Draft for legal review. This document is a working draft prepared for Wishfold's launch and has not yet been reviewed by counsel. It may change before the app is publicly released.
Privacy Policy
On this page
Wishfold (“we”, “us”) makes animated personal greeting cards. This policy explains what we collect when you use the Wishfold app and website (wishfold.in), why we collect it, how long we keep it, and the choices you have. It applies to senders (people with an account who create cards), recipients (people who open a card link, no account needed) and people in your vault (contacts a sender saves so we can remind them of dates).
1. What we collect
| Category | Examples | Who it concerns |
|---|---|---|
| Account | Name, email or phone number, sign-in provider (Google, Apple, phone OTP), locale, country | Senders |
| Card content | Occasion, tone, recipient name, your answers to prompts, the generated and edited text, photos, voice notes, stickers, template choice | Senders; recipients (as the subject of the card) |
| Vault | Names, relationship, birthday, anniversary, notes you add about people you send cards to | Senders and the people they add |
| Delivery & reactions | When a card was sent, opened, reacted to (❤️ 😂 😭 🥰) and any reply text (≤ 500 characters) | Senders and recipients |
| Device & usage | Push token, device platform, app version, crash reports, product analytics events (e.g. card_sent, card_opened), coarse IP-derived country | Senders; recipients (web page only, minimal) |
| Purchases | Plan, purchase and renewal events from the app stores or Razorpay. We never see full card numbers. | Senders |
| Waitlist | Email or phone number you submit on wishfold.in | Anyone who signs up |
Recipients do not need an account. When you open a card link we process the card slug, your browser's user agent and IP address (for rate limiting and abuse prevention), and the reaction or reply you choose to send. We do not set advertising cookies. The card page uses local storage only to remember that you already reacted.
2. Why we use it (purposes and legal bases)
- To provide the service — create, store, deliver and display your cards; send reminders you asked for; sync your vault. Contract.
- To generate card text with AI — see section 3. Contract / consent.
- To notify you — push notifications about reactions, scheduled sends and vault reminders. You can turn these off in the app or your OS. Contract / consent.
- To bill you — process subscriptions and single-card purchases through Apple, Google or Razorpay. Contract / legal obligation.
- To keep Wishfold safe — rate limiting, abuse and fraud prevention, security logging. Legitimate interests.
- To improve the product — aggregated analytics on how features are used. We do not sell personal data and do not use it for third-party advertising. Legitimate interests; consent where required.
3. AI processing
Wishfold drafts card text using a large language model provided by Anthropic (Claude). To do this we send the occasion, tone, relationship, language, the names you entered and your answers to the prompts to the model. We do not send your photos or voice notes to the AI provider. Prompts and responses are processed under Anthropic's commercial API terms, which do not permit training on customer data. We cache drafts by a hash of the input so identical requests are not re-sent. You can always edit or discard a generated draft; the text is only stored when you save the card.
4. Who we share it with
- Recipients — everything you put in a card, plus your display name, is visible to anyone who has the card link.
- Processors — Supabase (database, storage, authentication; hosted in the region shown in the app), Vercel (web hosting), Anthropic (AI drafting), RevenueCat and Razorpay (payments), PostHog (product analytics), Google Firebase and Apple (push notifications), MSG91 (SMS, only if you opt in to recipient SMS).
- Legal — if required by law, court order or to protect the rights and safety of users.
We do not sell personal data.
5. How long we keep it
- Card media (photos, voice notes) is encrypted at rest and deleted 90 days after the card is sent, unless you choose to save the card to your account. Card text remains in your inbox until you delete it.
- Card links stop working when the media is purged or when you delete the card.
- Account data is kept while your account is active. When you delete your account (Settings → Privacy → Delete my data, or by emailing us) we delete your profile, cards, vault, media and tokens within 30 days. Payment records are retained as required by tax and accounting law.
- Reactions and replies are kept with the card they belong to.
- Analytics is retained for up to 12 months in identifiable form, then aggregated.
- Waitlist entries are deleted within 90 days of public launch or on request.
6. Your rights
India — Digital Personal Data Protection Act, 2023
As a Data Principal you have the right to access a summary of your personal data and the processing we do, to correct or erase it, to withdraw consent, to nominate a person to exercise your rights if you are unable to, and to have your grievances addressed. Wishfold is the Data Fiduciary. Write to privacy@wishfold.in; we respond within 30 days. If you are not satisfied you may complain to the Data Protection Board of India.
European Economic Area & UK — GDPR
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your local supervisory authority. Where we rely on legitimate interests, you can object and we will stop unless we have compelling grounds.
Everyone
In-app: Settings → Privacy lets you export your cards and delete your account. Recipients who want a card about them removed can email us with the card link; we will contact the sender and remove the card where appropriate.
7. Children
Wishfold is for people aged 13 and over (16 where local law requires a higher age for consent to data processing). We do not knowingly collect data from younger children. If you believe a child has created an account, contact us and we will delete it.
8. Security
Data is encrypted in transit (TLS) and at rest. Media lives in a private storage bucket; recipient pages access it through short-lived signed URLs. Access to production data is limited to staff who need it. No system is perfectly secure; if we learn of a breach affecting you we will notify you and the relevant authority as the law requires.
9. International transfers
Our processors may store data outside your country, including in the United States and the EU. Where required we rely on Standard Contractual Clauses or equivalent safeguards.
10. Changes
We will post any changes here and, for material changes, notify you in the app. The “last updated” date at the top tells you when this policy last changed.
11. Contact
Wishfold · privacy@wishfold.in. Grievance Officer (India) and EU/UK representative details will be published here before launch.