OpenWish Privacy Notice
Effective date: [INSERT DATE]
Controller: [INSERT LEGAL ENTITY NAME, ADDRESS, AND COUNTRY]
Privacy contact: privacy@openwish.org
1. Scope
This notice explains how OpenWish collects, uses, shares, retains, and protects
personal data when people visit the website, create an account, publish or help
with a wish, communicate, upload files, receive notifications, or contact us.
OpenWish is an adults-only connection platform. It does not initially process
donations, payments, shipping, or escrow.
2. Data we collect
Depending on how you use OpenWish, we collect:
• **Account data:** email address, authentication-provider identifiers and
private provider-supplied name/photo, generated public alias and avatar,
alias history, age/eligibility confirmation, and account settings.
• **Profile data:** bio, country, generalised city, public visibility choice,
and verification status.
• **Wish data:** original submission, approved AI-formatted version, category,
urgency, sensitivity, status, generalised location, media, revision history,
views, offers, and fulfilment records.
• **Communications:** messages, replies, typing/delivery/read events,
attachments, consented contact-detail sharing, blocks, mutes, and reports.
• **Verification/supporting data:** verification-provider results and privately
uploaded supporting documents. Public badges show limited status only.
• **Technical data:** IP address, device/browser information, timestamps,
cookies or similar identifiers, logs, security events, crash data, and
approximate location inferred from network information where used.
• **Notification data:** email and push subscription information, delivery
status, and preferences.
• **Moderation data:** automated classifications, risk signals, detected policy
categories, model inputs/outputs, decisions, appeals, and enforcement history.
• **Support data:** correspondence and information supplied when seeking help
from OpenWish.
Do not put precise addresses, financial credentials, government identifiers,
or private medical records in public wishes.
3. Public information
Published wishes, chosen display name, avatar, general location, category,
status, verification badges, and selected profile information are public. They
may be indexed by search engines, included in sitemaps and social previews,
copied by visitors, or remain in third-party caches after deletion.
New accounts receive a generated public alias and avatar. Provider names,
provider photos, and email-derived names are not made public automatically.
The alias is the default identity on wishes and in chat. Users can change their
alias/avatar or deliberately select First Name or Public Profile. Choosing
“Anonymous” prevents public display of the alias or identity on that wish.
OpenWish still knows the account connected to the content and may disclose it
as described in this notice.
4. Why we use data
We use personal data to:
• create accounts, authenticate users, and maintain sessions;
• generate and validate privacy-preserving public aliases and avatars, prevent
collisions and impersonation, and retain limited alias history for safety;
• format, publish, discover, edit, and manage wishes;
• provide private chat, attachments, notifications, fulfilment tracking, and
consent-based sharing;
• personalise and rank discovery results;
• moderate content, detect scams and prohibited payment requests, investigate
reports, prevent abuse, and protect users;
• verify identity or supporting information where enabled;
• operate, secure, debug, measure, and improve the service;
• communicate service, safety, support, and policy updates;
• establish, exercise, or defend legal claims; and
• comply with legal obligations and lawful requests.
Where applicable, the legal basis may be performance of a contract, legitimate
interests in operating and securing OpenWish, consent, compliance with law, or
protection of vital interests. The final jurisdiction-specific basis table must
be approved before launch.
5. AI and automated processing
OpenWish sends relevant wish text, chats, images, attachments, reports, and
context to automated systems to rewrite wishes, suggest categories, identify
personal information, detect prohibited conduct, prioritise safety review, and
support enforcement.
AI can be inaccurate. A user approves wish rewrites before publication.
Automated moderation may block or flag activity. Where required by law,
OpenWish will provide information about significant automated decisions and a
way to request human review. OpenWish must not use user content to train its own
general-purpose model without a separate disclosed legal basis or consent.
6. How we share data
We share data only as needed:
• **With other users:** public content and information you explicitly choose to
share in a conversation.
• **With processors:** hosting, storage, authentication, email, push, security,
analytics, AI, support, and future identity-verification vendors under
appropriate contracts.
• **For safety and law:** with authorities, advisers, or affected parties when
reasonably necessary to comply with law, prevent serious harm, investigate
abuse, enforce terms, or protect rights.
• **Business changes:** during a merger, financing, reorganisation, insolvency,
or sale, subject to appropriate confidentiality and notice requirements.
• **At your direction:** when you consent or ask us to share information.
OpenWish does not sell personal data for money. Before launch, counsel must
confirm whether any analytics or advertising activity constitutes “sale” or
“sharing” under applicable regional law and add opt-out controls if required.
7. International transfers
OpenWish is global and providers may process data outside your country.
Where required, OpenWish will use an approved transfer mechanism, contractual
safeguards, and supplementary security measures. The production processor and
data-location list must be completed before launch.
8. Retention
OpenWish retains account, wish, chat, upload, and moderation data while needed
to provide the service, maintain safety history, resolve disputes, enforce
policies, and comply with law. Public content may remain until it is closed or
deleted, and third-party caches may persist independently.
The earlier product assumption of indefinite retention must not become the
production policy without legal review. A launch retention schedule must set
specific periods for active data, closed accounts, chats, uploads, security
logs, backups, verification data, and moderation evidence. Data should then be
deleted or irreversibly de-identified unless a legal hold, safety need, or
statutory obligation requires longer retention.
9. Security
OpenWish uses measures designed for the nature of the data, including access
controls, encryption in transit, restricted private storage, secret management,
logging, backups, abuse controls, and service-provider review. No system is
perfectly secure, and OpenWish cannot guarantee that unauthorised access or loss
will never occur.
Users should use secure authentication, protect devices, and report suspicious
activity promptly.
10. Your choices and rights
Product controls allow users to edit profiles, select public identity, manage
notifications, close wishes, block or mute users, leave conversations, and
request account closure.
Depending on location, users may also have rights to access, correct, delete,
restrict or object to processing, obtain a portable copy, withdraw consent,
appeal certain automated decisions, and complain to a regulator. Requests may
be sent to privacy@openwish.org. OpenWish may verify identity and may retain
limited records where legally permitted.
OpenWish will not discriminate against a user for exercising a privacy right.
Country-specific notices and appeal/authorised-agent procedures must be added
where required.
11. Cookies and local storage
OpenWish uses strictly necessary storage for authentication, security, user
choices, and core functionality. Analytics, personalisation, or advertising
technologies must not run before required notices and consent controls are
implemented. A production cookie inventory and preference centre are launch
requirements.
12. Children
OpenWish is not intended for anyone under 18. We do not knowingly permit minors
to create accounts. If we learn that a minor has provided personal data, we
will restrict the account and take appropriate deletion or preservation steps
consistent with safety and law. Concerns may be reported to
privacy@openwish.org.
13. Changes
We may update this notice to reflect service, legal, or operational changes.
The current version will show an effective date. Material changes will be
communicated by reasonable means, and consent will be requested where required.
14. Contact and complaints
[LEGAL ENTITY]
[REGISTERED ADDRESS]
privacy@openwish.org
[DPO OR REPRESENTATIVE, IF REQUIRED]
Users may also complain to the privacy or data-protection authority available
in their jurisdiction.
