Loni
Features Help
/

Legal

Privacy Policy

Effective from: August 17, 2026 · Last reviewed: August 17, 2026 · App version 1.21.0 · Controller: Benjamin Oelenberg

This Privacy Policy explains how personal data is processed when you use the native “Loni – Wishlist” app, the website loni-wishlist.app, or contact us.

1. Controller

Benjamin Oelenberg
Weg zum Stadtwald 2A
45529 Hattingen
Germany

Phone: +49 1573 0918061
Email: datenschutz@loni-wishlist.app

2. Principles and legal bases

We process personal data only where this is necessary to provide Loni, where consent has been given, where legal obligations apply, or where legitimate interests permit the processing. The relevant legal bases include:

  • Article 6(1)(b) GDPR for providing the app, account features, and paid Pro features;
  • Article 6(1)(a) GDPR and Section 25(1) TDDDG for optional app analytics;
  • Article 6(1)(c) GDPR for statutory retention and evidence obligations;
  • Article 6(1)(f) GDPR for IT security, prevention of misuse, support, legal defence, and the organisation and limited sharing of family data initiated by users. Our legitimate interests are to provide a secure, reliable service that can be used collaboratively.

Technically necessary information on the device, such as sign-in data or onboarding status, is stored or accessed on the basis of Section 25(2) no. 2 TDDDG.

3. Use of the website

3.1 Hosting and server logs

The website is provided through Google’s Firebase Hosting. When the website is accessed, technically necessary connection data is processed. This may include the IP address, date and time, requested address, amount of data transferred, status code, referrer, and browser and device information. The processing is used to deliver the website and ensure its stability and security (Article 6(1)(f) GDPR). Logs are deleted or anonymised in accordance with the retention periods applicable to the hosting service unless they are required for longer to investigate a security incident.

3.2 No marketing cookies or web analytics

The website uses no first-party web analytics, no marketing cookies, and no externally loaded fonts. Firebase Hosting evaluates the browser’s Accept-Language header to deliver the English or German version at the same address. If you explicitly choose EN or DE, a technically necessary firebase-language-override preference cookie stores that choice for one year. It is used only to provide the language requested by you and is not used for analytics or advertising.

The wish-list invitation page reads the invitation code from the URL, anonymously signs the browser into Firebase after a display name is entered, and then loads the list released for that membership. It displays child and list snapshots, standing wishes, wishes, photos, product links, and reservation and purchase statuses. By default, the display name and anonymous session are kept only for the current browser session. Only if “Remember on this device” is deliberately selected are they stored persistently in local browser storage. App Check uses reCAPTCHA v3 to prevent automated abuse; Google may set the technically necessary _GRECAPTCHA security cookie when the protected web view is initialised. For an existing anonymous wishlist session, Firebase Remote Config uses a Firebase installation identifier and app/project identifier and an IndexedDB cache to retrieve the operational affiliate switch; this request is not made merely by opening an invitation without a session. Parent-invitation pages, by contrast, only read the random invitation ID to open the matching app route and do not load invitation, child, or email content.

