This is a courtesy translation. The legally binding version is the Italian one; in case of any discrepancy, the Italian text prevails.
Giffit ("the Service") is developed and operated by Michele Furgeri.
This Privacy Policy describes how we collect, use and protect your personal
data under Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree
196/2003 (Italian Privacy Code) as amended by Legislative Decree 101/2018.
In short: we only collect the data needed to let you use Giffit. We do not sell your data to third parties. The advanced personalization features based on your browsing are always optional and you can withdraw them at any time from the app settings.
1. Data Controller
Michele Furgeri
Email: info@giffit.me
No Data Protection Officer (DPO) has been appointed. For any question about your personal data, or to exercise your rights, you can write to the Controller at the email address above.
2. Data Collected
Data provided directly by the user
- Registration data: email address, password (not stored in clear text — hashed with bcrypt)
- Profile data: username, display name, profile photo, gender, date of birth, interests, negative preferences ("things you don't like"), sizes and measurements (optional)
- Sizes and measurements: top, trouser, underwear and bra sizes, ring size and shoe size. Every field is optional, starts out visible to you only, and you choose which contacts may see it. This data is never sent to artificial intelligence providers: the model is only told that a measurement is available, never its value. We keep no history of it: only the current value is stored, and later changes overwrite it.
- Created content: wishlists, wishlist items, life events, chat messages
- Relationship data: connections with other users, invitations sent and received
Data collected automatically
- Usage data: login timestamps, theme preferences, session logs
- Push token: device identifier used to send push notifications
- Diagnostic and analytics data: technical error events (for the stability of the Service) and aggregated, pseudonymized usage statistics (to improve the Service). In-app usage analytics are enabled only with your prior consent.
Data collected with explicit consent (optional)
- In-app browser navigation data: URL, title and description of products visited through Giffit's in-app browser. This data is processed solely to personalize AI gift suggestions. It is never disclosed to third parties. You can deny or withdraw this consent at any time.
Data received from sign-in providers (Google, Apple)
If you choose to sign in with Google or Apple, authentication takes place on the provider's systems: Giffit never sees the password of your Google or Apple account. We only receive:
- Google: email address (verified), name, profile picture and a unique identifier;
- Apple: email address and name. Apple sends the name only on the first sign-in. If you choose "Hide My Email", Apple provides an anonymous forwarding address (
@privaterelay.appleid.com) and your real address remains unknown to Giffit.
This is the same data you would be asked for when registering, and it is used solely to create and identify your account: the legal basis is performance of a contract (Art. 6(1)(b) GDPR). We do not receive your contacts, calendar, photos, messages or any other content from your Google or Apple accounts, and we never post anything on your behalf.
Google and Apple process authentication data as independent controllers, under their own privacy notices (Google, Apple). You can revoke Giffit's access at any time from your Google or Apple account settings; to erase data already held by Giffit, use the account deletion described under "Your Rights".
3. Purposes and Legal Basis of Processing
| Purpose | Legal basis (GDPR) | Data involved |
|---|---|---|
| Registration and account management | Art. 6(1)(b) — Performance of a contract | Email, password, profile |
| Provision of the Service (wishlists, events, connections, chat) | Art. 6(1)(b) — Performance of a contract | All profile data and content |
| Showing your sizes to the contacts you have authorised | Art. 6(1)(b) — Performance of a contract | Sizes and measurements (optional) |
| Profile-based AI gift suggestions | Art. 6(1)(b) — Performance of a contract | Interests, preferences, age, gender |
| Push notifications and transactional emails | Art. 6(1)(b) — Performance of a contract | Push token, email |
| Suggestion personalization via browsing data | Art. 6(1)(a) — Consent (optional) | URLs and descriptions of browsed products |
| Security, fraud and abuse prevention | Art. 6(1)(f) — Legitimate interest | Access logs, usage data |
| Service improvement (aggregated analytics) | Art. 6(1)(f) — Legitimate interest | Anonymous/aggregated data |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation | Consent logs, data requested by authorities |
Processing based on legitimate interest (Art. 6(1)(f)) is always balanced against the rights of the data subject. You may object to such processing at any time by contacting the Controller.
4. Automated Decision-Making and AI Profiling
The Service uses artificial intelligence systems to generate personalized gift suggestions based on your profile data (interests, negative preferences, gender, age) and — if you have given consent — the products you explore in the in-app browser. Requests are routed through OpenRouter, which forwards them to third-party AI models and may rely on its own compute providers (sub-processors). According to OpenRouter's policy, request content is not used to train models. The model used may change over time without altering the purposes of processing or the categories of data involved.
Such suggestions are purely indicative and produce no legal effects nor significantly affect you within the meaning of Art. 22 GDPR. No binding automated decision is made. You have the right to contest the results and request human review by writing to info@giffit.me.
5. Local Storage (AsyncStorage)
The app uses AsyncStorage (local storage on the device) to keep session preferences, authentication tokens, theme settings and consent logs. This data resides exclusively on your device and is not transmitted to third parties. It is automatically deleted upon logout or uninstallation of the app.
