This is an earlier version. The current version took effect September 24, 2026. Read the current Privacy Policy.
Privacy Policy
How Fondfully handles personal information, where your vault lives (on your devices and in your own cloud, never on our servers), and the choices and rights you have.
The short version
- Your vault stays with you. The people you shop for, their sizes and dates, your ideas, gifts, receipts, photos, voice notes and notes live on your devices and in your own iCloud or Google Drive, encrypted on your device. They never reach our servers, and we can't read them.
- Our servers hold only what we need to run your account: your email address, how you sign in, your plan, the devices you're signed in on, messages you send us, and any gift briefs you share, which are encrypted so we can't read them.
- No ads, no selling, no tracking. Ever. There are no third-party analytics, advertising or tracking tools in Fondfully.
- You choose what we measure. Anonymous diagnostics help us fix bugs. Usage statistics are off unless you turn them on. Crash reports are sent only when you tap Send.
- You're in control. Export or delete your data from the app at any time, or write to privacy@fondfully.com.
1. Who we are
Fondfully is provided by Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States ("Fondfully", "we", "us" or "our"). We are the controller of the personal information described in this policy and, under California law, the "business" that collects it.
This policy covers the Fondfully apps for iPhone and Android, the website fondfully.com (including gift brief pages), our servers and our support channels (together, the "Service"). It doesn't cover services you use alongside Fondfully, such as your Apple or Google account, iCloud, Google Drive, the App Store, Google Play or the stores whose links you open. Their own privacy policies apply to them.
Fondfully is not currently offered in the European Economic Area or the United Kingdom, so we have not appointed a representative there under Article 27 of the GDPR or the UK GDPR. If you use Fondfully while you're there, the rights in section 13 still apply to you. You can reach us about anything in this policy at privacy@fondfully.com.
2. How Fondfully is built
Your vault stays with you
Your vault is the information you keep in Fondfully: the people you shop for and their relationships, birthdays, sizes, interests, likes, dislikes and allergies; your occasions, ideas, gifts, budgets, hiding spots, receipts and warranties; photos, voice notes, memories and notes; and your in-app settings.
Your vault is stored in the app's private storage on your device, protected by your device's own encryption, with an optional app lock. If you turn on backup or sync, the app encrypts your vault on your device with AES-256-GCM, using a vault key created on your device, before copying it to your own iCloud Drive (on iPhone) or Google Drive (on iPhone or Android). Apple or Google stores the encrypted files in your account, under your agreement with them.
We never receive your vault, your vault key, your vault passphrase or your recovery code. On iPhone with iCloud, the vault key is kept in your iCloud Keychain, which Apple protects with end-to-end encryption. With Google Drive, the key is protected by a passphrase you choose, which never leaves your device. Both also have a recovery code that only you hold. Because we hold none of these, we cannot read, recover, restore, hand over or delete your vault; only you can.
Fondfully asks only for access to its own folder in your cloud. In Google Drive, it uses Google's "app data" permission, which covers a hidden folder that only Fondfully can see, and nothing else in your Drive. In iCloud, it uses Fondfully's own app container. Fondfully's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What happens on your device
Several features work entirely on your device, so the information involved never reaches us:
- Link previews. When you paste a link, your device fetches the preview (title, picture, price) directly from that website. The website sees an ordinary request from your device; we don't.
- Receipt scanning and reading. On iPhone, Apple's document camera and text recognition run on your device. On Android, Google's ML Kit document scanner and text recognition run on your device; your receipt images and text are not sent to Google or to us. ML Kit may send Google limited technical information about how the feature is working (such as device and app details and performance metrics) to maintain and improve it, under Google's ML Kit terms.
- Voice notes. Recordings stay in your vault. Where your device supports on-device speech recognition, a suggested title is created on your device.
- Contacts import. If you import birthdays, the app reads names and birthdays from your contacts on your device and adds only the people you pick. Nothing is written back to your contacts, and nothing from them is sent to us.
- Reminders, budgets and repeat alerts are calculated and scheduled on your device.
- Exports are created on your device and go wherever you send them.
