The surprise stays in the middle.
WishCodes is an early product operated by Atharv Mantri, an individual based in India. This policy explains the current implementation in plain language; it is not a claim of legal compliance or a substitute for advice about the laws that apply to you.
Gift-givers never see
the recipient's raw answers or private structured profile.
Recipients never see
the recommendations generated for their private gift session.
No account is required
the product uses separate, high-entropy capability links instead.
The recipient can delete
their profile with the separate private management link.
1. Who operates WishCodes
WishCodes is the product name used by Atharv Mantri, an individual operator based in India. WishCodes is not currently presented as a registered company or other incorporated entity. Privacy questions and requests can be sent to work@atharv.me.
The service covered by this policy is the WishCodes website, including private recipient profiles, fragment-based share and management links, gift-giver sessions, recommendations and the public informational pages.
2. Information we receive and store
WishCodes aims to keep the durable record to the minimum structured information needed to operate the core loop. The following is what the current application persists while a profile exists:
- The first name supplied by the recipient.
- A structured private preference profile: a required age range, optional gender selection, normalized interests, hobbies, avoid categories, categories they already have too much of, and derived signals about deeper interests, routines, ownership, upgrade targets, aesthetics and gift preferences used for matching. The quiz does not ask for an exact date of birth.
- The safe Gift Personality card shown to the recipient and gift-givers.
- A public profile ID, creation timestamp, and an optional referring public profile ID for measuring the reciprocal sharing loop.
- One-way hashes of separate share and owner capabilities, plus a share-revocation timestamp when applicable.
- A salted one-way creator fingerprint hash used to discourage the profile creator from opening their own gift link. The raw network and browser values used to derive it are not stored by WishCodes.
The profile row does not contain a raw answer object or plaintext share/owner capabilities. The structured private profile remains server-side and is used only to generate recommendations. It is not placed in public HTML, metadata, OG assets, giver responses or analytics properties.
The application also persists limited operational records:
- Short-lived management and gift session hashes, their bound profile IDs and expiry timestamps.
- Giver context (relationship and selected subtype, occasion code, country, currency, budget code, gift type and vibe) and the generated recommendation set associated with a giver session. Custom occasion wording and custom numeric budget bounds are processed for generation but are not stored in the giver-session row.
- Allowlisted event names and safe properties such as a public profile ID, quiz question ID, channel, budget code, recommendation index, feedback and reason. Events do not contain raw answers, private profiles, names, email addresses, capabilities or free-form giver text.
- AI-generation metadata such as requested/returned model, provider when available, latency, success, retry count, validation failure type, token counters and cost when supplied by OpenRouter. Prompts and generated private profiles are not recorded in these logs.
- Public product-search cache records and provider-usage counters. Cached records contain normalized public listing information such as a title, merchant, URL, image and any evidence-backed price returned by a search provider or public page metadata; they do not contain a recipient profile or private query context. Search provider usage records contain counts and status, not search text.
- Short-lived salted rate-limit buckets and daily AI-budget counters. These do not contain raw IP addresses, prompts or profile content.
3. What is processed temporarily
“Not stored as raw quiz data” does not mean that quiz answers never leave the browser. When a recipient submits the quiz, the validated answers - including the selected age range and optional gender answer - are sent to the WishCodes server and held in memory long enough to generate and validate a structured private profile. WishCodes does not save that raw questionnaire as a profile record, and it does not ask for an exact date of birth.
For profile generation, the server sends the relevant validated quiz input to OpenRouter and the configured model. This includes the selected age range and optional gender answer, but not an exact date of birth. For recommendations, the server sends the structured private signal together with the giver's selected context to OpenRouter; raw quiz answers are not included in that recommendation request. The gift-giver's context is stored as part of the giver session after generation.
The recommendation path then turns the model's safe shopping intents into short, sanitized product or booking queries. Search providers may receive those queries to find public listings; they do not receive the recipient's name, private profile, raw answers, capability, relationship name, custom occasion wording or free-form quiz text. WishCodes may use Brave Search, Tavily or SerpApi when an operator has configured the corresponding server-side provider. Public result data can be cached for a limited period to reduce repeated searches. Prices are shown only when search or public page metadata provides evidence, and may be missing, stale or changed by the merchant.
Request network information may also be processed by hosting and network infrastructure. WishCodes reads a forwarding IP value transiently for rate limiting and for a creator-link device check, and reads the browser User-Agent transiently for that creator-link check. It derives salted one-way hashes, stores only the creator fingerprint hash with the profile, and does not store the raw IP or User-Agent for this purpose. Hosting/CDN providers may have their own network and access-log processing.
4. Why we use information
- to create and display the recipient's safe Gift Personality card;
- to authenticate the separate share and owner capabilities without accounts;
- to generate six gift directions for a giver's selected context;
- to revoke links, expire sessions and permanently delete a profile;
- to protect limited AI capacity and reduce abuse;
- to understand completion, sharing, recommendation and reciprocal-profile funnels through an allowlisted event stream; and
- to diagnose generation reliability using non-content AI operational metadata.
WishCodes does not currently sell personal information or use the product's data for third-party targeted advertising. There are no account credentials, payment details, contact lists, photos or precise-location fields in the current product.
5. AI processing and service providers
OpenRouter is the server-side AI routing service used by the current implementation. Requests use the configured model (currently defaulting to deepseek/deepseek-v4-flash-0731 in production), strict structured output and Zod validation. Profile generation may include the recipient's selected age range and optional gender as limited context; recommendation generation may include that structured context plus the giver's relationship subtype, occasion wording and custom budget bounds transiently. Taste and preference signals remain the primary personalization input. The model is instructed not to infer religion, ethnicity, sexual orientation, medical conditions or stereotypes from demographic context. The request includes provider controls equivalent to allow_fallbacks: true, require_parameters: true, data_collection: "deny" and throughput-oriented routing. WishCodes does not automatically fall back to a different model or a paid model.