4. Data processing in the app and web wish list

AreaDataPurpose
Technical identityFirebase user ID, authentication and session data, timestamps, technical device and connection dataSign-in, secure assignment, and synchronisation
App and device integrityApp and project identifier, short-lived security token, and integrity signals verified by Apple or GoogleDetect modified clients and protect particularly sensitive server functions against misuse
Guest usePseudonymous, randomly generated user ID; display name chosen for each wish listUse as a gift giver without a registered account
Parent accountEmail address, sign-in provider, global Loni display name, Pro statusAccount, management, and permissions
Child and familyName, optional date of birth, avatar colour, and ongoing wishes; names, email addresses, IDs, and roles of managing parentsFamily organisation and shared management
Wish listsTitle, occasion, target date, invitation code, activity status, visibility setting, child and creator snapshotsCreate, share, and display lists
WishesTitle, free-text note, manually entered price, priority, retailer name and domain, product link, optional photo, list assignmentDisplay and manage wishes
Optional clipboard link detectionAfter activation, an external web link read locally and, after ignoring or accepting it, only its SHA-256 fingerprintConveniently pass a copied link into the normal wish-creation flow and avoid offering the same content repeatedly
Participation and statusDisplay name and user ID of the participant, time of joining, reservation or purchase statusPrevent duplicate purchases and inform participants
Activity historyAction, time, user ID and display name of the person taking the action, affected wish or listMake changes traceable
Parent invitationEmail address of the invited person, names and IDs of the participants, and relation to the childSecurely authorise an additional managing parent
Push notificationsFirebase user ID, random device ID, FCM token, platform, app version, language, categories, and, depending on the event, wish, child, and display nameAfter optional activation, inform registered parents about important family and wish-list events
Optional app analyticsRandom Analytics app-instance identifier, app, device, operating-system, country, and usage information, stable screen names, feature-related events and parameters, and on iOS automatic StoreKit purchase events with product identifier, product name, and priceWith consent, pseudonymously analyse and improve usage and important product flows; StoreKit events constitute purchase history
Crash diagnosticsCrash report with stack trace and error location, app/build version, operating-system version, device model, language and region, memory and storage state, and a random installation identifier; no Firebase user IDDetect and fix crashes and severe errors; can be switched off at any time
Feedback and ratingsFor optional feedback email, text entered by the user and visibly pre-filled app/build version, platform, operating-system version, manufacturer/model, app language, environment, session type, and Firebase user ID as support ID; for a store rating, stars and optional review text directly in the storeHandle support requests, assign errors, and enable optional public store ratings
Loni ProPseudonymous RevenueCat ID or Firebase user ID, store, product, purchase receipt or token, purchase and entitlement status, technical device informationProcess purchases, verify and restore entitlements, and assign them to the current Loni account after confirmation

4.1 Anonymous use and accounts

When the app is first launched, Firebase Authentication creates an anonymous identity in the background. This allows gift givers to join a list without registering and assigns actions to their pseudonymous user ID. If a new account is subsequently created, this identity can be linked to the sign-in credentials. When signing in to an existing account, the previous anonymous identity is not transferred automatically.

A parent account can be created with an email address and password, Google, or Apple. When Google or Apple is used, Firebase receives the tokens required for sign-in and the basic data released by the provider, in particular a provider ID and email address. Apple may provide a private relay address. A person’s name supplied by Google or Apple is not automatically used as their public Loni display name.

4.2 Data about children and other people

Loni is intended for adults; children do not receive their own account. Parents or other legal guardians can enter a child’s data and share it with a limited group of people. Anyone who enters such data must be authorised to do so, limit the information to what is necessary, and in particular must not store health data or other particularly sensitive information in free-text fields.

If an additional managing parent is invited by email, we use their email address to assign the invitation. The app does not send an invitation email automatically; the invitation appears in the account area after sign-in with the matching verified email address and may additionally be announced by push notification if these notifications have been enabled there. On request, the app also opens the device’s share menu and provides explanatory text with a personal HTTPS link. The inviting person then decides whether and through which installed app to send this text; the provider of the selected app is responsible for that app’s data processing. The link contains a random invitation ID as a technical locator. Without the addressed, verified account, it displays no invitation content and does not itself grant parental permissions.

4.3 Invitation links, visibility, and shared use

Wish-list invitation links contain a randomly generated eight-character code. Anyone who receives the link or code can access and join the associated list after technical sign-in. It should therefore be shared only with the intended people. Separate parent invitation links contain a random document ID, are bound to an email address, and can only be loaded and accepted by an account with the exact matching verified email address.

Participating gift givers can see the shared child snapshots, ongoing wishes, wishes, photos, links, and reservation and purchase statuses. Depending on the feature, other participants’ display names may also be visible. Managing parents can see parent and membership data. When creating a Pro list, parents can choose whether they see reservation statuses in full, without names, or not at all; this setting does not restrict the visibility gift givers need to avoid duplicate purchases.

