Skip to content

Privacy Policy

Last updated: October 2026

WeddingRoom is built around one promise: your wedding photos belong to you, they are shared only with the people you invite, and they are deleted when the room expires. This policy explains what we collect, how long we keep it, and how deletion works.

1. Our privacy promise

  • Rooms expire. Every room has a storage period defined by its plan; when it ends, the room and all photos and videos are permanently deleted.
  • We never sell your photos or personal data.
  • We never use your photos for advertising.
  • We never use your photos to train AI models.
  • There is no permanent-retention option — by design, not by oversight.

2. Hosts and guests

Hosts (the couple) create a room and sign in with Google. We receive the name and email address associated with that OAuth sign-in, and use it only to administer your rooms, payments and expiry reminders.

Guests never create an account. Joining a room requires only its QR code or Room Number. Guests are represented by an anonymous session identifier; a display name is optional and never verified.

Rooms are private. There is no search, list or browsing of rooms — the only way in is the couple's QR code or Room Number.

3. Photos and videos

Guests who upload content authorize its display inside that room, to that room's members, for the life of the room. The couple acts as the content manager of the room and can remove any photo or video at any time.

Guests can download the originals of their own uploads. Originals of other guests' photos are available only if the couple unlocks them.

We process photos to create thumbnails and display variants so rooms load quickly. We do not otherwise analyze photo content.

4. How long we keep data

Storage periods follow the plan chosen by the couple — 30, 90, 180 or 365 days from the wedding day. Upload windows close earlier (7 to 90 days).

When the storage period ends, the room enters a 7-day recovery window during which the couple can still restore it. After that, deletion is permanent and irreversible.

  • Photo and video files are deleted from storage.
  • Database records are deleted.
  • Cached copies are purged from our content delivery network.

5. Where data lives

Structured data (accounts, rooms, photo records) is hosted on Supabase (PostgreSQL). European couples' data is hosted in the European Union by default to align with the GDPR.

Photos and videos are stored on Cloudflare infrastructure with global edge delivery. Deletion requests propagate to the storage origin and the edge cache.

6. Your rights

Depending on where you live — including under the GDPR (EU/EEA), PIPEDA (Canada) and the Australian Privacy Principles — you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing.

Guests are anonymous by default, so most requests start from the couple who manages the room, or from the email address on a host account. Contact us using the details below and we will respond within the statutory window.

7. Children

WeddingRoom is not directed at children and hosts must be adults. Wedding photos may naturally include children; we do not collect personal information from them and the couple is responsible for the content of their room. Parents and guardians may ask us to remove any photo through the contact below.

8. Security

Photos are stored with access-control policies scoped to each room; original files are only reachable through short-lived, authorized URLs. Traffic is encrypted in transit. We review access continuously and delete data as promised — the safest data is the data we no longer hold.

9. Changes to this policy

If we make material changes, we will announce them on this page with a new 'Last updated' date and, for hosts with active rooms, by email before the changes take effect.

10. Contact

Questions or requests: [email protected].

Privacy Policy — WeddingRoom