YOUR WORDS, YOUR CHOICE
Privacy at WishPop
What is stored
Your sign-in name, password hash, recovery-code hash, cards, and replies voluntarily sent to you are stored on the server. Plaintext passwords and recovery codes are not stored. A necessary session cookie keeps you signed in.
Only the signed-in card owner can retrieve their dashboard and submitted replies through the app. The service operator and hosting/database providers may have access to stored data. This is not end-to-end encrypted messaging.
Card links
Anyone holding a full birthday link can view that card. Share it with the intended recipient and avoid including sensitive information. Deleting a card from your dashboard also deletes its stored reply and disables that link.
Recipient wishes and answers
Your typed birthday wish and selected answer stay in the current browser page until you choose “Send my reply.” “Keep it private” sends neither. Preview mode does not send replies.
Hosting and fonts
Hosting providers may process connection details such as IP addresses and service logs. Fonts are requested from Google Fonts, which receives connection information. WishPop does not add advertising or analytics trackers.
Your choices
You can skip writing a wish, keep a reply private, or delete a card you created. Signing out removes your current session. Losing both your password and recovery code prevents account recovery.