Skip to content
Wishco
How it works Gift helper FAQ
Get the app →

Privacy

Privacy policy

Effective 17 August 2026 · Wishco is operated by Increment Loop d.o.o.

Contents

  1. Who we are
  2. What we collect
  3. Why, and on what basis
  4. Analytics and crash reporting
  5. Who we share it with
  6. Where your data goes
  7. How long we keep it
  8. Your rights
  9. Age
  10. Security
  11. Changes
  12. Complaints

Wishco is a wishlist app. To run it we hold your account details and the lists you make. This page says exactly what that means — what we collect, why, who else sees it, and how to get it back or have it erased.

Who we are

The controller of your personal data is:

Increment Loop d.o.o.
Vitezova Karađorđeve Zvezde 50, 11050 Belgrade, Serbia
Registration number 21826324 · Tax ID 113221699

We trade as Wishco. For anything in this policy — including a request to see, export or delete your data — write to privacy@wishco.app.

What we collect

Your account

Your email address and password (stored only as a bcrypt hash — we never see or store the password itself). If you sign in with Apple or Google we store which provider you used and the identifier they give us, instead of a password.

Your first and last name, your country, and your preferred currency. Optionally, a profile picture, your gender, and your date of birth — these three are genuinely optional, and the app works fully without them. We use gender and age band to pick which cover-art styles to suggest for your wishlists; that is the only thing they do.

What you put in the app

Your wishlists and the wishes in them: titles, prices, links, images and notes. When you paste a product link we fetch that page to read its title, price and image, and we keep a record of the link. Who you have shared a list with, and which wishes have been claimed by someone else.

Gift Helper

If you use the Gift Helper quiz we store your answers, the resulting profile, and — if you choose to share a result card — a shareable copy of that result.

Technical

Sign-in tokens, password-reset tokens, and ordinary server logs including your IP address. We use IP addresses to rate-limit abusive traffic; we do not build a profile from them.

We do not collect any special category data — nothing about health, beliefs, politics, or sexual orientation. We do not buy data about you from anyone, and we do not sell or rent your data to anyone.

Why, and on what basis

Under the GDPR we have to tell you our lawful basis for each thing we do. Ours are:

WhatWhyLawful basis
Account, wishlists, wishes, sharing, claims To provide the app you signed up for Performance of a contract (Art. 6(1)(b))
Gift Helper answers and results To generate and save your gift profile Performance of a contract (Art. 6(1)(b))
Gender and age band To suggest cover-art styles. Optional, and you can remove them at any time. Consent (Art. 6(1)(a)) — you choose whether to give them
Password reset and other service email To let you back into your account Performance of a contract (Art. 6(1)(b))
Rate limiting, abuse prevention, server logs To keep the service up and resist attacks Legitimate interests (Art. 6(1)(f)) — running a secure service
Analytics Not collected. This version of the app records nothing about how you use it. —
Crash reporting To find and fix crashes Legitimate interests (Art. 6(1)(f)) — an app we cannot see crashing is one we cannot repair

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time — see Your rights. Where we rely on consent, you can withdraw it at any time, and doing so does not affect anything done before you withdrew it.

Analytics and crash reporting

We do not collect product analytics. This version of the app does not record which screens you open or which actions you take. There is nothing to switch on and no question to answer, because there is nothing being collected.

"Off" here means off in the operating system's copy of the software, not merely off in our code: analytics collection is disabled in the app's build configuration, so it is inert from the moment the app launches, and disabled again explicitly when the app starts, which covers devices that were carrying an older setting.

Questions about how the service is doing — how many people have signed up, how many wishlists exist — we answer from our own database. That involves no third party and no record of your individual behaviour.

We do not use advertising. There are no ad networks in the app, we do not build advertising profiles, we do not share data for advertising, and on iOS we do not ask for tracking permission because we do not track you across other companies' apps or websites.

