1. Controller And Contact
Wedlune ("we", "our", or "us") is the controller for the account and service data described in this policy and provides the Wedlune mobile app and website. For privacy requests, contact us at support@wedlune.com. This address is monitored for access, correction, deletion, objection, consent, and other data-protection requests.
2. Information We Collect
We collect information you provide or create in the app or on guest-facing web pages:
- Account information: email address, name, partner name, authentication identifiers, language, currency, theme, subscription status, and partner-invitation details.
- Wedding details: wedding date, venue style, location, ceremony preferences, budget range, guest count, questionnaire answers, notes, and recommendation preferences.
- Planning data: guests and RSVP details, RSVP page designs and images, wishlists, wishlist images, private gift reservations, meal and dietary notes, seating, budgets, vendors, venues, accommodation, transport, attire, legal documents, timelines, checklists, payment milestones, message templates, photos, and shared shot list links. Dietary, accessibility, and similar notes may reveal sensitive information, so add only what is necessary. For a reservation, we retain the wishlist item, quantity, and minimal RSVP-party reference needed to let that party change or cancel it. The couple and other guests are shown quantities, not the reserving party's identity.
- AI feature data when you consent: accepted messages and responses, conversation titles and summaries, action proposals, recommendation criteria and results, feedback, source titles and URLs, consent records, and operational metadata such as the routed model, usage, cost, cache, and generation details.
- Technical data: device, app, and browser metadata; IP address and request data for website and Edge requests; local sync state; redacted error logs; security logs; rate-limit records; and timestamps needed to operate and protect the service.
- Optional analytics: limited usage events only if you explicitly enable analytics in the app's Settings. AI prompt and message content is not sent to application analytics.
3. How We Use Your Information
We use personal data to provide and secure the app and website, authenticate users, sync planning data, enable partner collaboration and public RSVP/gallery features, provide features you request, process subscriptions, support users, prevent abuse, comply with legal obligations, and improve the service when analytics are enabled.
Core features rely on contract performance; optional AI features, analytics, personalized advertising where offered, and device permissions rely on consent where applicable; and security, fraud prevention, rate limiting, required consent evidence, tax, accounting, and compliance records rely on legitimate interests or legal obligations. Section 6 explains the shared AI consent. We do not sell your wedding-planning data.
Account information is required to create and secure an account; other fields are optional unless a feature marks them as required. Wedlune does not make solely automated decisions that produce legal or similarly significant effects. AI output is advisory and planning changes require your review or confirmation.
4. Storage, Security, And Transfers
Cloud data, including private AI chat history and recommendation history, is stored with Supabase using authentication, Row-Level Security, per-wedding access controls, and encrypted transport (TLS). Uploaded photos, RSVP design images, wishlist images, and documents are stored in Supabase Storage with access controls. Cloudflare provides DNS, delivery, security, and hosting for wedlune.com and its public RSVP, gallery, and authentication-callback pages, and processes traffic and request metadata such as IP addresses.
The current OpenRouter connection uses its global endpoint, and OpenRouter, routed providers, Exa, Cloudflare, or other service providers may process relevant service data outside the EEA. Where GDPR requires it, transfers rely on adequacy decisions, Standard Contractual Clauses in the applicable data-processing agreement, or equivalent safeguards.
5. Local Data And Notifications
The app stores secure session tokens, "remember me" state, preferences, offline cache, pending offline changes, and local notification schedules on your device. Notifications are generated locally and may include task titles and due-date timing.
6. AI Features
AI chat, recommendations and business discovery, venue lookup, and missing-task suggestions share one optional consent for the current policy version. Consent is recorded per account, reused across signed-in devices, and independent for each wedding partner. It is checked before saved AI results, caches, quotas, wedding context, or model calls are accessed. Some features separately require Premium. Route calculations and deterministic timeline generation are outside this consent.
When you consent and use an AI feature, secure Supabase Edge Functions send only the data needed for that request to the AI and search services listed in Section 7. This may include your screened question, sanitized recent history, guest-safe planning summaries, relevant saved public business details, public location and search criteria, and a pseudonymous routing value. Guest and couple names, contacts and notes; account and planning identifiers; files; internal notes; private route labels; and route coordinates are excluded. Detection is not perfect, so do not manually enter third-party personal data. AI-generated action proposals cannot make changes themselves: the app resolves private fields locally and asks you to confirm the exact change.
Wedlune privately stores accepted messages and responses, conversation titles and summaries, proposals and their status, recommendation criteria and results, source titles and URLs, feedback, and operational metadata in Supabase. Raw web-search excerpts and page content are not stored. Revoking consent locks all covered AI features and permanently deletes your AI conversations, messages, proposals, feedback, recommendations, recommendation selections, and follow-up responses. Imported businesses, accepted tasks, and other confirmed planning changes remain. Required consent evidence and limited security or rate-limit records may be retained.
