Privacy Policy
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what you can do about it. It applies to the Darko mobile apps, the Darko web app, and the darko.gift website. Who "we" are, and how to reach us, is in §14.
1. Summary
- We collect the data the service requires: your account, the content you create, your social connections, your gifting activity, and your messages.
- We do not sell your personal data, and we never process payments.
- The ads are never personalised — no profiling, no advertising identifier, no cross-app tracking (§6).
- A photo is never sent for AI processing without your explicit consent (§4).
- You can export your data or delete your account from within the app at any time (§10).
2. What we collect
Free-text you supply. Many fields below accept text you compose yourself — descriptions, hints, notes, titles, invitation and RSVP messages, chat messages, and group-gift payment notes. We do not constrain what you enter, so these fields may contain personal data about you or about others going beyond the categories described here, including financial details such as an IBAN. Whatever you enter is disclosed to everyone with access to the surrounding content (§8).
2.1 Account and profile
| Data | Notes |
|---|---|
| Account identifier | Issued by Firebase Authentication when you sign up. |
| Email address | Optional at the data level. If you sign in with Apple and choose to hide your email, we receive and store Apple's private relay address instead and never learn your real one. |
| Display name | Required before you can create anything in Darko. |
| Profile picture | Optional. |
| Language and default currency | Croatian or English; an ISO currency code. |
| Account status and subscription tier | Free or premium. |
| Sign-in method | Google, Apple, email/password, or email link. |
We never see or store your password — it is handled entirely by Firebase Authentication and reaches us in no form, hashed or otherwise.
Optional profile details. Your clothing, shoe and trouser sizes and your date of birth, if you choose to provide them. Visible only to your accepted friends, never in user-lookup results returned before a friendship exists, and clearable at any time.
2.2 What you create
Wishlists (title, description, public/private setting, cover image); wishes (title, description, image, product link, price, and any private hint you add); tags; events (title, date, time, recurrence); parties (title, location text, and map coordinates if you set them, start time); party invitations and RSVPs including any message you attach.
2.3 Your social graph
Friend relationships and their status (pending, accepted, declined, blocked), who sent the request, who blocked whom, and how the connection was made. Invitation and share links you create: an unguessable token, what it points to, when it expires, and whether you revoked it. Some wishlist share links also carry a short, human-typeable code.
2.4 Gifting activity
Claims on wishes, group gifts and their membership, each member's pledged contribution and whether they have marked themselves as paid, any payment note an organiser adds, and the record of what you are holding for other people. No money moves through Darko, so we never receive or store payment card or transaction data.
2.5 Messages
Group-gift chats: message content, who sent what and when, and any files or images you attach. We also process "typing" and "online" presence signals while a chat is open. Messages are stored durably; presence signals are transient.
2.6 Device and technical data
| Data | Why we have it |
|---|---|
| Push notification token, platform, last-seen time | To deliver notifications to your device. |
| Server logs: IP address, request metadata, timestamps | Operating and securing the service. For public, signed-out pages (opening a share link) we use a hashed IP purely to rate-limit abuse. |
| Crash and error reports | Diagnosing failures — see §7. |
| Ad requests: your IP address and basic device details, sent to Google's ad servers | Showing ads — see §6. |
| Local storage on your device | Your login token and a local cache of your own data. |
2.7 Images and video you upload
Profile pictures, wish images, chat attachments, and party cover photos, album photos and videos.
Metadata in your files. Photos from a phone camera commonly carry embedded EXIF metadata, including the GPS coordinates of where the photo was taken. We strip that metadata from every image on upload, before it is stored — the stored file retains no camera location data.
How images are served. Images are delivered from a long, randomly-generated address that cannot be guessed. Anyone holding that address can retrieve the image without signing in, and it may be cached by our content delivery network (Cloudflare, §8). The address is disclosed only to people already authorised to see the content it belongs to, but access control is applied when the content is requested — it is not re-applied to the image file itself.
2.8 Records of consent and preference
Which consents you have granted or withdrawn, when, and which version of this policy was in force at the time. Your notification preferences by category and your quiet-hours window and timezone.
2.9 Outbound shop links
Each time you open a shop link from a wish, we record the event: your account, which wish, the destination link, and the time.
2.10 Security audit log
We keep an append-only record of security-relevant actions — sign-ins, actions taken on behalf of a family member, group-gift administration, consent changes, data export and erasure requests, and denied access attempts. By design this log contains only internal identifiers, timestamps and action codes — never names, email addresses, message text, or any other free-text personal data.
3. Why we use your data, and our legal basis
| What we do | Legal basis (GDPR Art. 6) |
|---|---|
| Run your account, your lists, claims, group gifts, chats, events and notifications | Contract — Art. 6(1)(b). This is the service you signed up for. |
| Turn a product link you paste into a draft wishlist item using AI | Contract — Art. 6(1)(b). You asked for it by pasting the link. |
| Turn a photo you take into a draft wishlist item using AI (§4) | Consent — Art. 6(1)(a). Off by default. |
| Send you service notifications (a friend request, a claim on a list you manage, a group-gift update), and the account emails needed to sign you in or verify your address | Contract — Art. 6(1)(b). Notifications are controlled per category in Settings. |
| Send you marketing messages | Consent — Art. 6(1)(a). Off by default. |
| Keep the service secure: rate limits, abuse detection, the audit log | Legitimate interests — Art. 6(1)(f), in a service not overrun by spam and account takeover. |
| Record when you open an outbound shop link (§2.9) | Legitimate interests — Art. 6(1)(f), in understanding which wishes lead to a purchase. |
| Show you non-personalised ads (§6) | Legitimate interests — Art. 6(1)(f), in funding a service we do not charge most users for. |
| Analytics and crash reporting (§7) | Consent — Art. 6(1)(a). |
| Manage a paid subscription and keep the records | Contract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c) — for tax and accounting records. |
| Respond to your privacy requests and prove we did | Legal obligation — Art. 6(1)(c). |
Where we rely on legitimate interests, we have weighed our interest against your rights. You can object to any of it — see §10.4.
4. AI processing of links and photos
When you add a wish from a link or a photo, we transmit that content to an AI provider to extract product details.
- Links: the page address and the page content we fetch from it are transmitted.
- Photos: the image is transmitted. This never occurs without your active consent (Settings → Privacy → AI image processing). Without that consent our server refuses the request before any image is transmitted.
- This is not automated decision-making within Art. 22 GDPR. Nothing about you is evaluated, scored or decided; product details are extracted from content you supplied, and the output is a draft you confirm or edit before it is stored.
- We cache extraction results, keyed by a cryptographic hash of the link or image.
Our AI providers process this content on our instructions only, as processors, and are not permitted to use it to train their models.
5. Children and family members
Minimum age. You must be at least 13 to have your own Darko account.
If you are under 16 and in Croatia (or under the equivalent age set by your own country, which is between 13 and 16 across the EU), we can only offer you the optional, consent-based parts of Darko — AI photo extraction, marketing email, analytics — with your parent's or guardian's authorisation. The core app works without any of them. Advertising is not on that list, because no user is profiled for ads at any age (§6).
Family member profiles are not accounts. A user may add a family member profile to their own lists. It has no credentials, cannot be signed in to, and is not a separate user of the service.
A family member profile is part of the creating account's own data. Everything in it is entered and controlled by that account holder, who is responsible for it. They can edit or delete it at any time, and any request concerning it reaches us through them. We do not verify who or what a family member profile represents.
6. Advertising and subscriptions
Advertising
The app displays ads supplied by Google AdMob.
The ads are never personalised, for any user. Accordingly:
- We do not profile you for advertising. No activity in Darko feeds ad targeting.
- We do not use your device's advertising identifier (Android advertising ID or Apple IDFA) to select ads, and we do not ask Google to.
- We do not track you across other apps or websites, and permit no one else to do so through Darko. Because no tracking occurs, iOS users are not shown the App Tracking Transparency prompt.
- Ads are selected from context — the app, the approximate region of the request, and the ad slot — not from any attribute of you.
