Privacy Policy
MakeTheFishRich has no accounts, no ads, no analytics, and no trackers. We store what you type when you make a wish, a record of confirmed donations (processed by Stripe), and a few small settings in your own browser. That’s the whole list.
Questions or removal requests: hello@makethefishrich.com.
1. Who we are
MakeTheFishRich (“we”) runs makethefishrich.com — a social experiment and entertainment project in which a fish attempts to build a fortune, in public, starting from $0. This page explains what data the site handles and why. For anything it doesn’t answer, write to hello@makethefishrich.com.
2. What we store
Wishes. When you make a wish we store the wish text you write and, optionally, a display name. You make two separate choices. First, whether your wish is public or private: a private wish’s text is never displayed anywhere — only the fact that a wish exists, its number, the fish’s net worth at that moment, and the date it was made. Second, whether to sign your place in the record: the display name, if you enter one, is shown publicly for both public and private wishes — the form says so next to the field — and leaving it blank keeps you anonymous. Each wish also records a permanent wish number. Making a wish requires no email address and no account.
The Wish Vault Key. Every wish comes with a one-time recovery key so you can reclaim your wish on a new device. We store only a cryptographic hash of that key — we cannot see or recover the key itself.
Community campaigns. If you submit an entry (like a fish name) we store the text of the entry. Votes are recorded against a random token generated in your browser — not your name, email, or address.
Donations. Payments are handled entirely by Stripe; we never see or store card numbers or payment credentials. When a donation is confirmed, we record it in our contributions ledger for bookkeeping — the transaction details Stripe reports to us, which may include information you provide to Stripe at checkout. We keep this privately and don’t publish it.
3. What stays in your browser
The site uses your browser’s local storage — not tracking cookies — for a few functional values: a cached copy of the project phase (so the page paints instantly), a device token that marks your wish as yours on this device, your local wish receipt, a random voter token, and flags that remember which campaigns you’ve already voted in. A service worker also caches the site’s files so the site loads fast and works offline. All of this lives on your device; clearing your browser data removes it (your wish stays safe if you saved your Wish Vault Key).
4. What we don’t do
- No analytics or usage tracking of any kind.
- No advertising, ad networks, or marketing pixels.
- No selling, renting, or sharing of your data with anyone.
- No profiling and no cross-site tracking.
- No raw IP addresses stored in our database.
5. Services we rely on
A small set of services makes the site work. Each processes only what its job requires, under its own privacy policy:
- Cloudflare — serves the site and shields it from abuse. Like any host, it processes standard connection data (such as your IP address) to deliver pages and block attacks. Our submission endpoints use Cloudflare’s Turnstile bot check, which may evaluate your connection to tell humans from bots.
- Supabase — hosts our database (the wishes, donations records, and campaign entries described above).
- Stripe — processes all donations on its own platform.
- Google Fonts — serves the site’s typefaces; your browser requests them directly from Google.
- jsDelivr — serves one open-source script the site needs.
- Live stream player — when the fish is live, the player is embedded from our streaming provider, which may set its own cookies while you watch.
The footer also links to our profiles on social platforms; those links simply take you there — nothing is loaded from those platforms on this site.
6. What’s public
Public wishes appear on the WishWall and on their own wish page with the text, the display name you chose, the wish number, and the date — including in share images for social platforms. Private wishes never expose their text, but the details that place a wish in the story — its number, the fish’s net worth at that moment, and the date it was made — are public for every wish; the optional display name, if you entered one, appears publicly beside the masked wish (the form states this where you type it). A private founding wish’s certificate page is deliberately content-free and never carries a name. Anything you choose to make public can be copied or cached by others once shared — choose public, and a display name, knowingly.
7. Your choices
Want a wish’s visibility changed, a wish removed, or a copy of what we hold about a donation you made? Email hello@makethefishrich.com and we’ll sort it out. We keep donation records as long as bookkeeping requires.
8. Children
The site is a general-audience entertainment project and does not knowingly collect personal data from children. Donations require an adult (or a guardian’s permission).
9. Changes
If the way the site handles data changes, this page changes with it — the date at the top always reflects the current version.