1. Who we are
ForeverAfter operates the website at getforeverafter.com and the ForeverAfter wedding planning apps for iOS and Android (the "Service"). We are the data controller for the personal data described in this policy, except where section 5 says otherwise.
- Contact: support@getforeverafter.com
This policy explains what we collect, why we collect it, how long we keep it, and what you can ask us to do about it. It applies to couples who use the Service, to people they invite to help them plan, and to wedding guests whose details reach us through a guest list or an RSVP.
2. The data we hold
2.1 Your account
Your name and email address, a profile picture if you sign in with Google, and a password that we store only as a hash. We record whether your email address is confirmed, which platform you signed up on, and the notification and email preferences you set.
2.2 Your wedding
Everything you enter: partner names, the date, the venue and its address, your budget, expenses, payments, receipts and contracts you upload, savings, contributors, checklist tasks, the day-of schedule, seating plans, and the content of your wedding website.
2.3 Your guests
Names, and the group each guest belongs to. If you collect RSVPs: the reply, the menu choices, any note the guest writes, and an email address if the guest chooses to give one after replying. Guests may also upload photographs and videos to your album. Section 5 explains who decides what happens to this data.
2.4 Payments
Premium bought on the web is processed by Stripe. Premium bought in our apps is processed by Apple or Google and verified through RevenueCat. We never see or store your card details. We keep the transaction reference, the amount, the currency, the status and the date.
2.5 Usage and device data
We record visits, page views, actions taken in the app, and web performance measurements. Each record can include your IP address, an approximate location derived from it (country, region, city), the referring page, the campaign parameters in the link you arrived on, the browser and operating system, the device type, the screen size, and whether you are on the web or in the app. Where we rate-limit a public page, we store a salted hash of the IP address rather than the address itself.
2.6 Support and messages we send you
Support tickets, their messages, and any file you attach. For emails we send you, we record that the email was sent and whether it was delivered, opened, clicked, bounced or reported as spam, so that we can tell whether our email reaches people and stop writing to an address that rejects us.
3. Why we use it, and our lawful basis
Under UK GDPR we must have a lawful basis for each purpose. These are ours.
| Purpose | Data | Lawful basis |
|---|---|---|
| Give you the Service you signed up for | Account, wedding, guest list | Performance of a contract |
| Sign you in and keep your account secure | Account, session, device | Performance of a contract |
| Take payment and grant Premium | Payment records, account | Performance of a contract |
| Keep accounting records of a sale | Payment records | Legal obligation |
| Answer your support messages | Support tickets, account | Performance of a contract |
| Run the AI planner and invoice scanning when you use them | Your request, the wedding data needed to answer it | Performance of a contract |
| Send planning reminders and product emails | Account, wedding progress | Legitimate interests: keeping our own customers informed. Every such email carries an unsubscribe link. |
| Schedule reminders on your phone | Wedding dates, tasks, payments | Consent: the notification permission you gave the app, which you can withdraw in your phone settings or in Settings |
| Understand how the Service is used and improve it | Usage and device data | Legitimate interests: knowing which features work. See section 9 for the cookies this uses. |
| Find and fix errors | Error reports, which can include your IP and account id | Legitimate interests: a working product |
| Prevent abuse, spam and fraud | Hashed IP addresses, request patterns, payment status | Legitimate interests: protecting the Service and its users |
| Alert our team to signups, purchases and support messages | Email address, wedding name, support message: sent to our private Discord channel | Legitimate interests: running a small business |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (section 8). We do not make decisions about you by automated means that have a legal or similarly significant effect. We do not sell personal data, and we never use wedding data for advertising.
4. How long we keep it
| Data | Kept for |
|---|---|
| Account and wedding data, including the guest list | Until you delete your account. Deletion is immediate, not queued |
| Guest photographs and videos | Three months after the wedding, or after the upload if that is later. Then the files and their records are deleted together |
| Payment records | Six years, because tax law requires it |
| Support tickets and attachments | Deleted with your account |
| Email addresses that bounced or reported us as spam (our suppression list) | Kept after account deletion, and held against the address itself. It is the only way to be sure we never write to that address again |
| Usage and device records | We do not currently delete them. When you delete your account the link to you is removed, so what is left does not name you |
You can delete your account and its wedding data yourself, from Settings in the app. It happens at once: the wedding, its guests, its photographs and the stored files all go in the same operation. A wedding you share with someone else is not deleted. Your membership is removed and another member becomes the owner.
5. Wedding guests
Most people in our database never signed up for anything. They are guests at somebody's wedding. This section is for them.
