Privacy Policy
How Fondfully handles personal information, where your vault lives (on your devices and in your own cloud, never on our servers), and the choices and rights you have.
The short version
- Your vault stays with you. The people you shop for, their sizes and dates, your ideas, gifts, receipts, photos, voice notes and notes live on your devices, and in your own iCloud or Google Drive if you turn on backup, encrypted on your device first. They never reach our servers, and we can't read them.
- Our servers hold only what we need to run your account: your email address, how you sign in, your plan, the devices you're signed in on, messages you send us, any gift briefs you share (encrypted so we can't read them) and short-lived technical logs.
- No ads, no selling, no tracking. Ever. We don't use third-party analytics, advertising or tracking tools in Fondfully, and we don't sell your information or share it for advertising.
- You choose what we measure. Anonymous diagnostics help us fix bugs. Usage statistics are off unless you turn them on. Crash reports are sent only when you tap Send.
- You're in control. Export or delete your data from the app at any time, or write to privacy@fondfully.com.
1. Who we are
Fondfully is provided by Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States ("Fondfully", "we", "us" or "our"). We decide how and why the personal information described in this policy is used, so we're responsible for it: its "controller", or under California law, the "business" that collects it.
This policy covers the Fondfully apps for iPhone and Android, the website fondfully.com (including gift brief pages), our servers and our support channels (together, the "Service"). It doesn't cover services you use alongside Fondfully, such as your Apple or Google account, iCloud, Google Drive, the App Store, Google Play or the stores whose links you open. Their own privacy policies apply to them.
Fondfully is not currently offered in the European Economic Area or the United Kingdom, so we have not appointed a representative there under Article 27 of the GDPR or the UK GDPR. If you use Fondfully while you're there, the rights in section 13 still apply to you. You can reach us about anything in this policy at privacy@fondfully.com.
2. How Fondfully is built
Your vault stays with you
Your vault is the information you keep in Fondfully: the people you shop for and their relationships, birthdays, sizes, interests, likes, dislikes and allergies; your occasions, ideas, gifts, budgets, hiding spots, receipts and warranties; photos, voice notes, memories and notes; and your in-app settings.
Your vault is stored in the app's private storage on your device, protected by your device's own encryption, with an optional app lock. If you turn on backup or sync, the app encrypts your vault on your device with AES-256-GCM, using a vault key created on your device, before copying it to your own iCloud Drive (on iPhone) or Google Drive (on iPhone or Android). Apple or Google stores the encrypted files in your account, under your agreement with them.
We never receive your vault, your vault key, your vault passphrase or your recovery code. On iPhone with iCloud, the vault key is kept in your iCloud Keychain, which Apple protects with end-to-end encryption. With Google Drive, the key is protected by a passphrase you choose, which never leaves your device. Both also have a recovery code that only you hold. Because we hold none of these, we cannot read, recover, restore, hand over or delete your vault; only you can.
Your phone's own backups. Fondfully keeps your vault out of your phone's own backups. On iPhone, it isn't included in iCloud Backup or in a backup to your computer; on Android, Fondfully opts out of Google's automatic device backup. Your vault is backed up only by Fondfully's own encrypted backup, if you turn it on.
Fondfully asks only for access to its own folder in your cloud. In Google Drive, it uses Google's "app data" permission, which covers a hidden folder that only Fondfully can see, and nothing else in your Drive. In iCloud, it uses Fondfully's own app container. The access you give Fondfully to Google Drive stays on your device: our servers never receive your Drive files or access to your Drive. Fondfully's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What happens on your device
Several features work entirely on your device, so the information involved never reaches us:
- Link previews. When you paste a link, your device fetches the preview (title, picture, price) directly from that website, without cookies. The website sees an ordinary request from your device; we don't.
- Receipt scanning and reading. On iPhone, Apple's document camera and text recognition run on your device. On Android, Google's ML Kit document scanner and text recognition run on your device, and your receipt images and text are not sent to Google or to us. ML Kit may send Google performance and usage metrics, including device details (manufacturer, model and system version), the app's name and version, how the feature was used and how it performed, and device and installation identifiers (which Google says aren't intended to identify you). Google says it uses these metrics to measure performance, fix problems, maintain and improve ML Kit and detect misuse, and doesn't transfer them to third parties; see Google's ML Kit data disclosure and ML Kit terms.
- Voice notes. Recordings stay in your vault. Where your device supports on-device speech recognition, a suggested title is created on your device.
