Privacy

What we do with your data

Last updated: 12 września 2026

This is a courtesy translation. The binding version of this notice is the Polish one at Prywatność. Where the two differ, the Polish text applies.

A wedding app is a list of the names of the people closest to you, sitting behind a public address. We take that seriously, so this page is specific: what reaches the server, where that server is, how long the data stays there, and what to do to make it disappear sooner.

We track nobody. Neither this site nor your wedding page carries Google Analytics, a Facebook pixel, or any other advertising tool. We neither sell nor share your guests' data with anyone. That is also why you get no cookie consent banner here — there is nothing to ask about.

Guest names do not leave Cloudflare's infrastructure. The rule below covers only the material the couple uploads in the admin panel for the machine to read and fill the app with:uploaded text is read on our side, an uploaded photograph of a document goes to Google. A pasted list, notes, and spreadsheet or document files are processed on Cloudflare. A photograph of a document — a sheet with the floor plan, a printed running order, the menu card — goes to Google AI Studio, so the model can read the table numbers, times and dish names off it.

Wedding photographs are a different thing entirely. The guest gallery and the photographs the couple uploads to their wedding page go to Google no more than to any other model. They sit on Cloudflare R2, and nothing reads or captions them.

That is why a guest list cannot be uploaded as a photograph. We accept it only as text, a spreadsheet or a document.

A model runs only when you ask it to. By uploading a file or pasting text to be read, or by ticking "translate" beside a caption you reworded. A couple who types everything in by hand and leaves that box alone runs no model at all — nothing here happens in the background. The detail is in Artificial intelligence.

Beyond that, the organiser's email address goes to Resend (sending mail) and Stripe (payment). Typefaces on this public site are served from our own server, so opening it does not connect you to Google. On a wedding page the typefaces still come from Google Fonts, and there a guest's IP address reaches Google when the page opens. All of them are named below.

Who the controller is

The controller is the entity operating calm.wedding, identified in the terms. Contact for personal-data matters: data@calm.wedding or the contact form.

For guest data the couple is the controller and we are the processor: it is the couple who decides who goes on the list and how long the event stays available. For the organiser's account data (email address, payment) we are the controller.

What we store

DataWhat forWhere
Guest names, table assignments, the couple's notesSo a guest can find their seat — the main feature that uses this dataCloudflare R2
The running order, venues, transport phone numbers, content entered by the coupleThe content of the guest appCloudflare R2
Photographs and videos added by guestsThe shared wedding galleryCloudflare R2
The organiser's email addressSign-in by link, draft and end-of-gallery notices, paymentCloudflare R2 + Resend + Stripe (payment for publication)
The organiser's session and an identifier for whoever uploads a photographStaying signed in, and upload limits; the identifier is random and anonymousCloudflare Durable Objects, a cookie in the browser
Request logs: IP address, browser type, page address, date and timeSecurity, abuse detection and fault diagnosis. We do not join them to the guest listCloudflare

What we do not collect

On what basis

The GDPR requires a stated legal basis for every processing operation. Ours are these:

WhatBasis
Building and publishing an event, handling payment, signing in by linkPerformance of a contract — art. 6(1)(b) GDPR
Guest data: names and table assignmentsEntrusted by the couple — art. 28 GDPR. The couple is the controller; we process on their instruction
Photographs and videos added by guestsEntrusted by the couple — art. 28 GDPR. A guest adds a file voluntarily and can delete it themselves
Request logs, rate limits, abuse preventionLegitimate interest — art. 6(1)(f) GDPR
Invoices and accounting recordsLegal obligation — art. 6(1)(c) GDPR

Providing data is voluntary, but without the organiser's email address an event cannot be created or signed into, and without a guest list the app has nothing to search. We send no newsletter and ask for no marketing consent, so there is no consent here that would need withdrawing.

Artificial intelligence

This section is about the material the couple uploads in the admin panel for the machine to fill the app with — not about wedding photographs.

All of it is optional. An automated read happens only when you ask for one, by uploading a file or pasting text to be read. Everything the machine does can be typed in by hand instead — the guest list, the tables, the running order, the menu and the attractions. A couple who enters everything themselves runs no model at all: nothing of theirs reaches Workers AI or Google AI Studio, because there is nothing to read. Nothing here runs in the background.

