1. Scope and controller
This notice covers the Wishmode website, no-login watchlists, automated public-page checks, optional browser notifications, and Wishmode Multiverse. It does not cover merchant sites, AI providers, browser push services, or infrastructure providers acting under their own notices.
2. Data Wishmode processes
Watchlist data: title, public product and brand URLs, desired colour, size or other variant, target rules, priority and desired date, owner-only note, page-check status, evidence-qualified prices, store-published stock status, promotion-like page text, timestamps, and trigger events. The server stores a SHA-256 digest of the owner key, not the reusable plaintext key.
Device state: the browser uses local storage for the Multiverse disclosure choice, fictional bag, an anonymous browser identifier (a session UUID), watchlist owner keys, and short-lived navigation notices. It uses session storage for an opaque AI-session token. Wishmode currently sets no advertising or cross-site tracking cookies and includes no non-essential analytics SDK.
Notification contacts: Email, SMS, and WhatsApp alerts are labelled as coming soon and are not available in this version. Wishmode does not currently collect email addresses or phone numbers for watchlist alerts.
Operational data: application request logs contain a request ID, HTTP method, route path, duration, and error code or internal diagnostic when needed. Request bodies, owner keys, AI keys, prompts, and full public URLs are not intentionally placed in routine request logs. A truncated hash derived from the connecting network address is held in Redis for approximately two hours to enforce sliding hourly abuse limits; the application does not put the raw address in that rate-limit key. Hosting, firewall, DNS, or push providers may separately process network and device data according to their configuration and terms.
Automated checks: Wishmode sends the public URL, its identified crawler user agent, and ordinary HTTP request headers to the destination site. The site can observe the Wishmode server's network address and request.
3. Why data is used
Wishmode processes this data to create and share watchlists; authenticate possession of an owner key; fetch user-supplied public pages; record qualified observations and rule crossings; send optional notifications; provide the fictional Multiverse; prevent abuse and unsafe network access; diagnose failures; enforce Terms; comply with law; and respond to rights or site-operator reports. Depending on applicable law, the legal basis may be performance of the requested service, consent for optional provider connections or notifications, legitimate interests in security and operation, and legal obligations.
4. What is public
Anyone with a watchlist short URL can view its title, product and brand links, variant requirements, target rules, observed evidence, status messages, and event history. Owner notes are stored on the server but removed from public API responses and returned only with a valid owner key. Watchlist pages send a no-index instruction to search engines, but that is not access control. Do not submit personal, confidential, or sensitive information.
5. Service providers and disclosures
PostgreSQL stores watchlists and observations; Redis stores rate-limit counters and short-lived encrypted AI sessions; configured object storage holds generated Multiverse media. Hosting and network providers transmit requests. A browser push service receives a subscription endpoint and cryptographic subscription keys if notifications are enabled.
If you connect an AI provider, the API key is sent to the Wishmode backend, encrypted into a time-limited Redis session, and not stored in local storage or the catalog database. Prompts and the minimum generation context go to the chosen provider. The provider's billing, retention, training, security, and international-transfer terms apply. Wishmode does not sell personal data or share it for cross-context behavioural advertising in this version.
Data may also be disclosed when reasonably necessary to comply with law, protect users or the service, investigate abuse, establish or defend legal claims, complete a properly disclosed business transfer, or act on your instruction. Wishmode does not give merchants the owner key.
6. Retention and deletion
Watchlists and their database records remain until an owner-key holder deletes the list or the operator removes it under the Terms. Active-database deletion cascades to product trackers, qualified price observations, brand monitors, events, and push subscriptions. Deletion from encrypted backups, if configured, follows the operator's backup lifecycle and may not be immediate; restored backups must be subject to the deletion process again.
Hourly rate-limit keys expire after approximately two hours, which the sliding-window limiter needs to compare adjacent hours. An encrypted AI session expires after the configured session period and is deleted earlier when disconnected. Local browser state remains until you clear it, forget an owner key, or use the relevant control. Delivered-notification bookkeeping records are pruned automatically after approximately thirty days; the underlying trigger events remain until the watchlist owner deletes them or the list. On the current public deployment, routine application logs are size-capped and rotate automatically, which in normal operation retains them for days rather than months; if a materially longer log retention is configured, this notice will be updated first.
7. Security
Wishmode uses bearer owner keys, server-side SHA-256 key digests, encryption for temporary AI credentials, HTTPS in a proper public deployment, input and size validation, resource-level authorization, rate limits, safe destination checks, identified crawler requests, and restricted browser security headers. No system is risk-free. Protect the owner key, use a trusted device, rotate a disclosed key, and report suspected misuse promptly.
8. Your choices and privacy rights
An owner-key holder can view and change owner-only fields, rotate or forget the key on a device, remove trackers, disable a push subscription, and permanently delete the active watchlist. Clearing browser storage removes local keys and fictional state but does not delete a server-side watchlist. Because there is no account or verified identity, possession of the owner key is normally required to authenticate control of a watchlist.
Depending on where you live, you may have rights to information, access, correction, deletion, restriction, objection, portability, consent withdrawal, nomination, or complaint to a regulator. Submit a request through the privacy contact below. Wishmode may need information sufficient to locate the data and verify authority without collecting more than necessary. Statutory exceptions may apply, and you may complain to the competent data-protection or consumer authority.
9. International processing and changes
Service providers and destination stores may process data outside your region. A public deployment must select providers and transfer safeguards appropriate to its users and applicable law. Material changes to this notice receive a new version and effective date; additional notice or consent will be provided where required.
10. Children
Wishmode is intended only for adults aged 18 or older and is not directed to children. Do not submit a child's personal data. Contact the privacy address if you believe such data has been submitted.
11. Contact and grievance process
Privacy requests and grievances are acknowledged within twenty-four hours where Indian intermediary rules apply, and resolved within fifteen days of receipt or any shorter statutorily prescribed period. If you are not satisfied with the response, you may escalate to the competent data-protection or consumer authority.
Privacy and grievance contacts for this deployment are being finalized and will be published here before general availability.