- Contacts import. If you import birthdays, the app reads names and birthdays from your contacts on your device and adds only the people you pick. Nothing is written back to your contacts, and nothing from them is sent to us.
- Reminders, budgets and repeat alerts are calculated and scheduled on your device.
- Exports are created on your device and go wherever you send them.
Permissions the apps ask for
The apps may ask for these permissions, only when you first use a feature that needs one. Each is optional, and you can change your mind in your device's settings:
- Notifications, for reminders.
- Contacts, to import birthdays (read only).
- Camera, to scan receipts and take photos.
- Photos, to choose a picture from your library.
- Microphone, and on iPhone speech recognition, for voice notes.
- Face ID or biometrics, for app lock. Your device checks your face or fingerprint itself; Fondfully only learns whether it matched, and never receives biometric data.
- iCloud or Google Drive, for backup and sync, as described above.
3. What we collect and why
Information you give us
- Account information: your email address; a password if you choose one (stored only as a salted scrypt hash, never in readable form); an optional display name; your confirmation that you're 18 or older (we record that you confirmed, and when, never your date of birth); and which versions of our Terms of Service and this Privacy Policy you accepted, when, and on which platform, app version and build. We also note when you last used Fondfully, and on which platform. We use this to create and secure your account and to show what you agreed to.
- Support messages: when you use Contact us, Report a problem or Suggest a feature in the app, we receive what you write, the email address you give us (or your account email if you're signed in), which account it came from if you're signed in, and which platform and app version you sent it from. A problem report can also include, if you leave "Include diagnostic details" on, your system version, device model and the last 200 lines of the app's technical log. The apps don't write vault content to that log, and email addresses, sign-in tokens and codes, web address details and long numbers are removed on your device and again on our servers. You can attach a screenshot (PNG, JPEG, HEIC or WebP, up to 2 MB). Screenshots show whatever was on your screen, so please check them first. We use all of this to help you and to fix problems.
- Emails you send us: when you write to support@, privacy@, security@ or hello@fondfully.com, your message, your email address and anything you attach arrive in our team's email inbox (see section 8). We use them to reply to you and to handle what you asked for.
- Promo codes you redeem, so we can give you what the code includes.
- Gift briefs you choose to share, which are encrypted before they leave your device (see "Gift briefs and the people you share them with" below).
- Privacy and deletion requests you send us, so we can act on them and show that we did.
Information from Apple and Google
- Sign in with Apple: a stable Apple user identifier, the email address Apple shares with us (which may be a private relay address if you choose Hide My Email), your name if you choose to share it, and a token that lets us end Fondfully's access to your Apple sign-in when you delete your account or disconnect Apple. We keep that token encrypted.
- Google Sign-In: a Google account identifier, your email address (which Google must have verified), and your name.
- Purchases of Fondfully Plus. Apple and Google process your payment; we never receive your card details or billing address. The app gives the store a reference derived from your account number, which contains no email or name, so that purchases can be matched to your account. The store then shares signed purchase information with us. Apple also sends us updates when a subscription renews, lapses or is refunded, and we check with Google Play when you open the app, as a subscription comes up for renewal, and daily for refunds. We keep the product, the store's transaction or order identifiers, whether it's your own purchase or shared with you through Family Sharing, its status, whether it will renew, and its renewal and expiry dates. We keep Google's purchase token encrypted. We also keep the price and currency you paid and, for Plus Yearly, the store's price for your next renewal, so our confirmation, receipt and reminder emails can show them. The information stores send us can also include the country of purchase; we don't keep it. We keep a record of each billing email we send you (which kind, for which purchase and renewal, and whether it was sent), so each goes out once. When you subscribe to Plus Yearly, we also keep a record that you agreed to its automatic renewal: the store, the store's transaction references (for Google Play, a one-way hash of the purchase token), the product, whether it was a test purchase, when you agreed, your app version and build, the version of our Subscription Terms, and when the subscription ends. It contains no email address or name.
- Your age range, where the law requires it. In US states whose app store laws require it, the app checks the age range Apple or Google provides for your store account (such as "18 or older") and doesn't let anyone under 18 use Fondfully. The check happens on your device, which remembers only the result and when it last checked; we don't receive or keep your age range.
