Skip to content

Privacy Policy

Last updated: April 11, 2026

1. Introduction & Controller Identity

Welcome to Anvaya (“we,” “our,” or “us”). Anvaya is operated by Automorphism LLC, doing business as Anvaya, a company registered in the United States. We provide a wedding planning platform available at anvaya.love, including subdomain-based wedding websites, guest management, budget tracking, vendor management, and AI assistant integrations via the Model Context Protocol (MCP).

For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK Data Protection Act 2018, Automorphism LLC is the data controller for personal data we collect directly through the platform. Where couples add guest data, the couple acts as data controller and Anvaya acts as data processor (see Section 8).

At our current scale, we are not required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. If this changes, we will update this policy accordingly.

You can reach us regarding any privacy matter at: privacy@anvaya.love

2. Information We Collect

The following table describes the categories of personal information we collect, organized according to the categories defined in the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). For each category, we indicate specific data elements, whether we collect them, and the source.

CCPA CategoryData ElementsSource
A. IdentifiersName, email address, IP addressDirectly from user
B. Personal information (Cal. Civ. Code §1798.80)Name, address, phone number (for guests)From user or couple
D. Commercial informationBudget items, vendor quotes, payment recordsFrom user
F. Internet/electronic activityPage views, feature usage, session dataAutomatically via PostHog (with consent)
G. Geolocation dataApproximate location via IP address; venue coordinates via Google PlacesAutomatically (IP); from user (venue selection)
K. InferencesWedding readiness score (derived from planning progress)Derived by Anvaya

Categories we do NOT collect: We do not collect Category C (characteristics of protected classifications), Category E (biometric information), Category H (audio, electronic, visual, thermal, olfactory, or similar information beyond user-uploaded photos), Category I (professional or employment-related information), or Category J (non-public education information).

3. Sources of Personal Information

We collect personal information from the following sources:

  • Directly from you: When you create an account, set up a wedding, add events, manage guests, track budgets, or upload content.
  • From couples (on behalf of guests): When a couple adds guest information such as names, email addresses, phone numbers, dietary preferences, and RSVP details. In this scenario, the couple is the data controller and Anvaya is the data processor (see Section 8 for the full Article 14 notice).
  • Automatically: We collect analytics data (page views, feature usage, session information) through PostHog, subject to your consent preferences. We also collect IP addresses and basic request metadata through our infrastructure providers.
  • From third-party authentication providers: If you sign in via Google OAuth, we receive the profile information you authorize (typically name and email address).

4. How We Use Your Information

We process your personal information for the purposes described below. For users in the EU/UK, we also identify the lawful basis under GDPR Article 6(1) for each purpose.

PurposeGDPR Lawful Basis
Providing, maintaining, and improving the Anvaya platform, including wedding websites, guest management, budget tracking, and AI assistant integrationsPerformance of a contract (Art. 6(1)(b))
Product analytics and usage metrics to improve features and user experienceConsent (Art. 6(1)(a))
Ensuring the security and integrity of our services, detecting fraud, and preventing abuseLegitimate interest (Art. 6(1)(f))
Complying with applicable laws, regulations, and legal processesLegal obligation (Art. 6(1)(c))

5. Cookies, Analytics & Tracking Technologies

We use cookies and similar technologies organized into the following tiers:

Necessary Cookies

These cookies are essential for the platform to function. They include our session cookie (better-auth.session_token) for authentication and consent preference cookies. These cannot be disabled.

Functional Cookies

These cookies remember your preferences and settings (such as theme selections and template choices) to provide a more personalized experience. They do not track you across other websites.

Analytics Cookies (PostHog)

We use PostHog for product analytics to understand how the platform is used. PostHog collects page views, feature usage patterns, and session data. We do not use advertising cookies or third-party ad trackers. Analytics cookies are loaded only with your consent.

