Privacy
Privacy Policy
Last updated May 25, 2026.
What Piki stores
Piki stores the account, list, event, item and reservation information needed to run private wish lists and lightweight event replies.
Guest access
Guests can open private links without creating an account. Guest reservation names and notes are used only for the list owner workflow.
Guest reservation recovery
A guest name and recovery email are optional. We do not create a guest account or associate recovery access with an account. In production, Piki does not store plaintext recovery email addresses: it stores a versioned, list-scoped HMAC lookup value instead.
Recovery links and delivery
Recovery requests and email-provider delivery are processed transiently. A recovery link contains its token only in the URL fragment, so the fragment is not sent in ordinary HTTP requests. The full fragment URL is still visible to the email provider and the recipient mailbox, and can be copied or forwarded.
Local development exception
Only local development on a loopback origin may write and read a plaintext guest-email outbox to help developers test. Production, custom development domains, and branch previews do not create those rows.
Retention and deletion
Recovery links expire after 15 minutes. Session grants and their selector expire after 30 days, and request limits are retained for two hourly windows. Resetting guest access, revoking a link, or deleting a list removes applicable recovery data. Reservations themselves do not expire, and recovery data is never used for marketing.
Tracking
Piki does not use advertising trackers or analytics pixels. Cookies are used for login sessions and essential app behavior only.
Contact
For privacy requests, contact the person or team that gave you access to Piki.