Who is responsible
Binary Data Technology operates WovenWish and is the controller of the information described here. For any privacy question, correction, or data request, write to binarydatatechnology151@gmail.com. We answer privacy requests from that inbox and will tell you what we need in order to verify that you control the account before we act on it.
You can use WovenWish without an account
The Android app works fully signed out. Occasions, wishes, prices, notes, priorities, archived items, and the 30-day Trash are stored only on your device, and we never receive them. Signing in is optional and exists solely so a verified owner can keep a private copy of their own lists in the cloud and recover them on another device.
What we collect when you sign in
- Account identity. Your email address, and a display name if your Google account provides one. We use it to authenticate you, to verify email ownership, and to contact you about your account.
- Your list content. Occasion names and dates, wish titles, product links you save, quantity, price and currency, priority, notes, and archive or Trash state. This is stored privately for you. It is not public, not sold, and not used to build advertising profiles.
- Operational records. Synchronization operations, content revisions, retry and idempotency records, and deletion job status, so that a lost connection cannot duplicate or silently drop your work.
- Security signals. A Firebase user ID, a Firebase installation identifier, and Google Play Integrity attestation, used to block automated abuse of the service. We do not collect an Advertising ID.
Photos stay on your device
A photo you attach to a wish is stored in app-private storage on your phone. In this release WovenWish does not upload, sync, moderate, or share item photos, and no other person can retrieve them through the service. Removing the wish or uninstalling the app removes the photo with it.
What we do not collect
WovenWish contains no advertising SDK and shows no ads. It does not collect location, contacts, calendar, health, financial account, or payment information. Analytics and crash reporting are switched off: we send no analytics events and receive no crash reports. A gift price you record is list metadata you typed, not a transaction.
Product links you save
When you save or share a retailer link into WovenWish, that link is treated as your own list content. If you are a verified signed-in owner, the app may fetch that page once to suggest a title, image reference, price, and currency, which you can accept or ignore. The service does not retain, return, or log the raw address after the lookup, and it does not follow you around the web or reconstruct your browsing history.
How reservations stay private
On the web, reservation records, availability, and giver identity are stored separately from owner-readable list documents, so an owner cannot see who reserved which item. A person who deliberately opens their own shared link as a guest cannot be technically distinguished from another unauthenticated giver.
Shared links
A shared link is an unlisted capability: anyone holding it can view the sanitized list and submit a bounded reservation, but cannot edit owner data. Owners can rotate, revoke, or expire a link. Shared pages are excluded from search indexing and suppress referrer data. Previews generated in the app contain only the list name and active wish titles; they exclude archived items, Trash, account details, and photos.
Who processes data for us
We use Google LLC as our service provider for Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, App Hosting, App Check, and Play Integrity. Google processes this information on our instructions in order to run the service. We do not sell personal information, and we do not share it with third parties for their own marketing. Data is processed on Google infrastructure in the European Union region europe-west4; if you use WovenWish from elsewhere, your information is transferred there under Google Cloud standard contractual protections.
Retailer links
Opening a retailer link takes you to that retailer, whose own privacy policy then applies. Affiliate link rewriting is disabled in this release and earns us nothing; if it is ever enabled, the interface will say so before you continue, and this policy will be updated first.
How long we keep information
Local content stays on your device until you delete it or uninstall the app. Trash content is recoverable for 30 days, then leaves active device and cloud item storage. For signed-in owners, private synchronization history may retain earlier item content until account deletion removes the owner tree. After a completed deletion we keep only a content-free marker recording that the account was deleted, so that delayed background work cannot recreate your data; it contains no list, item, photo, or message content.
Your choices and rights
You can export your data and delete your cloud account from Settings inside the app at any time. Deletion cascades through account data, shared projections, capabilities, reservations tied to deleted lists, and derived identifiers, with auditable job status. If you cannot reach the app, see the account deletion page. Depending on where you live you may also have rights to access, correct, port, or object to the processing of your information; write to binarydatatechnology151@gmail.com and we will respond.
Children
WovenWish is intended for adults and is not directed to children. We do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
If we change how we handle information, we will update this page and its effective date before the change takes effect, and we will describe material changes in the app release notes.