Geo-Based Consent

For users in jurisdictions that require prior consent for non-essential cookies (including the EU/UK under the ePrivacy Directive), we present a cookie consent banner before loading analytics scripts. For users in other jurisdictions, analytics may be loaded by default, subject to your ability to opt out at any time. For detailed information about each cookie, its purpose, and its duration, please refer to our cookie policy page.

6. Data Sharing & Disclosure

We do not sell or share personal information for cross-context behavioral advertising. As defined under the CCPA/CPRA, we have not sold or shared personal information in the preceding 12 months, nor do we have actual knowledge that we sell or share personal information of consumers under 16 years of age.

Your data is disclosed only in the following limited circumstances:

  • AI Assistants (OAuth): When you explicitly authorize an AI assistant (ChatGPT, Claude, Cursor, etc.) via OAuth 2.1, that assistant can access your wedding data within the scopes you granted (wedding:read and/or wedding:write). You may revoke access at any time. Data flows directly between your account and the connected assistant; we do not control how the third-party assistant processes data once received.
  • Wedding Collaborators: Members you invite to your wedding planning team can access shared wedding data according to their assigned role (Couple Primary, Family Admin, Family Contributor, or Guest).
  • Service Providers (Sub-Processors): We use infrastructure and service providers to operate the platform. These providers process data on our behalf under contractual data processing agreements. See Section 7 for the full list.
  • Legal Requirements: We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

7. Sub-Processors

We use the following third-party service providers (sub-processors) to operate the platform. Each operates under appropriate data processing agreements.

ProviderWhat They Process
CloudflareCDN, edge compute (Workers), object storage (R2), email routing, DNS, KV caching. Processes request data, static assets, uploaded files, and cached wedding data.
Amazon Web Services (AWS)Relational database hosting (RDS PostgreSQL). Stores all persistent application data including accounts, weddings, guests, events, budgets, vendors, and tasks.
OpenAIAI-powered vendor data extraction (gpt-5.4-mini model). Processes vendor email content and uploaded documents when explicitly triggered by the user. Subject to OpenAI's API data usage policy (API inputs are not used for model training).
PostHogProduct analytics. Collects page views, feature usage patterns, and session replay data (with input masking enabled). Loaded only with user consent.
GoogleMaps JavaScript API and Places API. Processes venue and location search queries, provides geocoding, timezone resolution, and place autocomplete.
ResendTransactional email delivery. Processes recipient email addresses and email content for account-related communications.

8. Guest Data & Third-Party Data (Art. 14 Notice)

This section constitutes a notice under Article 14 of the GDPR for guests whose personal data is added to the platform by a couple (the data subject did not provide the data directly to Anvaya).

Data Controller

The couple who added your information is the data controller for your guest data. They determine the purposes and means of processing your personal information within the Anvaya platform.

Data Processor

Automorphism LLC (Anvaya) acts as a data processor on behalf of the couple. We process your data only as instructed by the couple and as necessary to provide our wedding planning services.

Categories of Personal Data

The following categories of guest data may be processed: name, email address, phone number, mailing address, dietary restrictions, meal preferences, plus-one information, event assignments, RSVP responses, and any notes added by the couple.

Purpose of Processing

Guest data is used solely to provide wedding planning features, including RSVP tracking, event management, seating arrangements, meal planning, and communication with guests. Guest data is not used for marketing, advertising, or any purpose unrelated to the wedding.

Lawful Basis

The couple's lawful basis for processing your data is their legitimate interest (Art. 6(1)(f)) in organizing their wedding and managing their guest list. Anvaya's lawful basis as processor derives from our contractual obligation to the couple (Art. 6(1)(b) and Art. 28).

Source of Data

Your personal data was provided by the couple who is planning the wedding. It was not collected directly from you by Anvaya, except where you interact directly with the platform (e.g., submitting an RSVP via a shared link).

Recipients

Your data may be accessible to the couple and their authorized wedding planning team members (based on role permissions), AI assistants authorized by the couple via OAuth, and the sub-processors listed in Section 7 for the sole purpose of operating the platform.

Retention

Guest data is retained for the duration of the wedding planning process and as long as the couple maintains their Anvaya account. When the couple deletes their wedding or account, all associated guest data is permanently deleted.

