Privacy
What wishlist keeps about you, who can see it, what the Chrome extension and AI connections do with it, and how to have it deleted. Plain words on purpose.
Last updated 2026-09-09.
What we keep
Only what you give us, and only so the app works.
- Your account: the email address you signed up with and, if you set a password, a hash of it. We never store the password itself.
- If you sign in with Google: the account id and email address Google hands us. Nothing else from your Google account.
- Your profile: whatever you choose to fill in. Display name, bio, pronouns, photo, birthday, sizes, brands and colours you like, how you like to receive gifts, what you already own and what you don’t want, allergies and dietary needs, and a delivery address. Every field is optional.
- Your wishlist: each item’s name, link, notes, photo, size, category, priority, and who may see it.
- Your circle: who is in it, the requests and invites you sent or received (including the email address of anyone you invited), the nudges between you, and any item you reserved on someone else’s list.
- Housekeeping: reminder settings, which onboarding steps you finished, the notifications we showed you, and anything you typed into the feedback button.
Photos are re-encoded before they are stored. That strips the data a phone writes into the file, including where the picture was taken.
Who can see what
- Your username, pronouns, and photo are public. Anyone with the link to your page can see them, signed in or not, and anyone can find your page by searching for your username.
- Every other profile field, and every wishlist item, has its own switch: public, or circle only. Circle only means the people you have accepted into your circle and nobody else. Other people see your birthday as a month and a day; the year stays with you.
- Reservations are hidden from you on purpose. When someone in your circle reserves an item on your list, the rest of your circle can see it’s taken, never by whom, and you see nothing at all.
- Nudges are anonymous unless the sender chooses to sign them.
The Chrome extension
The extension does one thing: it saves something you spotted on a shop page to your own list.
- It reads a page only when you ask, with a click on its button, its keyboard shortcut, or its right-click menu, and only the tab you did that in. It has no permission to read pages on its own.
- What it reads is the product: the name, picture, price, and link. That goes to your wishlist account at
api.wishlist.fitand nowhere else. - It signs in with the same cookie the website set when you signed in there. It never sees your password, and it keeps no copy of anything you save.
- The only things it remembers are its own settings: which server to talk to and the visibility you picked last time. Chrome may sync those between your devices, as it does for any extension.
- Pick mode, the outline it draws over a grid of products, and the right-click menu run only in the tab you used them in. Pick mode removes itself as soon as you pick a tile or press Esc.
- It has no analytics, and it sends nothing to anyone but your own account.
AI assistants
You can connect Claude, ChatGPT, Codex, or any other app that speaks MCP. You sign in to wishlist and approve it, and from then on it can do what you can do on the site: read your profile and wishlist, including circle-only fields; look up other people’s pages the same way you can; add, change, and delete items on your own list; and send or accept circle invites. It cannot change anyone else’s list, and it cannot see anything you couldn’t.
The sign-in for this goes through WorkOS AuthKit, which issues the token the assistant holds. We tell WorkOS your account id and email so the token names you and nobody else. What the assistant then does with what it reads is between you and that assistant, under its own privacy policy.
To disconnect one, remove the connector inside that app. It stops asking from then on. The grant behind it runs out on its own, and we can’t end it early from our side.
Who we share with
Nobody buys your data, and nothing here is for advertising. These are the services that touch it so the app can run:
- Google, for sign in with Google. Google tells us your email address and account id. The sign-in also shows us your Google name and picture, which we don’t keep.
- Google Cloud runs the site, the API, and the database, in its Singapore region, and stores uploaded photos. A photo’s address is a long random name nobody can guess, but anyone who has the address can open it, so a photo isn’t protected by the circle-only switch the way text is.
- Resend delivers our email: circle invites and requests, nudges, and the reminders you turn on. Resend sees the address and the message, as any mail service does.
- WorkOS handles the sign-in for AI assistants, as above.
- Hugging Face hosts the model behind gift ideas. Ideas run in your own browser: the model (about 2 GB) is downloaded from Hugging Face once and kept in your browser’s cache, and nothing you type in the interview leaves your device, not to us and not to them. The download itself shows Hugging Face your IP address, as any download does.
- Anthropic. Feedback you send through the feedback button is read by us, and also by a planning routine we run on Anthropic’s Claude that turns feedback and usage counts into improvement proposals. Keep anything private out of feedback.
Analytics
We count what people do in the app ourselves. No analytics company is involved, and the site loads no third-party scripts, ad pixels, or fingerprinting.
The site sends our own API the name of what happened (page_view, login_succeeded, feedback_sent, and so on), the page it happened on, the time, and a random id kept in your browser’s storage (wl_anon_id) so one visit hangs together. When you’re signed in, the event is tied to your account. On the first page of a visit it also records which site sent you, as a hostname only, never the full address.
Cookies: one, the sign-in cookie (wishlist_session), which lasts seven days. A second, short-lived one protects Google sign-in while it happens and is gone within ten minutes.
Deleting your data
From the site you can delete any wishlist item, clear any profile field, remove anyone from your circle, and turn reminders off. Each takes effect at once.
There is no button yet to delete a whole account. To have yours removed, send a request through the feedback button while you’re signed in, so we know which account you mean. We delete the account and everything attached to it: profile, wishlist, circle links, photos, and events.
Two things we can’t take back: an email that has already gone out, an invite say, and anything someone saved from your page while it was public.
Questions
Ask through the feedback button on any page. This page changes when the product does, and the date at the top moves with it.
