Wishboard — Privacy Policy

Last updated: 1 August 2026

The short version. Wishboard stores the places you save, the boards you put them on, and the profile you choose to show other people. It does not request your location, does not read your photo gallery, shows no adverts and sells nothing to anybody.

Two things are worth knowing before you read further, because they are the parts people are most likely to be surprised by: a board you mark as shared becomes readable by anyone who has its link, and a photo you choose for a place is stored at an unguessable web address that does not require signing in. Both are explained in full below.

Who this is about

Wishboard is an Android app operated by Lyte Creations LLC (“we”), of 821 N St, Ste 102, Anchorage, AK 99501, US. For anything in this policy, including requests to see or delete your data, contact support@wishboard.travel.

Why we are allowed to hold your information

If you are in the United Kingdom or the European Economic Area, data protection law asks us to name a lawful basis for each thing we do with your information. What we do is set out in the sections below; the bases are:

Analytics sits inside that third basis, and is worth calling out rather than leaving buried there. Firebase Analytics starts when the app does, and there is no switch in the app to turn it off. The “Analytics” section below lists every event of our own that we record, and what none of them carries; if you would rather we did not, write to support@wishboard.travel and say so.

Where your information is held

Wishboard runs in the United States. We are a US company, and the Google Cloud and Firebase services behind the app are in US regions. The database holding your account, profile, boards and places is in Google’s United States multi-region — several US data centres treated as one place. The photos you upload sit in a single US region rather than a multi-region, in Iowa, which is also where the servers that run a scan are. If you use Wishboard from the UK, the EEA, or anywhere else outside the US, your information is transferred to the United States and handled there. The other companies named under “Who we share information with” below may in turn process it in countries of their own, each under its own terms.

What we collect, and why

Your account

To sign in you give us either an email address and a password, or your Google account — in which case Google passes us your email address, display name and profile picture. Sign-in is handled by Google Firebase Authentication; we never see or store your Google password, and passwords for email accounts are stored by Firebase, not by us.

Your profile

Your profile is a single record, and this is the whole of it: a display name, an @handle, a short bio, a profile picture, the account id we give you when you sign up, and four numbers — how many boards you have, how many places are saved on them, how many friends you have, and how many countries you have marked somewhere as visited. That last one is a total and nothing more: which countries they are is worked out from the visited marks on your boards, used to correct the total, and then thrown away — only the number is kept. Two more things sit on the record that you may not think of as profile fields, so they are worth naming:

Your profile is visible to other signed-in users — all of it, including those two — and that is what makes it possible for a friend to find you by your @handle and for your face to appear beside your votes on a shared board. It cannot be browsed or downloaded in bulk: there is no way to ask us for a list of accounts, so a profile has to be fetched one at a time by someone signed in who already knows which account they are asking for. Usually that is someone who has your @handle or shares a board with you — but not only those two, and the exception is worth being exact about. The web address of a place photo you upload contains your account id, and those addresses appear on any shared board page the photo is on, which anyone can read without signing in. So a stranger who opens a shared board page can take the id out of it and, once signed in, look up the profile it belongs to. Your email address is not part of your profile and is never shown to other users.

What you save

Boards and the places on them: titles, descriptions, locations, map coordinates, place types, your trip-planning choices, your votes on shared boards, whether you have marked somewhere as visited, and the links to any videos a place came from.

Photos you choose

If you pick your own photo for a place, the app resizes it on your device and uploads it to our storage. The app never browses your gallery — it uses the Android system photo picker, so you hand over one chosen image and nothing else is visible to us. Please see “What other people can see” below for how these are stored.

Notifications

If you allow notifications, your device registers a token with us so we can tell you when a scan finishes or when something happens on a shared board. You can revoke this at any time in Android’s settings, per category.

Analytics

We use Google Firebase Analytics, and these are the events of our own that we record, in full: that something was shared into the app, that a scanned place was saved to a board, that the introduction you see when you first open the app was finished or skipped, which screen of the app you opened (by name — for example “board” or “settings”), that a scan was refused because you had reached the free daily or monthly limit, that you tapped a booking link (recording only what kind it was — for example “stays” — which partner it went to, and whether you tapped it from a place or from a trip), and how an attempt to buy a paid tier ended (bought, restored, cancelled or failed, and nothing else — no price and no product). None of them carries the video, the place, the name of any board, or anything you typed. Firebase Analytics itself also collects standard device and usage information; Google documents this in its own terms.