DeepSeek does not invent the final product link or price. It proposes bounded shopping intents and, after public search results are retrieved, may help rank the normalized candidates. The final URL, merchant, image, currency and observed price come from the search provider or bounded public page metadata, not from the model. The search provider layer can skip an unconfigured provider, use cached public results and stop at its configured free quota; paid overage is disabled unless the operator explicitly enables it.
These settings are implementation controls, not a promise that every intermediary or downstream provider is incapable of retaining data. The current request does not set request-level zdr: true, and provider policies and routing availability can change. OpenRouter's current materials describe its provider logging controls and data-collection routing in its provider logging documentation, routing documentation, zero-data-retention documentation and privacy policy. Review the current provider terms before submitting anything sensitive; do not put secrets or sensitive personal information in the quiz.
WishCodes may use Vercel for hosting/runtime, Supabase for the database, and PostHog for optional server-side analytics capture when the operator configures a PostHog key. The browser does not load the PostHog SDK, autocapture, session replay or automatic pageview tracking. Each provider has its own terms and privacy policy: Vercel, Supabase and PostHog.
These providers may process information outside your country. WishCodes does not currently promise a particular hosting region or a particular international-transfer mechanism. That assessment should be reviewed if the audience, vendors or applicable law changes.
6. Analytics and logs
Analytics use explicit custom events only. The allowlisted properties are operational funnel fields such as a pseudonymous ID, public profile ID, question ID, country/currency code, budget code, gift type, relationship, occasion (including the custom code), vibe, recommendation index, feedback and reason, plus bounded numeric search counters such as candidate count, cache hits, provider attempts and final result count. Age range, gender, relationship subtype, custom occasion wording, custom budget amounts, search queries and product text are not analytics properties. The system rejects or drops raw answers, private profiles, names, email, capability tokens and free-form text at the analytics boundary.
Application and AI logs are intended to contain operational metadata only. They do not intentionally include prompts, raw answers, private preference profiles, recommendation URLs containing capabilities, owner/share tokens or raw IP addresses. A vendor's own infrastructure logs are outside the application's direct control and are governed by that vendor's policies.
7. Retention, revocation and deletion
A profile and its structured private signal remain stored until the recipient deletes it or the operator removes it as part of operating the service. There is currently no automatic expiry on the profile itself. A recipient can revoke the public share capability or permanently delete the profile from the private management link.
Management sessions expire after approximately 15 minutes, gift sessions after approximately two hours, and the operator stats session after approximately eight hours. Share rotation invalidates the old share capability and its bound gift sessions. Profile deletion removes the profile, its private signal, capability hashes, creator fingerprint hash, associated management/gift sessions, giver-session records and profile-linked events through the application/database cascade. Unlinked landing events and independent rate-limit buckets follow their own retention paths.
Giver-session, event and AI-generation operational records do not currently have a user-visible fixed deletion schedule; they are retained for operating, measuring and improving the early product and are deleted with their associated profile when linked. Public search-cache entries expire automatically according to the query's freshness window, generally within hours or a few days; provider-usage counters are retained by billing period for quota operations. Rate-limit buckets naturally expire, and old daily AI-budget rows are cleaned up. A more formal retention schedule is a review item as the product scales.
Because there is no account, the management link is the normal self-service control. If you lose it, email work@atharv.me with enough information for the operator to assess the request. Never email a share or owner capability or raw quiz answers.
8. Your choices and rights
Depending on where you live and which law applies, you may have rights to:
- ask what personal information is held about you, where applicable.
- request correction or deletion, where applicable.
- request restriction or object to processing, where applicable.
- request a portable copy where a portability right applies.
- withdraw a permission where processing relies on one, subject to lawful exceptions.
- raise a concern with a relevant data-protection authority.
To make a request, contact work@atharv.me and describe the request without sending secrets. We may need reasonable information to locate the relevant profile and prevent unauthorized deletion or disclosure. We will handle requests within the periods and exceptions required by applicable law. If we cannot honor a request, we will explain the relevant limitation where required.
9. Sensitive information and automated inference
Do not submit passwords, account numbers, government IDs, medical details, precise financial information, private secrets or other sensitive information. The quiz asks for an age range and an optional gender selection as personalization context; these remain private, are not shown to gift-givers or included in analytics, and are not used to infer interests or stereotypes. WishCodes does not ask for an exact date of birth.
10. Children and age guidance
WishCodes is not intentionally directed to children and does not currently run invasive age verification. If you are below the age required to use an online service where you live, use WishCodes only with a parent or guardian's involvement. If you believe a child submitted personal information, contact work@atharv.me so the operator can review the request.
The appropriate age approach, child-data duties and any parental-consent requirements depend on the countries served and remain matters for legal review before deliberately marketing the service to children.
11. Security
The current application uses separate high-entropy share and owner capabilities, stores only one-way capability hashes, exchanges fragments through POST bodies, uses short-lived secure HttpOnly SameSite=Strict session cookies, validates bounded inputs, applies shared rate limits, keeps AI/database credentials server-side, and relies on Supabase row-level security with no direct anonymous reads. These are risk-reduction controls, not an absolute security guarantee.
For a concise control summary, see Security at WishCodes. Do not put a capability in an email to support or in a bug report.
12. Changes to this policy
We may update this policy when the product, providers, data flows or applicable requirements change. The effective and last-updated dates at the top will change with a revision. Material changes should be reviewed before continuing to use the affected flow.
Privacy contact
Atharv Mantri · India
work@atharv.me