Separately, route geocoding sends the endpoint text and optional country hint you enter, followed by selected coordinates for distance and duration calculation, to openrouteservice. It does not receive wedding, user, guest, or planning-record identifiers. Do not enter a private home address or other third-party personal data.
AI results may be incomplete or incorrect. Always review and independently verify availability, pricing, legal, scheduling, and other important information before use.
Usage limits: Free recommendations allow one successful generation per section per wedding with up to two results; Premium allows 10 per rolling 24 hours with up to four results. Free missing-task scans allow one successful scan per wedding with up to three tasks; Premium allows five per rolling 24 hours with up to five tasks. Free venue lookup allows two successful unique lookups per wedding; Premium allows 20 per rolling 24 hours. Premium AI chat allows 20 completed turns per rolling hour and 100 per rolling 24 hours per account. Cached responses, failed provider calls, and released claims do not consume quota; background refreshes and refinements do. Separate burst-abuse limits may apply, and operational quota metadata is retained to enforce limits and protect the service.
7. Third-Party Services
We use the following services:
- Supabase: authentication, database, storage, and Edge Functions.
- Google Play or the Apple App Store, and RevenueCat: purchases, subscription status, product identifiers, expiry dates, and transaction metadata. We do not receive full payment-card details.
- Cloudflare: DNS, content delivery, security, and hosting for the public website, RSVP, gallery, and authentication-callback pages; it processes IP addresses and traffic/request metadata.
- Google AdMob: free-tier banner ads, which may collect device identifiers, approximate location, ad interactions, and diagnostics under Google's policies. Premium users do not see ads.
- OpenRouter and its routed model providers: processing of minimized AI-chat and verified business-discovery requests. Eligible model endpoints are limited to those OpenRouter marks as Zero Data Retention and non-collecting.
- Exa: public-web research queries and retrieval of public page evidence for verified business discovery. Wedlune does not persist the raw evidence.
- openrouteservice: geocoding of user-entered transport endpoint text and route calculation from selected coordinate pairs.
- Google Gemini: stateless missing-task suggestions. Provider notices explain processing practices and are not additional terms that users personally accept through Wedlune.
8. Partner Collaboration And Guest Data
Wedlune lets you invite a partner to a shared wedding plan. We store invitation emails, invitation status, partner permissions, and activity entries. Depending on the selected role, a partner may view or edit shared data such as guests, budget, vendors, timeline, photos, and documents.
Do not add third-party personal data, including guest contact or dietary information, unless you have a lawful reason to do so and can share this privacy information with them if needed.
A guest who opens a valid RSVP link can view a published wishlist and reserve quantities regardless of RSVP response. The reservation-party association is used to prevent duplicates and allow that same party to edit or cancel its reservation; it is not exposed in couple-facing or guest-facing responses.
If one member deletes their account while a partner remains, the shared wedding plan, contributions, activity history, and shared files remain with the partner. Account-specific data and private AI history are not transferred.
One partner with edit or view access and activity history is included on Free. Either member's direct Premium subscription unlocks the shared wedding; disconnecting removes only derived shared access. A valid public RSVP token is checked before plan state. Free RSVP uses the default presentation at up to 50 invited people and excludes wishlist data. Above 50, responses pause without revealing subscription details. Premium may show the preserved published design and wishlist; expiry preserves them and renewal restores them.
9. Usage Analytics
Usage analytics are off by default. If you turn them on in Settings, we collect limited in-app events such as sign-up, sign-in, questionnaire completion, recommendation generation, task actions, and aggregated screen/session counts. Events may be linked to your account so we can improve the product and understand feature adoption. You can turn analytics off at any time; doing so stops collection and clears locally queued analytics.
We do not use an external crash-reporting SDK.
10. Retention And Deletion
We keep account and planning data while your account is active. You can delete your account in the app under Settings → Delete Account or through our account deletion page. Deletion removes your authentication account, profile, private AI data and consent, analytics, and account-specific storage where technically possible. If no partner remains, the wedding plan and its planning data and shared files are also deleted. If a partner remains, the shared wedding plan, planning records, activity history, and shared files remain available to that partner; your private AI data is not transferred. Storage-file deletion may finish asynchronously after the account closes. You may also delete individual AI conversations or all chats without deleting the account.
We may retain limited records when required for security, fraud prevention, tax/accounting, dispute handling, or legal compliance.
11. Your Rights
If GDPR applies, you may request access, correction, deletion, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent. You can withdraw AI consent in Settings; Section 6 explains the resulting deletion and preservation of confirmed planning changes. You may lodge a complaint with your local EU/EEA data-protection authority.
12. Children
Wedlune is not intended for children under 16. Users must be at least 16 years old to create an account; if applicable law requires a higher age or legal capacity, that higher requirement applies.
13. Contact Us
For privacy-related questions or requests, contact support@wedlune.com.