Permissions the apps ask for
The apps may ask for these permissions, only when you first use a feature that needs one. Each is optional, and you can change your mind in your device's settings:
- Notifications, for reminders.
- Contacts, to import birthdays (read only).
- Camera, to scan receipts and take photos.
- Photos, to choose a picture from your library.
- Microphone, and on iPhone speech recognition, for voice notes.
- Face ID or biometrics, for app lock. Your device checks your face or fingerprint itself; Fondfully only learns whether it matched, and never receives biometric data.
- iCloud or Google Drive, for backup and sync, as described above.
3. What we collect and why
Information you give us
- Account information: your email address; a password if you choose one (stored only as a salted scrypt hash, never in readable form); an optional display name; your confirmation that you're 16 or older (we record that you confirmed, and when, never your date of birth); and which versions of our Terms of Service and this Privacy Policy you accepted, and when. We also note when you last used Fondfully, and on which platform. We use this to create and secure your account and to show what you agreed to.
- Support messages: when you use Contact us, Report a problem or Suggest a feature in the app, or email us, we receive what you write, the email address you give us (or your account email if you're signed in), and which account it came from if you're signed in. A problem report can also include, if you leave "Include diagnostic details" on: your app version, operating system version, device model and the last 200 lines of the app's technical log, from which personal details are removed on your device and again on our servers. You can attach a screenshot (PNG, JPEG, HEIC or WebP, up to 2 MB). Screenshots show whatever was on your screen, so please check them first. We use all of this to help you and to fix problems.
- Promo codes you redeem, so we can give you what the code includes.
- Gift briefs you choose to share, which are encrypted before they leave your device (see "Gift briefs and the people you share them with" below).
- Privacy and deletion requests you send us, so we can act on them.
Information from Apple and Google
- Sign in with Apple: a stable Apple user identifier, the email address Apple shares with us (which may be a private relay address if you choose Hide My Email), your name if you choose to share it, and a token that lets us end Fondfully's access to your Apple sign-in when you delete your account. We keep that token encrypted.
- Google Sign-In: a Google account identifier, your email address, whether Google has verified it, and your name.
- Purchases of Fondfully Plus. Apple and Google process your payment; we never receive your card details or billing address. The app gives the store a reference derived from your account number, which contains no email or name, so that purchases can be matched to your account. The store then shares signed purchase information with us, and sends us updates when a subscription renews, lapses or is refunded. We keep the product, the store's transaction or order identifiers, whether it's your own purchase or shared with you through Family Sharing, its status, and its renewal and expiry dates. We keep Google's purchase token encrypted. The information stores send us can also include the price, currency and country of purchase; we don't keep those.
Information collected automatically
- Connection information. When your device or browser talks to our servers, we necessarily process its IP address and basic request details. We use the IP address in the moment to deliver responses, to limit how often requests can be made, and to protect against abuse. Our own request logs record the time, the kind of request, the response and the app version, not your IP address or account. Our hosting provider, Cloudflare, also keeps short-lived request and security logs, which can include IP addresses, for no longer than 30 days.
- Signed-in devices. For each sign-in we keep the platform, the device name or model the app reports, the app version, and when the session was created, last used and ended. You can see these in Settings › Account › Signed-in devices. We use them to keep you signed in and let you sign out anywhere.
- Anonymous diagnostics. When something goes wrong in the app, like a failed sync, it sends a short technical report: the kind of event and how serious it is, a technical title and message, your app version and build, platform and operating system version, device model, language and region setting, whether the app was in use, and a few technical details about where the problem happened. Before a report is stored, email addresses, phone and card-like numbers, IP addresses and long identifiers are removed, web addresses are cut down to the site and page, and any detail that could hold vault content, like a name, title or note, is blanked out. We store them without your account details or IP address, so they aren't linked to you or your account. We use them to find and fix problems.
- Usage statistics (only if you turn them on). If you choose "Share anonymous stats" during setup, or turn on Settings › Privacy & security › Share anonymous usage statistics, the app sends counts of which screens and features are used (for example, that an idea was tucked away), with the time, your platform and app version, and a random identifier created on your device for this installation. The identifier isn't linked to your account and changes if you reinstall. These statistics never include your people, gifts, notes, titles, prices or anything you type, your location or any advertising identifier, and we store them without your IP address. We use them to understand which parts of Fondfully are useful and to improve it.