Information collected automatically
- Connection information. When your device or browser talks to our servers, it sends its IP address and basic details, such as the address it's asking for, its software (the "user agent") and, from the apps, the app version. We use your IP address in the moment to deliver responses, to limit how often requests can be made, and to protect against abuse; our servers don't keep it. They keep their own technical logs for 7 days, so we can spot and fix problems: for each request, its time, the kind of request, the full web address requested, the response and how long it took, and the platform and app version, plus short error messages and the results of our daily jobs. Cloudflare stores these logs for us. They contain no IP addresses, no request headers and nothing you send us. Because the web address is recorded in full, a log line can include the part of a gift brief link before the "#" (never its key) and, when our team looks up an account in our admin console, that account's number or the email address they searched for. Separately, Cloudflare's security tools keep sampled records of requests to our servers and website, which can include the IP address and the country it comes from, for up to 31 days.
- Signed-in devices. For each sign-in we keep the platform, your device model as the app reports it (such as "iPhone 17 Pro" or "Pixel 9", never the name you've given your device), the app version, and when the session was created, last used and ended. You can see these in Settings › Signed-in devices. We use them to keep you signed in, to let you sign out anywhere, and to email you when your account is signed in on another device.
- Anonymous diagnostics. When something goes wrong in the app, like a failed sync, it sends a short technical report: the kind of event, how serious it is and when it happened, a technical title and message, your app version and build, platform and system version, device model, language and region setting, and whether the app was in use. The apps never put vault content in these reports, and send them without your account details. Before a report is stored, our servers also remove email addresses, phone and card-like numbers, IP addresses and long identifiers, cut web addresses down to the site and page, and blank out any extra detail whose label suggests personal content, such as a name, title or note. We store reports without your account details or IP address, so they aren't linked to you or your account. We use them to find and fix problems.
- Usage statistics (only if you turn them on). If you choose "Share anonymous stats" during setup, or turn on Settings › Privacy & security › Share anonymous usage statistics, the app sends counts of which screens and features are used (for example, that an idea was tucked away and how it was added, or which cloud you chose for backup), with the time, your platform and app version, and a random identifier created on your device for this installation. The identifier isn't linked to your account and changes if you reinstall. These statistics never include your people, gifts, notes, titles, prices or anything you type, your location or any advertising identifier, and we store them without your account details or IP address. We use them to understand which parts of Fondfully are useful and to improve it.
- Crash reports (only when you tap Send). After the app closes unexpectedly, it can offer to send a crash report the next time you open it. If you tap Send, we receive technical details of the crash (such as the error, the app code involved, your app version, system and device model). Nothing is sent unless you tap Send.
- Feature rollouts. When the app checks for settings and new versions, it includes a random identifier, separate from the usage statistics one, so that new features can be switched on for a share of installations at a time. We use it only for that calculation and don't keep it.
- Notes from our team. If our support team helps you, they may add a short internal note to your account, or record that they gave you Plus, with a short note on why (for example, while a store problem was sorted out). These are deleted with your account.
Gift briefs and the people you share them with
A gift brief is a web page you create in the app to share sizes, interests and ideas with family. Depending on what you include, it can also list things to avoid and allergies. When you send one, the app encrypts it on your device with a new key made just for that brief. The key goes into the part of the link after the "#" sign, which browsers never send to servers, so it never reaches us. We store only the encrypted brief, its size, when it was created and when it expires, which account created it, and how many claims it has received and when the last one was made.
When someone opens your link, their browser downloads the encrypted brief from our servers and decrypts it on their device. If they claim an idea, the claim (their name, an optional note and which idea) is encrypted in their browser with the same key, so we can't read it either. Everyone who has the link can see who claimed what, so nobody buys the same thing twice. To keep automated abuse out, the claim form uses Cloudflare Turnstile, which checks the visitor's browser and connection and tells us only whether the check passed. We use a visitor's IP address in the moment to deliver the page, limit requests and run that check. We don't keep it (apart from Cloudflare's sampled security records, described in section 3), and we never use it to identify anyone.
Briefs and their claims are kept until the brief expires (at most 120 days after you create it) or you stop sharing it. When you stop sharing, the encrypted brief and its claims are deleted straight away, and the rest of its record within a day. When a brief expires, its link stops working at once, and we delete the encrypted brief, its claims and its record within 24 hours.
Anyone who has the whole link can open a brief, so please share links only with people you trust, and only information you're comfortable sharing.
4. What we never collect
- The contents of your vault, including the people you shop for and anything about them, your gifts, receipts, photos, voice notes and notes.
