Draft — not yet legally reviewed. This document was drafted as a starting point and has not been reviewed by a lawyer. Replace every bracketed placeholder with your real details and have it reviewed before relying on it with real users' data.

Privacy Policy — merrilyapp.com

Last updated: 2026-07-28 · Applies to the Merrily wedding-planning application (the "Service")

In plain language

(Only a summary — the sections below govern.)

1. Who is responsible for your data (the "Controller")

[Your full name or company name]
[Street address, postal code, city, Germany]
Email: inev-bit@mailbox.org

If you have appointed a Data Protection Officer, name them here: [DPO name/contact, or "not applicable"].

2. Two kinds of data, two different roles

Sensitive data warning

Please don't enter sensitive or private information into any free-text field. Avoid storing:

Most of the categories above are what GDPR Art. 9 calls "special category" data (health, religious or political beliefs, biometric or genetic data, sexual orientation) — we do not request, require, or want this data, and if it ends up in a free-text field anyway, we don't process, analyze, or use it for any purpose of our own; it simply sits there, encrypted at rest (§4), until you edit or delete it. More broadly, we apply data minimisation across the whole app: we only ask for the fields a feature actually needs to function, we don't request anything "just in case," and free-text fields exist because a wedding planner needs somewhere to write notes — not because we want that content. Like every other free-text field, our own staff only ever access the decrypted value when strictly necessary to provide technical support you've asked for (e.g. troubleshooting a bug report) — never routinely, and never for any other purpose. By using a free-text field, you're responsible for making sure you haven't put prohibited or sensitive information into it.

3. What we collect and why

In short: most of what we collect rests on performing our contract with you (Art. 6(1)(b)) — you use Merrily to organize your wedding, so we need to store your guest list, seating, expenses, and similar content to do that. A smaller set of aggregate, non-identifying signals (e.g. device type, active-day counts) rests on our legitimate interest in understanding and improving the app (Art. 6(1)(f)). Anything optional (language, self-declared country, marketing consent) rests on your consent (Art. 6(1)(a)), which you can withdraw at any time. The table below states the specific basis for each item.

WhatWhy / legal basis
Email, hashed password, display nameCreate and secure your account (Art. 6(1)(b))
Self-declared countryAggregate usage statistics (Art. 6(1)(a))
Language preferenceShow the app in your language
Device typeUnderstand usage in aggregate (Art. 6(1)(f))
Dates you were activeInternal aggregate statistics only (e.g. how many people return to the app versus visit once); we do not use this to build an individual usage profile beyond what's needed for that aggregate count (Art. 6(1)(f))
Guest data (encrypted at rest, see §4)Let you manage your guest list (Art. 6(1)(b), processor)
Expense entries and notesTrack your wedding budget (processor)
Helper contact infoTrack who is helping you (processor)
Wedding name/date/location/budgetPower the dashboard (processor)
Invite linksInvite collaborators (processor)
IP address of invite-link attemptsRate-limit abuse (Art. 6(1)(f))
Server access logsSecurity and debugging (Art. 6(1)(f))
Browser local storage: login tokenKeep you signed in (Art. 6(1)(b))
Marketing consent (opt-in)Send you occasional product updates, only if you tick the box at registration; withdrawable any time (Art. 6(1)(a))
Support messages you send us (encrypted at rest, see §4)Respond to your question, problem, or feedback (Art. 6(1)(b))
Referral code, and which user referred you (if any)Reward you and the person who invited you with free Premium time when you register via a referral link (Art. 6(1)(a))
Marketplace vendor quote-request details (your name, phone number, email, and message) (encrypted at rest, see §4)Sent directly to the vendor you're requesting a quote from, by email, so they can respond to you (Art. 6(1)(b))
Ratings and reviews you leave on a marketplace vendor (encrypted at rest, see §4)Shown to every user of the app, alongside your display name, to help other couples choose a vendor — not limited to your own wedding's collaborators (Art. 6(1)(a))
Email verification statusConfirm you control the email address you registered with, e.g. for account recovery (Art. 6(1)(f))
Password-reset tokensLet you reset a forgotten password; expire automatically after 60 minutes and are single-use (Art. 6(1)(b))
Mobile push notification device tokenOnly if you use our mobile app and enable notifications: lets us alert you when a collaborator changes your wedding, your support ticket status changes, or as a reminder about your own wedding-planning progress (e.g. an unconfirmed guest list, pending RSVPs, or an upcoming wedding date); removed when you sign out (Art. 6(1)(a))
Google account ID, email, and nameOnly if you choose "Sign in with Google" instead of a password: lets Google confirm your identity to us so we can create or log you into your account; we never see or store your Google password (Art. 6(1)(b))
Premium subscription status and payment provider transaction IDOnly if you upgrade a wedding to Premium: we never see, receive, or store your card number, PayPal password, or App/Play Store account details — those are entered directly with Stripe, PayPal, Apple, or Google, and we only ever receive a subscription confirmation and a transaction/subscription ID back from them, used to unlock Premium features and to reconcile a cancellation or payment failure (Art. 6(1)(b))
Technical error diagnosticsOnly if we enable error monitoring: stack traces, the page/action you were on, and your browser/device type, to help us detect and fix bugs; never request bodies, passwords, tokens, or your IP address (Art. 6(1)(f))

