Your information
Privacy Policy
Hushful is built for thoughtful sharing without spoiling surprises. This policy explains what information we collect, why we use it, and the choices you have.
Effective September 10, 2026Age eligibility
Hushful requires a complete birthday during account setup so it can derive an age range for safety controls. The birthday audience is your choice: only you, friends, or everyone who can view your profile. Hushful does not display your birth year or age to other users.
Who this policy covers
This policy applies to the Hushful iOS, Android, and web apps and the services that power them (together, the “Service”). “Hushful,” “we,” “us,” and “our” refer to the operator of the Hushful Service. If you do not agree with this policy, do not use the Service.
Information we collect
Account and profile information
When you create an account, we collect your email address, password in hashed form, display name, username, profile picture if you add one, discoverability setting, friend-request setting, privacy and notification choices, age-eligibility confirmation, and account creation and update dates. If you continue with Google, Google provides an identity identifier, verified email address, and may provide your name. We do not receive your Google password.
Age and profile safety information
During onboarding we ask for a birthday and whether you want birthday details displayed. The birthday is private by default. We use the birth year to derive an age range for age-appropriate list and profile visibility; we do not display a user’s age to other users. We also store mature-content choices and the visibility settings for birthdays and custom profile attributes. Birthday reminders are created only when a user enables them.
Content and social activity
We store the wishlists, item titles, links, prices, quantities, images, notes, cash-fund details, recurring occasions, sharing choices, collaborators, friendships, groups, blocks, pins, gift claims, recipient notes, comments, item-note mentions, feedback, reports, and activity notifications you create or receive. Guest visitors to a shared list receive a random viewer token so their claims, notes, and discussion comments remain associated with that browser.
Account protection and support
We process email-verification and password-reset records, rate-limit and security events, and support or safety reports. If an administrator enables multi-factor authentication, we store an encrypted or protected TOTP secret and recovery-code information needed to verify that administrator. We may keep an audit record of security and moderation actions.
Purchases
Apple and Google Play process Hushful Pro purchases. We receive purchase status, product and transaction identifiers, order or purchase-token identifiers, and an app-account identifier needed to unlock or restore Pro. We do not receive your full payment-card details.
Device, notification, and usage information
If you enable push notifications, we store a device push token, platform, and app environment. The iOS and Android apps may send a product URL to third-party product-metadata providers such as Microlink or a retailer’s product API to identify its title, price, or image. On the web, we create a random browser identifier and record page paths, whether the visitor was signed in, and timestamps to understand aggregate use. Hushful does not use this information for cross-app tracking or targeted advertising. Local preferences, access tokens, guest-viewer tokens, and reminder information may be stored on your device or browser.
Information collected automatically by infrastructure
Our hosting, content-delivery, security, email, analytics, product-metadata, and notification providers may process ordinary network information such as IP address, request time, user agent, diagnostic logs, product URLs, or app analytics events to deliver and protect the Service and understand aggregate use. We do not sell this information.
How we use information
- Provide accounts, wishlists, sharing, collaboration, reminders, notifications, and Hushful Pro.
- Authenticate users, prevent abuse, secure the Service, troubleshoot, and maintain reliability.
- Send password-reset and service messages you request or that are necessary to operate the Service.
- Measure aggregate product use and improve features.
- Comply with law and enforce our Terms.
How information is shared
We share information only as needed to provide the Service, when you direct us, or when legally required.
- With people you choose. Public profile and wishlist information is visible according to your settings. Private lists are shared only with selected friends, groups, collaborators, or people who have a guest link. A guest link should be treated as private: anyone with the link can access that list.
- Gift coordination. Claims and recipient notes are intended to remain hidden from a wishlist’s recipient but may be visible to other eligible gift planners. No online service can guarantee that another person will not reveal or capture information.
- Service providers. Hosting/database providers, Apple, Google Play, Google Sign-In, Firebase, email delivery, analytics, product-metadata, and notification providers process information for us under their own terms and privacy commitments.
- Legal and safety reasons. We may disclose information to comply with valid legal process, protect people, investigate abuse, or defend legal rights.
- Business changes. Information may transfer as part of a merger, financing, reorganization, or sale, subject to this policy or notice of materially different terms.
We do not sell personal information and do not share it for cross-context behavioral advertising.
Retention and deletion
We keep account information and content while your account is active and as needed to provide the Service. Verification, reset, guest, notification, and rate-limit records are retained only as long as reasonably needed for the stated security or operational purpose. Reports, moderation decisions, and security audit records may be retained longer when needed to prevent repeat abuse, resolve disputes, comply with law, or protect users.
You can delete individual content in the app or permanently delete your account through Account → Delete Account. Account deletion removes your account and associated wishlists, social relationships, groups, activity, images, and other account data from active systems. Limited records may remain temporarily in encrypted backups, security logs, or where retention is required for fraud prevention, accounting, dispute resolution, or law, after which they are deleted or de-identified. Guest content may remain until the associated list owner deletes the list or revokes the share.
Your choices and privacy requests
- Change your display name, profile picture, discoverability, friend-request, sharing, birthday, profile-attribute, mature-content, and notification choices in the app.
- Revoke a guest link or remove list access at any time.
- Disable system notifications in device settings.
- Delete your account in the app without contacting support.
- Request access, correction, portability, or deletion by emailing us. We may need to verify your identity and may have to retain information required by law or needed for security.
Depending on where you live, you may have additional privacy rights, including rights to object to or restrict certain processing and to complain to a data-protection authority. We do not discriminate against you for making a lawful privacy request.
Security and international processing
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network connections and hashed passwords. No method of storage or transmission is completely secure. The Service and its providers may process information in the United States and other countries, where privacy laws may differ from those where you live.
Children and age eligibility
Hushful is not directed to children under 13, and account creation requires the user to confirm that they are at least 13. We do not knowingly collect personal information from children under 13. A birthday is requested during onboarding for age-range safety controls, but it is private by default and displaying it is optional. If local law requires a higher age for a person to consent to data processing, a parent or guardian must authorize use. Contact us if you believe a child provided information without appropriate permission.
Changes and contact
We may update this policy as the Service changes. We will post the revised policy here and update the effective date; we will provide additional notice when required. Signed-in users can submit a feedback claim from Account → Send feedback; choose Purchase for purchase questions.