4.4 Wish photos and product links

A wish photo can only be selected after the operating-system permission for the media library has been granted. Loni receives only the selected and, where applicable, cropped image and uploads it to Cloud Storage for Firebase. In the MVP, wish photos are intended only for non-sensitive product and wish images. They are not a confidential family photo or document store; private photos of children, identity documents, and other confidential content must not be uploaded.

Uploads and deletions are limited to managing parents of the relevant child. Technical read access is currently available to app identities authenticated with Firebase; shared views also use a long-lived, non-public download address as the access key for the specific image. This address should not be shared. The image is removed from storage no later than when the associated deletion cascade is performed.

Product links are stored together with derived retailer details. Direct Amazon.de product links are reduced to a neutral product address. An Amazon-generated amzn.eu short link is resolved after the deliberate save action or, for old web entries, only after the click through the App Check and authentication-protected resolveAmazonShortLink Cloud Function. The function receives the authenticated Firebase user ID and short link, follows no more than five HTTPS redirects, and returns only a neutral Amazon.de product address. It performs no Firestore reads or writes and logs neither the short link nor the product.

When an eligible Amazon link is deliberately opened, Loni adds a general affiliate tag for iOS, Android, or web, depending on the channel. No Firebase user ID, wish, list, or child identifier and no personalised subtag is appended for Amazon. The link is immediately labelled as an “Ad”. As an Amazon Associate, Loni earns from qualifying purchases; the affiliate tag creates no additional cost for users. Our legitimate interest is the transparent, usage-based funding and continued development of Loni (Article 6(1)(f) GDPR). No background transmission to Amazon takes place.

When an external link is opened, the respective provider’s privacy terms also apply. In particular, the IP address, time, browser or device information, referrer, and, for Amazon, the affiliate tag are technically transmitted. Amazon may use its own cookies and identifiers in its app or website and processes this data under its own responsibility. Anyone who does not want this transmission should not open the external product link.

4.5 Local storage

Necessary session data and local settings are stored on the device, in particular whether onboarding has been completed and which notices have been dismissed. The decision about optional analytics is stored locally on the device together with the version of the consent text, the source of the decision, and the time it was changed. For push notifications, the device opt-in and a random installation-wide device ID are stored; this is not a hardware identifier. For occasional rating requests, Loni stores only capped counts of successful wishes or gift-giver actions, whether a share action was used, the most recent day of use, and the time of an automatic request or a manually opened store link. This information contains no wish, list, or child content and is evaluated only on the device, independently of analytics consent. These settings apply to the app installation. Development variants may additionally include a local test switch for Pro features. The device language is evaluated locally to select the appropriate app language.

Registered parents with a verified email address can also expressly enable Loni to check locally, when entering or returning to the app, whether the clipboard contains exactly one valid external HTTP(S) link. No clipboard content is read before activation, and the feature can be switched off at any time under “Privacy” in the account area. On iOS, the operating system may additionally request paste permission the first time the clipboard is actually read. Loni’s own links, free text, URLs containing credentials, and invalid content are rejected. Clipboard content is not sent to Loni, Firebase Analytics, or a retailer and is not saved as a wish in the background. Only the deliberate “Create wish” action passes the link to the local form; it is transmitted to the server only if the wish is then saved normally. After the link is ignored or accepted, Loni stores only a SHA-256 fingerprint so that the same current content is not offered again after every app launch. The legal basis for this optional device access is consent under Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. Switching the feature off applies to future checks; the preference and fingerprint are removed with the app/device data.

4.6 Optional feedback and store ratings

“Send feedback” opens the device’s email draft. The draft names support@loni-wishlist.app as the recipient and contains a freely editable feedback area. In addition, the app/build version, platform, operating-system version, manufacturer and model without a unique hardware identifier, app language, development or production environment, session type, and current Firebase user ID as support ID are visibly pre-filled. This information can be changed or removed before sending. Device name, advertising or hardware ID, sign-in email, display name, and child, list, wish, link, photo, or price data are not added automatically. The sender decides in the email app which sender address, content, and attachments to use and whether to send the message. If it is not sent, Loni receives no message.

