Wishing Tree privacy
Updated 25 May 2026
The Wishing Tree is governed by Indonesian Personal Data Protection Law No. 27 of 2022 (UU PDP). We designed this service to collect as little personal data as possible and give you control over your data.
What we collect
- Email for posting verification (not shown publicly)
- Alias / nickname (shown on the tree)
- Wish content + optional image (public after moderation)
- Wisher role (patient, caregiver, family, friend, community)
- Optional city (helps nearby helpers find you)
- For helpers: alias, email, optional phone number, optional city, optional message
What we do NOT collect
- Real names (alias-only design)
- ID numbers (NIK, passport)
- Financial information (the Wishing Tree is not involved in transactions)
- Geolocation (only the city you yourself enter)
How we use data
- Posting verification via email magic link
- Facilitating helper-to-wisher contact (with explicit consent)
- Content moderation
- Audit log for admin accountability
- Email notifications (new helper, wish granted, crisis)
Storage & retention
Wishes automatically expire after 6 months if not yet granted. Audit logs are kept indefinitely for accountability, but personally identifying data within them can be deleted on request. Magic-link emails expire after 24 hours.
Your rights
- Access: see what data we store about you
- Delete: request deletion of wishes or related data
- Opt-out: choose not to receive helper contact (at submit time)
- Correction: correct inaccurate data
Contact Solacea DPO: privasi@solacea.id
Data breach notification
Per UU PDP, we will notify the authority and affected users of data breaches within 3×24 hours.
Third parties
Data is processed by the following service providers, all with commitments not to use your data for AI training:
- Supabase — database + auth + image storage
- Resend — transactional email delivery
- OpenAI — automated content moderation
- Anthropic — language-context moderation
- Vercel — hosting