Privacy policy

Last updated: 15 August 2026

easywed. ("we", "the app", available at easywed.app) is a wedding seating planner. This policy explains what data we process, why, on what legal basis, who we entrust it to, and what your rights are. The short version: your wedding plan belongs to you, we collect only what the app needs to work, and we never sell your data. The rules for using the app itself are in the Terms of Service.

Data controller

The controller of your personal data is Szymon Kurek, trading as Szymon Kurek (address: Czarnucha 6/132, 61-612 PoznaƄ), NIP: 6653048328, REGON: 522102512 - the operator of easywed., available at easywed.app. For any question about personal data, write to [email protected]. We have not appointed a data protection officer; for GDPR matters contact us directly at that address.

What data we process

Depending on how you use the app, we process:

  • Account data - your email address and password (stored only as a hash), or your name and email from Google if you sign in with Google. Handled by our authentication provider, Supabase.
  • A display name, only if you set one in Settings - it is the single piece of your identity visible to the people you share a wedding with. Your email address is never shown to them.
  • Wedding content you enter - wedding name and date, hall layout, tables, your guest list with seat assignments, and reminders.
  • Guest dietary information, if you fill it in. Note that this can indirectly reveal health (an allergy, coeliac disease) or religious belief (kosher, halal meals) - special category data under Art. 9 GDPR. The app never asks for the reason behind a diet: enter the meal choice itself (e.g. "vegetarian"), never a medical diagnosis or its justification.
  • Files you import - guest spreadsheets (CSV/XLSX) are parsed entirely in your browser; only the resulting guest list is saved, never the file itself.
  • Usage data - product events (screens visited, features used) and basic device and browser information, collected via PostHog in cookieless mode.
  • Data stored only on your device - language, colour theme, guest-mode wedding plans, and the AI assistant's settings and API key. These live in your browser's local storage and are never sent to our servers.

Why we process it, and on what legal basis

Every purpose has its own legal basis under Art. 6 GDPR:

  • Providing the service - storing and displaying your wedding plan, guest list and reminders, and syncing them across devices. Basis: performance of a contract (Art. 6(1)(b) GDPR). Providing this data is voluntary, but the app cannot work without it.
  • Running your account - authentication, display name, inviting other people to a wedding and managing their permissions. Basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Product analytics - seeing which features are used so we know what to build. Analytics runs in cookieless mode and cannot recognise you across sessions. Basis: our legitimate interest in improving the app (Art. 6(1)(f) GDPR). You have the right to object to this processing.
  • Security - preventing unauthorised access and abuse, technical logs. Basis: legitimate interest (Art. 6(1)(f) GDPR).
  • Handling complaints and claims, and for the Venue Plan also invoicing and tax obligations. Basis: legal obligation (Art. 6(1)(c) GDPR) and our legitimate interest in establishing and pursuing claims (Art. 6(1)(f) GDPR).

Where your data lives

Account data and wedding content are stored in a Postgres database managed by Supabase. Access is enforced by the database itself (Row Level Security): only members of a wedding - the owner and the people they invite - can read or change its data. The app itself is served by Cloudflare.

Transfers outside the EEA

We keep data inside the European Economic Area wherever we can. Our Supabase database runs in region eu-west-3 (Paris). Some of our providers are linked to the United States - those transfers rely on an adequacy decision (the EU-U.S. Data Privacy Framework) or on Standard Contractual Clauses approved by the European Commission. If you configure the AI assistant, you choose the model provider, and where your prompts go depends on that provider's location - we are not an intermediary in that transfer.

Guest mode (no account)

You can plan without an account. In that case the entire plan is stored in your browser's local storage on this device only - nothing reaches our servers, we have no access to it, and we make no backups of it. Clearing browser data or using private browsing deletes the plan for good; signing in later lets you move it to your account once.

AI assistant (bring your own key)

The assistant is optional and uses an API key you provide. Your messages and the relevant parts of your wedding plan are sent directly from your browser to the AI provider you configured - they never pass through or get stored on our servers. Your API key is kept only in your browser's local storage. The privacy policy and terms of your chosen provider apply to those requests; check in particular whether that provider uses submitted content to train models. Do not put anything into the assistant that you would not hand to that provider.

Who processes data for us

We never sell your data. We entrust it only to the providers that make the app work, under data processing agreements:

  • Supabase - authentication and database hosting.
  • Cloudflare - serving the application and abuse protection.
  • PostHog - product analytics.
  • Google - only if you choose to sign in with Google.
  • Your chosen AI provider - only if you configure the assistant, and only directly from your browser, outside our infrastructure.

Your guests' data

Guest names and dietary details are other people's personal data, and you decide which of them you enter. If you are planning your own reception, you are acting in the course of a purely personal or household activity - the GDPR does not apply to your own processing (Art. 2(2)(c) GDPR). That exemption does not extend to us: as the operator storing this data on our servers we remain its controller and process it solely to store and display your plan, on the basis of Art. 6(1)(b) and (f) GDPR. Using the app professionally, as a venue, event organiser or wedding planner, requires the Venue Plan: you are then the controller of your clients' and their guests' data, we process it on your instructions as a processor, and we conclude a separate data processing agreement with you - write to [email protected] about it. Either way: enter only the details you actually need, and remove them when they are no longer needed.

Cookies and local storage

We use no advertising cookies, we do not profile you, and we show no cookie consent banner - because there is nothing to ask you about. The only things we store on your device are the ones the app needs to do what you asked: your Supabase sign-in session, your chosen language and theme, guest-mode wedding plans, and the AI assistant's settings and API key. Under the Polish Electronic Communications Law, storage of that kind needs no consent. PostHog analytics runs in cookieless mode: it neither stores nor reads anything on your device - no cookie, no identifier in browser storage - so it does not trigger the consent requirement either. The server-side processing of those events rests on our legitimate interest, and you can object to it by writing to [email protected].

How long we keep data

We keep data for as long as it is needed for the purpose we collected it for:

  • Account data - for as long as the account exists. Once you delete it, we erase the data promptly.
  • Wedding content - guests, tables, hall layout and reminders - until you delete the wedding or your account. Deletion is irreversible, so export your guest list first.
  • Backups - we do not currently maintain database backups, so deletion is immediate and irreversible.
  • Analytics data - in pseudonymised form, for no longer than 12 months.
  • Data in your browser's local storage - until you clear your browser data. We have no access to it and cannot delete it for you.

Your rights

Under the GDPR you have the following rights (legal basis in brackets). To exercise any of them, write to [email protected] - we respond within one month. We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you.

  • access to your data and a copy of it (Art. 15 GDPR),
  • rectification - you can correct most of it yourself in the app (Art. 16 GDPR),
  • erasure, the "right to be forgotten" - you can do this yourself by deleting a wedding or your account in Settings (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability - export your guest list to CSV or XLSX straight from the app, or ask us by email for a full export (Art. 20 GDPR),
  • objection to processing based on our legitimate interest, including analytics (Art. 21 GDPR),
  • withdrawal of consent at any time where processing is based on it, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR),
  • lodging a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) if you believe we process your data unlawfully.

Changes to this policy

If we change this policy, we will update this page and the date above. Significant changes will be announced in the app and, if you have an account, by email.