Legal
Privacy policy
What we hold, where it is, and how to get it back or get it removed.
Last updated 2026-09-02
This is a working draft, written from what the product does. It has not been reviewed by a lawyer and is not yet binding.
What we hold
For members: the name, email address and profile photo your sign-in provider gives us, your preferences, and what you have done in the app.
For guests: whatever the couple adds about you — your name, and often your email address, phone number, travel, room, meal choice, dietary needs and RSVP. Guests do not have accounts; you reach your page through a personal link.
For everyone: the ordinary technical records a website keeps, and the token counts and identifiers of assistant conversations. Never the content of a conversation for analytics.
Where it is
The database and file storage are in the European Union (eu-west-1). The application runs in European regions. Email is sent from the EU, product analytics and error reporting are on EU hosts.
The assistant sends the part of the plan it needs to Anthropic to answer a question. It does not send your data anywhere else.
Who else sees it
The people invited to a wedding, at the level the owner set. A vendor sees their own part of the plan, not the rest of it.
Our sub-processors: the hosting, database, email, authentication, payment, analytics, error-reporting and AI providers listed in the data processing agreement. Nobody else.
How long
While the wedding exists. A deleted wedding is recoverable for thirty days and then purged, files included. An account you delete is anonymised — we keep the fact that a change was made, without your name on it, so a shared history does not develop holes.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Members do this from their account; guests can do it from their own page or by asking the couple.
If you are in the EU or the UK you can complain to your data protection authority.