Crash reporting

We do use Firebase Crashlytics, so that a crash which hits you also reaches us. It records what the app was doing when it stopped working, your device model and operating system version, and an app installation identifier. It is not linked to advertising and is not used to profile you.

We rely on our legitimate interest in keeping the app working (Art. 6(1)(f)) rather than asking for your consent, because an app that crashes without telling us is one we cannot repair. You can object to this at any time: in the app, go to Settings > Support & Legal > Crash reports and turn the toggle off — this stops new crash reports from your device. You can also write to us — see Your rights — and ask us to delete crash data already collected.

Who we share it with

We share your data with the companies that run parts of our service for us. Each is bound by a contract that only lets them use it to provide that service to us. They are:

WhoWhat they handleWhere
NeonOur main database — everything described aboveEU (Frankfurt)
KoyebRuns our servers; sees requests and IP addressesEU (Frankfurt)
CloudflareImage storage, this website, and network protectionEU / global
OneSignalSends service email such as password resetsUnited States
Google (Firebase)Analytics and crash reportingUnited States
Apple, GoogleSign in with Apple, Sign in with GoogleUnited States
ScrapFlyHelps read product pages that block us directlyUnited States

We also share your data where the law requires it, and we would share it with a buyer if the business were ever sold — in which case we would tell you first.

Sharing you control: when you share a wishlist, the people you share it with see the list, its contents, and your first name. When you share a Gift Helper result card, anyone with that link can see the card. Those are the point of the feature, but they are still your data leaving your hands — share deliberately.

Where your data goes

Your account and your lists are stored in the European Union. Some of the services above are based in the United States, so some data is transferred outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses, and where applicable by the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards at privacy@wishco.app.

How long we keep it

WhatHow long
Your account and its contentsUntil you delete it
After you delete your accountInaccessible immediately, permanently erased within 30 days
Server logsUp to 30 days

When you delete your account it becomes inaccessible straight away, and the sign-in tokens, share links and notification registrations tied to it stop working at the same moment. The data itself is permanently erased within 30 days. That delay is a cooling-off period before irreversible work, not a recovery window: there is no way to restore a deleted account, and signing up again with the same address creates a new, empty one.

Your rights

You can ask us to:

  • Show you what we hold about you (Art. 15).
  • Correct anything wrong (Art. 16). Most of it you can edit yourself in the app.
  • Delete your account and data (Art. 17). You can do this yourself in the app.
  • Export your data in a portable format (Art. 20).
  • Restrict or object to processing based on legitimate interests (Arts. 18 and 21).
  • Withdraw consent for analytics, or for the optional profile fields, at any time.

Write to privacy@wishco.app and we will answer within one month. There is no charge. We may ask you to confirm you are who you say you are — that is to stop someone else getting your data, not to slow you down.

Age

Wishco is intended for people aged 16 and over, and the app is not directed at children. We do not ask for your date of birth at sign-up and we do not knowingly collect personal data from children.

If you believe someone under 16 has an account, tell us at privacy@wishco.app and we will delete it.

Security

Passwords are hashed with bcrypt and never stored in a readable form. Traffic between the app and our servers is encrypted with TLS. Access to production data is limited to people who need it. No system is perfectly secure, but if a breach ever affects your data we will tell you and the supervisory authority as the law requires.

Changes

When we change this policy we update the effective date at the top. If a change materially affects you — new categories of data, a new purpose, a new recipient — we will tell you in the app or by email before it takes effect, rather than quietly editing this page.

Complaints

If we have got something wrong, tell us first at privacy@wishco.app — we would rather fix it.

You also have the right to complain to a data protection authority. In Serbia that is the Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti. If you are in the EU or the UK you may complain to the authority where you live, where you work, or where you think the problem happened.

This policy is published at https://wishco.app/privacy.

Wishco

Wishlists worth sharing.

How it works Gift helper FAQ Support Privacy Terms Get the app

No app yet? Shared links and the gift helper work in any browser.

© 2026 Wishco · Made by Increment Loop Back to top ↑