Legal

Privacy Policy

Last updated: April 2026  ·  Iseoluwa Ink


Iseoluwa Ink(“we,” “us,” “our”) operates The Wishing Well. This Privacy Policy explains what information we collect, how we use it, and your choices. By using the app, you agree to this policy.


01

Information we collect

What you provide directly

DataWhen collectedWhy
Email addressAccount creation / sign-inAuthentication and account identification
Desire textSession creationAI processing to generate your scene
Refinement feedbackDuring sessionsImproving your generated scene
Payment informationAt purchaseProcessed by Stripe — we do not store card numbers

Collected automatically

DataSourceWhy
Session metadataSupabaseSession state and completion tracking
Payment event dataStripe webhookConfirming payment before unlocking sessions
Server request logsVercelError detection and uptime monitoring

What we do not collect

  • Device location
  • Contacts or calendar data
  • Photos or camera access
  • Health or biometric data
  • Social graph or relationship data
  • Advertising IDs — we run no ads

02

How we use your information

PurposeData usedLegal basis (GDPR)
Providing the serviceEmail, desire text, session dataContract performance
Processing paymentsPayment info via StripeContract performance
Delivering your session by emailEmail, generated sceneContract performance
AuthenticationEmail addressContract performance
Improving the serviceAggregated usage dataLegitimate interests
Legal complianceAs required by lawLegal obligation
Customer supportEmail, session dataLegitimate interests

We do not:

  • Sell your personal information
  • Use your desire text to train AI models
  • Share your session content with third parties except as described below
  • Send marketing emails without your consent

03

AI processing

Your desire text is sent to Anthropic’s API to generate your personalized scene. Anthropic processes this data to fulfill your request. Per Anthropic’s API terms, content submitted through the API is not used to train their models.

For details on Anthropic’s data practices, see anthropic.com/privacy.


04

Third-party services

We share data with these services only as needed to operate:

ServicePurposeWhat we shareTheir policy
SupabaseDatabase, authenticationEmail, session datasupabase.com/privacy
StripePayment processingPayment info, order amountstripe.com/privacy
AnthropicAI generationYour desire text, feedbackanthropic.com/privacy
ResendTransactional emailEmail address, session contentresend.com/privacy
VercelApp hostingRequest logsvercel.com/legal/privacy-policy

We do not share your data with advertisers, data brokers, or analytics networks.


05

Data retention

DataHow long we keep it
Account and session dataRetained while your account is active
Completed sessionsRetained for access via your Library
Payment recordsAs required by Stripe and tax law (typically 7 years)
Server request logsTypically 30–90 days

When you delete your account, we delete your personal data within 30 days, except where we are required by law to retain it.


06

Your rights

Depending on your location, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data
  • Withdraw consent for optional processing
  • Data portability — receive your data in a machine-readable format
  • Object to processing based on legitimate interests

To exercise any of these rights, email hello@thewishingwell.app. We will respond within 30 days.

California residents (CCPA): You have the right to know what personal information we collect, to delete it, and to opt out of sale. We do not sell personal information. Contact us at hello@thewishingwell.app.

EU / UK residents (GDPR): Our legal bases for processing are described in Section 02. You may lodge a complaint with your local supervisory authority.


07

Data security

We use industry-standard security measures including:

  • Encryption in transit (TLS / HTTPS)
  • Supabase Row Level Security — your data is only accessible to your authenticated session
  • Environment variable management for API keys
  • Private code repositories

No system is 100% secure. If you discover a security vulnerability, please report it to hello@thewishingwell.app before public disclosure.


08

Children's privacy

The app is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact hello@thewishingwell.app and we will delete it.


09

International transfers

Your data may be processed in the United States and other countries where our service providers operate. By using the app, you consent to these transfers. We use standard contractual clauses where required by applicable law.


10

Changes to this policy

We may update this policy from time to time. Material changes will be communicated with at least 14 days notice by email or in-app notification. Continued use after the effective date constitutes acceptance of the updated policy.


11

Contact

Privacy questions or requests:

Iseoluwa Ink
hello@thewishingwell.app

DisclaimerTerms of Use