Skip to content
Fondfully
  • Features
  • Pricing
  • Manual
  • Support
Legal documents
  1. Privacy Policy
  2. Terms of Service
  3. Subscription Terms
  4. Refund Policy
  5. Affiliate Disclosure
  6. Acceptable Use Policy
  7. Accessibility Statement
  8. Security and Vulnerability Disclosure
  9. Open-Source Licenses
  10. Cookie Statement
  11. Data Processing Summary
  12. Account Deletion
  13. Contact and Legal Details

All documents and earlier versions

LegalData Processing Summary

Data Processing Summary

Version 2026-09-24 · Effective September 24, 2026 · Permanent link to this version

Each purpose for which Fondfully processes personal data, with the data used, the legal basis, how long it is kept and who receives it.

Contents

  1. The short version
  2. 1. Controller and contacts
  3. 2. What we don't process: your vault
  4. 3. Account and sign-in
  5. 4. Consent and age records
  6. 5. Signed-in devices and sessions
  7. 6. Service emails
  8. 7. Plus purchases, codes and plans
  9. 8. Automatic renewal records
  10. 9. Gift briefs
  11. 10. People who open or claim from a gift brief
  12. 11. Support, problem reports and suggestions in the app
  13. 12. Emails you send to our addresses
  14. 13. Security, abuse prevention and server logs
  15. 14. Anonymous diagnostics and crash reports
  16. 15. Usage statistics (optional)
  17. 16. Feature rollouts
  18. 17. Business reporting
  19. 18. Privacy requests, deletion records and legal matters
  20. 19. Backups
  21. 20. Transfers, automated decisions and your rights

The short version

This page sets out, purpose by purpose, what we process, why, how long we keep it and who receives it. For people in the European Economic Area, the United Kingdom or Switzerland, it also gives the legal basis and the other information required by Articles 13 and 14 of the GDPR and the UK GDPR. Fondfully isn't offered there, but if you use it while you're there, these rights still apply to you. This page is a companion to our Privacy Policy; if the two ever differ, the Privacy Policy applies.

1. Controller and contacts

  • Controller: Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States.
  • Privacy contact: privacy@fondfully.com.

2. What we don't process: your vault

The information you keep in your vault (people, sizes, dates, interests, allergies, ideas, gifts, budgets, receipts, photos, voice notes, memories and notes) is stored on your devices and in your own iCloud or Google Drive, encrypted on your device with a key we never receive. We don't collect, store, access or otherwise process it, so we are neither its controller nor its processor. Fondfully also keeps it out of your phone's own backups, such as iCloud Backup. Your use of Fondfully to keep gift notes about family and friends is a personal and household activity.

3. Account and sign-in

  • Purpose: create and secure your account, verify your email, sign you in with a password, Apple or Google, reset passwords, connect sign-in methods, and end Fondfully's access to your Apple sign-in when you delete your account or disconnect Apple.
  • Data: email address and whether it's verified; optional display name; password as a salted scrypt hash; Apple or Google account identifier and the email they share; your name if Apple or Google shares it; an encrypted Apple token used to end Fondfully's access when you delete your account or disconnect Apple; account status; when you last used Fondfully, and on which platform; verification codes and reset links, stored only as hashes.
  • Legal basis: performance of a contract (Article 6(1)(b)).
  • Retention: until you delete your account; deleted from live systems within 24 hours and from backups within 30 days. If Apple can't be reached to end Fondfully's access, only the encrypted Apple token is kept, for up to 30 days, to try again. An account created with an email address and password whose address is never verified is deleted 30 days after the last attempt to sign up with it. Verification codes are deleted within two days of expiring, and reset links within eight days.
  • Recipients: Cloudflare (hosting and database, as processor); Apple or Google (identity verification and, for Apple, ending access on deletion, as independent controllers).
  • Source: you, and Apple or Google if you sign in with them.
  • Required? Yes. You need an account to use Fondfully.

