Privacy policy

Effective 4 September 2026

Reggie is a wishlist and gifting app. This policy explains what we collect when you use the Reggie website and the Reggie iOS app, why we collect it, who sees it, and how to get rid of it. It is written to be read, not skimmed, so it is specific about each feature.

Who we are

Reggie is operated by Reggie Inc., 1125 E Broadway, Glendale, CA 91205. We are the controller of the personal data described here. Questions go to support@shopreggie.com. [Founder decision: confirm whether a dedicated privacy address should replace support@shopreggie.com]

What we collect and why

Almost everything Reggie stores is something you typed or chose: your account details, the things you want, the people you connect with, the gifts you send and the messages that go with them. We use it to run those features for you and the people you share with. We do not sell personal data, we do not run advertising, and neither the website nor the app includes an analytics or ad tracking SDK.

The rest of this policy goes feature by feature. Each section names what is stored, who can see it and when it goes away.

Waitlist

If you join the waitlist, we store your email address, the date you joined, and the wording of your request to hear when Reggie is ready. We use this information to manage early access. Repeat signups keep the original record. Joining the waitlist does not create an account.

Only Reggie administrators can view or export waitlist signups. You can ask us to remove your signup by contacting support@shopreggie.com.

Accounts and sign-in

You can create an account with an email address and a password, or by signing in with Google or Apple. With Google we receive your email address, your name and your profile picture, and nothing else from your Google account. With Apple we receive your email address, or the private relay address Apple makes for you if you choose to hide your email, and your name the first time you sign in, and nothing else from your Apple ID. Passwords are stored only as a hash. Sign-in verification codes and password reset links are sent to your email address and expire on their own.

Each signed-in session records the IP address and browser or device it was opened from, so a session can be recognised and ended. On the iOS app the session is held in the device keychain, together with a single marker that the app has been used on that device before, which only decides whether you see the welcome or the sign-in screen.

Your profile holds a username, a display name and, if you add them, your full name, a short bio, an avatar, a phone number and your Instagram and TikTok handles. Profiles are public by default, meaning anyone with the link can see your name, avatar, bio and your public wishlists. You can make your profile private in Settings, after which it is reachable only through a link you hand out and can reset at any time.

During onboarding Reggie asks what you are into and the occasions you shop for, and offers an optional product audience preference: Woman, Man, Non-binary or Prefer not to say. You can skip or clear that preference at any time. A Woman or Man answer adds a small ranking signal from the product information stores provide; it does not hide products. Non-binary and Prefer not to say are neutral and do not change ranking. In the iOS app Reggie also offers a few products to start a wishlist with. On the website it asks whether your profile should be public and, if you want gifts sent to you, for a shipping address; both are described below. These answers are stored with your account and are not used for advertising.

Your profile and wishlists

A wishlist holds the items you save, a name, an optional cover image and a privacy level. When you save an item by pasting a store link, our server fetches that page to read the title, price and image. The product record is shared between everyone who saves the same product and stores the store's canonical link, never your original link, so referral codes and tracking parameters in what you pasted are dropped.

Each wishlist has one of three privacy levels, and you choose it:

  • Public: anyone with the link can view it, and it shows on your profile.
  • Friends only: people whose follow requests you approve, plus anyone you invite directly.
  • Invite only, the default for a new list: hidden from your profile and visible only to people you invite by email. An invite email carries a link that works for that one person and stops working if you revoke the invite.

When someone claims an item on your list so nobody else buys it, we store who claimed it, or for a guest without an account, the email address they gave. On a public list a guest confirms that address with a short-lived link before the claim stands. You can hide claimed items from yourself in the list's settings so the surprise holds.

Friends, followers and shared addresses

Reggie keeps the follow requests you send and receive, who you follow, who follows you and who your friends are, so it can decide who may see a friends-only list and who can send you a gift. Your activity, such as adding an item to a list, along with the cheers and comments on it, is visible to your friends.

You can save a shipping address (street, city, state, postcode and country) so friends can send you gifts. It is shared only with the people you share it with, or on request from a friend that you approve, and it is shown to them only inside the gift flow. When you type an address, the text you type is sent to Google Places to suggest matches, together with an approximate location derived from your IP address by our hosting provider so nearby suggestions rank first. Reggie stores the address you confirm, not your searches.

Gifts and gift messages

When you send a gift, Reggie records who it is from, who it is for, which item, and the order number, carrier and tracking number you enter so the recipient can be told when it arrives. The purchase itself happens on the store's website under the store's own terms and privacy policy. Reggie does not take payment for gifts and never sees your card details.

A gift can carry a message: a signed name, a delivery date and up to twenty photos, one video of up to fifteen minutes and one voice note. Media is uploaded from your device straight to private storage at Vercel Blob. It is never publicly readable: the recipient, and anyone you email the reveal link to, gets a short-lived signed address that lets them play it, and the address stops working after ten minutes. Someone without an account can open a gift only with the reveal link you sent them.

If you gift someone who is not on Reggie yet, we store the email address you addressed it to so the reveal can be delivered. Thank-you notes a recipient writes back are stored with the gift.

Birthdays from your contacts and calendars

The iOS app can read birthdays from your contacts to add them to your calendar. It asks for permission first, and reads only three fields from each contact card: the card's identifier, the name and the birthday. Phone numbers, addresses, photos and everything else on the card are never read. Nothing leaves your phone until you tick the birthdays you want, and only those are stored: a name, a month and a day, and a year only if the card had one. Your address book is not uploaded or stored.

