❉ wishesSign inMake one

privacy

What we keep, and for how long

Last updated 18 September 2026

Sending a card needs an account. Opening one needs nothing. There are no cookies. This page lists everything we hold, who else sees it, and when it is deleted.

What we hold

Your accountA confirmed email address, a name if you provided one, and a cryptographic hash of your password (never the password itself).
DraftsAn unfinished card started before sign-in stays in your browser's local storage, then saves against your account once you sign in. A draft has no public link until you publish it.
Your wordsThe page you picked and everything you typed into it. Anyone holding the link can read it.
PhotosUp to three, on cards that accept them. Your browser resizes and re-encodes them to WebP before upload, which strips camera metadata including GPS location. They are stored in our database beside the card, never on a public bucket or third-party CDN, and are deleted with it.
A recipient's email addressOnly if you asked us to send the link. Used for that one email and kept in a send log attached to the card.
A hash of your IPA salted SHA-256, never the address. Used only in rate-limiting counters for actions taken while signed out. It cannot be reversed, is never stored on the card, and is wiped after 24 hours. Once you are signed in, limits are tied to your account ID instead.
A hash of a recipient's addressA salted SHA-256, so one inbox cannot be sent an unlimited number of cards in a day. It is a 24-hour counter, not a list, and holds no record of who sent what.
PaymentsIf a card is charged for, an order record: the amount, its status, and the gateway's reference. We never see or store your card or UPI details.
OpensWhen the card was first opened and how many times it has been fetched. Both are shown to whoever sent it.
Their replyThe button outcome and up to five written replies, capped at 400 characters each. These appear on your page as they are sent.

What we do not collect

No scroll depth, no mouse movement, no device fingerprint, no session recording. No cookies: signing in stores a token in your own browser, which this site sends back deliberately on each request. The recipient signs in to nothing. The unique link is the whole of their access, which is why it can expire.

When it is deleted

You choose the lifetime when you make the card: one to three days, one by default. At expiry the page stops answering for everybody, and deleting it does the same at once.

An automated sweep runs every six hours and hard-deletes anything that expired more than seven days ago, so there is a grace window, after the card is unreachable, where the data still exists on disk. Photos, replies, and send logs go with the card. Drafts do not expire on their own; delete them from your dashboard whenever you like.

Rate-limiting counters clear after 24 hours. Reports are the exception: if someone reports a card we keep the report details (the card’s ID, the reason, and a contact if they gave one) even after the card is gone.

Who else sees any of it

There are no advertising tags, no social pixels, and no third-party widgets.

Analytics, in full

PostHog records a page view and a short named event when an action happens: a template was opened, a card was published, or a link was copied. An event can carry which template it was, how many photos, how many days it was set to live, and whether something failed. That is the whole vocabulary. It never carries:

It stores a random ID in local storage, not a cookie, so two page views in one visit count once. Signing out clears it. If your browser sends a Do Not Track header we do not start at all, and blocking it costs you nothing on this site. The file is analytics.js, served unminified.

What the recipient sees about you

A from-label you chose from a short fixed list. Not your name, not your email address, not your IP. If you want them to know it was you, say so in the card.

What you can do

Everything you have made is on your dashboard at /wishes: check replies, resume drafts, edit a published card on the same link, extend its lifetime by one to three days, and delete it. Deleting takes the card out of your account and stops the link; the row is kept only until the next sweep clears it, with its photos and replies. Losing a link does not lock you out, and you can reset a forgotten password from the sign-in page.

To ask what a specific card holds, or for anything you cannot do from your own page, write to hello@wishes.app with the link or your account address.

Closing your account

Write to hello@wishes.app from the address on the account. We delete the account, your drafts, and any live cards with it, which takes those pages down for anyone holding the link.

Children

This is not built for children and is not intended for anyone under 16.

Changes

If what we keep changes, this page changes with it and the date at the top moves.