This is an earlier version. The current version took effect September 24, 2026. Read the current Data Processing Summary.
Data Processing Summary
Each purpose for which Fondfully processes personal data, with the data used, the legal basis, how long it is kept and who receives it.
The short version
This page sets out, purpose by purpose, the information required by Articles 13 and 14 of the GDPR and the UK GDPR: what we process, why, on what legal basis, for how long and who receives it. It's a companion to our Privacy Policy; if the two ever differ, the Privacy Policy applies.
1. Controller and contacts
- Controller: Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States.
- Privacy contact: privacy@fondfully.com.
2. What we don't process: your vault
The information you keep in your vault (people, sizes, dates, interests, allergies, ideas, gifts, budgets, receipts, photos, voice notes, memories and notes) is stored on your devices and in your own iCloud or Google Drive, encrypted on your device with a key we never receive. We don't collect, store, access or otherwise process it, so we are neither its controller nor its processor. Your use of Fondfully to keep gift notes about family and friends is a personal and household activity.
3. Account and sign-in
- Purpose: create and secure your account, verify your email, sign you in with a password, Apple or Google, reset passwords and connect sign-in methods.
- Data: email address and whether it's verified; optional display name; password as a salted scrypt hash; Apple or Google account identifier and the email they share; your name if Apple or Google shares it; an encrypted Apple token used to end Fondfully's access when you delete your account; account status; when you last used Fondfully, and on which platform.
- Legal basis: performance of a contract (Article 6(1)(b)).
- Retention: until you delete your account; deleted from live systems within 24 hours and from backups within 30 days.
- Recipients: Cloudflare (hosting and database, as processor); Apple or Google (identity verification, as independent controllers).
- Source: you, and Apple or Google if you sign in with them.
- Required? Yes. You need an account to use Fondfully.
4. Consent and age records
- Purpose: record that you confirmed you're 16 or older, and which versions of the Terms of Service and Privacy Policy you accepted.
- Data: the versions accepted and when; when you confirmed your age. Never your date of birth.
- Legal basis: compliance with legal obligations (Article 6(1)(c)) and our legitimate interest in being able to show what was agreed (Article 6(1)(f)).
- Retention: until you delete your account.
- Recipients: Cloudflare (processor).
5. Signed-in devices and sessions
- Purpose: keep you signed in, show your signed-in devices, and let you sign out anywhere.
- Data: platform, the device name or model the app reports, app version, and when each session was created, last used and ended; refresh tokens stored as hashes.
- Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in account security (Article 6(1)(f)).
- Retention: while the session is active, then deleted within 30 days after it ends or expires (after 30 days without use).
- Recipients: Cloudflare (processor).
6. Service emails
- Purpose: send verification codes, password reset links, alerts about sign-ins on other devices, support confirmations and replies, deletion confirmations and important notices.
- Data: your email address and the message content; a delivery record with the address stored as a one-way hash, the kind of email, when it was sent and whether it was delivered.
- Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in account security (Article 6(1)(f)).
- Retention: delivery records for 30 days.
- Recipients: Cloudflare (email sending, as processor).
7. Plus purchases, codes and plans
- Purpose: verify purchases, keep your plan up to date, restore purchases, apply Family Sharing, redeem codes and resolve billing questions.
- Data: a reference derived from your account number that the app gives the store; the product, transaction or order identifiers, whether the purchase is yours or shared through Family Sharing, status, renewal and expiry dates; an encrypted Google purchase token; codes you redeem; any Plus our team grants you, with an internal note.
- Legal basis: performance of a contract (Article 6(1)(b)).
- Retention: until you delete your account. Purchase notifications from Apple and Google: 180 days.
- Recipients: Cloudflare (processor); Apple or Google (payment and verification, as independent controllers).
- Source: you, and Apple or Google.
8. Gift briefs
- Purpose: store and deliver the encrypted briefs you choose to share, and the encrypted claims made on them.
- Data: the encrypted brief (which we can't read); its link token, size, creation and expiry dates and which account created it; encrypted claims and when they were made; the claim count.
- Legal basis: performance of a contract (Article 6(1)(b)).
- Retention: until the brief expires (at most 120 days) or you stop sharing it. Stopping sharing deletes the encrypted brief and claims immediately; expired briefs and claims are deleted within 24 hours.
- Recipients: Cloudflare (hosting and storage, as processor); anyone you give the whole link to.
9. People who open or claim from a gift brief
- Purpose: deliver the brief page to the people it was shared with, record their claims for the person who shared it, and protect the page from bots and abuse.
- Data: the visitor's IP address and browser information, used in the moment to deliver the page, limit requests and run the Turnstile check; the claim itself (such as the visitor's name and the idea), encrypted in the visitor's browser with a key we never receive.
- Legal basis: our legitimate interests, and those of the person who shared the brief, in delivering the page and preventing abuse (Article 6(1)(f)).
