Privacy Policy
Last updated September 21, 2026
What we don't do
Hinted never asks to see your photo library. Importing or capturing an idea goes through the system's own picker, which hands the app only the one photo you choose. Hinted cannot see your camera roll, and it never asks to.
What we collect
Recognizing the text in a screenshot happens on your device, before anything is sent anywhere. Only the recognized text of an idea you keep reaches our server — an idea you discard along the way never leaves your phone. The image itself is uploaded only for ideas you keep, so it can be shown back to you and to whoever opens a hint list built from it.
How your ideas get smarter
The recognized text of a kept idea is sent to our server, and from there, through Vercel AI Gateway, to a third-party language model — currently google/gemini-2.5-flash-lite — that fills in details like the product, the price and the brand. Only that text goes to the model; the image itself is never sent to it. This is the step that turns a screenshot's raw text into a tidy idea card instead of a wall of OCR output.
Who else touches your data
Hinted runs on a small set of outside services, each doing one job. Naming every one of them, including the two that are easy to miss:
- Vercel — hosting, the image storage an uploaded idea photo lives in, the AI Gateway above, and the scheduled jobs that send reminders and clean up deleted accounts.
- Neon — the Postgres database that stores your account and everything you add to it: people, occasions and ideas.
- RevenueCat — manages subscriptions and renewals.
- Resend — sends the emails Hinted sends, including reminder emails to a partner.
- Expo Push — delivers the push notifications Hinted sends to your phone.
- PostHog — records product analytics from an EU-hosted instance, so usage patterns can be seen without a name attached.
- Sentry — receives crash reports so problems can be found and fixed.
- Apple and Google — sign-in providers, used only if you choose to sign in with one of them.
About the people you add
The people and occasions you track — a partner, a parent, a friend, a child — are not Hinted users and never agreed to anything. You are responsible for what you record about them. Hinted does not contact them on its own, does not build a profile of anyone beyond what you type, and does not use their information for anything other than showing it back to you and to whoever opens a hint list you choose to share.
Some of the people you add are children. South Africa's POPIA gives a child's information extra protection, and Hinted's own design already matches that: a name, a relationship and a birthday is all the app asks for about anyone, adult or child, and that information is used for exactly one purpose — reminding you what to get and by when.
Your hint list
A hint list's web link is unlisted, not private — anyone holding the link can open it, the same way a shared document link works. Claims made on a hint list are hidden from the list's own owner at the server level, not only in what the interface shows, so the person a list is for can never see what has already been claimed for them.
Deleting your account
Deleting your account is a hard delete. Within 24 hours, a scheduled job removes your account and everything in it from the database, and every image you uploaded is purged from storage.
Where your data lives
Your data is stored in Neon Postgres, hosted in the EU (Frankfurt) region — the closest region to South Africa that carries the European Union's own adequacy status, which keeps your data covered under both POPIA and GDPR.
Changes to this policy
A material change to this policy is reflected here, with the date above updated to match. Version 1.0 has no separate notification mechanism for a policy change — checking back here is the way to know.