- Health information. Allergy notes and similar details about the people in your vault stay in your vault. If you include allergies in a gift brief, they're encrypted with a key we never receive, so we can't read them.
- Your vault key, vault passphrase or recovery code.
- Your contacts. Importing birthdays happens on your device.
- Anything in your iCloud or Google Drive. The app reads and writes only its own encrypted files there, and never sends them to us.
- Your location. We never ask your device for it. (Cloudflare's sampled security records, described in section 3, can note the country an IP address comes from, never your precise location.)
- Advertising identifiers, such as Apple's IDFA or Google's Advertising ID.
- Your payment card details or billing address.
- Your date of birth or age range. We only record that you confirmed you're 18 or older.
- Biometric data.
- Which product links you open, or what you buy.
5. How we use information, and our legal bases
We use personal information only for the purposes below. If you're in the European Economic Area, the United Kingdom or Switzerland, the legal basis for each purpose is shown in brackets.
- Creating your account, signing you in, keeping you signed in, verifying your email, resetting your password and showing your signed-in devices (necessary to perform our contract with you).
- Recording your age confirmation and the versions of our terms you accepted, and checking your age range where state law requires it (our legitimate interest in showing what you agreed to and that we don't provide the Service to anyone under 18, and compliance with legal obligations).
- Providing Plus: verifying purchases, keeping your plan up to date across devices, restoring purchases, applying Family Sharing and redeeming codes (necessary to perform our contract with you).
- Automatic renewal records: keeping a record that you agreed to Plus Yearly's automatic renewal (compliance with legal obligations).
- Gift briefs: storing and delivering the encrypted briefs you share and the encrypted claims made on them (necessary to perform our contract with you; for the people who open a brief, our legitimate interest in delivering the page they were sent and protecting it from abuse).
- Support: answering your messages and emails, investigating problems you report and considering your suggestions (necessary to perform our contract with you, and our legitimate interest in improving the Service).
- Service emails: verification codes, password resets, sign-in alerts, support replies, subscription confirmations, Plus Lifetime receipts, renewal reminders, price change notices and other important notices (necessary to perform our contract with you, compliance with legal obligations, and our legitimate interest in keeping your account secure).
- Security and abuse prevention: limiting request rates, keeping short-lived technical logs and security records, detecting misuse and suspending accounts that break our terms (our legitimate interest in keeping Fondfully and its users safe, and compliance with legal obligations).
- Anonymous diagnostics: finding and fixing problems (our legitimate interest in providing a reliable app). You can object at any time; see section 13.
- Usage statistics (your consent, which you can withdraw at any time in Settings).
- Crash reports (your consent, given each time you tap Send).
- Feature rollouts: switching new features on for a share of installations at a time (our legitimate interest in releasing changes safely).
- Running our business: counting sign-ups, upgrades, cancellations and which app versions and platforms are in use, from our account and purchase records, as totals without names (our legitimate interest in understanding and sustaining the Service).
- Legal matters: complying with the law, responding to lawful requests, and establishing, exercising or defending legal claims (compliance with legal obligations, and our legitimate interests).
Where we rely on legitimate interests, we have weighed them against your rights and expectations, and we use the least information we can. We don't use your information to train artificial intelligence or machine learning models, including large language models, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
Providing an email address and password, or using Sign in with Apple or Google, is necessary to create an account; without it you can't use Fondfully. Other information, such as support messages, usage statistics, crash reports and gift briefs, is up to you.
6. Emails we send
We send only service emails: verification codes, password reset links, alerts when your account is signed in on another device, confirmations that we received your message, replies from our support team, confirmation that your account was deleted, and important notices about your account, the Service or changes to our terms. If you subscribe to Plus Yearly, the law also requires us to email you a confirmation of its renewal terms when you subscribe, reminders 35 and 20 days before each yearly renewal, and notice before any price increase; our Subscription Terms explain them. If you buy Plus Lifetime, we email you a receipt. Each of these goes once, and we try again the next day if sending fails. We don't send marketing emails. If we ever offer a newsletter, you'll only receive it if you ask for it, and you'll be able to unsubscribe from every issue.
Emails are sent from no-reply@fondfully.com, with replies going to support@fondfully.com, using Cloudflare's email service. They contain no tracking pixels or tracked links. To prevent duplicates and diagnose delivery problems, we record which kind of email was sent, when, and whether it was delivered, with your address stored only as a one-way hash, for 30 days. Cloudflare's email service also keeps a delivery log for us, with the sender's and recipient's addresses and the subject line, for up to 31 days. It doesn't keep copies of the messages.