Ratings are submitted exclusively through the native Apple App Store or Google Play interface. Loni does not use a preceding sentiment filter and receives neither the stars nor the review text from the store SDK, nor reliable information about whether the rating dialog was displayed or completed. The terms of the relevant store also apply to the processing of a voluntarily published rating.

4.7 Protection against abusive access

Firebase App Check verifies, when protected Firebase services are accessed, whether the access originates from an authentic Loni client. Short-lived attestation tokens are used for this purpose; integrity is checked on iOS through Apple App Attest or DeviceCheck, on Android through Google Play Integrity, and in the gift-giver web view through reCAPTCHA v3. For the web check, Google processes technical browser, device and interaction signals to distinguish legitimate use from automated abuse; the security cookie described in Section 3.2 may be used. The processing protects accounts and data and prevents automated or manipulated access. The legal basis is Article 6(1)(f) GDPR. Where applicable, technically necessary access to device information is based on Section 25(2) no. 2 TDDDG.

4.8 Optional push notifications

Registered parents can expressly enable push notifications on each device. Gift givers and anonymous sessions do not receive push notifications. Reservations and releases, fulfilled wishes, and parent invitations and access changes can be controlled separately across the account. The system permission and device switch can be revoked at any time.

For delivery, we store the Firebase Cloud Messaging token together with the Firebase user ID, random device ID, platform, app version, and language. Android receives messages through Firebase Cloud Messaging; on iOS, Firebase forwards them through the Apple Push Notification service. Depending on the list visibility setting, the visible message text may contain a wish, child, or display name and may therefore also appear on the lock screen. The preview can be restricted in the operating-system settings.

The data is processed to provide the notification feature you have activated, based on Article 6(1)(b) GDPR; the device token is accessed only after your selection and, where applicable, on the basis of Section 25(2) no. 2 TDDDG. Switching notifications off removes the account link and the local FCM token. Signing out removes the previous account link; deleting the account removes all stored push devices and settings. Tokens reported as invalid are deleted automatically.

5. Optional usage analytics with Firebase Analytics

Firebase Analytics is disabled when the native app starts and is activated only after your voluntary consent. The service then records a random app-instance identifier, technical app, device, operating-system, country, and usage information, understandable screen names, and events relating to important product flows. These include, for example, app launch and sign-in method; creating, editing, or deleting children, lists, and wishes; joining lists; reservation and fulfilment statuses; parent features; opening feedback or rating options; and viewing, starting, and successfully completing a Pro purchase. Feedback text, support ID, rating, stars, and review text are not transmitted as Analytics parameters.

Once Analytics is enabled, the iOS Firebase SDK also automatically records StoreKit in-app-purchase and subscription events. These purchase-history events contain the StoreKit product identifier, product name, and price and are associated with the random Analytics app-instance identifier. The Firebase user ID is not set as the Analytics user ID. The events are used only for product analytics, not for advertising or tracking activity across other companies’ apps or websites.

Only feature-related categories or quantities are used in Loni’s manually logged event parameters, such as account type, sign-in method, visibility level, Pro entry point and plan, or the number of linked lists or wishes. Names, email addresses, child, list, or wish identifiers, invitation codes, wish text, free-text notes, photos, prices, and product links are not transmitted as manual Analytics parameters. The automatic StoreKit events described above are the sole exception for product and price data; they contain no wish content or product link. Automatic screen collection and advertising signals are disabled. On iOS, Analytics is integrated without IDFA/AdSupport support and the IDFV is not collected; on Android, collection of the advertising ID and SSAID is disabled.