The couple decides. When a couple adds you to their guest list, they decide what is recorded and why. We hold and process it on their behalf and on their instructions, in the same way as a contacts app or a spreadsheet would. If you want your details changed or removed, ask the couple first. They can do it in seconds. You can also write to us at support@getforeverafter.com and we will help, and we will tell the couple.
What we collect directly from you. If a couple sends you an RSVP link, the reply you submit, whether you are coming, your menu choices, and any note, comes straight to us. After you reply we ask, optionally, for an email address, so the couple can send you wedding updates and photographs. You can skip that and your reply still counts. If a couple shares a photo link, anything you upload goes to us and into their album.
Who can see it. The couple and anyone they have invited to help plan. RSVP and photo links are unguessable web addresses, and anyone holding the link can see what the couple has shared there. A guest list is never public and is never shared with anyone else.
How long. Guest details last as long as the couple's account. Photographs and videos are deleted three months after the wedding.
We never sell guest details, never advertise to guests, and never use a guest list to market the Service. The only email we would send a guest is one the couple asked us to send.
6. Who we share it with
We use the companies below to run the Service. Each is bound by contract to use the data only for the work we ask of them.
| Provider | What they do | What reaches them |
|---|---|---|
| Cloudflare | Hosting, content delivery, and storage of uploaded photographs, receipts and attachments | Everything served or uploaded, plus request metadata |
| Neon | The database. It runs in London | All account, wedding and guest data |
| Stripe | Payments on the web | Your email address and the payment itself |
| Apple, Google, RevenueCat | In-app purchases and verifying them | Purchase records and a purchase identifier |
| Resend | Sending email and reporting what happened to it | Your email address, the message, and delivery and open events |
| Sentry | Error monitoring | Error reports, which can include your IP address and account id |
| Sign-in with Google, and website analytics | Sign-in identity if you use it; usage and device data for analytics | |
| OpenRouter and the AI model providers it routes to | The AI planner and invoice scanning | Only when you use those features: your request and the wedding information needed to answer it, including an invoice image you upload |
| Discord | Internal alerts to our own team | Signups, purchases, refunds and support messages, including the email address and the message text |
People you invite to your wedding, contributors and viewers, see the data you share with them, according to the role you gave them. We also disclose data where the law requires it, and our own staff can see wedding data when they are answering your support request or investigating abuse.
7. Sending data outside the UK
Our database runs in London. Some of the providers in section 6 are based outside the UK, or run their systems in more than one country, so your data may be transferred abroad. Where that happens we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses. Write to us if you would like details of the safeguard used for a particular provider.
8. Your rights
You have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- object to processing we base on legitimate interests, and to ask us to restrict processing while we consider it;
- receive the data you gave us in a portable format, or have it sent to another provider;
- withdraw consent where we rely on it, such as notification permission, without affecting anything done before you withdrew it; and
- ask us not to send you marketing email, at any time.
Write to support@getforeverafter.com. We answer within one month, and there is no charge. You can delete your account and all of its data yourself at any time from Settings.
If you are unhappy with how we have handled your data, please tell us first so that we can put it right. You can also complain to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113.
9. Cookies and storage on your device
We store the following on your device:
- Essential cookies: your sign-in session, and a small cookie that tells the site whether you are signed in before the page renders. Without these the Service cannot work.
- Preferences: your theme and currency choices.
- A copy of your own data: the app keeps recently loaded wedding data in your browser's local storage, so it opens instantly and still shows your plans when you have no signal. It never leaves your device. Signing out clears it.
- Analytics cookies: Google Analytics cookies, set when you use the Service, which tell us which pages and features people use. You can block or delete them in your browser settings, or with a content blocker, and the Service works normally without them.
10. Notifications
Our apps can schedule reminders on your phone about tasks, payments and your wedding date. They are scheduled by the app on the device itself. We record whether you granted the permission, so that we do not also send you the same reminder by email. Turn them off in Settings or in your phone's own settings at any time.
11. Security
We use encrypted connections, hashed passwords, access controls, and unguessable tokens for the links you share. We monitor errors and rate-limit public pages to stop abuse. No system is perfectly secure, and we cannot guarantee absolute security. If a breach puts your rights at risk we will tell you, and we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it.
12. Children
The Service is not for anyone under 16, and we do not knowingly collect their personal data. Children do attend weddings, and a photograph uploaded to an album may show one; the couple who runs that album decides what belongs in it. If you believe we hold data about a child that should not be there, write to us and we will remove it.
13. Changes to this policy
We may update this policy. If a change materially affects you, we will tell you by email or in the app before it takes effect, and we will update the date at the top of this page.
14. Contact us
Write to support@getforeverafter.com with any question about this policy or about your data.