You can also subscribe to a calendar by giving Reggie its feed address. Our server fetches that feed, offers only the events that repeat yearly, and stores only the ones you tick, again as a name, a month and a day. The feed address is kept so the calendar can be checked again; the rest of the calendar is discarded.

Store links

Buttons that take you to a store go through a Reggie link of the form shopreggie.com/r/(product). When you follow one we record a click: a random click identifier, the product, the time, and your account if you are signed in. The store is not told which page you came from. Reggie may earn a commission on what you buy through an affiliate network; when that is in place the click identifier travels with you to the store so the network can report the commission back to us, and that report is stored against the click.

To improve what Reggie shows you, we also keep which products were shown to you, what you said about them (such as hiding one) and whether a store visit followed. That detail is kept for 90 days, after which only daily totals with no reference to you remain.

Support reports

When you report a problem from inside Reggie, we store your description, the screen you were on, your browser family (such as Safari), the app version and the time, and email the same report to our support mailbox. Your raw browser signature and the exact page address are reduced to those summaries before anything is stored. In the app, reporting a gift message you received files the same kind of report with the gift named in it.

Notifications and email

Reggie shows notifications inside the app and sends email through Resend, our email provider, for things that happen on your account: a sign-in code, a password reset, a note that an account with your email already exists, an invite to a wishlist or to Reggie, a friend request, a gift that has been delivered, an item on your list that was claimed, a reminder to finish a purchase, a reminder to say thank you, and a copy of any support report you file. There is no marketing email. We do not send push notifications today.

Cookies and device storage

The website uses three small stores, all of them needed to work:

  • A session cookie that keeps you signed in.
  • While Reggie is in private testing, a cookie holding a digest of the site password, never the password itself.
  • Browser local storage on a shared wishlist page, holding the token that lets a guest release an item they claimed. The token is the only proof the claim was theirs.

There are no advertising or analytics cookies.

Who we share data with

Reggie runs on other companies' infrastructure. Each one sees only what its job needs:

  • Vercel hosts the website and the API and stores gift media and wishlist cover images.
  • PlanetScale hosts the Postgres database that holds everything else described here. Reggie moved there from Neon in August 2026; a copy of the database stays at Neon for a short rollback window after the move and is then deleted.
  • Resend delivers the emails listed above and receives the recipient address and the message.
  • Google receives your sign-in when you use Sign in with Google, and the address text you type when Reggie suggests addresses.
  • Apple receives your sign-in when you use Sign in with Apple, and relays email to you if you chose to hide your address.
  • An affiliate network, once one is connected, receives the click identifier when you follow a store link and reports commissions back.
  • The payment processor for group funding, once it is live, handles card details directly; Reggie stores the amount, the fund and a reference to the charge, never the card. [Founder decision: name the payment processor once group funding is live]
  • The stores you shop at see your visit and handle your purchase under their own policies.

We share data with other people only as this policy describes: with the people you share a list or a gift with, and at the privacy level you chose. We will disclose data if the law requires it, or to protect Reggie, its users or the public from harm.

How long we keep data

Your account, wishlists, gifts, friends and calendar are kept for as long as your account exists. Sessions expire on their own. Sign-in codes and invite links expire on their own. Discovery detail is reduced to totals after 90 days. Click records and commission records are kept for accounting, and once your account is deleted they no longer reference you.

Deleting your account

You can delete your account from Settings on the website or from your profile in the app. Deletion takes effect immediately: your email, phone number, name, bio, avatar and social handles are erased and your username is replaced; your shipping addresses, friendships, pending requests, onboarding answers, calendar subscriptions, activity, cheers, comments, support reports, notifications and the gift messages you sent, including their photos, video and voice notes, are deleted; and your sign-in credentials are removed so nobody, including you, can sign in as that account again.

The emptied account record itself is kept for 30 days so that anything still in flight, such as a media file queued for deletion, can finish, and is then permanently deleted. Items you claimed on other people's lists that had already become gifts are kept for those people, without your name on them. If you delete by mistake, there is no undo; make a new account.

Security

All traffic to Reggie is encrypted in transit. Passwords are hashed. Gift media lives in private storage and is only ever reachable through short-lived signed addresses. Invite links, reveal links and profile links are unguessable tokens that you can revoke or reset. Every request that changes data is checked against your session or the token you hold before anything is written.

Your choices and rights

You can see and edit your profile, addresses and onboarding answers in Settings, change the privacy level of any list, revoke any invite, reset your profile link, and delete your account at any time. To ask for a copy of your data, or to ask us to correct or delete something you cannot reach yourself, email us; we will answer as quickly as we can, and within the time the law where you live requires. Depending on where you live you may have further rights under laws such as the California Consumer Privacy Act or the GDPR, and you can exercise them through the same address.

Children

Reggie is not for children under 13, and we do not knowingly collect personal data from them. If you believe a child has made an account, email us and we will delete it. [Founder decision: confirm the minimum age, 13 is the floor United States law sets]

Changes to this policy

When a feature changes what Reggie stores, this policy changes with it, and the effective date at the top moves. If a change matters to how your data is used, we will tell you inside the app or by email before it takes effect.

How to contact us

Email support@shopreggie.com or write to Reggie Inc., 1125 E Broadway, Glendale, CA 91205.