Your Rights as a Guest

As a data subject, you have the right to request access to, rectification of, or erasure of your personal data. You also have the right to restrict or object to processing, and the right to data portability. To exercise these rights, contact the couple directly or reach out to us at privacy@anvaya.love, and we will assist in facilitating your request with the data controller.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EU, you may contact the data protection authority in your country of residence. See Section 20 for contact details.

9. Sensitive & Cultural Data

Wedding planning may involve culturally sensitive information, such as dietary restrictions (e.g., vegetarian, halal, kosher), ceremony types (e.g., Hindu, Sikh, Muslim, Christian, interfaith), religious customs, and cultural preferences. This data is:

  • Optional — provided entirely at your discretion
  • Purpose-limited — used solely for wedding planning features such as meal planning, ceremony scheduling, and event management
  • Not profiled — never used for advertising, behavioral profiling, or analytics
  • Deletable — you may remove this data at any time through your dashboard

Where such data constitutes special category data under GDPR Article 9 (e.g., data revealing religious beliefs), our lawful basis for processing is your explicit consent (Art. 9(2)(a)), which you provide by voluntarily entering this information.

10. AI-Powered Data Extraction

Anvaya offers an AI-powered feature that extracts structured vendor information from emails and uploaded documents. This feature works as follows:

  • User-initiated only: Extraction is triggered only by your explicit action — forwarding a vendor email to your Anvaya address or uploading a document through the dashboard.
  • AI model: We use OpenAI's gpt-5.4-mini model via the OpenAI API to extract vendor details such as names, contact information, pricing, and service descriptions.
  • No raw data retained: Raw email or document content is not persisted after extraction is complete. Only the structured extracted data (vendor name, contact details, pricing) is stored in your wedding account.
  • OpenAI API policy: Under OpenAI's API data usage policy, API inputs and outputs are not used for model training. OpenAI retains API data for up to 30 days for abuse monitoring, after which it is deleted.

Extracted data is stored in your wedding account and can be reviewed, edited, accepted, or dismissed at any time.

11. International Data Transfers

Anvaya is based in the United States, and your personal data is stored and processed on infrastructure located in the United States (AWS for database hosting, Cloudflare for edge compute and storage). When you use Anvaya from outside the United States, your data is transferred to the US for processing.

For EU Residents

Where we transfer personal data from the European Economic Area (EEA) to the United States, we rely on the following transfer mechanisms as appropriate:

  • EU-US Data Privacy Framework (DPF): Where our sub-processors are certified under the DPF, transfers are covered by that framework.
  • Standard Contractual Clauses (SCCs): Where the DPF does not apply, we use EU Commission-approved Standard Contractual Clauses as the legal mechanism for data transfers.

For UK Residents

For transfers of personal data from the United Kingdom, we rely on the International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, as appropriate.

You may request a copy of the safeguard documentation applicable to your data by contacting us at privacy@anvaya.love.

12. Data Retention

We retain your data according to the following schedule:

  • OAuth Access Tokens: Expire after 1 hour. Stored as SHA-256 cryptographic hashes only.
  • OAuth Refresh Tokens: Expire after 30 days. Rotated on each use; previous tokens are immediately revoked.
  • OAuth Authorization Codes: Expire after 10 minutes and are single-use.
  • Wedding Data: Retained until you delete specific data or your entire wedding. All wedding data (events, guests, budget, vendors, tasks, website content) is permanently deleted when the wedding is removed.
  • Account Data: Retained for the lifetime of your account. Upon account deletion, all associated data (including all weddings) is permanently removed.
  • Backup Data: Database backups follow a 7-day rotation. After deletion of your data from the live database, it may persist in backups for up to 7 days before being overwritten.
  • Analytics Data: Retained per PostHog's data retention policy. We do not control PostHog's retention schedule independently, but analytics data is anonymized and not linked to your account after deletion.

