WishDesk
Privacy Policy
Overview
WishDesk is a personal wishlist app. You can use it locally on a single device, or create an account to sync your lists across devices. We collect the minimum data needed to make the app work and we never sell personal data.
This policy describes what data WishDesk processes, why, for how long, and how you can review or delete it. It applies to the WishDesk iOS app and any WishDesk web page you visit at WishDesk-controlled URLs.
Data we process
| Category | Purpose | Stored where |
|---|---|---|
| Email address | Account login, password reset, transactional support emails | Supabase Auth (cloud account holders only) |
| Wishlist content (names, items, links, prices, images, notes, tags, status, favorites) | Showing your saved wishes and syncing them across devices | Local storage; Supabase Postgres if signed in |
| Public lists you publish in the Hub | Discovery for other users; aggregated likes/saves/opens | Supabase Postgres; visible to anyone using the Hub |
| Price history | Showing the price trend for items you saved | Local storage; Supabase Postgres if signed in |
| Push notification token | Delivering price-drop alerts you opted into | Supabase Postgres until you sign out or delete the account |
| Anonymous open counts | Trending ranking on the public Hub (no per-user attribution) | Supabase Postgres (aggregated only) |
Reading product pages
When you paste a product link, WishDesk fetches that public web page once to read what it can show in the wishlist card — title, image, price, brand, store. This happens through our hosted scanner service or, when available, your device's network stack. We do not log the page bodies and we do not share the link with third parties for advertising.
Some stores block automated reads. In those cases, the card stays editable and you can fill the fields manually.
Sharing and disclosure
WishDesk does not sell personal data and does not run third-party advertising. The technical services we rely on to deliver the app are:
- Supabase — authentication, database, storage, edge functions, push token delivery.
- Apple Push Notification Service (APNs) — delivering price-drop alerts you opted into.
- Optional store-scrape providers — when configured, the scanner may delegate fetches for stores that block direct access. Only the URL you pasted is sent.
We disclose data when required by law, with valid legal process, or when needed to protect the safety of users.
Retention
Local data stays on your device until you remove it from the app or uninstall the app. Cloud data linked to your account is kept while your account is active. When you delete your account, your wishlists, items, price history, alerts and push tokens are removed from our systems within 30 days. Backup snapshots used for disaster recovery are rotated within 90 days.
Your rights
Under GDPR (EU), LGPD (Brazil), CCPA (California) and similar laws, you can request:
- Access — a copy of the personal data we have linked to your account.
- Correction — fix any inaccurate data.
- Deletion — remove your account and the data linked to it. The fastest path is the in-app "Delete account and data" flow described at /delete-account.
- Portability — your wishlists exported as CSV from the app at any time (Profile → Export CSV).
- Withdraw consent — turn off push notifications and sign out at any time.
To exercise any of these rights, write to the contact email below. We will respond within 30 days.
Children
WishDesk is not directed at children under 13 and we do not knowingly collect data from anyone under 13. If you believe a child has provided personal data, contact us and we will delete it.
Security
Cloud data is transmitted over HTTPS and stored encrypted at rest on Supabase. We rely on Supabase Row Level Security policies so each account can only access its own data. No system is perfectly secure: please choose a strong password and contact us if you suspect any incident with your account.
Updates to this policy
We may update this policy as the app evolves. We will change the "Last updated" date above and, when changes affect how we use your data, we will surface a notice in the app the next time you sign in.
Contact
Support and privacy requests: [email protected].
WishDesk is run by an individual developer based in Brazil. Email is the official channel; we do not have a phone line.
Resumo em portugues
O WishDesk pode ser usado localmente ou com conta para sincronizar wishlists entre dispositivos. Coletamos apenas o necessario para o app funcionar (email da conta, wishlists, links de produtos, historico de preco, token de notificacao). Nao vendemos dados, nao usamos para publicidade. Voce pode acessar, corrigir, exportar (CSV) ou apagar seus dados a qualquer momento pelo proprio app ou escrevendo para [email protected]. A exclusao da conta remove wishlists, itens, historico de preco, alertas e tokens em ate 30 dias.
Resumen en espanol
WishDesk puede usarse localmente o con cuenta para sincronizar wishlists entre dispositivos. Recolectamos solo lo necesario para que la app funcione (email de la cuenta, wishlists, enlaces de productos, historial de precio, token de notificacion). No vendemos datos ni los usamos para publicidad. Puedes acceder, corregir, exportar (CSV) o eliminar tus datos en cualquier momento desde la app o escribiendo a [email protected]. La eliminacion de la cuenta retira wishlists, items, historial, alertas y tokens en hasta 30 dias.