7. How long we keep information
- Account information is kept for as long as you have an account. When you delete your account in the app, we delete it from our live systems within 24 hours. When you ask us by email, we do the same within 24 hours of confirming the request is yours. If Apple can't be reached to end Fondfully's access to your Apple sign-in, we keep only the encrypted Apple token, for up to 30 days, to try again.
- Unverified accounts. An account created with an email address and password can't be used until the address is verified. If it never is, we delete the account 30 days after the last attempt to sign up with that address.
- Server backups. Our database keeps a rolling 30-day history for recovery, and we keep nightly backup copies (without passwords) for 30 days, so deleted information disappears from backups within 30 days. We use backups only to recover from a technical failure, and if we ever restore one, we delete again any information that had been deleted since.
- Signed-in devices are kept while you're signed in on them, and for 30 days after you sign out, sign out everywhere, or the session expires (after 30 days without use); then they're deleted.
- Verification codes expire after 15 minutes and are deleted within two days. Password reset links expire after 30 minutes and are deleted within eight days.
- Purchase records, including the price and currency, are kept while you have an account. Records of the billing emails we send you are kept for two years (reminders and price change notices) or until you delete your account (confirmations and receipts), and all of them go when you delete your account. Apple's notifications about purchases, which identify a purchase only by Apple's transaction number, are kept for 180 days.
- Records of your agreement to automatic renewal are kept for at least three years, or until one year after your Plus Yearly subscription ends if that's later, even if you delete your account, because California law requires it (Business and Professions Code section 17602(a)(6)). They contain no email address or name, and we delete them when that period ends. After you delete your account, Apple's purchase notifications can still update when an App Store subscription ends, which sets that period.
- Anonymous diagnostics and crash reports are deleted 90 days after we receive them.
- Usage statistics: individual events are deleted after 90 days. Daily totals (how many times each screen or feature was used, and by how many installations, per platform and app version) contain no identifiers and are kept indefinitely.
- Support conversations in the app are kept until two years after we mark them resolved or closed or, if one is still open, two years after its last message or update, unless you ask us to delete them sooner. Screenshots are deleted with their conversation, and no later than two years after you send them; one that never gets sent with a report (for example, because sending failed) is deleted within two days. When you delete your account, conversations linked to your account or sent from your account's email address are deleted with it, screenshots included.
- Emails you send to our addresses are kept in our team's inbox for up to two years after the conversation ends, unless you ask us to delete them sooner. Deleting your account in the app doesn't reach our inbox, so if you'd like those emails deleted too, tell us; our Account Deletion page explains how.
- Gift briefs and claims are kept until the brief expires or you stop sharing it, as described in section 3.
- Our servers' technical logs are kept for 7 days, and Cloudflare's sampled security records for up to 31 days.
- Email records: our delivery records are kept for 30 days, and Cloudflare's delivery log for up to 31 days.
- Privacy requests and our replies are kept like other emails, for up to two years after the request is complete, so we can show how we handled them.
- A record of each account deletion is kept for three years so we can show we honored it. It contains only a one-way code derived from the deleted account's internal number, who asked for the deletion (you or our team) and when; no email address, name or other details.
- Our team's audit log records actions staff take on accounts (such as granting Plus or suspending an account), referring to accounts only by an internal number. When your account is deleted, its entries are detached from that number and any notes or reasons are removed. Audit entries are deleted after two years.
8. Who we share information with
We don't sell your personal information, and we don't share it for advertising. We disclose it only as follows, and we've named every company that receives it.
Service providers
These companies process information for us, only to provide their services to us. Our contracts with them limit how they may use it and require them to keep it confidential and secure, so it gets the same protection as this policy provides:
- Cloudflare, Inc. hosts our servers and website, and provides our database, file storage (for encrypted gift briefs, support screenshots and backups), server logs, email sending and receiving, bot protection (Turnstile) and network security. Cloudflare may also use request information to keep its network secure, and uses the signals Turnstile collects to improve its bot detection; it says it doesn't use them to identify, profile or target anyone.
- Google LLC provides our team's email inbox (Google Workspace). Emails you send to our @fondfully.com addresses are forwarded there, and we read and answer them there.