4. Consent and age records

  • Purpose: record that you confirmed you're 18 or older, and which versions of the Terms of Service and Privacy Policy you accepted; and, in US states whose app store laws require it, check the age range Apple or Google provides and turn away anyone under 18.
  • Data: the versions accepted, when, and on which platform, app version and build; when you confirmed your age. Never your date of birth. The age range from Apple or Google is checked on your device, which remembers only the result and when it last checked; we don't receive or keep it.
  • Legal basis: our legitimate interest in being able to show what was agreed and that we don't provide the Service to anyone under 18 (Article 6(1)(f)), and compliance with legal obligations where they apply (Article 6(1)(c)).
  • Retention: until you delete your account.
  • Recipients: Cloudflare (processor).

5. Signed-in devices and sessions

  • Purpose: keep you signed in, show your signed-in devices, let you sign out anywhere, and alert you to sign-ins on other devices.
  • Data: platform, your device model as the app reports it (never the name you've given your device), app version, and when each session was created, last used and ended; refresh tokens stored as hashes.
  • Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in account security (Article 6(1)(f)).
  • Retention: while the session is active, then 30 days after it's signed out or expires (after 30 days without use).
  • Recipients: Cloudflare (processor).

6. Service emails

  • Purpose: send verification codes, password reset links, alerts about sign-ins on other devices, support confirmations and replies, deletion confirmations and important notices; and, for Plus Yearly, a confirmation of the renewal terms when you subscribe, reminders 35 and 20 days before each yearly renewal, and notice before any price increase; and, for Plus Lifetime, a receipt. Each billing email goes once, and is tried again daily if sending fails.
  • Data: your email address and the message content, including for billing emails your plan, price and renewal date; our delivery record, with the address stored as a one-way hash, the kind of email, when it was sent and whether it was delivered; Cloudflare's delivery log, with the sender's and recipient's addresses and the subject line.
  • Legal basis: performance of a contract (Article 6(1)(b)); compliance with legal obligations for the subscription emails (Article 6(1)(c)); and our legitimate interest in account security (Article 6(1)(f)).
  • Retention: our delivery records for 30 days; Cloudflare's delivery log for up to 31 days. Cloudflare doesn't keep copies of the messages.
  • Recipients: Cloudflare (email sending, as processor).

7. Plus purchases, codes and plans

  • Purpose: verify purchases, keep your plan up to date, restore purchases, apply Family Sharing, redeem codes, handle refunds and resolve billing questions.
  • Data: a reference derived from your account number that the app gives the store; the product, transaction or order identifiers, whether the purchase is yours or shared through Family Sharing, status, whether it renews, renewal and expiry dates; the price and currency you paid and, for Plus Yearly, the store's price for the next renewal (never the country of purchase); an encrypted Google purchase token; records of the billing emails we send you (which kind, for which purchase and renewal, when, and whether it was sent); codes you redeem; any Plus our team grants you, with an internal note.
  • Legal basis: performance of a contract (Article 6(1)(b)); for billing email records, also compliance with legal obligations (Article 6(1)(c)).
  • Retention: until you delete your account. Records of reminder and price change emails: two years at most; confirmation and receipt records stay with their purchase. Apple's purchase notifications, which identify a purchase only by Apple's transaction number: 180 days.
  • Recipients: Cloudflare (processor); Apple or Google (payment and verification, as independent controllers).
  • Source: you, and Apple or Google.

8. Automatic renewal records

  • Purpose: keep proof that you agreed to Plus Yearly's automatic renewal, as California law requires.
  • Data: the store; the store's transaction references (for Google Play, a one-way hash of the purchase token); the product; whether it was a test purchase; when you agreed; your app version and build; the version of the Subscription Terms you agreed to; and when the subscription ends. No email address or name.
  • Legal basis: compliance with legal obligations (Article 6(1)(c)).
  • Retention: at least three years, or until one year after your subscription ends if that's later (California Business and Professions Code section 17602(a)(6)), even if you delete your account sooner; then deleted. After an account is deleted, Apple's purchase notifications can still update when an App Store subscription ends, which sets this period.
  • Recipients: Cloudflare (processor).
  • Source: you, and Apple or Google.