- Crash reports (only when you tap Send). After the app closes unexpectedly, it can offer to send a crash report the next time you open it. If you tap Send, we receive technical details of the crash (such as the error, the app code involved, your app version, operating system and device model). Nothing is sent unless you tap Send.
- Feature rollouts. When the app checks for settings and new versions, it can include a random installation identifier so that new features can be switched on for a share of installations at a time. We use it only for that calculation and don't store it.
- Notes from our team. If our support team helps you, they may add a short internal note to your account, for example that we gave you Plus while a store problem was sorted out. These notes are deleted with your account.
Gift briefs and the people you share them with
A gift brief is a web page you create in the app to share sizes, interests and ideas with family. When you send one, the app encrypts it on your device with a new key made just for that brief. The key goes into the part of the link after the "#" sign, which browsers never send to servers, so it never reaches us. We store only the encrypted brief, its expiry date, which account created it, when, and how many claims it has received.
When someone opens your link, their browser downloads the encrypted brief from our servers and decrypts it on their device. If they claim an idea, the claim (for example, their name and the idea) is encrypted in their browser with the same key, so we can't read it either. To keep automated abuse out, the claim form uses Cloudflare Turnstile, which checks the visitor's browser and connection and tells us only whether the check passed. We use a visitor's IP address in the moment to deliver the page, limit requests and run that check; we don't store it or use it to identify anyone.
Briefs and their claims are kept until the brief expires (at most 120 days after you create it) or you stop sharing it. When you stop sharing, the encrypted brief and its claims are deleted straight away. When a brief expires, its link stops working at once, and we delete the encrypted brief and its claims within 24 hours.
Anyone who has the whole link can open a brief, so please share links only with people you trust, and only information you're comfortable sharing.
4. What we never collect
- The contents of your vault, including the people you shop for and anything about them, your gifts, receipts, photos, voice notes and notes.
- Your vault key, vault passphrase or recovery code.
- Your contacts. Importing birthdays happens on your device.
- Anything in your iCloud or Google Drive beyond Fondfully's own encrypted files, which only your devices can open.
- Your location.
- Advertising identifiers, such as Apple's IDFA or Google's Advertising ID.
- Your payment card details or billing address.
- Your date of birth. We only record that you confirmed you're 16 or older.
- Biometric data.
- Which product links you open, or what you buy.
5. How we use information, and our legal bases
We use personal information only for the purposes below. If you're in the European Economic Area, the United Kingdom or Switzerland, the legal basis for each purpose is shown in brackets.
- Creating your account, signing you in, keeping you signed in, verifying your email, resetting your password and showing your signed-in devices (necessary to perform our contract with you).
- Recording your age confirmation and the versions of our terms you accepted (compliance with legal obligations, and our legitimate interest in being able to show what you agreed to).
- Providing Plus: verifying purchases, keeping your plan up to date across devices, restoring purchases, applying Family Sharing and redeeming codes (necessary to perform our contract with you).
- Gift briefs: storing and delivering the encrypted briefs you share and the encrypted claims made on them (necessary to perform our contract with you; for the people who open a brief, our legitimate interest in delivering the page they were sent and protecting it from abuse).
- Support: answering your messages, investigating problems you report and considering your suggestions (necessary to perform our contract with you, and our legitimate interest in improving the Service).
- Service emails: verification codes, password resets, sign-in alerts, support replies and important notices (necessary to perform our contract with you, and our legitimate interest in keeping your account secure).
- Security and abuse prevention: limiting request rates, detecting misuse, suspending accounts that break our terms, and keeping short-lived security logs (our legitimate interest in keeping Fondfully and its users safe, and compliance with legal obligations).
- Anonymous diagnostics: finding and fixing problems (our legitimate interest in providing a reliable app). You can object at any time; see section 13.