Apple and Google
When you use Sign in with Apple or Google Sign-In, buy Plus through the App Store or Google Play, back up to iCloud or Google Drive, or use Google's ML Kit on Android, Apple or Google provides that service to you under its own terms and privacy policy, generally as an independent controller. We exchange with them only what the service needs, as described in section 3, including, when you delete your account or disconnect Apple, asking Apple to end Fondfully's access to your Apple sign-in. Your iCloud and Google Drive accounts are yours, under your own agreements with Apple and Google.
People you choose to share with
When you send a gift brief, anyone who has the whole link can open it, and everyone with the link can see the names people give when they claim ideas.
Legal requests and safety
We may disclose information if we believe in good faith that the law requires it (for example, a valid court order), or that it's necessary to protect the rights, property or safety of our users, the public or Fondfully. We'll tell you about a request for your information unless the law or the circumstances don't allow it. Because we don't have your vault or its keys, we can't disclose your vault to anyone.
Business changes
If Fondfully is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that deal. We'll make sure this policy continues to protect it, or give you notice and a choice before it becomes subject to a different policy.
With your consent
We'll share information for any other purpose only with your consent.
9. No ads, no selling, no tracking
- There are no ads in Fondfully, and there never will be.
- We don't sell personal information, we don't share it for cross-context behavioral advertising, and we don't use it for targeted advertising or profiling, as US state privacy laws define those terms. We haven't done any of these in the past 12 months.
- The apps contain no third-party analytics, advertising, attribution, crash-reporting or tracking software. We don't track you across other companies' apps or websites, don't let other companies do so through our apps or website, and never use advertising identifiers. (Apple's and Google's own software that the apps rely on, such as ML Kit on Android, may report technical information to Apple or Google, as described in section 2.)
- fondfully.com sets no cookies of its own and has no analytics. See our Cookie Statement.
- Affiliate links are optional and off by default. If you turn them on, the tag is added to some store links on your device when you open them, and we don't learn what you opened or bought. The store may use its own cookies to credit the purchase to our tag. See our Affiliate Disclosure.
- Opt-out signals. Because we don't sell or share personal information or use it for targeted advertising, there's nothing to opt out of, and you don't need to do anything. If your browser sends a Global Privacy Control or "Do Not Track" signal, we treat it as a request to opt out of sale and sharing for that browser, and for your account if we can tell it's you. That changes nothing, because we already don't do either.
10. International transfers
We are based in the United States. Cloudflare processes information in the United States and in other countries where it operates, and Google processes our team's email in the United States and other countries. Some countries may not have data protection laws equivalent to those where you live.
When we transfer personal information from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, or on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss adaptations where needed (including those in Cloudflare's and Google's data processing terms). You can ask us for a copy of the relevant safeguards at privacy@fondfully.com.
11. How we protect information
- Your vault is encrypted on your device with AES-256-GCM before it reaches your cloud. Vault passphrases are strengthened with PBKDF2-HMAC-SHA256 at 600,000 iterations, and recovery codes carry 160 bits of randomness.
- Gift briefs and their claims are encrypted on the sender's and visitor's devices, with a key we never receive.
- Every connection to our servers is encrypted in transit, and our servers enforce HTTPS.
- Passwords are stored only as salted scrypt hashes. Sign-in tokens last 30 minutes; longer-lived refresh tokens are stored as hashes and replaced each time they're used, and reusing an old one signs the account out everywhere.
- An account created with an email and password can't be used until its email address is verified. Signing in with Apple or Google joins an existing account automatically only when both have the same verified email address; otherwise you connect them yourself in Settings while signed in.
- Requests are rate-limited, and our servers send strict security headers.
- Information on our servers is stored with Cloudflare, encrypted at rest. Especially sensitive items, such as Google purchase tokens and Apple sign-in tokens, are also encrypted with our own key.
- Only authorized team members can use our admin console, which sits behind Cloudflare Access and requires separate staff accounts with roles, lockouts after failed sign-ins and an audit log. Staff can see account and support information when they need it to help you, never your vault.
- The apps contain no third-party analytics, advertising or tracking code.
No system is perfectly secure. If a breach affects your personal information, we'll notify you, and the authorities where required, without unreasonable delay and as the law requires. You can help by using a strong password, turning on app lock, and keeping your recovery code somewhere safe. To report a security issue, see our Security and Vulnerability Disclosure policy.
