Privacy Policy
Last updated: January 2025
Introduction
GiftSnitch ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our gift tracking application.
Information We Collect
Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Password (encrypted)
- Profile information from Google if you sign in with Google OAuth
Gift and Family Data
To provide our service, we collect information you enter about:
- People's names, ages, and favorites
- Gift details including names, prices, descriptions, and status
- Wishlist items and their sources
- Images you upload
Automatically Collected Information
When you use GiftSnitch, we automatically collect:
- IP address (for rate limiting and security)
- Browser type and version
- Device information
- Usage patterns and feature interactions
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Track gifts and calculate spending fairness across children
- Generate AI-powered gift suggestions based on people's ages and favorites
- Send transactional emails (password resets, magic links, wishlist shares)
- Protect against fraud and abuse
- Communicate with you about service updates
Third-Party Services
We use the following third-party services to operate GiftSnitch:
Cloudflare
Our application is hosted on Cloudflare Workers, and we use Cloudflare D1 for database storage and R2 for image storage. Cloudflare may collect technical data as described in their privacy policy.
Google OAuth
If you choose to sign in with Google, we receive your email address and basic profile information. We do not access your Google contacts, calendar, or other data.
Anthropic (Claude AI)
We use Anthropic's Claude AI to generate personalized gift suggestions. When you request suggestions, we send people's ages, favorites, and budget parameters to generate recommendations. This data is not stored by Anthropic for training purposes.
Resend
We use Resend for transactional email delivery. Your email address is shared with Resend solely for the purpose of delivering emails you've requested or that are necessary for service operation.
Data Storage and Security
We implement appropriate technical and organizational measures to protect your personal data:
- All data is transmitted over HTTPS
- Passwords are hashed using industry-standard algorithms
- Session tokens are securely generated and stored
- Database access is restricted and monitored
- Images are stored in secure cloud storage with access controls
Data Sharing
We do not sell your personal information. We share data only in the following circumstances:
- With your group members: When you invite group members or share wishlists, they can see relevant gift and member information.
- With wishlist viewers: When you share a wishlist link, recipients can see the items on that list.
- With service providers: As described above, to operate our service.
- For legal requirements: If required by law or to protect our rights.
Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your account and data
- Export: Export your gift and group data
To exercise these rights, please contact us at the email address below.
Children's Privacy
GiftSnitch is designed for group members to track gifts for others. We do not knowingly collect information directly from children under 13. The child information entered into GiftSnitch is provided by parents or guardians.
Cookies and Local Storage
We use essential cookies and local storage to:
- Maintain your login session
- Remember your preferences
- Provide security features
We do not use advertising or tracking cookies.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at: