Wishboard — Privacy Policy
Last updated: 1 August 2026
The short version. Wishboard stores the places you save, the boards you put them on, and the profile you choose to show other people. It does not request your location, does not read your photo gallery, shows no adverts and sells nothing to anybody.
Two things are worth knowing before you read further, because they are the parts people are most likely to be surprised by: a board you mark as shared becomes readable by anyone who has its link, and a photo you choose for a place is stored at an unguessable web address that does not require signing in. Both are explained in full below.
Who this is about
Wishboard is an Android app operated by Lyte Creations LLC (“we”), of 821 N St, Ste 102, Anchorage, AK 99501, US. For anything in this policy, including requests to see or delete your data, contact support@wishboard.travel.
Why we are allowed to hold your information
If you are in the United Kingdom or the European Economic Area, data protection law asks us to name a lawful basis for each thing we do with your information. What we do is set out in the sections below; the bases are:
- Performing our agreement with you. Your account, your profile, your boards and the places on them, the photos you choose, running a scan you asked for, and publishing a board you told us to share. None of that is possible without holding the information it is made of.
- Your consent. Notifications. Android asks you for these separately, and you can withdraw at any time in Android’s settings, per category.
- Our legitimate interests in keeping Wishboard working, affordable and safe: the 30-day scan cache described under “Magic Scan” below, which exists so that something many people share is analysed once rather than repeatedly; the daily and monthly scan limits and the rate limits behind them; the reports, the blocks and the security logging set out under “Reporting, blocking and keeping the service safe”; and understanding which parts of the app are actually used, which is what the events listed under “Analytics” are for.
- Legal obligation, where the law requires us to keep or disclose something.
Analytics sits inside that third basis, and is worth calling out rather than leaving buried there. Firebase Analytics starts when the app does, and there is no switch in the app to turn it off. The “Analytics” section below lists every event of our own that we record, and what none of them carries; if you would rather we did not, write to support@wishboard.travel and say so.
Where your information is held
Wishboard runs in the United States. We are a US company, and the Google Cloud and Firebase services behind the app are in US regions. The database holding your account, profile, boards and places is in Google’s United States multi-region — several US data centres treated as one place. The photos you upload sit in a single US region rather than a multi-region, in Iowa, which is also where the servers that run a scan are. If you use Wishboard from the UK, the EEA, or anywhere else outside the US, your information is transferred to the United States and handled there. The other companies named under “Who we share information with” below may in turn process it in countries of their own, each under its own terms.
What we collect, and why
Your account
To sign in you give us either an email address and a password, or your Google account — in which case Google passes us your email address, display name and profile picture. Sign-in is handled by Google Firebase Authentication; we never see or store your Google password, and passwords for email accounts are stored by Firebase, not by us.
Your profile
Your profile is a single record, and this is the whole of it: a display name, an @handle, a short bio, a profile picture, the account id we give you when you sign up, and four numbers — how many boards you have, how many places are saved on them, how many friends you have, and how many countries you have marked somewhere as visited. That last one is a total and nothing more: which countries they are is worked out from the visited marks on your boards, used to correct the total, and then thrown away — only the number is kept. Two more things sit on the record that you may not think of as profile fields, so they are worth naming:
- Your home airport, if you have set one — the three-letter code of the airport you fly from, which is what lets a flight we show you start from your end of the journey rather than from nowhere. You choose it in the app’s settings and can clear it again at any time; blank is the starting point and we never fill it in for you. It says which airport your searches begin at — for a large airport, that is the city or region it serves; for a small one it is a smaller area — and it is not a location: the app does not ask for your location and does not have it.
- Roughly when you last opened the app — one value, written over each time, not a history of your sessions. Its only purpose is to decide whether to send you a reminder about a shared board: if you have been using the app, we stay quiet.
Your profile is visible to other signed-in users — all of it, including those two — and that is what makes it possible for a friend to find you by your @handle and for your face to appear beside your votes on a shared board. It cannot be browsed or downloaded in bulk: there is no way to ask us for a list of accounts, so a profile has to be fetched one at a time by someone signed in who already knows which account they are asking for. Usually that is someone who has your @handle or shares a board with you — but not only those two, and the exception is worth being exact about. The web address of a place photo you upload contains your account id, and those addresses appear on any shared board page the photo is on, which anyone can read without signing in. So a stranger who opens a shared board page can take the id out of it and, once signed in, look up the profile it belongs to. Your email address is not part of your profile and is never shown to other users.
What you save
Boards and the places on them: titles, descriptions, locations, map coordinates, place types, your trip-planning choices, your votes on shared boards, whether you have marked somewhere as visited, and the links to any videos a place came from.
Photos you choose
If you pick your own photo for a place, the app resizes it on your device and uploads it to our storage. The app never browses your gallery — it uses the Android system photo picker, so you hand over one chosen image and nothing else is visible to us. Please see “What other people can see” below for how these are stored.
Notifications
If you allow notifications, your device registers a token with us so we can tell you when a scan finishes or when something happens on a shared board. You can revoke this at any time in Android’s settings, per category.
Analytics
We use Google Firebase Analytics, and these are the events of our own that we record, in full: that something was shared into the app, that a scanned place was saved to a board, that the introduction you see when you first open the app was finished or skipped, which screen of the app you opened (by name — for example “board” or “settings”), that a scan was refused because you had reached the free daily or monthly limit, that you tapped a booking link (recording only what kind it was — for example “stays” — which partner it went to, and whether you tapped it from a place or from a trip), and how an attempt to buy a paid tier ended (bought, restored, cancelled or failed, and nothing else — no price and no product). None of them carries the video, the place, the name of any board, or anything you typed. Firebase Analytics itself also collects standard device and usage information; Google documents this in its own terms.
Magic Scan: what leaves your device
You can scan three kinds of thing, and each sends something different to our server.
A link
We accept links from Instagram, TikTok, YouTube, Reddit, Pinterest and Google Maps. The link goes to our server, which then, on your behalf:
- fetches the post — from Instagram, TikTok, Reddit or Pinterest using a third-party service (Bright Data), or reads it directly from YouTube;
- sends the video, images and caption to Google Gemini to identify the places shown or mentioned. Uploaded video is deleted after the scan;
- looks the resulting place names up with the Google Places API.
A screenshot
If you share an image into Wishboard, the image itself is sent to Google Gemini to read the places out of it, and the names it finds are looked up with the Google Places API. We do not keep the image: only the place names it produced are stored, against a fingerprint of the picture.
A note you typed
If you share or type plain text, that text is sent to Google Gemini and the place names it produces are looked up in the same way. Keep in mind that whatever you type is what gets sent — so a note is not the place for anything private.
No identifier of yours is sent to any of them. None of these services is told who you are, which account made the request, or anything about your other boards. They receive a link, or a name to look up, and nothing else.
We keep the result of a scan for 30 days — against the link’s address, or against a fingerprint of the screenshot or note — so that something many people share is analysed once rather than repeatedly. That cache holds the extracted place names only. It is not linked to you.
Scans are also limited, a number per day and a number per month, and unlike the cache those counts are kept against your account — there is no way to enforce a per-person limit without counting per person. Rate limits sit behind them for the same reason. Both exist because every scan costs us money to run; the Terms of Service set out what happens when you reach one, and the counts go when your account does.
What other people can see
This is the section worth reading twice.
- Private boards are private. Boards are private unless you choose otherwise.
- A shared board is readable by anyone with its link. Turning sharing on for a board publishes a web page showing its title, its country, and the places on it with their names, locations, photos and source links. No sign-in is needed. Turning sharing off takes the page down within about a minute.
- Group boards are visible to everyone on them, including anyone who joins later through an invite link. Everyone on a group board can add and edit its places, and can see who voted what.
- An invite link is a key. Anyone holding one can join that board. The page it opens shows only the board’s name and how many places and people are on it — never its contents.
- Place photos are stored at a public web address. A photo you choose is given a random, unguessable name, and anyone who has that exact address can open it without signing in. This is necessary because a shared board page has to display it to people who are not logged in. The address cannot be guessed or listed, but it is not secret, and it contains your account id — see “Your profile” above for what follows from that. Treat a photo you upload as something you are willing to be seen.
Reporting, blocking and keeping the service safe
The reports, the blocks and the security logging named among the legitimate interests at the top of this policy are what this section is about, so here is what they actually involve.
If you report something
In the app you can report a person, a shared board, or a single place on one. A shared board page carries its own link to report that board, and using it needs no account, because the people who can read one of those pages are not all account holders.
A report records what it is about, the reason you picked from a fixed list, anything you typed in the box alongside it, and, if you were signed in, which account filed it — that last so that a pattern of malicious reporting is visible. A report filed from the shared board page records no account, and your network address is not stored: a rate limit needs some handle on where a flood is coming from, so what we keep instead is a hash of that address together with the day’s date, which changes every midnight. That is a rate-limiting handle rather than a promise of anonymity — the date is not a secret, so the hash is easier to work backwards than a hash usually sounds. The Terms of Service set out what we do about a report once it reaches us.
If you block someone
Blocking records that account against yours, ends the friendship in both directions, deletes any friend request pending either way, and clears from your inbox the notifications that account had put there. Only you can read your own block list — the person you blocked cannot see it, and neither can anybody else, which is deliberate: a block somebody can see is a block that invites a reply. The check that stops a blocked account reaching you again runs on our servers rather than in the app, so a modified app cannot step around it.
