Privacy
Privacy is a product rule, not an afterthought.
Wishwell is designed so visibility, discovery, and purchase-state behavior are enforced by the backend rather than left to client-side convention.
What is visible
Shared wishlists can be viewed by other signed-in people. Private wishlists are not exposed to non-owners. Search by username or verified phone number only works when the profile owner has enabled that discovery method.
Purchase-state protection
One of Wishwell's core rules is that wishlist owners do not see bought-state spoilers on their own items. Buyers can coordinate claims without revealing that state back to the owner.
Current MVP note
Privacy export/download and account deletion flows are not part of the current web MVP. Those controls will be revisited after launch as dedicated product work.