9. Gift briefs

  • Purpose: store and deliver the encrypted briefs you choose to share, and the encrypted claims made on them.
  • Data: the encrypted brief (which we can't read, and which can include things to avoid and allergies if you choose); its link token, size, creation and expiry dates and which account created it; encrypted claims and when they were made; the claim count and when the last claim was made.
  • Legal basis: performance of a contract (Article 6(1)(b)).
  • Retention: until the brief expires (at most 120 days) or you stop sharing it. Stopping sharing deletes the encrypted brief and claims immediately and the rest of its record within a day; expired briefs, their claims and records are deleted within 24 hours.
  • Recipients: Cloudflare (hosting and storage, as processor); anyone you give the whole link to, who can also see every claim.

10. People who open or claim from a gift brief

  • Purpose: deliver the brief page to the people it was shared with, record their claims for everyone with the link, and protect the page from bots and abuse.
  • Data: the visitor's IP address and browser information, used in the moment to deliver the page, limit requests and run the Turnstile check, and not kept by our servers; the claim itself (the visitor's name, an optional note and which idea), encrypted in the visitor's browser with a key we never receive.
  • Legal basis: our legitimate interests, and those of the person who shared the brief, in delivering the page and preventing abuse (Article 6(1)(f)).
  • Retention: IP addresses can stay in Cloudflare's sampled security records for up to 31 days; encrypted claims as in section 9.
  • Recipients: Cloudflare (hosting and Turnstile, as processor; Cloudflare also uses Turnstile signals to improve its bot detection, as an independent controller); the person who shared the brief and everyone else with the link, who can decrypt the claim.
  • Source: the visitor's browser.

11. Support, problem reports and suggestions in the app

  • Purpose: answer your messages, investigate problems, and consider suggestions.
  • Data: what you write; your email address; your account, if you're signed in; the platform and app version you sent it from; for problem reports, if you choose, your system version, device model and the last 200 lines of the app's log, with email addresses, tokens, codes, web address details and long numbers removed; any screenshot you attach (up to 2 MB); our replies.
  • Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in improving the Service (Article 6(1)(f)).
  • Retention: until two years after we mark the conversation resolved or closed or, while it's still open, two years after its last message or update, unless you ask us to delete it sooner; screenshots with their conversation and no longer than two years after you send them, or within two days if they never get sent with a report; deleted with your account, screenshots included, if it's linked to your account or email address.
  • Recipients: Cloudflare (hosting, storage and email, as processor).

12. Emails you send to our addresses

  • Purpose: read and answer emails you send to support@, privacy@, security@ or hello@fondfully.com, and handle what you ask for.
  • Data: your email address and name as your email shows them, your message and anything you attach, and our replies; Cloudflare's routing log, with the addresses and subject line.
  • Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in answering people who contact us (Article 6(1)(f)).
  • Retention: up to two years after the conversation ends, unless you ask us to delete it sooner; Cloudflare's routing log for up to 31 days. Deleting your account in the app doesn't delete these emails; ask us, and we will.
  • Recipients: Cloudflare (email routing, as processor); Google (Google Workspace, which hosts our team's inbox, as processor).

13. Security, abuse prevention and server logs

  • Purpose: keep the Service available and secure, limit request rates, detect and stop abuse, find and fix problems, and enforce our Terms.
  • Data: IP address and request details, used in the moment for rate limiting and not kept by our servers; our servers' technical logs, recording for each request its time, kind and full web address, the response and how long it took, and the platform and app version, plus short error messages and the results of scheduled jobs, with no IP addresses, request headers or content you send (the full web address can include a gift brief's link token, never its key, and, for our team's admin requests, the account number or email address they looked up); Cloudflare's sampled security records, which can include IP addresses and the country they come from; account status; our team's audit log of actions taken on accounts, which refers to accounts only by an internal number.
  • Legal basis: our legitimate interest in protecting the Service and its users (Article 6(1)(f)), and compliance with legal obligations (Article 6(1)(c)).
  • Retention: server logs for 7 days; Cloudflare's sampled security records for up to 31 days; audit log entries for two years.
  • Recipients: Cloudflare (processor).