Magic Scan: what leaves your device

You can scan three kinds of thing, and each sends something different to our server.

A link

We accept links from Instagram, TikTok, YouTube, Reddit, Pinterest and Google Maps. The link goes to our server, which then, on your behalf:

A screenshot

If you share an image into Wishboard, the image itself is sent to Google Gemini to read the places out of it, and the names it finds are looked up with the Google Places API. We do not keep the image: only the place names it produced are stored, against a fingerprint of the picture.

A note you typed

If you share or type plain text, that text is sent to Google Gemini and the place names it produces are looked up in the same way. Keep in mind that whatever you type is what gets sent — so a note is not the place for anything private.

No identifier of yours is sent to any of them. None of these services is told who you are, which account made the request, or anything about your other boards. They receive a link, or a name to look up, and nothing else.

We keep the result of a scan for 30 days — against the link’s address, or against a fingerprint of the screenshot or note — so that something many people share is analysed once rather than repeatedly. That cache holds the extracted place names only. It is not linked to you.

Scans are also limited, a number per day and a number per month, and unlike the cache those counts are kept against your account — there is no way to enforce a per-person limit without counting per person. Rate limits sit behind them for the same reason. Both exist because every scan costs us money to run; the Terms of Service set out what happens when you reach one, and the counts go when your account does.

What other people can see

This is the section worth reading twice.

Reporting, blocking and keeping the service safe

The reports, the blocks and the security logging named among the legitimate interests at the top of this policy are what this section is about, so here is what they actually involve.

If you report something

In the app you can report a person, a shared board, or a single place on one. A shared board page carries its own link to report that board, and using it needs no account, because the people who can read one of those pages are not all account holders.

A report records what it is about, the reason you picked from a fixed list, anything you typed in the box alongside it, and, if you were signed in, which account filed it — that last so that a pattern of malicious reporting is visible. A report filed from the shared board page records no account, and your network address is not stored: a rate limit needs some handle on where a flood is coming from, so what we keep instead is a hash of that address together with the day’s date, which changes every midnight. That is a rate-limiting handle rather than a promise of anonymity — the date is not a secret, so the hash is easier to work backwards than a hash usually sounds. The Terms of Service set out what we do about a report once it reaches us.

If you block someone

Blocking records that account against yours, ends the friendship in both directions, deletes any friend request pending either way, and clears from your inbox the notifications that account had put there. Only you can read your own block list — the person you blocked cannot see it, and neither can anybody else, which is deliberate: a block somebody can see is a block that invites a reply. The check that stops a blocked account reaching you again runs on our servers rather than in the app, so a modified app cannot step around it.

One thing a block honestly cannot do is take either of you off a group board you are both on: it changes who can reach you, not who is on a board. Unblocking removes the record; it does not put back the friendship the block ended.

Security logging

When the server refuses a request — a sign-in token it will not accept, a caller who has hit a limit, an upload larger than we allow — it writes one line saying which endpoint refused it and why, with the account id where there is one. That is what lets us tell one account grinding against a limit from many accounts each trying once, which is most of the difference between ordinary use and an attack. Those lines carry no email address, no network address and nothing you typed, they are written only when something is refused rather than for normal traffic, and they age out with the rest of our server logs.

What we do not do

Booking links

Wishboard may show links to travel booking sites, and we may earn a commission if you book after following one. These links are marked where they appear. They are ordinary links: nothing is sent to those companies unless you tap one, and even then no identifier of yours is included — the link carries the place or dates you were looking at and nothing about you. Following one takes you to that company’s own site, under its own privacy policy.

Who we share information with

We do not sell your information. We share it only with the services needed to run the app:

We may also disclose information where the law requires it.

How long we keep things

Your choices and your rights

Depending on where you live you may have additional rights — to a copy of your data, to have it corrected or erased, to object to how it is used, or to complain to your data protection regulator. Contact us and we will help.

Deleting your account

Deletion is permanent, immediate and not something we can undo: it erases your profile, your @handle, your own boards and the places on them, the photos you chose for places, your friends list, your inbox, your own block list and the record of your scans, and a board of your own that you had shared stops being reachable. A group board is not yours alone, and is handled differently — see just below.

Some things survive it. Some of that is deliberate, because a deletion that quietly destroyed other people’s things would be its own kind of wrong; the rest is a consequence of how the deletion works, set down here rather than left to be found out:

The ways to delete an account, most direct first:

Children

Wishboard is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will remove it.

Changes

If this policy changes in a way that matters, we will update the date at the top and say so in the app.