Privacy Policy

Effective 8 aug 2026

This explains what Things To Have does with your personal data. It is deliberately short. If anything is unclear, email us and we will answer.

1. Who is responsible

The controller of your data is Tsimur Brachkou, a sole trader (jednoosobowa działalność gospodarcza) entered in the Polish CEIDG register — NIP 5214164635, REGON 544707296, ul. Stefana Batorego 18/108, 02-591 Warszawa, Poland.

Contact for anything about your data: support@thingstohave.app. We have not appointed a data protection officer; that email reaches the operator directly.

2. What we collect, why, and on what basis

Because you give it to us

DataWhyLegal basis
Email addressTo sign you in and send account and security messagesContract, Art. 6(1)(b)
Username (we generate one; you can change it)Your public identity on the serviceContract, Art. 6(1)(b)
Your lists and items — names, notes, links, prices, imagesThe thing the service is forContract, Art. 6(1)(b)
Profile picture, appearance settingsYour profileContract, Art. 6(1)(b)
Birthday — day and month only, never the yearOptional. Shown to mutual friends and used for birthday remindersConsent, Art. 6(1)(a) — clear it any time
Passkeys, if you use themSigning in without a codeContract, Art. 6(1)(b)

Because using the service creates it

DataWhyLegal basis
Sign-in records: IP address, approximate city and country, browserSecurity, and so you can see and end your own sessionsLegitimate interest, Art. 6(1)(f) — keeping accounts safe
One-time codes and sign-in linksTo sign you inContract, Art. 6(1)(b)
Who follows whom, and an activity record of lists and items you createFeeds and friend featuresContract, Art. 6(1)(b)
Gift reservationsSo two people do not buy the same giftContract, Art. 6(1)(b)
Rate-limit and abuse countersTo stop abuse and spamLegitimate interest, Art. 6(1)(f)
Server logs kept by our hosting provider, including IP addresses and requested addressesRunning and debugging the service, and securityLegitimate interest, Art. 6(1)(f)
Usage analytics (Section 3)Understanding how the app is usedLegitimate interest, Art. 6(1)(f) — improving the app

We do not use your data to make automated decisions with legal or similarly significant effects.

We ask you not to put sensitive information into item names, notes or images. If you do, you are choosing to publish it and we process it only as part of your content.

3. Analytics

We use OpenPanel to understand how the app is used. It is cookieless — it stores nothing on your device and reads nothing from it — so there is no cookie banner to click through. We rely on our legitimate interest in seeing how the app is used, and you can object at any time, which switches it off for you completely.

  • Events are counts and categories — which screens are opened, which features are used. We record the address of the page you are on, which for a profile or list page contains a username and the list's name.
  • Your email address is never sent to the analytics provider. You are identified only by an internal account ID and your public username.
  • Your IP address is sent so the provider can tell roughly what country a visit came from.
  • Requests go through our own domain, so an ad-blocker will not necessarily stop them. The switch in Settings does.
  • We do not record your screen. There is no session replay.
  • We do not use analytics for advertising, we do not sell your data, and we run no ad networks or ad pixels.

You can turn analytics off at any time in Settings, with immediate effect. We also honour the Global Privacy Control browser signal automatically, for signed-in and signed-out visitors alike. Turning it off does not affect processing that already happened.

We deliberately do not record the fact that you objected as an analytics event.

4. Cookies and browser storage

We use no advertising or cross-site tracking cookies. Our analytics provider sets no cookies at all — it identifies a visit from the IP address and browser we forward.

Necessary — these make the service work and cannot be switched off:

NamePurposeKept for
__Secure-tth.session_tokenKeeps you signed in7 days
tth_login_emailCarries your address from the sign-in form to the code screen15 minutes
tth_login_link_nonceTies an emailed sign-in link to the browser that asked for it15 minutes
tth_return_toBrings you back to the page you were on before signing in30 minutes
inertia_clear_historyClears cached pages when you sign out60 seconds

Preferencestth_prefs (1 year) stores your light/dark and layout choices and your analytics decision. Older installs may still carry a tth_view_mode cookie, which we only read.

In your browser's session storage we keep the email you typed while signing in (removed once you are in), keys used to encrypt page data in your browser history, and scroll positions.

Cloudflare, which serves the site, may set its own security cookies. You can clear or block cookies in your browser, but the service will not work properly without the necessary ones.

5. Who else sees your data

We use these providers. They act on our instructions, except where noted.