14. Anonymous diagnostics and crash reports

  • Purpose: find and fix problems in the apps.
  • Data: the kind and severity of the event; a technical title and message with identifying details removed; app version and build, platform, system version, device model, language and region setting, and app state; for crash reports you choose to send, technical details of the crash. Stored without your account details or IP address.
  • Legal basis: diagnostics, our legitimate interest in providing a reliable app (Article 6(1)(f)); crash reports, your consent (Article 6(1)(a)), given each time you tap Send.
  • Retention: deleted 90 days after we receive them.
  • Recipients: Cloudflare (processor).
  • Your choice: you can object to diagnostics by writing to privacy@fondfully.com; crash reports are sent only when you tap Send, and you can turn off being asked.

15. Usage statistics (optional)

  • Purpose: understand which parts of Fondfully are used, to improve it.
  • Data: a random identifier created on your device for this installation; platform and app version; the names of screens and features used, with times, and a few details such as how an idea was added or which cloud you chose. Never vault content, location or advertising identifiers. Stored without your account details or IP address.
  • Legal basis: your consent (Article 6(1)(a)), which also covers storing and reading the installation identifier on your device.
  • Retention: individual events for 90 days; daily totals without identifiers indefinitely.
  • Recipients: Cloudflare (processor).
  • Your choice: off unless you turn it on; withdraw consent any time in Settings › Privacy & security.

16. Feature rollouts

  • Purpose: switch new features on for a share of installations at a time, so changes can be released safely.
  • Data: a random identifier created on your device for this purpose, separate from the usage statistics one, sent when the app checks for settings.
  • Legal basis: our legitimate interest in releasing changes safely (Article 6(1)(f)), which also covers storing and reading the identifier on your device where the law allows.
  • Retention: used only for the calculation, and not kept.
  • Recipients: Cloudflare (processor).

17. Business reporting

  • Purpose: understand how Fondfully is doing, for example how many people sign up, upgrade or cancel, and which app versions and platforms are in use.
  • Data: account and purchase records, used only to produce totals.
  • Legal basis: our legitimate interest in running and sustaining the Service (Article 6(1)(f)).
  • Retention: totals contain no personal data; the underlying records follow the retention periods above.
  • Recipients: none outside Fondfully, other than Cloudflare as processor.

18. Privacy requests, deletion records and legal matters

  • Purpose: handle your privacy requests, show that we honored them, comply with the law and establish, exercise or defend legal claims.
  • Data: your request and our correspondence; for each account deletion, a one-way code derived from the deleted account's internal number, who asked for it and when.
  • Legal basis: compliance with legal obligations (Article 6(1)(c)) and our legitimate interests (Article 6(1)(f)).
  • Retention: request correspondence for up to two years after the request is complete; deletion records for three years, so we can show deletions were honored. Deletion records contain no email address, name or other details.
  • Recipients: Google (our team's inbox, as processor); professional advisers and authorities where the law requires.

19. Backups

  • Purpose: recover from technical failures.
  • Data: copies of our database (account, purchase, support and deletion records; passwords are left out of our nightly copies).
  • Legal basis: our legitimate interest in keeping the Service reliable (Article 6(1)(f)).
  • Retention: a rolling 30-day recovery history and nightly copies kept for 30 days. If we ever restore a backup, we delete again anything that had been deleted since.
  • Recipients: Cloudflare (processor).

20. Transfers, automated decisions and your rights

  • International transfers: Cloudflare and Google process data in the United States and other countries. We rely on a recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, or on the European Commission's Standard Contractual Clauses, with the UK Addendum and Swiss adaptations where needed. You can ask for a copy at privacy@fondfully.com.
  • Automated decisions and AI: we don't make decisions based solely on automated processing that have legal or similarly significant effects on you, and we don't use personal data to train artificial intelligence or machine learning models.
  • Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Section 13 of our Privacy Policy explains them, and section 14 explains how to use them.

Other versions

  • Version 2026-09-22 · effective September 22, 2026
Fondfully

Gifts, remembered.

A private gift planner and memory vault for iPhone and Android. No ads. No tracking. Ever.

Fondfully

  • Features
  • Privacy by design
  • Pricing
  • User manual
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Subscription Terms
  • Refund Policy
  • Affiliate Disclosure
  • Cookie Statement
  • Security
  • Delete your account
  • All legal documents

Contact

  • support@fondfully.com
  • privacy@fondfully.com
  • security@fondfully.com
  • hello@fondfully.com

© 2026 Fondfully

This site sets no cookies of its own.