12. Children and teenagers
Fondfully is only for adults, 18 and older. Everyone confirms they're 18 or older when they create an account, and in US states whose app store laws require it, the app also checks the age range Apple or Google provides and doesn't let anyone under 18 use Fondfully. The Service isn't directed to children or teenagers, and we don't knowingly collect personal information from anyone under 18, including children under 13 protected by the US Children's Online Privacy Protection Act. If we learn that an account belongs to someone under 18, we'll delete it. If you believe someone under 18 has given us personal information, please contact privacy@fondfully.com.
Many people use Fondfully to plan gifts for their children. Anything a parent or guardian records about their children (names, birthdays, ages, sizes, interests, allergies, photos and notes) stays in the parent's vault, on their devices and in their own cloud, and never reaches our servers. If you share a gift brief about your child, it's encrypted so we can't read it; please share it only with people you trust.
13. Your rights
For everyone
Wherever you live, you can:
- See and export the information we hold about your account. In the app, open Settings › Privacy & security and choose Export account data (on iPhone, it's at the bottom of the Export your vault page there). It includes your profile, sign-in methods (with your Apple or Google account identifier), signed-in devices, plan, purchases and codes, support messages and the details sent with them, shared briefs, and any notes our team added or actions we took on your account. For a copy of the screenshots or emails you sent us, write to privacy@fondfully.com. You can also export your vault (Settings › Privacy & security › Export your vault).
- Correct your name in the app, or write to us to correct anything else, such as your email address.
- Delete your account and the information on our servers (Settings › Account › Delete account), and choose whether to delete your vault from your cloud and device.
- Change your mind about usage statistics and crash reports in Settings › Privacy & security.
- Ask us about anything in this policy at privacy@fondfully.com.
We won't treat you differently, or charge you more, for using any of these rights.
European Economic Area, United Kingdom and Switzerland
Under the GDPR, the UK GDPR and the Swiss Federal Act on Data Protection, you have the right to:
- access your personal information and receive a copy;
- have inaccurate information corrected;
- have your information erased;
- restrict how we use your information;
- receive information you gave us in a structured, commonly used, machine-readable format, and have it sent to another controller (portability);
- object at any time to our use of your information based on legitimate interests, including diagnostics;
- withdraw your consent at any time, without affecting what we did before you withdrew it;
- not be subject to decisions based solely on automated processing that significantly affect you (we don't make any); and
- complain to a data protection supervisory authority, particularly where you live or work, or where you think the law was broken. In the UK, that's the Information Commissioner's Office. We'd appreciate the chance to help first.
California
If you're a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), gives you the rights below. This section, with sections 3, 5, 7 and 8, is also our notice at collection. It covers the 12 months before the effective date at the top of this policy.
What we collect. We have collected these categories of personal information:
- Identifiers: email address, account number, Apple or Google account identifier, IP address and random installation identifiers.
- Customer records: name and email address.
- Commercial information: records of Plus purchases (including price and currency), of your agreement to automatic renewal, of the billing emails we send you, and of codes you redeem.
- Internet or other electronic network activity: server logs, signed-in device records, diagnostics, crash reports, support diagnostics and, if you turn them on, usage statistics.
- Geolocation data: only the country that Cloudflare's security tools work out from an IP address in their sampled security records, never your precise location.
- Audio, electronic or visual information: screenshots you choose to attach to a problem report, and anything you attach to an email.
- Sensitive personal information: your account login (email address and password). We use it only to let you sign in and keep your account secure, as the CCPA regulations allow, not to infer anything about you.
We collect this information from you, from your device and browser, and from Apple and Google. We collect and use it for the business purposes in section 5: providing and securing your account and the Service, handling purchases, answering support, sending service emails, finding and fixing problems, releasing features safely, understanding how the Service is used (if you turn on usage statistics), and complying with the law.
Who receives it. In the past 12 months, we've disclosed each category above, for the business purposes above, to our service providers named in section 8: Cloudflare (hosting, storage, logs, email and security) and, for emails you send us, Google (our team's inbox). We also exchange identifiers and commercial information with Apple and Google when you ask us to, to sign you in and to verify your purchases. We have not sold or shared personal information in the past 12 months, and we have no actual knowledge of selling or sharing the personal information of consumers under 16. We don't use or disclose sensitive personal information for any purpose other than those allowed by section 7027(m) of the CCPA regulations.
How long we keep it. Section 7 has the details. In short:
- Identifiers, customer records and your login: while you have an account. Our server logs can hold an account number or email address our team looked up for 7 days. Our servers don't keep IP addresses, but Cloudflare's sampled security records can hold them for up to 31 days. The usage statistics identifier is deleted with its events, after 90 days, and the feature rollout identifier isn't kept.
