Overview
WrapSheet (“we,” “our,” or “the app”) is a gift-tracking and thank-you note app for iOS, developed by Brian Perrella. This privacy policy explains what information WrapSheet collects, how it is used, and the choices you have.
Effective date: June 29, 2026.
Information We Collect
Account Information
When you sign in with Apple, we receive your Apple User ID and, on first sign-in only, the name and email address Apple provides. WrapSheet uses Firebase Authentication to create and manage your account session. Firebase assigns a user ID to your account, which we use for authentication, account deletion, purchase access, trial limits, analytics user identification, and support.
Gift, Event & Document Data
The gift entries, events, giver names, thank-you notes, imported WrapSheet files, exported backup files, and other content you create in WrapSheet are stored locally on your device. If you enable iCloud sync, this data is also stored in your personal iCloud account, which is controlled by Apple and subject to Apple’s privacy policy. WrapSheet does not use your gift, event, or thank-you note content for advertising.
Photos
When you use the camera to scan gifts, photos are temporarily sent to Google’s Gemini API for AI-powered gift identification. Photos are processed in real time and are not stored by WrapSheet or on our servers after processing. We do not access your photo library — only the camera.
Purchase Information
In-app purchases are processed by Apple’s App Store and RevenueCat, our purchase management provider. RevenueCat may receive purchase history, product identifiers, transaction status, entitlement status, expiration dates, app/device information, and the Firebase user ID we use to link purchases to your WrapSheet account. We use this information to verify purchases, activate or restore access, prevent abuse, provide support, and understand purchase funnel performance. We do not have access to your payment card, Apple ID password, or full billing details.
Device Identifiers
WrapSheet may use app-generated or service-generated identifiers, including local device identifiers, Firebase installation or app instance identifiers, and RevenueCat app user identifiers. These identifiers are used for app functionality, authentication, analytics, purchase management, fraud prevention, and resolving sync conflicts. They are linked to your account where needed to provide the app, but they are not used for third-party advertising tracking.
Usage, Analytics & Campaign Data
WrapSheet uses Firebase Analytics / Google Analytics for Firebase to understand how the app is used and to improve onboarding, reliability, features, and purchase flows. This may include app events such as app launches, onboarding steps, tab selections, gift or event creation, scan attempts and results, thank-you note actions, paywall views, purchase flow events, restore events, and error categories. We may also set user properties such as authentication state and pass state.
When you open WrapSheet from a link, deep link, or universal link, we may capture campaign and attribution parameters included in that URL, such as utm_source, utm_medium, utm_campaign, utm_content, utm_term, source, medium, campaign, the link host or path, and whether the app was opened by a URL or universal link. We use this information to measure campaign performance and understand which links lead to app activity. We do not use this information for third-party advertising tracking.
We also track the number of AI scan or AI generation requests you have made to manage free trial limits and paid access. These counts are stored on our server and linked to your account.
Data Summary
Third-Party Services
WrapSheet uses third-party services to provide app functionality, authentication, analytics, AI processing, purchase management, storage, and App Store distribution. These services process information according to their own privacy policies and the settings you maintain with them.
- Google Gemini API: processes photos and prompts for real-time AI-powered gift identification and thank-you note assistance.
- Firebase Authentication: manages account authentication and Firebase user IDs.
- Firebase Analytics / Google Analytics for Firebase: collects app events, user properties, device/app identifiers, and campaign attribution parameters for product analytics and campaign measurement.
- RevenueCat: manages in-app purchase status, entitlement status, purchase history, and account-to-purchase linking using the Firebase user ID.
- Apple: provides Sign in with Apple, App Store purchases, iCloud storage/sync, device permissions, and App Store distribution.
In app version 2.0.3 and later, WrapSheet does not include TikTok or Meta advertising SDKs, does not request App Tracking Transparency permission, and does not configure SKAdNetwork identifiers for third-party ad attribution.
How We Use Your Information
- To authenticate your account and manage your session.
- To identify gifts from photos using AI.
- To generate thank-you note assistance when requested.
- To store your gift and event data locally and, if enabled, sync it across your devices via iCloud.
- To import, export, and restore WrapSheet document or backup files.
- To manage your in-app purchase status, entitlement status, free trial, and account deletion requests.
- To link RevenueCat purchase records to your Firebase-authenticated WrapSheet account.
- To measure app usage, onboarding, product interactions, errors, paywall performance, purchase flow performance, and campaign attribution using Firebase/Google Analytics.
- To resolve data conflicts across multiple devices.
- To prevent abuse, troubleshoot issues, and provide support.
Advertising, Tracking & Sale of Data
WrapSheet does not show third-party ads and does not sell your personal data. In app version 2.0.3 and later, WrapSheet does not use TikTok, Meta, or other third-party advertising SDKs for cross-app tracking, does not request App Tracking Transparency permission, and does not use SKAdNetwork identifiers for third-party ad attribution.
Some data collected by Firebase/Google Analytics and RevenueCat is linked to your account or device for app functionality, analytics, purchase management, and campaign measurement. We do not use this data to track you across apps or websites owned by other companies for third-party advertising purposes.
Data Storage & Security
Your gift and event data is stored locally on your device using iOS file protection. Authentication tokens are stored in the iOS Keychain. If you enable iCloud sync, your data is additionally stored in your personal iCloud account and protected according to Apple’s iCloud security practices. Analytics, authentication, purchase, campaign, and usage-limit data may be stored by Firebase, Google Analytics for Firebase, RevenueCat, Apple, and our backend systems as needed to provide the app. Network communication uses HTTPS encryption.
Retention & Deletion
Your gift and event data remains on your device for as long as you keep the app installed, unless you delete it in the app or remove local files. If you delete the app, locally stored app data is removed from that device. Data stored in your personal iCloud account may remain available through iCloud unless you delete it from iCloud or your Apple account settings.
To delete your WrapSheet account and server-side data, including Firebase Authentication records, Firebase user ID, purchase access records, RevenueCat-linked identifiers where applicable, trial or usage counts, and support-related account data, contact us at the email address below. We will process deletion requests within 30 days unless a longer period is required or permitted by law, fraud prevention, security, App Store records, tax, accounting, or dispute-resolution obligations.
Firebase/Google Analytics and campaign measurement data may be retained in aggregated, de-identified, or event-level form according to our analytics retention settings and the service providers’ policies.
Children’s Privacy
WrapSheet is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information through the app, contact us and we will promptly delete it.
Your Rights & Choices
Depending on your location, you may have the right to access, correct, delete, export, or withdraw consent for certain processing of your personal data. To exercise any of these rights, contact us at the email address below.
- You can choose whether to sign in with Apple.
- You can choose whether to enable iCloud sync through Apple/iCloud settings and app behavior.
- You can delete local app data by deleting entries in the app or removing the app from your device.
- You can request deletion of your WrapSheet account and server-side data by contacting us.
- You can manage App Store purchases, subscriptions, refunds, and Apple account settings through Apple.
- You can avoid campaign attribution capture by opening the app directly rather than through campaign links containing UTM or campaign parameters.
Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the effective date or last-updated date on this page. Continued use of WrapSheet after changes constitutes acceptance of the updated policy.
Contact Us
Brian Perrella
Email: brian@brianperrella.com
Website: wrapsheet.site