- Usage statistics (your consent, which you can withdraw at any time in Settings).
- Crash reports (your consent, given each time you tap Send).
- Running our business: counting sign-ups, upgrades, cancellations and which app versions and platforms are in use, from our account and purchase records, as totals without names (our legitimate interest in understanding and sustaining the Service).
- Legal matters: complying with the law, responding to lawful requests, and establishing, exercising or defending legal claims (compliance with legal obligations, and our legitimate interests).
Where we rely on legitimate interests, we have weighed them against your rights and expectations, and we use the least information we can. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
Providing an email address and password, or using Sign in with Apple or Google, is necessary to create an account; without it you can't use Fondfully. Other information, such as support messages, usage statistics, crash reports and gift briefs, is up to you.
6. Emails we send
We send only service emails: verification codes, password reset links, alerts when your account is signed in on another device, confirmations that we received your message, replies from our support team, confirmation that your account was deleted, and important notices about the Service or changes to our terms. We don't send marketing emails. If we ever offer a newsletter, you'll only receive it if you ask for it.
Emails are sent from no-reply@fondfully.com, with replies going to support@fondfully.com, using Cloudflare's email service. They contain no tracking pixels or tracked links. To prevent duplicates and diagnose delivery problems, we record which kind of email was sent, when, and whether it was delivered, with the address stored only as a one-way hash, for 30 days.
7. How long we keep information
- Account information is kept for as long as you have an account. When you delete your account in the app, or ask us to, we delete it from our live systems within 24 hours.
- Server backups. Our database has point-in-time recovery for 30 days, and we keep nightly backup copies for 30 days. So deleted information disappears from backups within 30 days. We use backups only to recover from a technical failure, and if we ever restore one, we delete again any information that had been deleted since.
- Signed-in devices are kept while you're signed in on them, and deleted within 30 days after you sign out, sign out everywhere, or the session expires (after 30 days without use).
- Verification codes expire after 15 minutes and password reset links after 30 minutes; both are deleted within a week of expiring.
- Purchase records are kept while you have an account. Notifications from Apple and Google about purchases are kept for 180 days.
- Anonymous diagnostics and crash reports are kept for 90 days.
- Usage statistics: individual events are kept for 90 days. Daily totals (how many times each screen or feature was used, and by how many installations, per platform and app version) contain no identifiers and are kept indefinitely.
- Support conversations are kept for up to two years after the conversation is closed, unless you ask us to delete them sooner. When you delete your account, conversations linked to your account or sent from your account's email address are deleted with it.
- Gift briefs and claims are kept until the brief expires or you stop sharing it, as described in section 3.
- Email delivery records are kept for 30 days, and security logs for no longer than 30 days.
- A record of each account deletion is kept so we can show we honored it. It contains only a one-way code derived from the deleted account's internal number, who asked for the deletion (you or our team) and when; no email address, name or other details.
- Our team's audit log records actions staff take on accounts (such as granting Plus or suspending an account), referring to accounts only by an internal number. Once your account is deleted, that number is no longer connected to you and any details are removed. Audit entries are deleted after two years.
8. Who we share information with
We don't sell your personal information, and we don't share it for advertising. We disclose it only as follows.
Service providers
- Cloudflare, Inc. hosts our servers and website, and provides our database, file storage (for encrypted gift briefs, support screenshots and backups), email sending and receiving, bot protection (Turnstile), and network security. Cloudflare processes information on our behalf, under a data processing agreement, and may not use it for its own purposes except as that agreement allows, such as to keep its network secure.
Apple and Google
When you use Sign in with Apple or Google Sign-In, buy Plus through the App Store or Google Play, back up to iCloud or Google Drive, or use Google's ML Kit on Android, Apple or Google provides that service to you under its own terms and privacy policy, generally as an independent controller. We exchange with them only what the service needs, as described in section 3. Your iCloud and Google Drive accounts are yours, under your own agreements with Apple and Google.
People you choose to share with
When you send a gift brief, anyone who has the whole link can open it.