- Commercial information: while you have an account (records of reminder and price change emails for two years at most); Apple's purchase notifications for 180 days; and records of your agreement to automatic renewal for at least three years, or one year after your subscription ends if that's later, as California law requires.
- Internet or other electronic network activity: server logs for 7 days; signed-in devices until 30 days after they end; diagnostics, crash reports and usage events for 90 days; support diagnostics with the support conversation.
- Approximate geolocation: up to 31 days, in Cloudflare's sampled security records.
- Screenshots and email attachments: with the conversation, and screenshots no longer than two years after you send them.
Your rights. You have the right to:
- know what personal information we have collected about you, the categories of sources, the purposes, the categories of third parties we disclose it to, and the specific pieces of information;
- delete personal information we collected from you, subject to certain exceptions (for example, the automatic renewal records the law requires us to keep, described in section 7);
- correct inaccurate personal information;
- opt out of the sale or sharing of your personal information (we don't sell or share it);
- limit the use of sensitive personal information (we use it only for the purposes the regulations allow, so there's nothing further to limit); and
- not be discriminated or retaliated against for using any of these rights.
Section 14 explains how to make a request, how we verify it, and how someone you authorize can make one for you. Section 9 explains how we handle Global Privacy Control and other opt-out preference signals.
California's "Shine the Light" law lets you ask about disclosures to third parties for their direct marketing. We don't make any such disclosures.
Other US states
Residents of other states with comprehensive consumer privacy laws, currently Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia (and Alabama, Louisiana, Oklahoma and Vermont once their laws take effect), have similar rights: to confirm whether we process their personal information, to access, correct and delete it and get a portable copy, and to opt out of targeted advertising, sale and profiling with legal or similarly significant effects. We don't sell personal information or use it for targeted advertising or such profiling, and we honor the other rights for everyone, wherever they live. Some states also let you ask for a list of the specific third parties we disclose personal information to; they're the companies named in section 8.
Appeals. If we decline your request, you can appeal by replying to our decision with the word "Appeal" or by writing to privacy@fondfully.com. We'll respond in writing within 45 days, explaining what we did and why. If you're not satisfied with the outcome of your appeal, you can contact your state's attorney general, and we'll tell you how in our reply.
Consumer health data. Washington's My Health My Data Act, and similar laws in Nevada, Connecticut and other states, protect information about a person's health. We don't collect, share or sell consumer health data. Allergy notes and similar details stay in your vault, and when you include them in a gift brief, they're encrypted with a key we never receive, so we can't read them or link them to anyone.
Nevada residents: we don't sell covered information as Nevada law defines it.
14. How to exercise your rights
- In the app: Settings › Privacy & security › Export account data (on iPhone, at the bottom of the Export your vault page), Settings › Privacy & security › Export your vault, and Settings › Account › Delete account.
- By email: write to privacy@fondfully.com from the email address on your account and tell us what you'd like. If you can't sign in, our Account Deletion page explains how we'll help.
Verifying your request. We'll confirm the request comes from you, usually by email to the address on your account. For information that isn't tied to an account, such as an email you sent us, we may ask for details only the sender would know. We'll never ask for your password, vault passphrase or recovery code, and we use what you give us to verify a request only for that purpose.
Authorized agents. Someone you've authorized can make a request for you. We'll ask them for your signed permission, and we may ask you to confirm your identity with us directly, unless they have a power of attorney.
Timing. We'll confirm we've received your request within 10 business days, and respond within 45 days. If we need more time, we'll tell you why within those 45 days and may take up to 45 more. Under the GDPR and UK GDPR, we respond within one month, which we may extend by up to two further months for complex requests. Requests are free, unless they're clearly unfounded or excessive.
Because your vault never reaches us, we can't access, correct, export or delete it on your behalf. You can do all of that yourself in the app, or directly in your iCloud or Google Drive.
15. Changes to this policy
When we change this policy, we'll publish the new version with a new date at the top, and earlier versions will stay available on fondfully.com. If a change is significant, we'll tell you in the app or by email before it takes effect, and where the law requires your consent, we'll ask for it. We won't start using information we already hold in a materially different way without your consent. The app records which version you accepted.
16. Contact us
- Email: privacy@fondfully.com
- Post: Epicalin, LLC, 1810 N Burning Bush Ln, Mount Prospect, Illinois 60056, United States
Other versions
- Version 2026-09-22 · effective September 22, 2026