1. Who we are

ForeverAfter operates the website at getforeverafter.com and the ForeverAfter wedding planning apps for iOS and Android (the "Service"). We are the data controller for the personal data described in this policy, except where section 5 says otherwise.

This policy explains what we collect, why we collect it, how long we keep it, and what you can ask us to do about it. It applies to couples who use the Service, to people they invite to help them plan, and to wedding guests whose details reach us through a guest list or an RSVP.

2. The data we hold

2.1 Your account

Your name and email address, a profile picture if you sign in with Google, and a password that we store only as a hash. We record whether your email address is confirmed, which platform you signed up on, and the notification and email preferences you set.

2.2 Your wedding

Everything you enter: partner names, the date, the venue and its address, your budget, expenses, payments, receipts and contracts you upload, savings, contributors, checklist tasks, the day-of schedule, seating plans, and the content of your wedding website.

2.3 Your guests

Names, and the group each guest belongs to. If you collect RSVPs: the reply, the menu choices, any note the guest writes, and an email address if the guest chooses to give one after replying. Guests may also upload photographs and videos to your album. Section 5 explains who decides what happens to this data.

2.4 Payments

Premium bought on the web is processed by Stripe. Premium bought in our apps is processed by Apple or Google and verified through RevenueCat. We never see or store your card details. We keep the transaction reference, the amount, the currency, the status and the date.

2.5 Usage and device data

We record visits, page views, actions taken in the app, and web performance measurements. Each record can include your IP address, an approximate location derived from it (country, region, city), the referring page, the campaign parameters in the link you arrived on, the browser and operating system, the device type, the screen size, and whether you are on the web or in the app. Where we rate-limit a public page, we store a salted hash of the IP address rather than the address itself.

2.6 Support and messages we send you

Support tickets, their messages, and any file you attach. For emails we send you, we record that the email was sent and whether it was delivered, opened, clicked, bounced or reported as spam, so that we can tell whether our email reaches people and stop writing to an address that rejects us.

3. Why we use it, and our lawful basis

Under UK GDPR we must have a lawful basis for each purpose. These are ours.

PurposeDataLawful basis
Give you the Service you signed up forAccount, wedding, guest listPerformance of a contract
Sign you in and keep your account secureAccount, session, devicePerformance of a contract
Take payment and grant PremiumPayment records, accountPerformance of a contract
Keep accounting records of a salePayment recordsLegal obligation
Answer your support messagesSupport tickets, accountPerformance of a contract
Run the AI planner and invoice scanning when you use themYour request, the wedding data needed to answer itPerformance of a contract
Send planning reminders and product emailsAccount, wedding progressLegitimate interests: keeping our own customers informed. Every such email carries an unsubscribe link.
Schedule reminders on your phoneWedding dates, tasks, paymentsConsent: the notification permission you gave the app, which you can withdraw in your phone settings or in Settings
Understand how the Service is used and improve itUsage and device dataLegitimate interests: knowing which features work. See section 9 for the cookies this uses.
Find and fix errorsError reports, which can include your IP and account idLegitimate interests: a working product
Prevent abuse, spam and fraudHashed IP addresses, request patterns, payment statusLegitimate interests: protecting the Service and its users
Alert our team to signups, purchases and support messagesEmail address, wedding name, support message: sent to our private Discord channelLegitimate interests: running a small business

Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (section 8). We do not make decisions about you by automated means that have a legal or similarly significant effect. We do not sell personal data, and we never use wedding data for advertising.

4. How long we keep it

DataKept for
Account and wedding data, including the guest listUntil you delete your account. Deletion is immediate, not queued
Guest photographs and videosThree months after the wedding, or after the upload if that is later. Then the files and their records are deleted together
Payment recordsSix years, because tax law requires it
Support tickets and attachmentsDeleted with your account
Email addresses that bounced or reported us as spam (our suppression list)Kept after account deletion, and held against the address itself. It is the only way to be sure we never write to that address again
Usage and device recordsWe do not currently delete them. When you delete your account the link to you is removed, so what is left does not name you

You can delete your account and its wedding data yourself, from Settings in the app. It happens at once: the wedding, its guests, its photographs and the stored files all go in the same operation. A wedding you share with someone else is not deleted. Your membership is removed and another member becomes the owner.

5. Wedding guests

Most people in our database never signed up for anything. They are guests at somebody's wedding. This section is for them.

The couple decides. When a couple adds you to their guest list, they decide what is recorded and why. We hold and process it on their behalf and on their instructions, in the same way as a contacts app or a spreadsheet would. If you want your details changed or removed, ask the couple first. They can do it in seconds. You can also write to us at support@getforeverafter.com and we will help, and we will tell the couple.

