Privacy Policy
Last updated: 21 September 2026
Giftyr is a gift wishlist app built around keeping a surprise intact. This policy explains what we collect, why, how long we keep it, and what you can do about it. It covers both the app and giftyr.app.
Who we are
Giftyr is operated by Johannes Meißner, the controller for your data under the GDPR. You can reach us at contact@giftyr.app; the imprint has our full details and the support page is the fastest route for anything practical.
What the app collects
Your account. When you sign in with Apple we store the account identifier Apple gives us, your display name, and your email address if you choose to share it rather than hide it. Apple decides what to pass on; we never see your Apple ID password.
What you create. Wishes, occasions, circles and their memberships, notes, prices, links, and any photos you upload. This is the content the app exists to hold.
Reservations. When someone reserves or marks a gift as bought, we store that against their account so they can see their own reservations. The person an occasion's gifts are for never learns who reserved what — that restriction is built into the database and the API, not just hidden in the interface. There is one deliberate exception: on an occasion you create for someone else, everyone taking part sees who is giving what, because the person being surprised is not there. That includes anyone holding the share link — the page is not restricted to invited people, so whoever the link reaches, or is forwarded to, sees the same attribution. The terms of service explain that case.
Notification tokens. If you turn on notifications, we store the push token Apple issues for your device, along with the platform and whether it is a test or production token. This is what lets us send a reminder; it is deleted with your account, and turning notifications off stops us using it.
Product analytics. The app uses TelemetryDeck for anonymous usage counts — which screens get used, which features people reach. TelemetryDeck receives no name, email or IP address. Any identifier we send is hashed twice: once on your device before it is transmitted, and again on TelemetryDeck's servers. You can switch this off entirely (see Your choices).
Crash and error diagnostics. The app uses Sentry to report crashes and errors so we can fix them, including the device model, OS and app version. Sentry also receives your Giftyr account identifier, so that repeated crashes can be recognised as affecting one person rather than many. That identifier is not your name or email, but it is tied to your account, and we would rather say so plainly than describe this as anonymous.
What the website collects
Waitlist. If you sign up, we store your email address and a one-way HMAC-SHA256 hash of your IP address. The hash is used only to rate-limit abuse and cannot be reversed to identify you. You get a confirmation email and one message when the app launches.
Reserving from a share link. If you reserve a gift from a shared wishlist without installing the app, we store the email address and display name you enter, plus an IP hash, so we can send you the confirmation link and show the reservation as yours when you come back.
This also creates a Giftyr account for you. Reserving by email sets up an account against that address, with a profile holding the display name you gave — that is what lets the reservation be yours, survive the confirmation link, and still be there if you install the app later. You are not asked to choose a password and nothing is charged, but an account exists from that point and it holds your email and display name. If you would rather it did not, email contact@giftyr.app and we will delete it; installing the app and signing in with the same address gives you the in-app deletion route described below.
Page counts. We count anonymous events on the share pages — that a page was opened, that a reservation was completed. These are counts and timestamps only: no identifier, no wish, no link token, nothing that ties an event to a person.
We use no advertising trackers and no third-party analytics cookies anywhere on giftyr.app.
Where your data is held
App data is stored by Supabase in the European Union (eu-west-1, Ireland). The website runs on Cloudflare's network, and the waitlist and share-link records live in a Cloudflare D1 database. Some of our processors are outside the EU; where that is so, transfers rely on the European Commission's Standard Contractual Clauses.
Why we are allowed to do this
- To provide the service you asked for (Art. 6(1)(b)) — your account, your content, reservations, share links.
- Our legitimate interest (Art. 6(1)(f)) — crash diagnostics, so the app works; IP hashing, so the forms cannot be abused.
- Your consent (Art. 6(1)(a)) — push notifications, product analytics, waitlist email. You can withdraw any of these at any time, without affecting what came before.
How long we keep it
- Your account and content — until you delete your account, which removes it immediately (see below).
- Crash and error reports — retained by Sentry on its standard retention period, currently 90 days.
- Analytics — aggregate counts with no identifier, kept indefinitely; there is nothing in them to attribute to you.
- Waitlist — until you unsubscribe, which deletes your address immediately, or until the launch email has been sent and the list is no longer needed.
- Share-link reservations made without an account — the email address and display name you entered are deleted 30 days after the confirmation link is used or expires. The Giftyr account that reserving created is not deleted automatically; email us and we will remove it.
- Backups — encrypted backups may briefly contain data you have deleted, and are overwritten on our provider's rolling backup cycle.
Your choices
- Analytics — turn off in the app under Profile → Privacy. Nothing further is sent.
- Notifications — turn off under Profile → Notifications, which stops us sending them. Turning them off in iOS Settings stops your device showing them, but does not by itself remove the push token we hold; that is deleted when you delete your account, or on request.
- Waitlist — use the unsubscribe link at the foot of any waitlist email. That deletes your address rather than just flagging it.
Deleting your account
In the app: Profile → Privacy → Delete account. This is immediate and cannot be undone. It removes your account, your wishes, occasions, circles, uploaded images and notification tokens, and revokes the Sign in with Apple authorisation you gave us.
One thing deliberately survives: if you reserved a gift on someone else's wishlist, that reservation stops being linked to you but the gift stays marked as taken. If it flipped back to available, the others giving gifts could work out that you had left — which would undo the privacy the app is built to protect.
If you cannot reach the app, email contact@giftyr.app and we will delete your account for you. Deleting your data lists every route, including for people who reserved a gift without installing the app.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, a portable copy, restriction of processing, and you can object to processing based on legitimate interest. Write to contact@giftyr.app and we will respond within 30 days.
You also have the right to complain to a supervisory authority. In Germany that is the data protection authority for the state where you live.
Children
Giftyr is not directed at children. You must be 16 or older to create an account, and we do not knowingly collect data from children directly. Wishes for a child are kept by their parent or guardian on that adult's own account.
Who else processes your data
- Supabase — database, authentication and file storage, hosted in the EU. supabase.com/privacy
- Cloudflare — serves giftyr.app and holds the waitlist and share-link records. cloudflare.com/privacypolicy
- Apple — Sign in with Apple and push notification delivery. apple.com/legal/privacy
- Sentry — crash and error diagnostics. sentry.io/privacy
- TelemetryDeck — anonymous product analytics. telemetrydeck.com/privacy
- Resend — sends our confirmation and notification emails. resend.com/legal/privacy-policy
Changes
We will update this page if anything material changes, and the date at the top will tell you when. If a change materially affects your rights we will tell you in the app or by email before it takes effect.