Back to Sposai

Privacy Policy

Last updated August 2026

Draft — not yet final. This document is published while the operating company, its registered address, the governing law and the data-protection contact are still being confirmed, and it has not been reviewed by counsel. It describes how Sposai works today, but do not rely on it as settled legal text.

Questions, or need the finalized version before you sign up? Email [email protected].

This Privacy Policy explains how Sposai (“Sposai,” “we,” “us”) collects, uses, shares, and protects personal data, and the rights you have. It reflects how the product is built today.

1. Who we are

The data controller for your account is [TO BE COMPLETED], [TO BE COMPLETED], contactable at [email protected]. Data-protection requests reach us at [TO BE COMPLETED]. Where you add information about your wedding guests, you are the controller of that guest data and Sposai acts as your processor — see §7.

2. Data we collect

Account data: email, authentication credentials, and login metadata. Wedding data you enter: event details, vendors, budget, tasks, and your guest website content. Guest data you enter: the names, email addresses, postal addresses, phone numbers, dietary requirements, and RSVP responses you record for your guests. Payment data: processed by our payments provider — we don’t store full card numbers. Usage & device data: logs, IP address, and basic analytics needed to operate and secure the Service. Anonymous usage counts: we count how many people reach our landing page, open the demo, request beta access, create an account, create a wedding and publish a guest site. These are counts only — no name, email, IP address, account identifier or cookie is recorded with them, so they cannot be traced back to you, and they are deleted after 180 days. Cookies: see §10.

3. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service to you); legitimate interests (to secure, maintain, and improve the Service, balanced against your rights); consent (where required, e.g. certain cookies — withdrawable at any time); and legal obligation (to comply with law). For guest data you upload, your lawful basis as controller is your responsibility (§7).

4. How we use data

To create and run your account; store and display your plans; render your guest website; send the emails you trigger (invites, reminders, confirmations); process payments; provide support; secure and debug the platform; understand how many people find and start using Sposai, so we can improve it (using the anonymous counts described in §2); and meet legal obligations. We do not sell personal data, and we don’t use guest data for advertising.

5. Sub-processors

We use vetted providers that process data on our behalf under data-processing terms: hosting/database & authentication ([Supabase]), email delivery ([Resend]), payments ([Stripe]), and application hosting ([Vercel]). The finalized policy will list each sub-processor, its purpose, and a link to its own privacy terms, and will be kept current.

6. International transfers

Our providers may process data outside your country (including the United States). Where required, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and the providers’ data-protection frameworks. [Confirm hosting regions and transfer mechanisms with counsel.]

7. Couples and their guests

When you add guest information, you confirm you have a lawful basis to share it with us and to invite those guests. As your processor, we handle that data only on your documented instructions to provide the Service, assist with security and data-subject requests, and delete or return it on termination. Guests with questions about how a couple uses their data should contact that couple directly.

8. Retention

We keep account and wedding data while your account is active. When you delete a record or your account, we remove it from active systems, subject to short backup-retention windows [specify, e.g. 30 days] and any retention the law requires (e.g. financial records).

8a. What happens to what you paste

When you use the brain dump (or paste notes, screenshots, or PDFs for Sposai to read), here is exactly what happens. Your text and files are sent once to our AI provider (Google Gemini, under a data-processing agreement) to be read — they are never used to train any model, and never shared beyond that processing. What the AI understood is shown to you for review; nothing becomes wedding data until you confirm it. Files you upload are stored privately with your wedding’s documents.

Raw pastes age out on a fixed clock: if you discard a dump (or it fails), the raw content is deleted within 7 days; a dump you never confirm is deleted within 30 days; after you confirm one, the raw paste is redacted within 90 days, leaving only the wedding data you approved and the files in your document library. Deleting your wedding deletes all of it — including any search indexes built from your documents.

Your conversations with the assistant follow the same 90-day clock. A saved turn keeps two things: what was said, and the structured record of any action the assistant took — which for something like a guest import contains the details you gave it, such as addresses and dietary notes. That structured record is removed after 90 days, leaving the conversation readable but no longer holding a second copy of your guest data. The wedding data you approved stays where it belongs, in your guest list. Starting a new chat retires the old thread rather than deleting it; deleting your wedding deletes every conversation with it.

9. Your rights

Subject to your jurisdiction, you may have the right to access, correct, delete, export (portability), restrict, or object to our processing of your personal data, and to withdraw consent. To exercise these, email [email protected]; we’ll respond within the legally required timeframe. You may also lodge a complaint with your local data-protection authority.

10. Cookies

We use cookies that are strictly necessary to keep you signed in and remember preferences (e.g. theme, active wedding, locale). We do not use advertising or tracking cookies, and our usage counting (§2) sets no cookie and stores nothing on your device — which is why you are not asked to accept anything. [If non-essential cookies or device storage are ever added, this section and a consent banner must be updated accordingly.]

11. Security

We use measures including encrypted transport (TLS), hashed passwords, scoped access tokens, and tenant isolation. No method is perfectly secure, but we work to protect your data and will notify you and regulators of a breach where the law requires.

12. Children

Sposai is not directed to children and you must not use it to collect data from anyone below the age your jurisdiction protects [e.g. 16 in parts of the EEA].

13. Changes & contact

We’ll post updates here and revise the date above; material changes will be communicated where required. Questions or requests: [email protected].