Skip to content
Wishco
How it works Gift helper FAQ
Get the app →

Privacy

Privacy policy

Effective 17 August 2026 · Wishco is operated by Increment Loop d.o.o.

Contents

  1. Who we are
  2. What we collect
  3. Why, and on what basis
  4. Analytics and crash reporting
  5. Who we share it with
  6. Where your data goes
  7. How long we keep it
  8. Your rights
  9. Age
  10. Security
  11. Changes
  12. Complaints

Wishco is a wishlist app. To run it we hold your account details and the lists you make. This page says exactly what that means — what we collect, why, who else sees it, and how to get it back or have it erased.

Who we are

The controller of your personal data is:

Increment Loop d.o.o.
Vitezova Karađorđeve Zvezde 50, 11050 Belgrade, Serbia
Registration number 21826324 · Tax ID 113221699

We trade as Wishco. For anything in this policy — including a request to see, export or delete your data — write to privacy@wishco.app.

What we collect

Your account

Your email address and password (stored only as a bcrypt hash — we never see or store the password itself). If you sign in with Apple or Google we store which provider you used and the identifier they give us, instead of a password.

Your first and last name, your country, and your preferred currency. Optionally, a profile picture, your gender, and your date of birth — these three are genuinely optional, and the app works fully without them. We use gender and age band to pick which cover-art styles to suggest for your wishlists; that is the only thing they do.

What you put in the app

Your wishlists and the wishes in them: titles, prices, links, images and notes. When you paste a product link we fetch that page to read its title, price and image, and we keep a record of the link. Who you have shared a list with, and which wishes have been claimed by someone else.

Gift Helper

If you use the Gift Helper quiz we store your answers, the resulting profile, and — if you choose to share a result card — a shareable copy of that result.

Technical

Sign-in tokens, password-reset tokens, and ordinary server logs including your IP address. We use IP addresses to rate-limit abusive traffic; we do not build a profile from them.

We do not collect any special category data — nothing about health, beliefs, politics, or sexual orientation. We do not buy data about you from anyone, and we do not sell or rent your data to anyone.

Why, and on what basis

Under the GDPR we have to tell you our lawful basis for each thing we do. Ours are:

WhatWhyLawful basis
Account, wishlists, wishes, sharing, claims To provide the app you signed up for Performance of a contract (Art. 6(1)(b))
Gift Helper answers and results To generate and save your gift profile Performance of a contract (Art. 6(1)(b))
Gender and age band To suggest cover-art styles. Optional, and you can remove them at any time. Consent (Art. 6(1)(a)) — you choose whether to give them
Password reset and other service email To let you back into your account Performance of a contract (Art. 6(1)(b))
Rate limiting, abuse prevention, server logs To keep the service up and resist attacks Legitimate interests (Art. 6(1)(f)) — running a secure service
Analytics To see which screens and pages are used and where people get stuck, in the app and on this website Legitimate interests (Art. 6(1)(f)) — improving a service you asked for; you can object at any time
Crash reporting To find and fix crashes Legitimate interests (Art. 6(1)(f)) — an app we cannot see crashing is one we cannot repair

Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time — see Your rights. Where we rely on consent, you can withdraw it at any time, and doing so does not affect anything done before you withdrew it.

Analytics and crash reporting

In the app

We collect product analytics. The app records which screens you open and which actions you take — creating a wishlist, adding a wish, sharing a list — so we can see where the app is confusing or broken. It is our own product we are measuring, not you across anyone else's.

This runs through Google's Firebase Analytics. It records an app installation identifier, your device model and operating system version, an approximate country derived from your network address, and the events above. Once you are signed in it is associated with your account, so that a session which begins before sign-up and continues after it reads as one person rather than two.

We rely on our legitimate interest in understanding and improving a service you asked to use (Art. 6(1)(f)). You can object at any time — see Your rights — and we will stop. We do not sell this data, we do not share it for advertising, and we do not combine it with data about you from anywhere else.

Questions about how the service is doing overall — how many people have signed up, how many wishlists exist — we answer from our own database. That involves no third party and no record of your individual behaviour.

We do not use advertising. There are no ad networks in the app, we do not build advertising profiles, we do not share data for advertising, and on iOS we do not ask for tracking permission because we do not track you across other companies' apps or websites.

Website analytics

This website is measured the same way the app is. Google Analytics records which pages you view, whether the Gift Helper is started and finished, and whether you click through to the App Store or Google Play. It is configured for measurement only, with every advertising feature turned off. It also records your device and browser type and an approximate country derived from your network address.

