Skip to content

Legal

Privacy Policy

VoyaLife ("we") runs VoyaLife, a tool for planning celebrations. This explains what we hold, who else touches it, and how to get it deleted. It is written to be read once, not skimmed forever.

Last updated 9 September 2026

Not yet in force

This document describes how VoyaLife actually handles data today, but it is not a binding agreement until 3 details are configured: the registered entity name (NEXT_PUBLIC_LEGAL_ENTITY); a contact address that receives mail (NEXT_PUBLIC_LEGAL_CONTACT); the governing jurisdiction (NEXT_PUBLIC_LEGAL_JURISDICTION).

01The two kinds of people in here

Almost every privacy policy assumes you are describing yourself to us. VoyaLife is not like that, and the difference matters more than anything else on this page.

Hosts create an account and plan an event. They chose VoyaLife and agreed to this policy.

Guests and vendors mostly did not. A host types their name, phone number, home address and what they can't eat, and they may never see this page. For that data the host decides what is collected and why — they are the controller; we hold and process it on their instruction. So when a guest asks us to correct or remove something, we will act on it, and we will also tell the host, because it is their event record and they may be under their own obligation to keep parts of it.

02What we hold

Your account
Name, email address, phone number, a one-way hash of your password (never the password), profile photo, and — if you sign in with Google — the Google account identifier only. Organisers can also add a brand name and logo.
Your event
Ceremonies and their schedule, venues, budgets and payments, seating plans, run sheets, invitation and website designs, announcements, and the photographs uploaded to the album.
People on your list
For each guest: name and preferred name, email, phone, postal address, which side they belong to, relationship to the hosts, whether they are an adult or a child, language, time zone, photo, free-text notes, and their RSVP per ceremony. Also dietary requirements, accessibility needs, an emergency contact, and VIP handling notes where a host has entered them.
Vendors and staff
Name, company, role, email, phone, contract status, arrival times, and emergency contacts.
Technical
A session cookie (voyalife_session) that keeps you signed in, your device push token if you enabled notifications, and request metadata such as IP address and browser, which we use to rate-limit and to spot abuse.

We do not collect payment card numbers, precise device location, contact lists from your phone, or anything from advertising networks.

03Dietary needs, accessibility and other sensitive details

“No shellfish” and “uses a wheelchair” are health information in most of the world, even when a host types them casually into a spreadsheet. We store them because catering and venue access genuinely need them, and we treat them accordingly:

They are used only to run the event — headcounts for the caterer, access notes for the venue, seating. They are never used for advertising, profiling, scoring, or any automated decision about a person. They are visible to the host and to the collaborators the host has given the relevant permission, and to a caterer or vendor only through a read-only link the host deliberately creates. If you are a guest and would rather we did not hold yours, write to our published contact address and we will remove the field.

04Children

Children appear in VoyaLife only as entries on a guest list — a name, an age band, and perhaps a meal. Children do not get accounts, we do not knowingly let anyone under 16 sign up, and we do not build profiles of them. If you believe a child's details are held here and should not be, write to our published contact address and we will delete them.

05Why we use it

To run the thing you asked for: show your event, send the invitations and reminders you choose to send, collect RSVPs, generate passes and guest websites, keep the album, and split the money. To keep accounts secure and rate-limit abuse. To answer support requests. To meet legal obligations such as tax records.

We do not sell personal data, we do not share it with advertisers, and we do not use it to train our own models.

06Who else touches it

VoyaLife runs on other companies' infrastructure. Each of these receives only what its job requires, and only when the corresponding feature is used:

Amazon Web Services
Hosting, the database, and photo/file storage. United States.
Resend
Sends transactional email — verification, invitations, reminders.
Twilio
Sends SMS and WhatsApp messages when a host chooses those channels.
Google
Verifies Google sign-in; delivers push notifications via Firebase; issues Google Wallet passes.
Apple
Issues Apple Wallet passes.
Anthropic and Google
Power the optional AI features — see the next section for exactly which.

We also disclose data if the law compels us, and if VoyaLife is ever acquired the data moves with it — you would be told before anything changed.

07The AI features, specifically

Several features send content to a model provider. They are opt-in in the sense that nothing is sent unless you use the feature, and here is the whole list: invitation and card design, seating suggestions, the planning concierge, itinerary extraction from a document you upload, and translation all send the relevant text to Anthropic. Generated imagery and video use Google's Gemini and Veo models.

We send this to the providers' business API endpoints and we do not use any of it to train our own models. What each provider retains is governed by its own API terms — Anthropic's and Google's. If you would rather no guest data reached a model provider, simply do not use these features; every part of VoyaLife that matters works without them.

08Connecting an AI assistant

You can connect VoyaLife to an AI assistant such as ChatGPT or Claude. This is off unless you set it up, and it is worth understanding what it does.

When you connect one, you are shown a consent screen listing exactly what the assistant is asking for — viewing your celebrations, viewing the guest list, editing guests, sending invitations on your behalf, or viewing money — and you grant only what you approve. An assistant can never reach an event you yourself cannot reach: every request runs through the same permission checks as the app, so a connected assistant is always a narrower key than your own login, never a wider one.

Whatever the assistant reads then sits in that assistant's conversation history under its own privacy policy, not ours. You can revoke a connection at any time from your settings, which invalidates its tokens immediately.

09How long we keep it, and how to get it deleted

Event data lives until you delete it. Deleting a guest removes their record; deleting an event removes the event and everything hanging off it. Sign-in sessions and connected-app tokens expire on their own.

Deleting your whole account is a manual request today, not a button in the app. We would rather admit that than imply a self-serve control that does not exist. Write to our published contact address from the address on the account and we will delete it, and the events you own, within 30 days. Backups age out within 35 days after that. We keep the minimum needed for legal and accounting purposes, and we will tell you if that applies to you.

10Your rights

Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Depending on your country you may also have the right to receive it in a portable form or to complain to a data protection authority. Hosts can already export their guest list as a spreadsheet from the dashboard at any time.

Write to our published contact address. We answer within 30 days and we do not charge for it. We may ask you to confirm who you are first — for a guest that usually means replying from the email address or phone number on the record, because otherwise the request itself would be a way to extract someone else's details.

11Where it lives, and how it is protected

Our servers and database are in the United States, so if you are elsewhere your data is transferred there and handled under this policy and our contracts with the providers listed above.

Passwords are stored only as one-way hashes and cannot be read back, even by us. All traffic is encrypted in transit. Events are invitation-only unless you deliberately publish them, guest links are unguessable codes rather than sequential numbers, and access inside a team is governed per-module by the permissions the host sets. No system is perfect; if we ever suffer a breach affecting you we will tell you and the relevant regulator as the law requires.

12Cookies

One cookie, voyalife_session, which keeps you signed in and is deleted when you sign out. There are no advertising cookies, no analytics trackers, no third-party pixels, and nothing to consent to beyond staying signed in. The usage numbers you see in your dashboard are computed from your own event data on our own servers.

13Changes, and reaching a person

If we change this materially we will update the date at the top and tell account holders by email before it takes effect. Reach us at our published contact address.

See also our Terms & Conditions.