Legal requests and safety
We may disclose information if we believe in good faith that the law requires it (for example, a valid court order), or that it's necessary to protect the rights, property or safety of our users, the public or Fondfully. We'll tell you about a request for your information unless the law or the circumstances don't allow it. Because we don't have your vault or its keys, we can't disclose your vault to anyone.
Business changes
If Fondfully is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that deal. We'll make sure this policy continues to protect it, or give you notice and a choice before it becomes subject to a different policy.
With your consent
We'll share information for any other purpose only with your consent.
9. No ads, no selling, no tracking
- There are no ads in Fondfully, and there never will be.
- We don't sell personal information, and we don't share it for cross-context behavioral advertising, as California law defines those terms. We haven't done so in the past 12 months.
- The apps contain no third-party analytics, advertising, attribution, crash-reporting or tracking software. We don't track you across other companies' apps or websites, and we never use advertising identifiers.
- fondfully.com sets no cookies of its own and has no analytics. See our Cookie Statement.
- Affiliate links are optional and off by default. If you turn them on, the tag is added to some store links on your device when you open them, and we don't learn what you opened or bought. The store may use its own cookies to credit the purchase to our tag. See our Affiliate Disclosure.
- We treat a Global Privacy Control signal as a request to opt out of selling and sharing, although we don't do either.
10. International transfers
We are based in the United States, and Cloudflare processes information in the United States and in other countries where it operates. Some countries may not have data protection laws equivalent to those where you live.
When we transfer personal information from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss adaptations where needed (including those in Cloudflare's data processing agreement), or on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where that applies. You can ask us for a copy of the relevant safeguards at privacy@fondfully.com.
11. How we protect information
- Your vault is encrypted on your device with AES-256-GCM before it reaches your cloud. Vault passphrases are strengthened with PBKDF2-HMAC-SHA256 at 600,000 iterations, and recovery codes carry 160 bits of randomness.
- Gift briefs and their claims are encrypted on the sender's and visitor's devices, with a key we never receive.
- Every connection to our servers is encrypted in transit, and our servers enforce HTTPS.
- Passwords are stored only as salted scrypt hashes. Sign-in tokens last 30 minutes; longer-lived refresh tokens are stored as hashes and replaced each time they're used, and reusing an old one signs the account out everywhere.
- An account can't be used, or connected to Apple or Google, until its email address is verified.
- Requests are rate-limited, and our servers send strict security headers.
- Information on our servers is stored with Cloudflare, encrypted at rest. Especially sensitive items, such as Google purchase tokens and Apple sign-in tokens, are also encrypted with our own key.
- Only authorized team members can use our admin console, which sits behind Cloudflare Access and requires separate staff accounts with roles, lockouts after failed sign-ins and an audit log. Staff can see account and support information when they need it to help you, never your vault.
- The apps contain no third-party analytics, advertising or tracking code.
No system is perfectly secure. If a breach affects your personal information, we'll notify you and the relevant authorities as the law requires. You can help by using a strong password, turning on app lock, and keeping your recovery code somewhere safe. To report a security issue, see our Security and Vulnerability Disclosure policy.
12. Children
Fondfully is for people 16 and older, and everyone confirms their age when they create an account. The Service is not directed to children, and we don't knowingly collect personal information from anyone under 16 (or under 13, for the purposes of the US Children's Online Privacy Protection Act). If we learn that someone under 16 has created an account, we'll delete it. If you believe a child has given us personal information, please contact privacy@fondfully.com.
Many people use Fondfully to plan gifts for their own children. Anything a parent or guardian records about their children (names, birthdays, ages, sizes, interests, allergies, photos and notes) stays in the parent's vault, on their devices and in their own cloud, encrypted, and never reaches our servers. If you share a gift brief about your child, it's encrypted so we can't read it; please share it only with people you trust.
13. Your rights
For everyone
Wherever you live, you can:
- See and export the information we hold about your account (Settings › Privacy & security › Export account data), and export your vault (Settings › Privacy & security › Export your vault).
- Correct your name in the app, or write to us about anything else.
- Delete your account and the information on our servers (Settings › Account › Delete account), and choose whether to delete your vault from your cloud and device.
