Privacy Policy
Version 2026.07-v6
This page describes Heart’s True Desire as it is actually built today, not as it is eventually intended to work. Where a planned capability isn’t live yet, it is labelled Not yet available rather than implied.
What this application does
Heart’s True Desire allows each authenticated person to submit one active wish.
Wishes are anonymous by default.
Why sign-in is required
Sign-in is used to:
- Enforce the one-person, one-wish rule
- Recognise you if you return
- Let you view your existing wish
- Help deter basic abuse
A wish is permanent once submitted — there is no self-service way to edit or delete it. Whether your identity is revealed is likewise decided once, at the moment you submit your wish — see “Your rights today” below for the current list.
Authentication information
When you sign in, the authentication provider may send the application information such as:
- A provider-specific account identifier
- Name
- Email address
- Profile details
The application uses only the provider-specific account identifier to produce a keyed pseudonymous account code. The raw provider identifier is not stored with the wish, and it is not retrievable from the account code.
Information stored for an anonymous wish
The application stores:
- Your wish text
- Your pseudonymous account code
- Submission and last-updated timestamps
- The privacy-policy version you accepted, and when
- Your identity-disclosure preference
Your name, email address and social profile are not attached to an anonymous wish.
Separately, our hosting, database and authentication providers may retain their own standard operational logs (for example, request metadata) as part of running the service. That is outside the application’s own data and governed by those providers’ own practices — see “Limits of anonymity” below.
Choosing to reveal yourself
You may explicitly choose to let me know that a wish is yours.
The disclosure control is a single checkbox, labelled “Anonymous” and checked by default, shown only once — at the moment you submit your wish. Unchecking it reveals your identity — there is nothing to type. Your name and email address are taken automatically from your sign-in profile at that moment and stored in a separate table the application code accesses only through restricted server-side operations. Unchecking it also implies permission for me to contact you about the wish — there is no separate contact-permission control.
This option is voluntary and is never selected by default. It can only be chosen at submission — there is no later reveal once a wish already exists, and no way to withdraw it afterward if chosen.
Giving feedback
You may share feedback about the app itself — separate from your wish — at any time, whether or not you are signed in.
A feedback submission never contains your wish text, and is not linked to your wish. If you are signed in, an optional pseudonymous code may be attached to your feedback so it can be recognised as coming from the same person again; this code is deliberately different from the one used for your wish, so it cannot be used to work out which wish is yours.
Feedback is anonymous by default. You may separately choose to allow a reply, either by typing an email address or, if you have already revealed your identity for your wish, by reusing that contact information — in that case the email is copied onto your feedback at the moment you submit it, not linked to your wish afterward.
AnalyticsNot yet available
No analytics or usage tracking is currently active in this application. Analytics are part of the design, and this policy will be updated before any is turned on. When it is, analytics will never contain wish text, names, email addresses, social handles, or raw authentication identifiers.
Data use
Data is used only to:
- Operate the application
- Enforce the one-person, one-wish rule
- Prevent misuse
- Improve the application
- Respond to users who have explicitly permitted contact
Analysing aggregate usage is also an intended use, but is inactive until that feature ships.
Data will not be sold or used for advertising.
Data retention
Once submitted, your wish is permanent — there is no self-service way to edit or delete it. Your anonymous wish remains stored until:
- The project is closed
- Removal is required for moderation, safety or legal reasons
There is no automatic retention time limit — a wish is kept until one of the above applies.
Your rights today
A returning, signed-in user can currently:
- View their existing wish
- Submit feedback about the app
Anyone, signed in or not, can submit feedback about the app. For anything not covered above — including a request to remove your wish — please use the feedback form.
Limits of anonymity
Honestly stated, rather than implied:
- The authentication provider itself processes your sign-in.
- Hosting and infrastructure providers may retain standard operational logs outside this application’s control.
- Someone with direct access to server infrastructure could, in principle, inspect it.
- Data may have to be disclosed where legally required.
- Absolute anonymity can’t be guaranteed against every possible infrastructure compromise.
What the system is designed to do is prevent me, working through the application and its database in the ordinary course of running it, from linking an anonymous wish back to your social identity.
Contact
Questions about this policy, or requests covered under “Your rights today,” can be submitted using the feedback form.