We rely on the same legitimate interest as for the app (Art. 6(1)(f)), and you can object at any time — see Your rights. If your browser sends the Global Privacy Control signal we honour it automatically. You can also opt out here — the choice is stored in this browser and applies from your next page load:

Crash reporting

We do use Firebase Crashlytics, so that a crash which hits you also reaches us. It records what the app was doing when it stopped working, your device model and operating system version, and an app installation identifier. It is not linked to advertising and is not used to profile you.

We rely on our legitimate interest in keeping the app working (Art. 6(1)(f)) rather than asking for your consent, because an app that crashes without telling us is one we cannot repair. You can object to this at any time: in the app, go to Settings > Support & Legal > Crash reports and turn the toggle off — this stops new crash reports from your device. You can also write to us — see Your rights — and ask us to delete crash data already collected.

Who we share it with

We share your data with the companies that run parts of our service for us. Each is bound by a contract that only lets them use it to provide that service to us. They are:

WhoWhat they handleWhere
NeonOur main database — everything described aboveEU (Frankfurt)
KoyebRuns our servers; sees requests and IP addressesEU (Frankfurt)
CloudflareImage storage, this website, and network protectionEU / global
OneSignalSends service email such as password resetsUnited States
Google (Firebase)Analytics and crash reportingUnited States
Apple, GoogleSign in with Apple, Sign in with GoogleUnited States
ScrapFlyHelps read product pages that block us directlyUnited States

We also share your data where the law requires it, and we would share it with a buyer if the business were ever sold — in which case we would tell you first.

Sharing you control: when you share a wishlist, the people you share it with see the list, its contents, and your first name. When you share a Gift Helper result card, anyone with that link can see the card. Those are the point of the feature, but they are still your data leaving your hands — share deliberately.

Where your data goes

Your account and your lists are stored in the European Union. Some of the services above are based in the United States, so some data is transferred outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses, and where applicable by the EU–US Data Privacy Framework. You can ask us for a copy of the safeguards at privacy@wishco.app.

How long we keep it

WhatHow long
Your account and its contentsUntil you delete it
After you delete your accountInaccessible immediately, permanently erased within 30 days
Server logsUp to 30 days
Analytics dataKept by Google Analytics for 14 months, then deleted or reduced to aggregate totals
Crash reportsKept by Google (Crashlytics) for 90 days

When you delete your account it becomes inaccessible straight away, and the sign-in tokens, share links and notification registrations tied to it stop working at the same moment. The data itself is permanently erased within 30 days. That delay is a cooling-off period before irreversible work, not a recovery window: there is no way to restore a deleted account, and signing up again with the same address creates a new, empty one.

Your rights

You can ask us to:

  • Show you what we hold about you (Art. 15).
  • Correct anything wrong (Art. 16). Most of it you can edit yourself in the app.
  • Delete your account and data (Art. 17). You can do this yourself in the app.
  • Export your data in a portable format (Art. 20).
  • Restrict or object to processing based on legitimate interests (Arts. 18 and 21).
  • Withdraw consent for analytics, or for the optional profile fields, at any time.

Write to privacy@wishco.app and we will answer within one month. There is no charge. We may ask you to confirm you are who you say you are — that is to stop someone else getting your data, not to slow you down.

Age

Wishco is intended for people aged 16 and over, and the app is not directed at children. We do not ask for your date of birth at sign-up and we do not knowingly collect personal data from children.

If you believe someone under 16 has an account, tell us at privacy@wishco.app and we will delete it.

Security

Passwords are hashed with bcrypt and never stored in a readable form. Traffic between the app and our servers is encrypted with TLS. Access to production data is limited to people who need it. No system is perfectly secure, but if a breach ever affects your data we will tell you and the supervisory authority as the law requires.

Changes

When we change this policy we update the effective date at the top. If a change materially affects you — new categories of data, a new purpose, a new recipient — we will tell you in the app or by email before it takes effect, rather than quietly editing this page.

Complaints

If we have got something wrong, tell us first at privacy@wishco.app — we would rather fix it.

You also have the right to complain to a data protection authority. In Serbia that is the Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti. If you are in the EU or the UK you may complain to the authority where you live, where you work, or where you think the problem happened.

This policy is published at https://staging.wishco.app/privacy.

Wishco

Wishlists worth sharing.

How it works Inside the app Gift helper FAQ Support Privacy Terms Get the app

Shared links and the gift helper work in any browser, any time.

© 2026 Wishco · Made by Increment Loop Back to top ↑