Last updated: August 11, 2026
Idea Box ("we", "us", "our app") is an Android application that helps you keep track of gift ideas, events, and the people in your life. This Privacy Policy explains what data the app collects or processes, how it is used, and your rights regarding that data.
Idea Box is developed and provided by an individual developer, contactable at w33kendapp@gmail.com. The app is available worldwide through the Google Play Store.
Idea Box is built to keep almost all of your data on your own device. We do not require you to create an account, and we do not collect your name, email address, or phone number to use the app.
| Category | Collected? |
|---|---|
| Account data (email, login, name) | No — no account or login is required |
| Content you create (persons, events, ideas, notes, dates, photos) | Yes — stored locally on your device only |
| Data sent to our AI feature ("Joy AI") | Yes, only when you actively request suggestions — see Section 3 |
| Automatic interface translation into your phone's language | Yes, automatically in the background if needed (no personal data involved) — see Section 3 |
| Camera / Photo library access | Yes, only if you choose to set a profile picture |
| Location, contacts, microphone | No — never accessed |
| Advertising or analytics/tracking tools | No — we do not use Google Analytics, ad networks, or any tracking SDKs |
| Anonymous, aggregated feature-usage counters | Yes — a small number of shared counters (e.g. how many ideas were created app-wide, and how much total time the app is used for), never tied to your device or identity — see Section 4 |
| Payments | No — the app does not process payments or sell anything |
| Data sale | No — we never sell your data to anyone |
When you add a person, event, or idea in the app (e.g. names, birthdays, notes, tags, budgets, or a profile photo you select), this information is stored only in a local database on your own device (using on-device SQLite storage). It is never transmitted to us or to any server, except for the limited, specific case described in Section 3 below. If you uninstall the app or clear its data, this information is permanently deleted.
If you choose to set a profile picture for a person or event, the app requests access to your camera or photo library. The selected image is stored locally on your device as part of that person's or event's record and is not uploaded anywhere by us.
Idea Box includes an optional feature that uses artificial intelligence (Google's Gemini AI model) to suggest gift ideas or activity ideas. This suggestion feature only runs when you actively tap "Get suggestions" — it is never triggered automatically or in the background. (A separate, automatically-triggered feature that translates the app's own interface text is described further below in this section — it involves no personal data and works differently from the suggestion feature described here.)
To generate suggestions, a limited, deliberately narrow set of information is sent from your device, via our backend (Google Firebase Cloud Functions), to the Google Gemini API:
We deliberately do not send the person's or event's actual first/last name, photo, birthday, address, or phone number to the AI service — and the same applies to any photo you've attached to an idea's notes, which is never sent either — only the descriptive information listed above, which is what is actually needed to generate a relevant suggestion.
Suggestions generated this way are cached on our backend (Firebase) so the same suggestions can be shown again without repeating the AI request, until you request new ones or use them.
We also keep a log of the narrow information listed above (the traits/preferences/budget or event details, plus your device's language) together with the AI-generated response it produced, for up to 90 days, after which it is automatically deleted. This log is separate from the daily-request counter described under "Anonymous identifier" below. We need to retain this data so that, in the event of unlawful or abusive use of the feature, we are able to investigate and respond appropriately — the log is never used to identify you personally, and never contains your name, photo, or any other directly identifying information.
The app does not call the Gemini API directly. Requests go through a Firebase Cloud Function that we control, which authenticates the request, applies a fair-use rate limit (currently 20 AI requests per day per installation), and forwards only the narrow data described above to Gemini. No API key or credential for the AI service is stored in the app itself.
To apply the daily rate limit, the app signs in anonymously to Firebase Authentication when first used. This creates a random, anonymous identifier (UID) that is not linked to your name, email, or any other personal identifier. Firebase Firestore stores this UID together with a daily request counter, and — for the AI suggestion feature only — alongside the 90-day suggestion-request log described just above, so that log entries can be grouped by anonymous UID (e.g. to see how many requests came from the same installation) without that UID ever being linked back to you personally.