What Google receives. Serving an ad requires your device to contact Google's ad servers, which therefore receive your IP address and basic technical details of the request (device type, operating system, app version), processed to deliver the ad, measure it in aggregate, and detect click fraud. For that data Google acts as an independent controller under its own privacy policy, not as our processor. Your account contents — wishes, lists, friends, claims, group gifts and messages — are never disclosed to Google's advertising business or any advertiser, and never used to select an ad.
Legal basis: legitimate interests in funding the service — Art. 6(1)(f) GDPR. We rely on that rather than consent because these ads neither profile you nor read an identifier from your device.
Subscriptions
Subscription transactions are handled entirely by the Apple App Store or Google Play, which send us a confirmation and a transaction reference so we can apply the entitlement.
7. Analytics and crash reporting
What is collected. Production releases include Google Analytics for Firebase and Firebase Crashlytics, which collect app opens, screens visited, a per-installation identifier, device model, operating system version, app version, a coarse location derived from your IP address, and, on a crash, a crash report describing the state of the app. On the web app, where Crashlytics does not run, uncaught errors are sent to our own servers instead, including your account identifier when you are signed in.
Why. To understand how the app is used, diagnose faults, and improve the service. This data is never sold, never used to select advertising, and never combined with an advertising profile.
Legal basis: your consent — Art. 6(1)(a) GDPR. Collection runs only while the Analytics switch in Settings → Privacy is on. Operating-system controls (Android: "Delete advertising ID"; iOS: "Share iPhone Analytics") also apply, and take effect independently of us.
8. Who we share your data with
We share personal data with the service providers below, each acting as our processor under a data processing agreement, and each only to the extent it needs to do its job. We do not sell personal data to anyone.
| Provider | What it handles | Where |
|---|---|---|
| Google Cloud / Firebase | Authentication — including the account emails we ask it to send you, such as address verification and sign-in links — the app's servers, the darko.gift website and web app, file storage, live updates, push notifications, logging, analytics and crash reporting | Our servers and stored files are in the EU (Belgium, europe-west1). Some Google services are operated globally. |
| Neon | The main database holding your account and content | EU region |
| OpenAI | AI extraction of products from links and photos (primary provider) | United States |
| Anthropic | AI extraction, used when the primary provider cannot resolve an item | United States |
| Jina AI | Fetching a product page's content before extraction | Outside the EU |
| Hetzner | Hosting the mail server that receives email sent to our darko.gift addresses, including the privacy requests and complaints described in §10 and §14. That server is operated by one of the joint controllers named in §14. | EU |
| Google AdMob | Delivering and measuring the app's ads (§6). An independent controller for that data, not our processor. | Global |
| Apple, Google | Subscription purchases and billing | Global |
| Cloudflare | DNS, content delivery network and security layer in front of darko.gift — terminates HTTPS, caches responses, filters malicious traffic, applies rate limits. Processes your IP address and the metadata of every request you make to us. | Global network |
We also disclose data to other users, strictly per the access rules you set: accepted friends see your public lists and optional profile details; users you grant access to a private list see that list; group-gift members see each other and the chat. A group-gift organiser additionally sees each member's contribution amount; other members see only the aggregate total.
If you screenshot a private wishlist, we notify that list's owner that a screenshot was taken. Detection depends on the operating system and is not guaranteed.
We will disclose data to public authorities where we are legally required to. We will tell you if that happens unless we are legally barred from doing so.
International transfers
OpenAI, Anthropic, Jina AI, Cloudflare, and some Google and Apple services process data outside the European Economic Area. Those transfers are covered by the European Commission's Standard Contractual Clauses, or by the EU–US Data Privacy Framework where the provider is certified under it.
