Who we are and what we process
Wishfox is operated by Ondřej Kandera, company ID 06824579, based in the Czech Republic. You can write to us at info@wishfox.app.
On your account we store your e-mail, name, username, avatar, cover image, bio, date of birth and language.
We also store the content you create: lists, items, comments, gift reservations, recipients and groups including Secret Santa.
We record your social connections: friendships, follows and blocks.
We store gift preferences such as clothing and shoe sizes or interests, along with the settings that control who can see them. The same goes for your e-mail settings.
We also keep technical data on your account: IP address, country, browser identification (user agent) and the time of your last sign-in and last activity. This data is not anonymous. It is tied to your account, so it can identify you.
If you create a list without registering, we store the name, IP address, country and user agent of the guest who created it.
If someone invites you to a group (Secret Santa) by link and you do not register, we store your name and e-mail.
When you write to support, we store the message, your name and your e-mail.
Purpose and legal basis
Performance of a contract: we run your account, lists, sharing and reservations, and send e-mails about what happens on your lists.
Legitimate interest: we protect the app against abuse and bots using Cloudflare Turnstile, we monitor errors and we measure aggregate traffic.
Consent: only for marketing e-mails. You can withdraw it at any time with one click.
Legal obligation: we hand over data only on a lawful request from an authorised body.
Beyond these cases we do not pass your data to anyone other than the processors listed below.
Processors
The application and the database run on Hetzner servers in Germany, inside the EU. We also use the processors listed below, each only for the purpose stated next to it.
Where a processor is based outside the EU, the transfer is covered by an adequacy decision (the EU-US Data Privacy Framework) or by standard contractual clauses.
We do not sell your data and we do not use it for third-party advertising.
| Processor | What it does | Data it receives | Location | Transfer safeguard |
|---|
| Cloudflare | Hosts the website, delivers it worldwide and protects forms against bots | IP address, request details, uploaded images | Global | EU-US Data Privacy Framework |
|---|
| Hetzner | Runs the application server and the database, in Germany | All account and content data | EU | Not needed |
|---|
| Sentry | Reports application errors so we can fix them | User ID, e-mail address, IP address, technical error details | USA | EU-US Data Privacy Framework |
|---|
| Better Stack | Collects server logs for security and troubleshooting | IP address, e-mail address, request details | EU | Not needed |
|---|
| Resend | Sends e-mail, both service messages and newsletters | Name, e-mail address | USA | EU-US Data Privacy Framework |
|---|
| Google (Gemini) | Generates gift suggestions | Interests, bio, gift preferences and item names, as described in the AI section | USA | EU-US Data Privacy Framework |
|---|
| Google, Apple, Meta | Signs you in, only if you choose that provider | Account ID, name, e-mail address | USA | EU-US Data Privacy Framework |
|---|
| ImageKit | Delivers and resizes images | Image address, viewer IP address | Global | Standard contractual clauses |
|---|
| Plausible Analytics | Measures aggregate traffic, without cookies and without cross-site tracking | Page address, referring site, rough country | EU | Not needed |
|---|
| Bright Data, scrape.do | Loads a product page when you paste a link, so we can fill in the item for you | The product address only | Global | Standard contractual clauses |
|---|
| Buy Me a Coffee, Ko-fi, Patreon | Handles donations and awards the supporter badge | Donor e-mail address | USA | EU-US Data Privacy Framework |
|---|
Cloudflare
- What it does
- Hosts the website, delivers it worldwide and protects forms against bots
- Data it receives
- IP address, request details, uploaded images
- Location
- Global
- Transfer safeguard
- EU-US Data Privacy Framework
Hetzner
- What it does
- Runs the application server and the database, in Germany
- Data it receives
- All account and content data
- Location
- EU
- Transfer safeguard
- Not needed
Sentry
- What it does
- Reports application errors so we can fix them
- Data it receives
- User ID, e-mail address, IP address, technical error details
- Location
- USA
- Transfer safeguard
- EU-US Data Privacy Framework
Better Stack
- What it does
- Collects server logs for security and troubleshooting
- Data it receives
- IP address, e-mail address, request details
- Location
- EU
- Transfer safeguard
- Not needed
Resend
- What it does
- Sends e-mail, both service messages and newsletters
- Data it receives
- Name, e-mail address
- Location
- USA
- Transfer safeguard
- EU-US Data Privacy Framework
Google (Gemini)
- What it does
- Generates gift suggestions
- Data it receives
- Interests, bio, gift preferences and item names, as described in the AI section
- Location
- USA
- Transfer safeguard
- EU-US Data Privacy Framework
Google, Apple, Meta
- What it does
- Signs you in, only if you choose that provider
- Data it receives
- Account ID, name, e-mail address
- Location
- USA
- Transfer safeguard
- EU-US Data Privacy Framework
ImageKit
- What it does
- Delivers and resizes images
- Data it receives
- Image address, viewer IP address
- Location
- Global
- Transfer safeguard
- Standard contractual clauses
Plausible Analytics
- What it does
- Measures aggregate traffic, without cookies and without cross-site tracking
- Data it receives
- Page address, referring site, rough country
- Location
- EU
- Transfer safeguard
- Not needed
Bright Data, scrape.do
- What it does
- Loads a product page when you paste a link, so we can fill in the item for you
- Data it receives
- The product address only
- Location
- Global
- Transfer safeguard
- Standard contractual clauses
Buy Me a Coffee, Ko-fi, Patreon
- What it does
- Handles donations and awards the supporter badge
- Data it receives
- Donor e-mail address
- Location
- USA
- Transfer safeguard
- EU-US Data Privacy Framework
How long we keep data
We keep account data for as long as the account exists.