The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. The app remains fully usable without consent. You can change your decision at any time under “Privacy” in the account area. Withdrawal applies to the future: new Analytics events are stopped, consent for Analytics storage is withdrawn, and the local Analytics app-instance identifier is reset. Data already transmitted is not retrospectively removed from aggregated reports. You can also contact datenschutz@loni-wishlist.app.

User and event data is retained in Google Analytics for fourteen months. New activity does not extend this period. Aggregated reports may remain for longer. Because analytics requires optional consent, it covers only part of app usage; stores and RevenueCat remain the authoritative sources for actual purchases, subscriptions, and revenue.

6. Crash diagnostics with Firebase Crashlytics

The app uses Firebase Crashlytics to detect and fix crashes and severe errors. In the event of an error, it records the technical crash report with stack trace and error location, app and build version, operating-system version, device model, language and region settings, memory and storage state, and a random installation identifier generated by the service. It also records whether the app is a production or development build.

The Firebase user ID is expressly not transmitted to Crashlytics, so crash reports cannot be assigned to a Loni account. Names, email addresses, child, list, or wish content, invitation codes, photos, prices, and product links are likewise not transmitted. The installation identifier is reset if the app is deleted and reinstalled.

The legal basis is our legitimate interest in a stable, secure, and functional app under Article 6(1)(f) GDPR. Crash diagnostics are therefore enabled by default. You may object at any time by using the “Crash reports” switch under “Privacy” in the account area. The objection applies to the future, is stored on the device, and stops collection immediately; reports already transmitted remain unaffected. The app remains fully usable without crash diagnostics. You can also contact datenschutz@loni-wishlist.app.

Crash reports are retained by Google for no longer than ninety days; aggregated stability metrics may remain for longer.

7. Purchases and Loni Pro

Purchases are processed through the Apple App Store or Google Play. We do not receive payment data such as complete card or bank details. We use RevenueCat to manage entitlements. RevenueCat receives a pseudonymous app user ID, the Firebase user ID for a signed-in account, technical device information, and store, product, transaction, and purchase receipt data. The legal basis is Article 6(1)(b) GDPR.

If optional Analytics consent is active on iOS, Firebase Analytics additionally processes the StoreKit purchase-history events described in Section 5. Stores and RevenueCat remain the authoritative sources for purchases, entitlements, subscriptions, and revenue.

The store account and Loni account are separate identities. Restoration does not happen automatically. After express confirmation, RevenueCat can assign a store purchase previously linked to a different Loni account to the Loni account currently displayed. The previous and current Firebase user IDs are processed as the source and target accounts so that the Pro entitlement can be withdrawn from the previous account and checked for the current account. Wish-list, child, and wish content is not transmitted to RevenueCat for this purpose.

8. Recipients and service providers

  • Google Ireland Limited / Google LLC: Firebase Authentication, Firebase App Check, Cloud Firestore, Cloud Storage, Cloud Functions, Firebase Cloud Messaging, Firebase Analytics, Firebase Crashlytics, and Firebase Hosting. Google generally processes customer data for us as a processor. According to the provider, Firebase Authentication is operated exclusively in data centres in the United States; other services use global infrastructure depending on the service and selected location.
  • Google Sign-In: optional identity provider. The privacy terms of the Google account also apply.
  • Apple Distribution International Limited / Apple Inc.: optional identity provider, App Store distribution, purchase processing, App Attest/DeviceCheck, iOS push delivery through APNs, email relay where applicable, and iCloud Mail for incoming support and privacy enquiries. Apple’s privacy terms also apply.
  • RevenueCat, Inc., USA: management of in-app purchases and Pro entitlements; according to the provider, data is stored on AWS infrastructure in the United States.
  • Amazon Europe Core S.à r.l., Amazon EU S.à r.l., and affiliated Amazon companies: destination of voluntarily opened Amazon product links and operator of the Amazon Associates programme. When a link opens, Amazon receives the usual connection data and the general platform affiliate tag and processes data independently on the Amazon website or in the Amazon app.

Other recipients receive data only where this is necessary to perform the contract, you have consented, or we are legally obliged to disclose it.