9. How long we keep things
| Data | Retention |
|---|---|
| Your account, lists, wishes, events, friendships | For as long as your account exists. |
| A deactivated account | 30 days, then it is irreversibly anonymised. See §10.2. |
| Chat messages | For the life of the conversation they belong to; removed when the account that sent them is anonymised. |
| Push notification tokens | Until the device stops being used or the account is erased. |
| Invitation and share links | Until they expire or you revoke them. |
| AI extraction cache | A short fixed period, then deleted automatically. |
| Rate-limit counters | Hours to days. |
| Shop link clicks | Deleted with your account. |
| Ad request data held by Google | Per Google's own retention policy — we hold no copy. |
| Subscription records | For the life of the subscription, then as long as tax and accounting law requires. |
| Security audit log | For the life of the service. It holds no directly identifying data (§2.10), so anonymising your account leaves nothing personal in it. |
| Server logs | A short operational period, typically 30 days. |
| Crash reports | Per Firebase Crashlytics' own retention, currently around 90 days. |
| Analytics events | 2 months — Google Analytics' default event-data retention, which we have not changed. Aggregated reports that do not identify you are kept longer by Google. |
10. Your rights
Under GDPR you have the following rights. All of them are free, and we will answer within one month — extendable by two further months for genuinely complex requests, in which case we will tell you within the first month.
10.1 Access and portability
Settings → Privacy → Export my data returns a copy of the data we hold about you, immediately and without a request to us, as JSON — structured, commonly used and machine-readable, and yours to take elsewhere. It excludes claims made on your own wishes: that data identifies another person, and Art. 15(4) GDPR provides that the right to obtain a copy must not adversely affect the rights and freedoms of others.
10.2 Erasure
Settings → Privacy → Delete my account deactivates the account immediately and signs you out. A 30-day grace period applies — contact us within it and we can restore the account. After 30 days an automated process irreversibly anonymises your personal data in our database, deletes your login, and removes your push notification tokens, uploaded files, and presence and message traces from our live-update systems. Any claim you still held is released.
Deactivation first requires you to resolve obligations only you can discharge: transferring or cancelling a group gift you administer, and transferring or deleting a family member profile you solely administer.
10.3 Rectification
Profile data is editable in the app. Anything not editable there can be corrected on request.
10.4 Objection and restriction
Object to processing based on our legitimate interests (§3), or ask us to restrict processing while a dispute is resolved. Tell us which processing and why, and we will stop unless we can demonstrate compelling grounds that override your interests.
10.5 Withdraw consent
Settings → Privacy has a switch for each consent-based feature. Withdrawing is as easy as granting, and takes effect going forward — it does not make our earlier processing unlawful.
10.6 Complain
If you consider that we have handled your data unlawfully, we ask that you raise it with us first. You may also complain to your national data protection agency at any time, without contacting us first. You can do that with the agency in the EU or EEA country where you live, where you work, or where you believe the problem happened; each one publishes its own contact details on its website.
11. How we protect your data
- Data is encrypted in transit (TLS) and at rest.
- No client device reaches our database directly. All access passes through our API, which re-derives the caller's permissions from their verified identity and current database state on every request, and never trusts client-supplied claims of identity or ownership.
- Share and invitation links are cryptographic tokens, never derived from your email address and not enumerable.
- Uploads are validated against a file-type allowlist and a size limit; camera photos on the wish path are re-encoded. See §2.7 for the limits of this regarding image metadata and image addresses.
- Our security log cannot be altered or deleted, enforced by database permissions rather than application code.
- Our code is automatically scanned for vulnerabilities, vulnerable dependencies and leaked secrets on every change.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and notify you directly where the law requires it.
12. Cookies and local storage
- The app stores your login token and a cache of your own content on your device. This is strictly necessary to provide the service and cannot be disabled separately from using the app.
- The web app additionally uses browser storage for your login session.
- No advertising storage. Because the ads are never personalised, no advertising identifier is read and no ad profile is built on your device (§6).
- No tracking cookies on darko.gift. Cloudflare (§8) may set a cookie to distinguish genuine visitors from automated traffic; that is strictly necessary and cannot be declined separately from using the site.
- Analytics storage is covered by §7.
13. Changes to this policy
We will update this policy as Darko changes. Every version carries a version number, and the version in force when you granted a consent is recorded against that consent.
14. Contact
Questions, requests, or complaints about anything in this policy go to [email protected]. We will confirm receipt and answer within one month.
Until Darko is incorporated as a company, the data controllers responsible for your data are, jointly, Leo Kolar and Marko Žužić, reachable at the email address above.
We are not required to appoint a Data Protection Officer and have not appointed one. When Darko is incorporated, the company will become the controller in our place; we will update this policy and tell you before that happens.