Privacy Policy

Last updated July 10, 2026

1. What we collect

Account data: your email address and the identity provided by your sign-in method (Google, Apple, or email), your handle, display name, bio, and any avatar image you upload. Content: the wishes you save (titles, notes, links, images), lists, likes, sends, friendships, and reports you file. Preferences: settings like language, currency, theme, and reminder preferences. Payment status: whether you have an active Plus entitlement. Card details are handled entirely by our payment processors (RevenueCat/Stripe on the web, Apple on iOS) and never touch our servers. Profile views: when you're signed in and open someone's public page, we record your account id and the time of your last visit with that profile, so the owner can see how many unique accounts viewed their list. The owner sees counts, never who visited. Basic technical data: error reports.

2. What's visible to whom

Wishes are private by default to guests and visible only to you. Wishes marked friends are visible to accepted friends. Wishes marked public, plus your handle, display name, bio, avatar, and chosen theme, appear on your public page for anyone with the link, and public wishes can appear in the community Explore feed. Your email is never public.

3. How we use data

To run the product: syncing your list across devices, rendering public pages, delivering sends between users, powering Explore, showing you stats about your own list (unique visitors, saves, your yearly recap), processing Plus entitlements, moderating reported content, and fixing crashes. For speed and offline use, a copy of your own data is also cached on your device and can be cleared by clearing your browser's site data. We do not sell your data, show ads, or track you across other websites.

4. Who processes it

Wishlet runs on Google Firebase (authentication, database, file storage, cloud functions, all Google Cloud). Subscriptions run through RevenueCat, with payments handled by Stripe (web) or Apple (iOS). Error reporting uses Sentry. Link previews are fetched server-side from the URL you paste (sometimes via the r.jina.ai rendering service). These providers process data only to provide their service to us.

5. Blocking, reporting, and moderation

When you report content, the report (including your account id and any note) is visible to our moderation team. When you block someone, the block is stored on your account and is not shown to the blocked user. Moderation actions are recorded in an internal audit log.

6. Data retention and deletion

Your data is kept while your account exists. You can delete your account yourself at any time from the account page (or inside the iOS app): this permanently deletes your profile, handle, wishes, lists, friendships, sends, likes, uploaded images, and blocks. Residual copies leave backups within 30 days. You can also delete individual wishes and images at any time, or email us for help.

7. Your rights

Depending on where you live (GDPR, CCPA, and similar laws), you may have rights to access, correct, export, or erase your personal data, and to object to certain processing. Most of these are self-service in the app; for anything else, email us and we'll respond within 30 days.

8. Children

Wishlet is not directed at children under 13 (or the local minimum age of digital consent), and we don't knowingly collect their data. If you believe a child is using Wishlet, contact us and we'll remove the account.

9. Changes

If this policy changes materially we'll give notice in the app or by email before the change takes effect.

10. Contact

support@wishlet.io. We're happy to answer anything about your data.