Skip to content

Privacy

Our privacy pledge

This page is the plain-language version. It describes what the software actually does today.

Your guests come first

The invitation page carries no advertising and no third-party analytics or tracking scripts. The only measurement is a first-party counter that increments a daily total; it sets no cookie and stores no address or device information about the visitor.

We never use guest information to market to anyone. We do not collect guest email addresses, and we do not send your invitations for you — you share the link yourself.

Dietary notes can reveal health information, so they are optional, visible only to you, excluded from any analytics, and flagged when you export them.

What a hidden invitation actually means

Invitations ask search engines not to index them, and the server sends the same instruction in a header. That is a request to well-behaved crawlers, not access control: anyone holding the link can open the page.

For real protection, set a password. Password-protected invitations show a generic preview to link unfurlers — no names, no photo, no date — so a forwarded message does not leak the invitation to a group chat.

Chat apps cache link previews. If you share a public invitation and add a password afterwards, previews already cached by iMessage, WhatsApp or Facebook are outside our reach.

Your management link

The management link is the credential for your project. It travels in the URL fragment, which browsers never send to a server, and is exchanged once for a session cookie before the address is cleaned up.

We show it exactly once. If you lose it and your session too, support cannot recover the project for you — being able to would mean anyone could claim someone else’s invitation.

When things are deleted

A published project is unpublished and purged six months after the wedding date; the exact date is shown in your dashboard, and you can delete earlier or extend it there.

A draft that was never published is removed after 90 days without activity. Export files and their input snapshots are removed after 7 days; download links expire in 15 minutes.

Deleting removes the database record immediately and queues the stored images and export files for removal. Encrypted backups age out within 35 days, so a very recent deletion can still exist in a backup for that window.

Security exceptions worth naming

If an anti-abuse challenge is ever switched on, it loads only at the moment you submit a form, and this page will say so. We do not simultaneously claim "zero third-party scripts" and quietly ship one.

This service runs on a single server. That is honest, not high-availability. Planned maintenance and incidents are posted on the status page.

Contact

For data access or deletion requests, takedown notices, or any privacy question, write to support@lunavows.com.