- Retention: IP addresses aren't stored by us beyond short-lived security logs (at most 30 days); encrypted claims as in section 8.
- Recipients: Cloudflare (hosting, and Turnstile bot protection, which Cloudflare also uses to improve its bot detection); the person who shared the brief, who can decrypt the claim.
- Source: the visitor's browser.
10. Support, problem reports and suggestions
- Purpose: answer your messages, investigate problems, and consider suggestions.
- Data: what you write; your email address; your account, if you're signed in; for problem reports, if you choose, your app version, system version, device model and the last 200 lines of the app's log with personal details removed; any screenshot you attach (up to 2 MB); our replies.
- Legal basis: performance of a contract (Article 6(1)(b)) and our legitimate interest in improving the Service (Article 6(1)(f)).
- Retention: up to two years after the conversation is closed, unless you ask us to delete it sooner; deleted with your account if it's linked to your account or email address.
- Recipients: Cloudflare (hosting, storage and email routing, as processor).
11. Security and abuse prevention
- Purpose: keep the Service available and secure, limit request rates, detect and stop abuse, and enforce our Terms.
- Data: IP address and request details, used in the moment for rate limiting; short-lived request and security logs kept by Cloudflare, which can include IP addresses; account status; our team's audit log of actions taken on accounts, which refers to accounts only by an internal number and is kept for two years.
- Legal basis: our legitimate interest in protecting the Service and its users (Article 6(1)(f)), and compliance with legal obligations (Article 6(1)(c)).
- Retention: request and security logs at most 30 days.
- Recipients: Cloudflare (processor).
12. Anonymous diagnostics and crash reports
- Purpose: find and fix problems in the apps.
- Data: the kind and severity of the event; a technical title and message with personal details removed; app version and build, platform, system version, device model, language and region setting, and app state; for crash reports you choose to send, technical details of the crash. Stored without your account details or IP address.
- Legal basis: diagnostics, our legitimate interest in providing a reliable app (Article 6(1)(f)); crash reports, your consent (Article 6(1)(a)), given each time you tap Send.
- Retention: 90 days.
- Recipients: Cloudflare (processor).
- Your choice: you can object to diagnostics by writing to privacy@fondfully.com; crash reports are sent only when you tap Send, and you can turn off being asked.
13. Usage statistics (optional)
- Purpose: understand which parts of Fondfully are used, to improve it.
- Data: a random identifier created on your device for this installation; platform and app version; the names of screens and features used, with times. Never vault content, location or advertising identifiers. Stored without your account details or IP address.
- Legal basis: your consent (Article 6(1)(a)), which also covers storing and reading the installation identifier on your device.
- Retention: individual events for 90 days; daily totals without identifiers indefinitely.
- Recipients: Cloudflare (processor).
- Your choice: off unless you turn it on; withdraw consent any time in Settings › Privacy & security.
14. Business reporting
- Purpose: understand how Fondfully is doing, for example how many people sign up, upgrade or cancel, and which app versions and platforms are in use.
- Data: account and purchase records, used only to produce totals.
- Legal basis: our legitimate interest in running and sustaining the Service (Article 6(1)(f)).
- Retention: totals contain no personal data; the underlying records follow the retention periods above.
- Recipients: none outside Fondfully, other than Cloudflare as processor.
15. Privacy requests, deletion records and legal matters
- Purpose: handle your privacy requests, show that we honored them, comply with the law and establish, exercise or defend legal claims.
- Data: your request and our correspondence; for each account deletion, a one-way code derived from the deleted account's internal number, who asked for it and when.
- Legal basis: compliance with legal obligations (Article 6(1)(c)) and our legitimate interests (Article 6(1)(f)).
- Retention: request correspondence as for support conversations; deletion records are kept for three years so we can show deletions were honored, and contain no email address, name or other details.
- Recipients: professional advisers and authorities where the law requires.
16. Backups
- Purpose: recover from technical failures.
- Data: copies of our database (account, purchase, support and deletion records; passwords are left out of our nightly copies).
- Legal basis: our legitimate interest in keeping the Service reliable (Article 6(1)(f)).
- Retention: point-in-time recovery for 30 days and nightly copies for 30 days. If we ever restore a backup, we delete again anything that had been deleted since.
- Recipients: Cloudflare (processor).
17. Transfers, automated decisions and your rights
- International transfers: Cloudflare processes data in the United States and other countries. We rely on the European Commission's Standard Contractual Clauses, with the UK Addendum and Swiss adaptations where needed, or on a recipient's certification under the EU-U.S. Data Privacy Framework and its extensions, where that applies. You can ask for a copy at privacy@fondfully.com.
- Automated decisions: we don't make decisions based solely on automated processing that have legal or similarly significant effects on you.
- Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Section 13 of our Privacy Policy explains them, and section 14 explains how to use them.
Other versions
- Version 2026-09-24 · effective September 24, 2026 (current)