Privacy Policy
Last updated: 6 May 2026
This Privacy Policy explains what data Wrapped Things collects, why we collect it, who we share it with, and what rights you have. We tried to keep it specific and short. If anything's unclear, write to us.
Who we are
Wrapped Things is operated by Hugo García Benjumea, based in Spain.
- Contact for privacy questions: privacy@wrappedthings.app
For the purposes of the EU General Data Protection Regulation (GDPR), Hugo García Benjumea is the data controller for personal data processed through the Wrapped Things app and the website at wrappedthings.app.
What we collect, and why
Account data
When you join the waitlist or create an account, we store:
- Email address — to create your account, send service emails (waitlist invitation, password reset, billing receipts), and contact you about your account.
- Optional profile fields (username, display name, avatar) — visible only to the friends or groups you choose.
Legal basis (GDPR): contract performance, and your consent for non-essential features.
Sign in with Apple / Google
If you sign in with Apple or Google, that provider shares with us:
- A unique user identifier from the provider.
- Your email address (Apple users may opt to use a private relay email at
privaterelay.appleid.com; we honor it). - Your name as registered with the provider (you can edit this in our app).
We do not receive your password. We do not request additional permissions beyond email and name. Sign-in providers may log the fact that you signed in to Wrapped Things; their data practices are governed by their own privacy policies.
Legal basis: contract performance (to authenticate your account).
Counters and shared content
The counters you log, groups you create, and Versus matches you join are stored so the app can sync across your devices and show your friends what you opted to share.
- Counters are private by default. Sharing — to a friend, a group, or as a Wrap — is opt-in.
- We retain this data while your account is active and for up to 30 days after account deletion to honor backups and handle abuse reports.
Legal basis: contract performance.
Subscriptions and billing
If you subscribe to Premium, the App Store (Apple) or Play Store (Google) handles the payment. We do not see your card number or billing address. We receive a transaction identifier so we can verify your subscription status.
We may use RevenueCat to manage subscription state across platforms.
Legal basis: contract performance.
Advertising (free tier only)
The free tier shows opt-in rewarded ads through Google AdMob. You choose when to watch an ad to receive a reward inside the app — ads are never forced into the experience.
When you choose to watch a rewarded ad, AdMob may collect:
- Device identifiers (Apple Identifier for Advertisers / Android Advertising ID), unless you opt out via your device settings or App Tracking Transparency on iOS.
- IP address, used briefly for ad delivery and fraud prevention.
- Ad interaction data (whether the ad was shown, viewed, completed).
- Coarse geolocation derived from IP, for ad relevance.
Google is the data controller for this data once it leaves the app. Their privacy practices are described at https://policies.google.com/privacy.
Legal basis: consent. You can withdraw consent at any time:
- iOS: Settings → Wrapped Things → Allow Tracking → Off.
- Android: Settings → Google → Ads → Reset advertising ID, or Opt out of ads personalization.
- Within the app, you can choose not to engage with rewarded-ad prompts. Premium removes ads entirely.
Authentication (Sign in with Apple / Google)
If you sign in with Apple or Google, we receive an authentication token plus the email address (and, for Google, the display name) you choose to share. We do not receive your password. Apple may relay your email through a private-relay address; we honor that.
Legal basis: contract performance.
Analytics
We use PostHog, hosted in the European Union (eu.i.posthog.com), to understand how the app is used in aggregate — which screens are visited, which features are used, where users drop off. We do not use PostHog for advertising or for selling data.
Events may include a pseudonymous user identifier (linked to your account so we can recognize repeat sessions across devices), the app version, the device platform and OS version, and a coarse, anonymized IP-derived region.
Legal basis: legitimate interest in understanding and improving the product. You can opt out at any time from the Privacy section in the app's settings.
Diagnostic data
We use Sentry to capture crash reports and anonymous error logs. These help us fix bugs faster. We don't link error reports to your account.
Legal basis: legitimate interest in improving stability and security of the service.
Push notifications
If you opt in to push notifications, we send the notification through Expo's push service, which forwards it to Apple Push Notification service (APNs) on iOS or Firebase Cloud Messaging (FCM) on Android. Your device push token is stored on our servers so we can deliver notifications addressed to your account.
Legal basis: consent. You can disable notifications at any time in your device settings or inside the app.
Web analytics (this website)
This marketing site (wrappedthings.app) uses only first-party hosting infrastructure (Vercel) and runs no third-party analytics, advertising, or tracking scripts. Vercel may collect IP addresses and standard server logs for security and abuse prevention.
We do not set non-essential cookies on the website. The waitlist sets one essential cookie (wt_waitlist_id) to remember your signup, kept for one year.
Sub-processors
We use the following service providers to operate Wrapped Things. Each is bound by a Data Processing Agreement and processes data only on our instructions.
| Service | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, waitlist | Email, account data, counters, groups | EU / US |
| Vercel | Web hosting | IP, server logs | EU / US |
| Apple Sign In | "Sign in with Apple" authentication | Apple ID token, email | US |
| Google Sign In | "Sign in with Google" authentication | Google ID token, email, name | US |
| Apple App Store | iOS distribution and IAP for Premium | Transaction ID, receipt | US |
| Google Play Store | Android distribution and IAP for Premium | Transaction ID, receipt | US |
| Apple Push Notification service (APNs) | iOS push notification delivery | Device push token | US |
| Firebase Cloud Messaging (FCM) | Android push notification delivery | Device push token | US |
| Expo | Push notification routing | Push token | US |
| Google AdMob | Rewarded ads (free tier only) | Device IDs, IP, ad interactions | US |
| RevenueCat | Subscription management | Subscription state, transaction ID | US |
| PostHog | In-app product analytics | Pseudonymous user ID, events, app version | EU |
| Sentry | Crash and error reporting | Anonymous error data | US |
For transfers outside the European Economic Area, we rely on the Standard Contractual Clauses approved by the European Commission, plus supplementary measures where required.
Your rights (GDPR)
You can:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and personal data (we retain backups for up to 30 days for security and abuse handling).
- Export your data in a portable format.
- Object to processing based on legitimate interest.
- Withdraw consent for processing based on consent (e.g., personalized ads) at any time.
- Lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, https://www.aepd.es) or your local supervisory authority.
To exercise any right, write to privacy@wrappedthings.app. We respond within 30 days. We may ask for additional information to verify your identity.
Children
Wrapped Things is not directed to children under 14 (the local minimum digital consent age in Spain). We do not knowingly collect personal data from children below this age. If you believe a child has registered, contact us and we will delete the account.
Data retention
| Data | Retention |
|---|---|
| Active account data | Duration of your account |
| Deleted account data | Up to 30 days (backups and abuse handling) |
| Waitlist email (un-converted) | Until you ask us to delete it, or up to 24 months after launch |
| Anonymous crash reports | Up to 90 days |
| Subscription receipts | 5 years (Spanish tax law) |
Changes to this policy
We will update this page when our processing practices change. Material changes will be announced in the app and by email to active users. The "Last updated" date at the top reflects the most recent revision.
Contact
Privacy questions and rights requests:
- Email: privacy@wrappedthings.app