- Change your mind about usage statistics and crash reports in Settings › Privacy & security.
- Ask us about anything in this policy at privacy@fondfully.com.
European Economic Area, United Kingdom and Switzerland
Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection, you have the right to:
- access your personal information and receive a copy;
- have inaccurate information corrected;
- have your information erased;
- restrict how we use your information;
- receive information you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller (portability);
- object at any time to our use of your information based on legitimate interests, including diagnostics;
- withdraw your consent at any time, without affecting what we did before you withdrew it;
- not be subject to decisions based solely on automated processing that significantly affect you (we don't make any); and
- complain to a data protection supervisory authority, particularly where you live or work, or where you think the law was broken. In the UK, that's the Information Commissioner's Office. We'd appreciate the chance to help first.
California
If you're a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights below. This section also serves as our notice at collection.
In the past 12 months we have collected these categories of personal information, from you, your device, and Apple and Google, for the business purposes described in sections 3 and 5:
- Identifiers: email address, account number, Apple or Google account identifier, IP address (used transiently), and random installation identifiers.
- Customer records: name and email address.
- Commercial information: records of Plus purchases and codes you redeem.
- Internet or other electronic network activity: signed-in device records, diagnostics, crash reports, support diagnostics and, if you turn them on, usage statistics.
- Audio, electronic or visual information: screenshots you choose to attach to a problem report.
- Sensitive personal information: your account login (email and password). We use it only to let you sign in and keep your account secure, as the CCPA regulations permit, not to infer anything about you.
We disclose these categories only to the service providers and in the circumstances described in section 8. We keep each category for the periods in section 7. We do not sell or share personal information, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.
You have the right to:
- know what personal information we have collected about you, the categories of sources, the purposes, and the categories of recipients, and to get a copy of specific pieces of it;
- delete personal information we collected from you;
- correct inaccurate personal information;
- opt out of the sale or sharing of your personal information (we don't sell or share it);
- limit the use of sensitive personal information (we use it only for the permitted purposes above, so there's nothing further to limit); and
- not be discriminated against for exercising any of these rights.
You can use an authorized agent to make a request on your behalf. We may ask the agent for signed permission from you, and ask you to confirm your identity with us directly.
California's "Shine the Light" law lets you ask about disclosures to third parties for their direct marketing. We don't make any such disclosures.
Other US states
Residents of other states with consumer privacy laws, including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, have similar rights to access, correct, delete and port their information, and to opt out of targeted advertising, sale and profiling. We don't do any of those things, and we honor these rights for everyone, wherever they live.
If we decline your request, you can appeal by replying to our decision with the word "Appeal" or by writing to privacy@fondfully.com. We'll respond within 45 days (or the time your state's law sets). If you're not satisfied with the outcome of your appeal, you can contact your state's attorney general.
Nevada residents: we don't sell covered information as Nevada law defines it.
14. How to exercise your rights
- In the app: Settings › Privacy & security › Export account data, Settings › Privacy & security › Export your vault, and Settings › Account › Delete account.
- By email: write to privacy@fondfully.com from the email address on your account and tell us what you'd like. If you can't sign in, our Account Deletion page explains how we'll help.
We'll confirm the request comes from you, usually by email to the address on your account. We will never ask for your password, vault passphrase or recovery code.
We respond within one month under the GDPR and UK GDPR, which we may extend by up to two further months for complex requests, and within 45 days under the CCPA, which we may extend by up to 45 further days. We'll tell you if we need longer, and why. Requests are free, unless they're clearly unfounded or excessive.
Because your vault never reaches us, we can't access, correct, export or delete it on your behalf. You can do all of that yourself in the app, or directly in your iCloud or Google Drive.
15. Changes to this policy
When we change this policy, we'll publish the new version with a new date at the top, and earlier versions will stay available on fondfully.com. If a change is significant, we'll tell you in the app or by email before it takes effect, and where the law requires your consent, we'll ask for it. The app records which version you accepted.
16. Contact us
- Email: privacy@fondfully.com
- Post: Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States
Other versions
- Version 2026-09-24 · effective September 24, 2026 (current)