9. Transfers to third countries

Google, Apple, RevenueCat, and Amazon may process data in the United States and other countries outside the European Economic Area. Transfers to US recipients certified under the EU-US Data Privacy Framework may be covered by the European Commission’s adequacy decision; Google states that it holds the relevant certification. Where a transfer is not covered by an adequacy decision, the providers use in particular the European Commission’s Standard Contractual Clauses and supplementary safeguards. You can request information about the safeguards used in each case or a copy by contacting datenschutz@loni-wishlist.app. Despite these safeguards, residual risks may exist when data is processed in third countries, such as access by foreign authorities.

10. Retention and deletion

  • Account, profile, child, list, wish, and membership data is generally retained for as long as the account or relevant content exists and the data is needed to provide the service.
  • Open parent invitations remain stored until they are accepted, declined, or withdrawn. There is no general automatic expiry period in the MVP.
  • When a person voluntarily leaves or is removed by a parent, the membership is deleted. Reservation or fulfilment statuses already set remain in place to prevent duplicate purchases. The stored display name and user ID are removed when the wish is corrected to “available”, the associated content is deleted, the account is deleted, or a justified deletion request is received.
  • Activity histories have no general automatic deletion period in the MVP. Personal entries of the account being deleted and entries relating to that account’s own children are removed when the account is deleted. Further review or deletion can be requested through the privacy contact.
  • Uploaded images are removed from Firebase Storage when they are replaced or when the associated wish, list, child, or account is deleted. The specific object path is stored technically with the wish for this purpose; older Firebase download URLs are evaluated for backward compatibility.
  • Firebase Analytics user and event data is retained for fourteen months without new activity extending the period; aggregated reports may remain for longer.
  • Crashlytics crash reports are retained for no longer than ninety days; aggregated stability metrics may remain for longer.
  • Push device links remain until notifications are switched off, the user signs out, the account is deleted, or Firebase reports the token as invalid. No more than five devices are stored per account.
  • Purchase and billing data may be retained for longer by stores, RevenueCat, or us in accordance with statutory retention periods.
  • Support messages are deleted once the request has been resolved unless statutory retention or evidence obligations prevent deletion.

Registered accounts can be deleted completely under “Account” in the app. Before deletion, Loni displays the specific scope affected and requires the user to sign in again. The account’s own children and their complete data trees are deleted without transfer. For children belonging to others whom the account only co-manages, the child and content remain with the existing main managing parent; the parental permission and personal creator details are removed. Personal references in reservations are removed, while a neutral status may remain to prevent duplicate purchases. The deletion cascade covers the profile, authentication identity, Firestore data, push devices and settings, wish photos, and RevenueCat customer data. Alternatively, deletion can be requested at datenschutz@loni-wishlist.app. Details are available on the Delete your Loni account page.

11. Security

We take appropriate technical and organisational measures to protect personal data against loss, alteration, and unauthorised access. These include encrypted transmission, pseudonymous identifiers, role-based access restrictions, app and device attestation, renewed identity verification before account deletion, and a server-side block on new write operations while the deletion cascade is running. Invitation codes and image download addresses must be treated as personal access keys and should be shared only with the intended people. The MVP limitation for wish photos described in Section 4.4 remains unaffected.

12. Your rights

Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection. You can withdraw consent at any time with effect for the future. To exercise these rights, contact datenschutz@loni-wishlist.app. To prevent unauthorised disclosure, we may request appropriate proof of identity.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.

13. No automated decision-making

There is no decision based solely on automated processing that produces legal or similarly significant effects, and no profiling within the meaning of Article 22 GDPR. Pro restrictions are derived exclusively from the purchased product and the documented Free limits.

14. Changes

We update this Privacy Policy when features, data flows, service providers, or the legal situation change. The current version, including its date and associated app version, is available on this page. We will provide appropriate in-app information about material changes.

Loni

Share wishes. Give joy.

Legal notice Privacy Terms Support Delete account
/

Version 1.24.0