What we collect directly from you. If a couple sends you an RSVP link, the reply you submit, whether you are coming, your menu choices, and any note, comes straight to us. After you reply we ask, optionally, for an email address, so the couple can send you wedding updates and photographs. You can skip that and your reply still counts. If a couple shares a photo link, anything you upload goes to us and into their album.

Who can see it. The couple and anyone they have invited to help plan. RSVP and photo links are unguessable web addresses, and anyone holding the link can see what the couple has shared there. A guest list is never public and is never shared with anyone else.

How long. Guest details last as long as the couple's account. Photographs and videos are deleted three months after the wedding.

We never sell guest details, never advertise to guests, and never use a guest list to market the Service. The only email we would send a guest is one the couple asked us to send.

6. Who we share it with

We use the companies below to run the Service. Each is bound by contract to use the data only for the work we ask of them.

ProviderWhat they doWhat reaches them
CloudflareHosting, content delivery, and storage of uploaded photographs, receipts and attachmentsEverything served or uploaded, plus request metadata
NeonThe database. It runs in LondonAll account, wedding and guest data
StripePayments on the webYour email address and the payment itself
Apple, Google, RevenueCatIn-app purchases and verifying themPurchase records and a purchase identifier
ResendSending email and reporting what happened to itYour email address, the message, and delivery and open events
SentryError monitoringError reports, which can include your IP address and account id
GoogleSign-in with Google, and website analyticsSign-in identity if you use it; usage and device data for analytics
OpenRouter and the AI model providers it routes toThe AI planner and invoice scanningOnly when you use those features: your request and the wedding information needed to answer it, including an invoice image you upload
DiscordInternal alerts to our own teamSignups, purchases, refunds and support messages, including the email address and the message text

People you invite to your wedding, contributors and viewers, see the data you share with them, according to the role you gave them. We also disclose data where the law requires it, and our own staff can see wedding data when they are answering your support request or investigating abuse.

7. Sending data outside the UK

Our database runs in London. Some of the providers in section 6 are based outside the UK, or run their systems in more than one country, so your data may be transferred abroad. Where that happens we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses. Write to us if you would like details of the safeguard used for a particular provider.

8. Your rights

You have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted;
  • object to processing we base on legitimate interests, and to ask us to restrict processing while we consider it;
  • receive the data you gave us in a portable format, or have it sent to another provider;
  • withdraw consent where we rely on it, such as notification permission, without affecting anything done before you withdrew it; and
  • ask us not to send you marketing email, at any time.

Write to support@getforeverafter.com. We answer within one month, and there is no charge. You can delete your account and all of its data yourself at any time from Settings.

If you are unhappy with how we have handled your data, please tell us first so that we can put it right. You can also complain to the Information Commissioner's Office, the UK data protection regulator, at ico.org.uk or on 0303 123 1113.

9. Cookies and storage on your device

We store the following on your device:

  • Essential cookies: your sign-in session, and a small cookie that tells the site whether you are signed in before the page renders. Without these the Service cannot work.
  • Preferences: your theme and currency choices.
  • A copy of your own data: the app keeps recently loaded wedding data in your browser's local storage, so it opens instantly and still shows your plans when you have no signal. It never leaves your device. Signing out clears it.
  • Analytics cookies: Google Analytics cookies, set when you use the Service, which tell us which pages and features people use. You can block or delete them in your browser settings, or with a content blocker, and the Service works normally without them.

10. Notifications

Our apps can schedule reminders on your phone about tasks, payments and your wedding date. They are scheduled by the app on the device itself. We record whether you granted the permission, so that we do not also send you the same reminder by email. Turn them off in Settings or in your phone's own settings at any time.

11. Security

We use encrypted connections, hashed passwords, access controls, and unguessable tokens for the links you share. We monitor errors and rate-limit public pages to stop abuse. No system is perfectly secure, and we cannot guarantee absolute security. If a breach puts your rights at risk we will tell you, and we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it.

12. Children

The Service is not for anyone under 16, and we do not knowingly collect their personal data. Children do attend weddings, and a photograph uploaded to an album may show one; the couple who runs that album decides what belongs in it. If you believe we hold data about a child that should not be there, write to us and we will remove it.

13. Changes to this policy

We may update this policy. If a change materially affects you, we will tell you by email or in the app before it takes effect, and we will update the date at the top of this page.

14. Contact us

Write to support@getforeverafter.com with any question about this policy or about your data.