ProviderWhat they getWhat for
CloudflareEverything: the database, uploaded images, sign-in records, server logs, bot checksHosting, storage, security, logs
ResendYour email address and the content of messages we send you, plus a stored contact record — see belowSending email
OpenPanelAccount ID, username, usage events, IP address — never your emailAnalytics. Runs on EU infrastructure, and hashes the IP rather than storing it
RailwayYour uploaded images, as they are resized for displayImage processing
Automattic (Gravatar)A one-way hash of your email address, when you first sign upFetching a profile picture if you have one. Automattic decides on its own how it uses that request
Open Exchange Rates · DiscogsNo personal data — currency rates, and product details for a link you pastePrices and autofill

We also disclose data to public authorities where the law requires it. Note that most of these providers can be compelled directly by authorities without involving us.

If you subscribe to the birthday calendar feed, your calendar provider (Google, Apple, or whoever you choose) will receive your mutual friends' usernames and birthdays.

Every birthday email carries an unsubscribe link, and your mail app's own one-click unsubscribe button works too. Account and security messages — sign-in codes, password- free login links, alerts about changes to your account — have no unsubscribe, because you cannot opt out of those while you have an account.

A contact record at Resend. When your account is created, your email address and username are also stored as a contact in a mailing list held at Resend. We have never sent a marketing campaign to it, and we will not send you marketing email without asking you first. If you would rather not be on the list, email us and we will remove you; deleting your account removes you automatically.

We do not sell your personal data.

6. Data leaving the EU

Our providers operate internationally, so your data may be processed outside the European Economic Area, including in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. Analytics is an exception: OpenPanel runs on EU infrastructure, so those events stay in the EEA.

We have not pinned our database and file storage to a specific region, so your data may be processed wherever those providers operate.

7. How long we keep it

  • Your account and content — until you delete them.
  • Deleting your account — we deactivate it immediately and erase it after 14 days, so you can change your mind. You can also erase it straight away.
  • Sign-in records and one-time codes — deleted 7 days after they expire.
  • Gift reservations — 30 days.
  • Caches (product details, exchange rates) — 24 hours.
  • Server logs held by Cloudflare — a short rolling window set by Cloudflare, after which they are deleted automatically.
  • Backups — our providers may hold short-term point-in-time copies of the database; these expire automatically on their own schedule.

What survives deleting your account, and why:

  • Items another user copied from your public list stay in that user's account, including the image, because it is now their content.
  • Analytics events already collected cannot be deleted — the provider has no way to delete them. We blank out your profile there.
  • Preview images generated for sharing may remain in storage for a while after deletion.
  • Search engines and anyone who saved a link may still hold copies of what was public. We cannot reach those.

8. What is public

  • If you set a birthday, we email your mutual friends to tell them it is coming up, and their emails name you. Turning birthday emails off in Settings stops the emails you receive; to stop your birthday being shared with friends at all, clear it.
  • Your username, profile picture and profile page are public and can be found by search engines. We list qualifying profiles and public lists in our sitemap, which actively tells search engines they exist.
  • A list is private unless you make it public. Public lists and everything on them are visible to anyone.
  • Images are served from unguessable signed links that work for up to 14 days. Someone who has such a link can open the image without signing in — including after you make the list private again. Treat an image link as public once it has been shared.
  • Anyone signed in can see who you follow and who follows you.
  • Reservations are anonymous: the owner sees that an item was reserved and how many times, never by whom.

9. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another provider. Where we rely on legitimate interest you can object, and where we rely on consent you can withdraw it at any time.

Several of these you can do yourself in Settings, immediately: export your lists and items, change your email or username, edit or delete anything, end sessions, turn analytics off, turn birthday emails off, and delete your account.

For anything else, email support@thingstohave.app. We reply within one month. We may need to check that the request really comes from you before we act.

If you think we have handled your data badly, please tell us first — but you can always complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

10. Children

Things To Have is for adults. Our Terms require you to be 18 or over, and we do not knowingly process children's data. If you believe a child has an account, email us and we will delete it.

11. Security

Sign-in is passwordless — one-time email codes or passkeys — and sensitive actions need a fresh confirmation. Traffic is encrypted with HTTPS. Uploaded images have hidden metadata such as GPS location stripped before they are stored. Private files are not publicly listable.

No online service is completely secure. If you think something is wrong with your account, contact us immediately.

12. Changes

If we change this policy in a way that materially affects you, we will tell you by email or in the app before it takes effect. The current version is always at /privacy, with its effective date at the top.

13. Contact

support@thingstohave.app — Tsimur Brachkou, ul. Stefana Batorego 18/108, 02-591 Warszawa, Poland.