Privacy Policy
Last updated: 27 July 2026
Wishler is a social wishlist app. You keep a list of things you are hoping for, and friends can reserve a gift or chip in on one together. This page explains what that means for your data, in plain words and without hiding the parts that are less flattering.
Who runs Wishler
Wishler is built and operated by Gari Epranosyan, an individual based in Tbilisi, Georgia. For anything on this page — a question, a correction, a deletion request, a complaint — write to gepran@gmail.com.
Wishler is a small independent project, not a company with a privacy department. The upside is that the person who wrote the code is the person who answers the email.
What we collect
| Data | Where it comes from |
|---|---|
| Name, email address, profile photo | Your Google account, or the sign-up form |
| Handle, bio, city, birthday, phone number | Optional — only what you type into Edit Profile |
| Wishes, collections, photos and links you add | You |
| Reservations, chip-ins, comments, likes | Your activity, and other people's activity on your list |
| Who you follow and who follows you | You and them |
| Video greetings | Recorded by visitors to your profile, and shown only after you accept them |
| Push notification token, Telegram chat ID | Only if you turn those notifications on |
| Anonymous usage events | Only if you accept analytics — see below |
Reserving a gift or chipping in does not require an account. A guest who does either is given an anonymous identifier by Firebase so the app can tell one guest from another; it is not tied to a name or an email address, and it is what makes "you already reserved this" work on a return visit.
Why we are allowed to
If you are in the EEA or the UK, the GDPR asks us to name a legal basis for each use. Ours:
- Performing the service you asked for — your account, your wishes, reservations, chip-ins, follows, notifications you switched on. Without these Wishler cannot do the thing you opened it to do.
- Your consent — analytics and the advertising pixel, which load only after you say yes and stop the moment you withdraw it.
- Our legitimate interest — keeping the service secure and abuse-free, and the operator's alerts about new sign-ups and reports so a problem gets noticed.
What is public
If Settings → Public profile is on, your profile is readable by anyone at
/your-handle without signing in. A signed-out visitor sees your photo, name, bio,
wish titles, wish photos and funding progress. They do not see prices,
comments, or who reserved what.
Turning Public profile off makes that address stop resolving. Everything else — your list, your collections — is visible only to you and to signed-in people you have shared it with.
Who reserved a gift is never shown to the person who owns the wish. That is the point of the feature.
Public by link is not the same as public in search. Wishler asks search engines not to index profile pages, and the site tells them the only page worth indexing is the homepage. That is a request, which every major search engine honours, rather than a lock — a link you have given out can still be forwarded by whoever you gave it to.
Analytics, and the choice you are offered
Wishler uses two measurement tools, and neither of them loads until you accept them:
- Google Analytics 4, to see which steps of the app people complete and which ones they abandon.
- The Meta pixel, which is an advertising tool. It is what lets ads on Facebook and Instagram be measured against real sign-ups instead of against clicks.
What they receive is a short event name — that a wish was added, that a link was shared, that a
guest reserved something — plus counts and fixed labels like profile or
pot. No wish titles, prices, names, handles, emails or photos are ever
sent to either. Both set their own cookies and both can infer an approximate
location from your IP address, which is ordinary for tools of this kind and is the reason we ask
first.
Until you accept, not one byte is requested from Google or Meta. This is a genuine gate, not a notice printed over tracking that has already started: the vendor scripts are not fetched at all, so declining leaves you not merely untracked but unannounced.
You can change your answer at any time in Settings → Cookies & analytics. Declining costs you nothing — no feature is withheld, and you will not be asked again. If your browser sends a Do Not Track signal we treat that as a no and never show the banner at all.
What stays on your device
Wishler sets no cookies of its own. It uses your browser's localStorage, which
behaves like a cookie that is never sent to a server:
- Your AI provider key. If you connect Anthropic, OpenAI or Google Gemini in Settings, the key is stored in your browser and never sent to us. Requests go straight from your browser to that provider. Note that any script running on this site could read it — we say so rather than implying otherwise.
- Your analytics answer, so we do not ask twice.
- Your blocked list. Blocking controls what you see, in this browser. It does not hide your list from the person you blocked.
- Your language, theme and layout preferences.
Who else sees your data
Wishler is a small app standing on other people's infrastructure. These are all of them:
| Service | What it gets, and why |
|---|---|
| Google Firebase (Authentication, Firestore, Storage, Cloud Messaging) |
Your account, profile, wishes, reservations, chip-ins and uploaded photos. This is where Wishler's data lives. |
| OpenAI | When you paste a shop link or ask Wishler to fill in a gift by name, the gift name or the text of that public product page is sent to OpenAI to extract a title, price and description. Your identity is not sent with it. |
| Microsoft Bing | The gift name you are typing, when you ask for photo suggestions — that word alone, as a search query. |
| Telegram | Your chat ID and the reminder text, only if you connect the bot. |
| Google Analytics, Meta | Anonymous usage events, only after you accept. See above. |
| Content delivery networks (Google Fonts, jsDelivr, unpkg, Tailwind CDN) |
Fonts and code libraries are fetched from these, so they see your IP address and browser, as with any website that loads an external font. They receive nothing about you or your list. |
None of them are permitted to use your data for their own purposes, except Google and Meta within the analytics products you consented to. Nobody's data is sold, ever.
Where it is stored
On Google's servers, which may be outside your country — Firebase operates globally and Wishler does not pin a region. If you are in the EEA or the UK, that means your data may be transferred abroad; Google offers standard contractual clauses for exactly this. See Firebase's privacy documentation.
How long we keep it
| What | How long |
|---|---|
| Your profile, wishes and collections | Until you delete them, or delete your account |
| Video greetings | 24 hours, then deleted automatically along with the video file |
| Your activity feed entries | 7 days |
| Birthday reminder records | 60 days |
| Telegram sign-in links | 15 minutes |
| Cached product data from shop links | Up to 30 days, then re-fetched |
Money
Wishler does not process payments and never holds your money. A chip-in records what somebody pledged; the money itself moves directly between the people involved, by whatever means they arrange. We do not collect card or bank details.
Incognito mode
With incognito on, chip-ins are recorded as "Anonymous", profile visits are not recorded, likes and reserves are not added to your activity, and you are removed from the search directory. The substitution happens where the record is written, not when it is displayed — your real name is not stored and then hidden.
Your rights
- See your data. Nearly all of it is visible in the app: your profile, your wishes, your activity (Settings → Privacy), your gifts. For a copy of anything that is not, write to us.
- Correct it. Edit Profile, and the edit control on any wish.
- Delete it. Settings → Delete account removes your published profile, your wishes, your follow relationships and your sign-in credentials. This is immediate and cannot be undone.
- Withdraw consent. Settings → Cookies & analytics, at any time.
- Object or complain. Write to gepran@gmail.com. If you are in the EEA or UK you may also complain to your local data protection authority.
Some traces necessarily survive deleting your account, because they are other people's records rather than yours — a chip-in you made toward somebody else's gift stays on their pot as an anonymous contribution, since removing it would silently change what they were told had been collected.
Children
Wishler is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, write to us and it will be removed.
Changes
If this policy changes in a way that affects you, the app will say so. The date at the top always reflects the current version.