One thing a block honestly cannot do is take either of you off a group board you are both on: it changes who can reach you, not who is on a board. Unblocking removes the record; it does not put back the friendship the block ended.
Security logging
When the server refuses a request — a sign-in token it will not accept, a caller who has hit a limit, an upload larger than we allow — it writes one line saying which endpoint refused it and why, with the account id where there is one. That is what lets us tell one account grinding against a limit from many accounts each trying once, which is most of the difference between ordinary use and an attack. Those lines carry no email address, no network address and nothing you typed, they are written only when something is refused rather than for normal traffic, and they age out with the rest of our server logs.
What we do not do
- We do not ask for or collect your device’s location. The app requests only internet access and, optionally, permission to send notifications.
- We do not read your photo gallery, contacts, calendar, messages or installed apps.
- We do not show adverts, and we do not sell or rent your information to anyone.
- We do not use your content to train our own models.
Booking links
Wishboard may show links to travel booking sites, and we may earn a commission if you book after following one. These links are marked where they appear. They are ordinary links: nothing is sent to those companies unless you tap one, and even then no identifier of yours is included — the link carries the place or dates you were looking at and nothing about you. Following one takes you to that company’s own site, under its own privacy policy.
Who we share information with
We do not sell your information. We share it only with the services needed to run the app:
- Google — Firebase (sign-in, database, file storage, notifications, analytics), Google Places and Google Maps, and Google Gemini for scanning.
- Bright Data — used only to fetch the public Instagram, TikTok, Reddit or Pinterest post you shared.
- RevenueCat — our subscription service, and only where we offer a paid tier. It is given your account id, and it is what tells our server whether a subscription of yours is running or has ended. The purchase itself goes through Google Play.
We may also disclose information where the law requires it.
How long we keep things
- Your account, profile, boards and places: until you delete them, or until you delete your account.
- The record of a scan in your in-app inbox, and the shared cache of scan results: 30 days, then deleted automatically.
- Reports, and the record that somebody blocked somebody: for as long as they are useful for moderation and safety. Neither is tied to the life of the account it is about — see “Deleting your account” below.
- Server logs used to operate and debug the service, including the security logging above: a short period, in line with Google Cloud’s defaults.
Your choices and your rights
- See or correct your data — your profile, boards and places are all editable in the app.
- Stop sharing — turn sharing off for a board at any time.
- Notifications — scan results and shared-board activity are separate categories in Android’s notification settings, so you can silence one and keep the other.
- Delete your account and everything in it — the routes are set out just below.
Depending on where you live you may have additional rights — to a copy of your data, to have it corrected or erased, to object to how it is used, or to complain to your data protection regulator. Contact us and we will help.
Deleting your account
Deletion is permanent, immediate and not something we can undo: it erases your profile, your @handle, your own boards and the places on them, the photos you chose for places, your friends list, your inbox, your own block list and the record of your scans, and a board of your own that you had shared stops being reachable. A group board is not yours alone, and is handled differently — see just below.
Some things survive it. Some of that is deliberate, because a deletion that quietly destroyed other people’s things would be its own kind of wrong; the rest is a consequence of how the deletion works, set down here rather than left to be found out:
- Places you added to a group board stay on it. That board belongs to everyone on it, and taking your places out of it would gut a shared trip plan the moment one person left. We take your account off the collaborator list and leave the board standing. Your name comes off your places, since the profile it pointed at is gone. A photo you chose for one of those places does go with your account, so a place like this keeps its name and location and loses its picture. The exception is a group board where you were the last person left: with nobody to keep it for, it is deleted along with everything on it.
- Reports about your account are kept, in full. If somebody reported you, that report stays as it was written, account id included. Letting the subject of a report erase it by closing their account would make reporting useless against exactly the accounts it exists for. Reports you filed about other people are kept as well, but the link back to you is cut: your account id is removed from them and they are marked as having no reporter any more.
- Blocks other people made against you stay. That is their own safety decision, recorded against your account id, and closing your account must not quietly undo it. Your own block list is not kept — it goes with your profile.
- Your account id stays on those group-board places. It is what recorded that you added a place, voted on it, marked it visited, or chose its picture, and it sits inside the places the first point keeps.
- A profile picture you uploaded stays in our storage. The profile record that pointed at it goes; the image file itself is not deleted.
The ways to delete an account, most direct first:
- In the app — Settings → Delete account. This works however you signed up: it asks you to confirm it is you, with your password or through Google, and then erases everything.
- On the web, with no app needed — wishboard.travel/delete-account. The form asks for your email address and your password, so it can only work for an account made with an email address and a password. If you signed up with Google you have no password with us, and the in-app route or an email to us is the way.
- By email — write to support@wishboard.travel and we will erase it for you.
Children
Wishboard is not directed at children under 13, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will remove it.
Changes
If this policy changes in a way that matters, we will update the date at the top and say so in the app.