YOUR WORDS, YOUR CHOICE

Privacy at WishPop

What is stored

Your sign-in name, password hash, recovery-code hash, cards, and replies voluntarily sent to you are stored on the server. Plaintext passwords and recovery codes are not stored. A necessary session cookie keeps you signed in.

Only the signed-in card owner can retrieve their dashboard and submitted replies through the app. The service operator and hosting/database providers may have access to stored data. This is not end-to-end encrypted messaging.

Card links

Anyone holding a full birthday link can view that card. Share it with the intended recipient and avoid including sensitive information. Deleting a card from your dashboard also deletes its stored reply and disables that link.

Recipient wishes and answers

Your typed birthday wish and selected answer stay in the current browser page until you choose “Send my reply.” “Keep it private” sends neither. Preview mode does not send replies.

Hosting and fonts

Hosting providers may process connection details such as IP addresses and service logs. Fonts are requested from Google Fonts, which receives connection information. WishPop does not add advertising or analytics trackers.

Your choices

You can skip writing a wish, keep a reply private, or delete a card you created. Signing out removes your current session. Losing both your password and recovery code prevents account recovery.