EverAfter Privacy Policy

Effective July 19, 2026

Information we process

Wedding profile, guest, RSVP, seating, schedule, vendor, budget, collaboration, approved communication, subscription entitlement, credit, and synchronization data you choose to enter. Vendor Access also processes business identity and contact details, service locations and travel radius, packages, credentials, website and approved social-profile links, application decisions, promotion entitlement, impressions, and external-link actions. Google sign-in supplies your account identity.

How it is used

Data is used to provide wedding planning, offline recovery, authorized synchronization, guest invitations, approved notifications, Concierge automation, vendor discovery, Vendor Access review and promotion, privacy-conscious product analytics, and account support. Digital purchases are verified with Apple or Google and never trusted from the mobile client alone.

Storage and sharing

The app stores a local copy on your device. Signed-in synchronization stores encrypted-in-transit records with Cloudflare D1. Vendor pictures, logos, videos, and social-media embeds are not uploaded, copied, cached, proxied, or displayed by EverAfter; vendors may provide external HTTPS website and social-profile links. Guest links are scoped, expiring, and revocable. Data is shared only with infrastructure and service providers needed to operate features you request.

Analytics

Owner analytics records allowlisted event names and counts, sessions, feature usage, and measured AI token and cost totals. It does not record wedding content, AI prompts or responses, vendor form values, passwords, or payment credentials. Identifiable analytics is retained for up to 13 months and then deleted after aggregate daily totals are produced.

Your controls

Settings lets you export your local and cloud account data or delete your account and local data. You may also follow the instructions on the EverAfter account deletion page. Deleting an owner account immediately deletes wedding workspaces that account owns. A shared wedding the account does not own remains for its other authorized members, with the deleted member removed.

Security and retention

Private APIs require expiring signed sessions and wedding membership. An RSVP link is permanently deleted 3 days after a response. An unanswered dated link expires 1 day after the wedding; an unanswered undated link expires after 90 days. Wedding workspace data is permanently deleted 30 days after the wedding date. A wedding with no date is deleted after 24 months without cloud activity. We send workspace deletion reminders approximately 14 days and 3 days beforehand. After account deletion, only billing, purchase-reconciliation, fraud-prevention, and signed-contract evidence is retained for 24 months, then permanently deleted. Non-identifying retention tombstones may be kept temporarily to prevent an offline device from recreating deleted data.

Contact

Email support@taronlevicompany.com for privacy questions or requests.