Separately from the suggestion feature above, if your phone's language is one the app doesn't already have professionally-reviewed built-in text for (currently only German and English), the app automatically translates its own fixed interface text — button labels, screen titles, and similar fixed wording; never anything you type, and never any personal information — into your phone's language the first time you use the app in that language. Unlike the suggestion feature, this happens automatically in the background, without you tapping anything, at most once per language per app version, using the same Google Gemini API and Firebase Cloud Function backend described in this section.
The translated interface text is cached on our backend (Firebase) so it only ever needs to be generated once per language, and the same result is then reused for every other installation whose phone is set to that language.
If you'd rather this not happen automatically, you can set the app's own in-app language (the "More" tab) to English or German regardless of your phone's language — the automatic translation only runs for a language the app doesn't already have built in.
To understand whether people actually find and use certain features (in particular, whether the AI suggestion feature described in Section 3 is used at all) and roughly how much the app is used overall, the app increments a small, fixed set of counters on our backend (Google Firebase) whenever you create, delete, or complete a person/event/idea, request or use an AI suggestion, change the language or color theme, or open the app.
These counters are not a log of individual actions. A single shared counter document simply goes up (by one, or — for the two counters that measure how long the app was open in one sitting — by the number of seconds that sitting lasted) — the same document any other installation's use of that feature also increments. Nothing is tied to your device, to the anonymous identifier described in Section 3, or to any other data: from this data alone we cannot tell how many people use the app, which features a particular installation used, or when any specific action happened — only a running total per counted action, across all installations combined.
We do not use this data for advertising or profiling, and it is never combined with the AI suggestion log or any other data described elsewhere in this policy.
We use the following third-party service providers ("data processors") to operate the AI suggestion, automatic interface translation, and anonymous feature-usage statistics features described above. No other third-party services (no advertising networks, no analytics tools, no crash reporting SDKs) are integrated into the app.
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Google Firebase (Cloud Functions, Firestore, Anonymous Authentication) |
Backend infrastructure for these features: request handling, rate limiting, anonymous authentication, caching, aggregated usage counters | firebase.google.com/support/privacy |
| Google Gemini API | Generates the gift/activity suggestions and the interface translations described in Section 3 | ai.google.dev/gemini-api/terms |
These providers may process data on servers located outside your own country, including in the United States. Google provides appropriate safeguards for such international transfers (e.g. Standard Contractual Clauses) under its own data processing terms.
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, our legal basis for processing the limited data described in Section 3 for the AI suggestion feature is your consent (Art. 6(1)(a) GDPR), given each time you actively request AI suggestions.
For the automatic interface translation described in Section 3, our legal basis is legitimate interest (Art. 6(1)(f) GDPR) rather than consent: only your phone's language code and the app's own fixed, non-personal interface text are processed, so we consider a separate consent prompt disproportionate for processing this narrow and low-risk. You can opt out at any time as described in Section 3 (set the app's language manually instead of following your phone's language).
For the anonymous feature-usage counters described in Section 4, our legal basis is likewise legitimate interest (Art. 6(1)(f) GDPR): the counters carry no identifier of any kind and cannot be linked back to you or your device, so we do not consider them personal data in the first place — but we rely on legitimate interest (understanding overall feature usage to guide development) as a legal basis out of caution, in case they were ever considered personal data.
All other app data (persons, events, ideas you create) is processed solely on your own device and is not "processed by us" in the legal sense, as we have no access to it.
Depending on your location, you may have the right to:
Because all of your content (persons, events, ideas, photos) is stored only on your own device, you can delete it at any time by removing the entry in the app or by uninstalling the app — we have no copy of it and cannot restore or access it on your behalf.
To exercise any of these rights regarding the anonymous data described in Section 3, contact us at w33kendapp@gmail.com.
Idea Box is not directed at children under the age of 13, and we do not knowingly collect data from children under 13. The AI feature requires no account and collects no age information, but is not intended for use by children.
Data stored on your device is protected by your device's own operating system security. Communication with our Firebase backend and the Gemini API is encrypted in transit (HTTPS/TLS). No method of transmission or storage is 100% secure, but we take reasonable measures to protect the limited data we process.
We may update this Privacy Policy from time to time, for example if we add new features that change what data is processed. The "Last updated" date at the top of this page will reflect the most recent revision. Continued use of the app after a change constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or how your data is handled, please contact us at: