Privacy
What we do with your data
This is a courtesy translation. The binding version of this notice is the Polish one at Prywatność. Where the two differ, the Polish text applies.
A wedding app is a list of the names of the people closest to you, sitting behind a public address. We take that seriously, so this page is specific: what reaches the server, where that server is, how long the data stays there, and what to do to make it disappear sooner.
We track nobody. Neither this site nor your wedding page carries Google Analytics, a Facebook pixel, or any other advertising tool. We neither sell nor share your guests' data with anyone. That is also why you get no cookie consent banner here — there is nothing to ask about.
Guest names do not leave Cloudflare's infrastructure. The rule below covers only the material the couple uploads in the admin panel for the machine to read and fill the app with:uploaded text is read on our side, an uploaded photograph of a document goes to Google. A pasted list, notes, and spreadsheet or document files are processed on Cloudflare. A photograph of a document — a sheet with the floor plan, a printed running order, the menu card — goes to Google AI Studio, so the model can read the table numbers, times and dish names off it.
Wedding photographs are a different thing entirely. The guest gallery and the photographs the couple uploads to their wedding page go to Google no more than to any other model. They sit on Cloudflare R2, and nothing reads or captions them.
That is why a guest list cannot be uploaded as a photograph. We accept it only as text, a spreadsheet or a document.
A model runs only when you ask it to. By uploading a file or pasting text to be read, or by ticking "translate" beside a caption you reworded. A couple who types everything in by hand and leaves that box alone runs no model at all — nothing here happens in the background. The detail is in Artificial intelligence.
Beyond that, the organiser's email address goes to Resend (sending mail) and Stripe (payment). Typefaces on this public site are served from our own server, so opening it does not connect you to Google. On a wedding page the typefaces still come from Google Fonts, and there a guest's IP address reaches Google when the page opens. All of them are named below.
Who the controller is
The controller is the entity operating calm.wedding, identified in the terms. Contact for personal-data matters: data@calm.wedding or the contact form.
For guest data the couple is the controller and we are the processor: it is the couple who decides who goes on the list and how long the event stays available. For the organiser's account data (email address, payment) we are the controller.
What we store
| Data | What for | Where |
|---|---|---|
| Guest names, table assignments, the couple's notes | So a guest can find their seat — the main feature that uses this data | Cloudflare R2 |
| The running order, venues, transport phone numbers, content entered by the couple | The content of the guest app | Cloudflare R2 |
| Photographs and videos added by guests | The shared wedding gallery | Cloudflare R2 |
| The organiser's email address | Sign-in by link, draft and end-of-gallery notices, payment | Cloudflare R2 + Resend + Stripe (payment for publication) |
| The organiser's session and an identifier for whoever uploads a photograph | Staying signed in, and upload limits; the identifier is random and anonymous | Cloudflare Durable Objects, a cookie in the browser |
| Request logs: IP address, browser type, page address, date and time | Security, abuse detection and fault diagnosis. We do not join them to the guest list | Cloudflare |
What we do not collect
- We run no guest accounts or individual sign-ins. The Organiser may set one shared password for the gallery only.
- We do not collect RSVPs or information about diets and allergies. That was a deliberate product decision: less data, less risk.
- We use no external analytics, no advertising pixels and no marketing cookies. Cloudflare, as our host, produces aggregate traffic statistics — with no cookie and without tying them to a particular guest.
- We strip the metadata from every photograph and video before storing it, including GPS coordinates. We reject HEIC files, because their metadata cannot be removed safely without rewriting the whole file.
On what basis
The GDPR requires a stated legal basis for every processing operation. Ours are these:
| What | Basis |
|---|---|
| Building and publishing an event, handling payment, signing in by link | Performance of a contract — art. 6(1)(b) GDPR |
| Guest data: names and table assignments | Entrusted by the couple — art. 28 GDPR. The couple is the controller; we process on their instruction |
| Photographs and videos added by guests | Entrusted by the couple — art. 28 GDPR. A guest adds a file voluntarily and can delete it themselves |
| Request logs, rate limits, abuse prevention | Legitimate interest — art. 6(1)(f) GDPR |
| Invoices and accounting records | Legal obligation — art. 6(1)(c) GDPR |
Providing data is voluntary, but without the organiser's email address an event cannot be created or signed into, and without a guest list the app has nothing to search. We send no newsletter and ask for no marketing consent, so there is no consent here that would need withdrawing.
Artificial intelligence
This section is about the material the couple uploads in the admin panel for the machine to fill the app with — not about wedding photographs.
All of it is optional. An automated read happens only when you ask for one, by uploading a file or pasting text to be read. Everything the machine does can be typed in by hand instead — the guest list, the tables, the running order, the menu and the attractions. A couple who enters everything themselves runs no model at all: nothing of theirs reaches Workers AI or Google AI Studio, because there is nothing to read. Nothing here runs in the background.
No exceptions and no asterisk. The only place in the panel besides uploading a file where your text reaches a model is translating a caption ("Your words") into the other languages your wedding serves — and that happens only when you tick the box for it as you save. It is unticked by default. Leave it alone and only your own language is stored, with our text standing in the others. The translation, if you ask for one, runs on Cloudflare Workers AI and covers that one caption — never the guest list, and never any data belonging to your guests.
Text is read on Cloudflare, photographs of documents in Google. A pasted guest list, notes about the day and spreadsheet or document files are read by models running on Cloudflare Workers AI. A photograph of a document — a sheet with the floor plan, a printed running order, the menu card — is sent to Google AI Studio (Google Ireland Limited), which reads the table numbers, times and dish names off it.
We do not accept a guest list as a photograph, so a guest's name is never part of an image sent to Google.
Gallery photographs and videos — the ones guests add, and the ones the couple uploads to their own page — are sent nowhere and passed through no model. They stay on Cloudflare R2.
We do not train any models on your data and we make no automated decisions about anyone. The result of every read is shown to you for correction before it is saved — the machine proposes, you decide.
How much of a name a guest sees
The seating plan sits behind an address your guests know — but it is still a public address. So in the panel, next to the guest list, you choose one of three display modes: the full name, a first name with an initial (“Anna K.”), or the first name alone. Search matches only the text visible on screen. If you choose “Anna K.”, the full surname never reaches a guest's browser and cannot be used to find that person.
For how long
- An untouched draft — deleted 7 days after the last edit, after a warning sent on the fifth day.
- Guests' names — deleted from the event document 60 days after the wedding date. On every plan, without exception: longer retention of guest data is not something anyone can buy from us. The seat lookup stops working then; the page itself stays.
- Guests' photographs and videos — the gallery remains available for the term the couple chose: 60 days to 5 years from the wedding date. The term for this wedding is shown on the upload screen before a guest sends anything. Two weeks before the end we send the couple a link to download everything; then the files are deleted. We store nothing indefinitely.
- The event document (guest list, plan, running order) — deleted together with the gallery.
- Accounting data — kept as long as tax law requires.
- Request logs — held by the infrastructure provider for a short period following its own settings; we build no archive of our own from them.
Your rights
You have the right of access, to a copy, to rectification, to erasure, to restriction of processing, to portability, and to object to processing. Requests go through the contact form (subject “Personal data”) or by email to data@calm.wedding. We answer without undue delay and within one month. If a request is complex or we receive many requests, that period may be extended by two further months; we will tell you within the first month.
A couple does not need to ask us: in the organiser panel, under “Download or delete” (“Pobierz albo usuń”), you can at any time download every photograph at original resolution and the whole event document as JSON, and delete the entire event immediately. Deletion is immediate and irreversible — we keep no backups from which it could be restored.
A guest can use this channel too, not only the couple — if somebody does not want to be on the list, writing to us is enough. You may also lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warszawa).
Sub-processors
We use 5 processors. The full, dated register — with purpose, location and the data involved — is published on the sub-processors page.
How we know an advertisement worked
Our advertisements and posts link here with a ?ref= parameter — for examplecalm.wedding/en/?ref=ig. It is one word from a closed list: ig, fb, tiktok, pin, google, yt, partner, grupa, qr, stopka, poradnik, narzedzia, organic. A channel name, nothing more — no identifier, so there is nothing to join across pages or across devices.
Two things are stored from it: a server-side arrival counter (the channel name and the page language, no IP address and no browser identifier), which Cloudflare discards afterabout three months, and — if a couple starts a draft wedding with us — that same one word on their event document, which goes when the document goes, on the schedule in “For how long”. Beyond that, we store nothing on your device: the parameter travels in the address and ends with the visit.
Cookies and browser storage
We use at most three cookies, all strictly necessary: the organiser's session, an anonymous identifier for whoever uploads a photograph (for limits and deletion of their own file), and — only when the Organiser protects the gallery — a signed record that the shared password was entered correctly. It does not contain the password.
Beyond that we keep two things in the guest's own browser storage: the name they picked from the list — so the app remembers whose seat to show — and their progress in the photo challenges. That data stays on the guest's device and does not reach us. The language follows the page address, not a cookie.
There are no analytics or advertising cookies here, so we do not ask for a consent we do not need. That includes measuring whether our advertising works: we do it with a parameter in the address rather than a cookie, precisely so we never have to put a banner in front of you.
Security
All traffic runs over HTTPS. The organiser panel opens with a link sent to the email address given when the event was created — there is no password to steal or reuse elsewhere. Event data sits in storage reached only by our application, and organiser pages are not indexed by search engines.
Two things we do because neglecting them cannot be undone: we strip the metadata from every photograph before it reaches the gallery, and we delete data on schedule automatically rather than when somebody remembers. No system is proof against everything — if a personal data breach happens anyway, we will notify the supervisory authority and, where the law requires it, the people concerned.
Changes
We email the organisers of active events about material changes to this page. The date of the last update is always at the top.