per celebration:- The celebrant’s first-name handle (display name)
- Celebration type: birthday or anniversary
- Timing framing: today, tomorrow, or weekend-shifted
- Year count (for anniversaries only)
Deleting your data
As an individual member:- Run
/cakeday mein Slack and select Remove me entirely to permanently delete your roster entry - Click No thanks on an invite DM to decline being added
- Go to the Roster page → three-dot menu next to a member → Remove
- To delete all workspace data, uninstall Cake Day from Slack — all data is deleted within 30 days
Stripe billing records (customer ID, subscription history, invoice metadata) are retained for up to 7 years regardless of uninstall, as required by U.S. tax law. This is noted in the Privacy Policy.
Sub-processors
These are the services Cake Day relies on to operate:
Full sub-processor list: cakeday.io/sub-processors
Links
- Privacy Policy
- Terms of Service
- Security contact: info@cakeday.io