6. Service Providers (Sub-Processors)
Your data may be processed by the following providers, with whom we have entered into appropriate data processing agreements (DPAs) in accordance with Art. 28 GDPR:
| Provider | Location | Purpose | Transfer safeguard |
|---|---|---|---|
| Supabase Inc. | USA | Database, authentication, storage | SCC (Art. 46(2)(c) GDPR) |
| OpenRouter, Inc. | USA | Routing of AI requests to third-party AI models; according to OpenRouter's policy, content is not used for training. May rely on its own compute providers (sub-processors) | SCC (Art. 46(2)(c) GDPR) |
| Resend Inc. | USA | Transactional emails | SCC (Art. 46(2)(c) GDPR) |
| Expo / 650 Industries Inc. | USA | App distribution, push notifications | DPF + SCC |
| Render Services Inc. | USA | Backend hosting | SCC (Art. 46(2)(c) GDPR) |
| Cloudflare Inc. | USA | Static website hosting (Cloudflare Pages), CDN and DDoS protection | DPF + SCC |
| Functional Software, Inc. (Sentry) | EU (Germany) | Error monitoring and technical diagnostics for the stability of the Service (no IP address or personal request content) | Data in the EU — no extra-EU transfer |
| PostHog, Inc. | EU | Aggregated, pseudonymized usage analytics to improve the Service (in-app analytics only with consent) | Data in the EU — no extra-EU transfer |
EU-U.S. Data Privacy Framework (DPF): adequacy framework approved by the
European Commission with Decision 2023/1795 of 10 July 2023.
Standard Contractual Clauses (SCC): model approved by the European Commission
with Decision 2021/914 of 4 June 2021.
For further information on the safeguards applied, contact the Controller.
7. Data Retention
| Data category | Retention period |
|---|---|
| Account and profile data | Until account deletion, then erased within 30 days. If you do not open the app for 30 months the account is deleted automatically, after two email warnings at 12 and 24 months. |
| Incomplete sign-ups or Terms never accepted | Automatic deletion: 30 days if sign-up was never completed, 60 days if the Terms were never accepted. |
| In-app browser navigation data | Up to 12 months from collection (or until consent is withdrawn) |
| Consent logs (proof of T&C acceptance) | 5 years from acceptance (legal documentation obligation) |
| Security and access logs | 90 days |
| Chat messages | Until account or conversation deletion |
After account deletion, personal data is erased or anonymized within 30 days, except for consent logs retained for legal obligations.
8. Your Rights
Under Arts. 15–21 GDPR you have the following rights:
- Access (Art. 15): obtain a copy of the personal data concerning you and information about its processing
- Rectification (Art. 16): correct inaccurate data or complete incomplete data
- Erasure ("right to be forgotten") (Art. 17): delete your account and all associated data — available directly in-app (Profile → Settings → Delete account)
- Restriction of processing (Art. 18): request the suspension of processing in certain cases
- Portability (Art. 20): receive your data in a structured, machine-readable format (JSON/CSV)
- Objection (Art. 21): object to processing based on legitimate interest
- Withdrawal of consent (Art. 7(3)): withdraw at any time your consent to personalization via browsing data, without affecting the lawfulness of processing prior to withdrawal — available directly in-app (Profile → Settings → Privacy)
To exercise your rights, write to info@giffit.me stating your request. We will reply within 30 days of receipt (extendable by a further 60 days in complex cases, with notice of the reason).
9. Minimum Age
The Service is intended for users aged at least 16, in accordance with Art. 8 GDPR and Art. 2-quinquies of Legislative Decree 196/2003. We do not knowingly collect data from minors under 16. Should we become aware of having collected data from a minor without the consent of the holder of parental responsibility, we will delete it immediately.
10. Data Security
We adopt the following technical and organizational measures (Art. 32 GDPR):
- Password hashing with bcrypt (salt factor ≥ 10)
- Encrypted transmissions via HTTPS/TLS 1.2+
- JWT-based authentication with expiry
- Row-Level Security (RLS) on the database to isolate data per user
- Data access limited to authorized personnel only
- Regular backups with encryption at rest
In the event of a personal data breach likely to result in risks to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR. Notification to the Supervisory Authority (Art. 33 GDPR) will be made within 72 hours of becoming aware of the breach.
11. Complaints
You have the right to lodge a complaint with the Italian Data Protection Authority
(Garante Privacy):
www.garanteprivacy.it
Garante per la Protezione dei Dati Personali
Piazza Venezia, 11 — 00187 Rome, Italy
Tel: +39 06.69677.1
We nonetheless encourage you to contact us before filing a formal complaint, so that we can resolve the issue directly.
12. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy in the event of regulatory, technological or Service changes. Changes will be classified as:
- Material changes (new purposes, new providers, new data categories): in-app and email notice with at least 15 days' advance notice. Consent will be requested again where necessary.
- Non-material changes (corrections, clarifications): version update without specific notice.
The updated version is always available at giffit.me/en/privacy.html and in the app's Profile → Settings section.