When you delete your account we deactivate it and anonymise your e-mail immediately. We permanently remove the remaining records within 30 days.
We keep operational logs and security records for a limited time, so we can investigate security incidents.
You can delete your account yourself in your account settings.
Your rights
You have the right to access your data, to correct it, to erase it or to restrict its processing. You have the right to object, the right to data portability and the right to withdraw consent at any time.
You can do most of this yourself in your account settings. You can download your data there as JSON or CSV, and delete your account there too.
For anything else, write to us at info@wishfox.app.
You also have the right to complain to the Czech data protection authority, Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.cz.
Cookies
Wishfox sets no analytical or marketing cookies. Every cookie we use is either necessary for the service to work or remembers your language choice. That's why there's no cookie banner.
We run our analytics (Plausible) without cookies and without cross-site tracking. We measure aggregate traffic only.
The full list of cookies is in the table below.
You can block cookies in your browser, but signing in will then stop working.
| Name | What it is for | Category | Lifetime | Recipient |
|---|
| __Secure-auth | Keeps you signed in | Necessary | 30 days | Wishfox |
|---|
| __Secure-guest | Identifies you as the author of a list created without an account | Necessary | 360 days | Wishfox |
|---|
| __Secure-list_access | Remembers that you unlocked a protected list | Necessary | 7 days | Wishfox |
|---|
| twofa_challenge | Carries the second step of two-factor sign-in | Necessary | 5 minutes | Wishfox |
|---|
| googleState, googleCodeVerifier, facebookState, oauthIntent | Protects the social sign-in process against forgery | Necessary | 10 minutes | Wishfox |
|---|
| lang | Remembers your language choice | Preference | 1 year | Wishfox |
|---|
| main | Stores your profile so pages render signed in straight away | Necessary | 1 year | Wishfox |
|---|
| wishfox:api:* | Caches your lists in the browser so they open faster | Necessary | 1 day | Wishfox |
|---|
__Secure-auth
- What it is for
- Keeps you signed in
- Category
- Necessary
- Lifetime
- 30 days
- Recipient
- Wishfox
__Secure-guest
- What it is for
- Identifies you as the author of a list created without an account
- Category
- Necessary
- Lifetime
- 360 days
- Recipient
- Wishfox
__Secure-list_access
- What it is for
- Remembers that you unlocked a protected list
- Category
- Necessary
- Lifetime
- 7 days
- Recipient
- Wishfox
twofa_challenge
- What it is for
- Carries the second step of two-factor sign-in
- Category
- Necessary
- Lifetime
- 5 minutes
- Recipient
- Wishfox
googleState, googleCodeVerifier, facebookState, oauthIntent
- What it is for
- Protects the social sign-in process against forgery
- Category
- Necessary
- Lifetime
- 10 minutes
- Recipient
- Wishfox
lang
- What it is for
- Remembers your language choice
- Category
- Preference
- Lifetime
- 1 year
- Recipient
- Wishfox
main
- What it is for
- Stores your profile so pages render signed in straight away
- Category
- Necessary
- Lifetime
- 1 year
- Recipient
- Wishfox
wishfox:api:*
- What it is for
- Caches your lists in the browser so they open faster
- Category
- Necessary
- Lifetime
- 1 day
- Recipient
- Wishfox
AI features
For gift suggestions we use the Gemini model from Google.
It works in two modes. Suggestions for yourself: you start them, and only your own content goes to the model.
Suggestions for a giver are started by someone else: a confirmed friend who is looking at your list and searching for a gift for you. At that moment we send the model your interest profile, your bio, their note about you, your gift preferences if you made them visible, and the names of your recent items. So your data can go to the AI even when you did not start the feature.
Only a confirmed friend can start it. A stranger who merely has a link to a shared list cannot.
We never send passwords or payment details to the model.
We store only the number of tokens used, never the text of the request or the response.
AI output is indicative only and can be wrong. Always check it.
Changes to this policy
We update this policy from time to time. We publish changes on this page, and for significant changes we notify registered users by e-mail. The date of the last update is at the top.
Copyright complaints are handled separately, on the copyright page.