← Santa’s InternYOUR INFORMATION

A little care for
your information.

What the gift finder uses

Your description, budget, optional occasion, needed-by date, roast style, gift replacement request, and follow-up answer are sent through our server to Google Gemini to generate a roast and gift ideas. We do not need a social login. A name is optional. The labeled sample works without sending a description to Gemini.

Optional social profile lookup

If you analyze an Instagram, TikTok, X, Facebook, or LinkedIn profile, we send its link or username to Apify to attempt to read public information. When available, we analyze public profile text and up to six recent public posts (LinkedIn uses the About section). Instagram may also use up to three post images with Google Gemini to suggest gift interests. You receive an editable description based on those interests. Check the person and sources, remove anything that does not fit, and add your own details before choosing “Roast them. Find gifts.” We do not request social passwords or account access, read private posts, or fetch friends lists or messages. Availability depends on what each network exposes publicly.

The generated draft becomes part of the description saved in your tab for up to 24 hours, including your edits. Source excerpts stay in the page’s memory until you refresh or clear the tab, and in a temporary server receipt for up to 10 minutes. Gift generation uses the description you review and submit. We attempt to delete each completed Apify run and its default storage after processing. If a network interruption prevents cleanup, provider records may remain subject to Apify’s retention settings. Apify and Google process the data under their respective service terms. We do not store downloaded post images in our database or include them in the share card.

What stays in this tab

Your latest brief, result, and request-recovery information are saved in this tab’s session storage for up to 24 hours. Refreshing or visiting this page keeps them. “Start over & clear this tab” removes that local information. Closing the tab normally clears it; browser session restoration can restore it until its expiry. Creating a court link is a separate action. Clearing this tab does not remove an already shared case; use Remove this case.

Server processing and temporary recovery

The roast finder does not save descriptions to a database. A completed result can stay in the web server’s memory for 10 minutes to recover a repeated request without making another AI call. Expired entries are removed on the next gift request or when the server restarts. Cancelling stops your browser waiting; the bounded AI request may finish and remain available for that recovery period.

An essential, random session cookie lasts up to one hour and supports request recovery and usage limits. It contains no description or name. We record aggregate token counts and general error categories, not the submitted description, result text, or API key. Google processes the submitted text as the AI provider; its handling is governed by the terms of the configured Gemini API service.

Roasts and sharing

Roasts are comic exaggerations inspired by the details you provide. They are not personality assessments. Saving a roast creates an image in your browser with the roast text, name when included, original artwork, and branding. Gift suggestions, your budget, and the full brief are left out. A saved image can include a QR code to your case if you have created a link. Nothing is posted automatically.

Shared cases and appeals

Creating a share link saves the displayed name, edited roast, reactions, defense, and Santa’s ruling in our database. Anyone with that unlisted link can view and respond; it is not confidential. Your original brief and profile sources are never included. Gift ideas and budget are saved separately from the public court record so the browser that created the case can return to its recommendations after a reply. They are only returned to that browser, identified by its court cookie; recipients and other visitors cannot see them. They expire with the case and are erased when it is removed or hidden. Amazon catalog details are shown for less than 24 hours from their check time, then removed on subsequent court activity; the generated ideas and search links remain. Cases stop being available after 30 days. Expired records are removed on subsequent court activity. A creator can remove a case, and a person with an unwanted roast link can hide it for everyone. Removal immediately erases the case text and replies; service records may remain until expiry. Other people may retain screenshots or platform previews already shared.

Publishing a summons uses a short local list of blocked explicit words, without sending it to an AI service for approval. The same word check applies to defenses. Rejections log only the matched blacklist word, without the submitted text or identity. When someone submits a defense, the shared roast and defense go to Google Gemini to write Santa’s short fictional ruling. Pending defenses are private to the submitting browser until the ruling is ready. A failed request preserves the draft for one explicit retry. The random court session cookie lasts 30 days and lets this browser manage its cases and recover its defense. Losing that cookie loses creator access; no account or cross-device identity is required.

Optional reply notifications

If you choose “Notify me when they reply” and allow your browser’s permission request, we save its push subscription endpoint and encryption keys with your court browser session for up to 30 days. Notifications cover new guilty pleas and completed defenses on summons created by that session. They contain a general reply message and case link, not names, roast text, defenses, budgets, or gifts. Your browser’s push service processes delivery; notification display also depends on your device settings. There are no promotional push messages.

You can turn notifications off in My cases → Notification settings or your browser settings. We remember dismissing the optional notification offer in local browser storage for seven days, and show it at most once per tab session. Turning them off in My cases deletes the saved subscription and pending deliveries for it. Expired subscriptions are removed during later court notification activity. Delivery receipts are kept until the case or subscription expires or is removed; delayed delivery attempts stop after 24 hours. Our service worker handles notifications only and does not cache private pages or gift results. Without notifications, you can check My cases or receive a reply link shared by the other person.

Measuring what works

First-party events record pseudonymous browser sessions, funnel steps, gift direction, whether a link is a product or search, marketplace, timing, and case relationships. They exclude descriptions, roast text, defenses, social handles, and credentials. The local event records are retained for up to 30 days and removed on subsequent court activity. We honor browser Do Not Track and Global Privacy Control signals. Sharing attempts and Amazon clicks do not prove delivery or purchase; purchases and commissions are reported separately by Amazon.

Our Weblinker (PN2) analytics service at api2.santasintern.com also receives page views, button and link clicks, and these funnel steps. A random first-party cookie, _t_sid, lasts up to 90 days to connect visits from the same browser. Campaign and advertising click identifiers are kept for the tab session so later steps can be attributed to the visit. We also keep a general source category, such as search, AI search, or direct, and the public landing page for that tab session. These help us understand which guides lead to useful gift suggestions. We remove private case identifiers, unrelated URL parameters, and URL fragments before sending page addresses. We do not send input values, recipient names, visible button text, or shopping search terms. The analytics service records the browser and device information, screen dimensions, IP address, approximate location, and referring origin with events in our BigQuery analytics dataset. These analytics records are separate from the local 30-day event store.

Shopping links and estimated prices

When a recent Amazon price is available, it is labeled with its check time; otherwise prices are AI estimates. Amazon links search for product terms and a budget range. We also send generic product terms and your budget to Amazon’s Creators API to find product links; we do not send your full brief. Found products are options to review, not guarantees of suitability. Check current prices, delivery, suitability, and the final total at the retailer. Amazon has its own privacy practices. See our Amazon affiliate disclosure.

Back to the gift finder