We don't use cookies. Login token and language preference live in local storage.

Providing email, password, and accepting the Privacy Policy/Terms is required to create an account. Everything else is optional or collected only when you use the relevant feature. We do not use automated decision-making or profiling.

4. Security measures

Passwords are stored only as bcrypt hashes. Every free-text field is encrypted at rest using a dedicated server-held encryption key (DATA_ENCRYPTION_KEY), separate from password hashing and separate from disk-level encryption. Fixed-choice fields (e.g., expense-paid toggle) are not encrypted. Invite links are single-use, expire after 7 days, and are rate-limited. All traffic is encrypted via HTTPS. No security measure is perfect; we work continuously to keep protections proportionate.

Users may export their own guest data to PDF. Exports are generated on demand — the export only happens when you click the button, never automatically or in advance — and contain only data from your own wedding. Each export is built in memory on our server and streamed straight back to your browser over HTTPS; it is never written to disk or stored anywhere on our servers, and never sent to any third party. You choose a password when exporting, which locks the PDF itself using standard AES-256 PDF encryption — anyone you don't share that password with cannot open the file, even if it later ends up somewhere you didn't intend.

5. Who we share data with

We share data only with service providers who help us run the Service, acting as our processors under data-processing agreements, or — where you initiate it yourself — with an independent third party you're dealing with directly:

We do not sell or rent your data, and we do not currently use third-party advertising or analytics. Our optional referral program (see §3) only shares information between accounts you both already control on this Service — it doesn't involve an external third party.

Future plans: advertising

If we introduce advertising:

6. How long we keep your data

We keep your account and wedding data as long as your account is active. You can delete your account at any time; this deletes your account and any wedding you own. Collaborators deleting their accounts do not delete shared weddings. Backups are kept for up to 14 days. Invite-link IP addresses used for rate-limiting are deleted after 24 hours.

7. International data transfers

Our own infrastructure — the application server and database — runs on Google Cloud Platform in the EU, and your data is stored only there; we don't maintain backup servers in any other region. Some of the processors listed in §5 (e.g. SMTP2GO, Firebase Cloud Messaging, Stripe, PayPal, Apple, Google, and Sentry if enabled) may process or transfer data outside the EU/EEA as part of their own global infrastructure; where they do, they rely on their own appropriate safeguards (e.g. EU Standard Contractual Clauses or an adequacy decision).

8. Your rights

Under GDPR, you have the right to:

Contact us at inev-bit@mailbox.org to exercise these rights.

9. US state privacy rights (California and other states)

Merrily is deployed worldwide, including to users in the United States. If you're a resident of California, you have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); residents of a growing number of other US states (e.g. Virginia, Colorado, Connecticut, Utah, and others with comprehensive privacy laws) have broadly similar rights under their own state's law. In every case, these are in addition to — not instead of — the GDPR rights in §8, and we handle a request under either framework the same way, through the same contact channel.

To exercise any US state privacy right, contact us at inev-bit@mailbox.org — the same address used for GDPR requests in §8. We may need to verify your identity before acting on a request, proportionate to the sensitivity of the data involved.

10. Children

The Service is not directed at anyone under 16, and we do not knowingly collect data from children under that age.

11. Changes to this policy

We'll update this page whenever what we collect or how we process it changes. Material changes will be highlighted to registered users before they take effect.

12. Contact

Questions about this policy or your data: inev-bit@mailbox.org

Terms of Service · Impressum