No exceptions and no asterisk. The only place in the panel besides uploading a file where your text reaches a model is translating a caption ("Your words") into the other languages your wedding serves — and that happens only when you tick the box for it as you save. It is unticked by default. Leave it alone and only your own language is stored, with our text standing in the others. The translation, if you ask for one, runs on Cloudflare Workers AI and covers that one caption — never the guest list, and never any data belonging to your guests.

Text is read on Cloudflare, photographs of documents in Google. A pasted guest list, notes about the day and spreadsheet or document files are read by models running on Cloudflare Workers AI. A photograph of a document — a sheet with the floor plan, a printed running order, the menu card — is sent to Google AI Studio (Google Ireland Limited), which reads the table numbers, times and dish names off it.

We do not accept a guest list as a photograph, so a guest's name is never part of an image sent to Google.

Gallery photographs and videos — the ones guests add, and the ones the couple uploads to their own page — are sent nowhere and passed through no model. They stay on Cloudflare R2.

We do not train any models on your data and we make no automated decisions about anyone. The result of every read is shown to you for correction before it is saved — the machine proposes, you decide.

How much of a name a guest sees

The seating plan sits behind an address your guests know — but it is still a public address. So in the panel, next to the guest list, you choose one of three display modes: the full name, a first name with an initial (“Anna K.”), or the first name alone. Search matches only the text visible on screen. If you choose “Anna K.”, the full surname never reaches a guest's browser and cannot be used to find that person.

For how long

Your rights

You have the right of access, to a copy, to rectification, to erasure, to restriction of processing, to portability, and to object to processing. Requests go through the contact form (subject “Personal data”) or by email to data@calm.wedding. We answer without undue delay and within one month. If a request is complex or we receive many requests, that period may be extended by two further months; we will tell you within the first month.

A couple does not need to ask us: in the organiser panel, under “Download or delete” (“Pobierz albo usuń”), you can at any time download every photograph at original resolution and the whole event document as JSON, and delete the entire event immediately. Deletion is immediate and irreversible — we keep no backups from which it could be restored.

A guest can use this channel too, not only the couple — if somebody does not want to be on the list, writing to us is enough. You may also lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warszawa).

Sub-processors

We use 5 processors. The full, dated register — with purpose, location and the data involved — is published on the sub-processors page.

How we know an advertisement worked

Our advertisements and posts link here with a ?ref= parameter — for examplecalm.wedding/en/?ref=ig. It is one word from a closed list: ig, fb, tiktok, pin, google, yt, partner, grupa, qr, stopka, poradnik, narzedzia, organic. A channel name, nothing more — no identifier, so there is nothing to join across pages or across devices.

Two things are stored from it: a server-side arrival counter (the channel name and the page language, no IP address and no browser identifier), which Cloudflare discards afterabout three months, and — if a couple starts a draft wedding with us — that same one word on their event document, which goes when the document goes, on the schedule in “For how long”. Beyond that, we store nothing on your device: the parameter travels in the address and ends with the visit.

Cookies and browser storage

We use at most three cookies, all strictly necessary: the organiser's session, an anonymous identifier for whoever uploads a photograph (for limits and deletion of their own file), and — only when the Organiser protects the gallery — a signed record that the shared password was entered correctly. It does not contain the password.

Beyond that we keep two things in the guest's own browser storage: the name they picked from the list — so the app remembers whose seat to show — and their progress in the photo challenges. That data stays on the guest's device and does not reach us. The language follows the page address, not a cookie.

There are no analytics or advertising cookies here, so we do not ask for a consent we do not need. That includes measuring whether our advertising works: we do it with a parameter in the address rather than a cookie, precisely so we never have to put a banner in front of you.

Security

All traffic runs over HTTPS. The organiser panel opens with a link sent to the email address given when the event was created — there is no password to steal or reuse elsewhere. Event data sits in storage reached only by our application, and organiser pages are not indexed by search engines.

Two things we do because neglecting them cannot be undone: we strip the metadata from every photograph before it reaches the gallery, and we delete data on schedule automatically rather than when somebody remembers. No system is proof against everything — if a personal data breach happens anyway, we will notify the supervisory authority and, where the law requires it, the people concerned.

Changes

We email the organisers of active events about material changes to this page. The date of the last update is always at the top.