13. Your Rights Under GDPR (EU/UK Residents)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018:

  • Right of Access (Art. 15): You have the right to obtain confirmation as to whether your personal data is being processed and, if so, to receive a copy of that data along with information about how it is used.
  • Right to Rectification (Art. 16): You have the right to have inaccurate personal data corrected and incomplete data completed.
  • Right to Erasure (Art. 17): You have the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, you withdraw consent, or the data has been unlawfully processed.
  • Right to Restriction of Processing (Art. 18): You have the right to request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
  • Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
  • Right to Object (Art. 21): You have the right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent (e.g., analytics cookies), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority.

UK Supervisory Authority

Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113

EU Supervisory Authority

You may contact the data protection authority in your country of residence. A directory of EU data protection authorities is available on the European Data Protection Board (EDPB) website.

How to Exercise Your Rights

You may exercise your rights by emailing us at privacy@anvaya.love or by using the self-service tools available in your dashboard (e.g., data export, account deletion). We will respond to your request within 30 days. If additional time is needed due to the complexity or number of requests, we may extend this period by up to 60 days, and we will inform you of the extension within the initial 30-day period.

14. Your Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your data.
  • Right to Delete: You may request deletion of the personal information we have collected from you, subject to certain exceptions (e.g., legal obligations).
  • Right to Correct: You may request correction of inaccurate personal information we hold about you.
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information and do not share personal information for cross-context behavioral advertising. Therefore, there is no need to opt out, but you retain this right should our practices change.
  • Right to Limit Use of Sensitive Personal Information: We use sensitive personal information (such as dietary restrictions indicating religious beliefs) only for the purposes of providing our wedding planning services. You may request that we limit our use to these purposes.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing, quality, or service levels for exercising your rights.

How to Exercise Your Rights

To submit a request, email us at privacy@anvaya.love. We verify your identity by matching the email address on your request to the email associated with your Anvaya account.

Response Timeline

We will respond to verifiable consumer requests within 45 days. If additional time is needed, we may extend this period by an additional 45 days (90 days total), and we will notify you of the extension.

Authorized Agents

You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide written authorization from you and may be required to verify their own identity. We may also contact you directly to confirm that you authorized the agent.

15. Global Privacy Control (GPC)

We honor the Global Privacy Control (GPC) signal. When we detect a GPC signal from your browser, we will:

  • Automatically disable analytics and non-essential tracking cookies for your session
  • Treat the signal as a valid opt-out request under applicable privacy laws, including the CCPA/CPRA
  • Display a visible confirmation that your GPC preference has been recognized

You do not need to take any additional action beyond enabling GPC in your browser. For more information about GPC, visit globalprivacycontrol.org.

16. Automated Decision-Making & Profiling

Anvaya does not make automated decisions that produce legal effects or similarly significantly affect you. Specifically:

  • AI vendor extraction is entirely user-initiated. You trigger the extraction by forwarding an email or uploading a document. Extracted data is presented as a draft for your review — you decide whether to accept, edit, or dismiss it.
  • Wedding readiness score is an informational metric that summarizes your planning progress (e.g., whether events have dates, guests are assigned, RSVPs are collected). It is calculated algorithmically from your wedding data and is displayed for your convenience only. It does not affect your access to features, pricing, or service levels.

Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not engage in such processing.

17. Children's Privacy

Anvaya is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@anvaya.love.

18. Security Measures

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Token security: OAuth tokens stored as SHA-256 cryptographic hashes; refresh tokens rotated on each use with immediate revocation of previous tokens
  • PKCE: Proof Key for Code Exchange (S256 method) required for all OAuth authorization flows to prevent code interception attacks
  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security)
  • Role-based access control (RBAC): Wedding data is protected by a four-tier role hierarchy (Couple Primary, Family Admin, Family Contributor, Guest) with granular permission checks on every server action
  • Content Security Policy (CSP): HTTP security headers restrict the sources from which scripts, styles, and other resources can be loaded
  • Input masking in session recording: When analytics session replay is enabled (with consent), sensitive form fields are masked to prevent personal data from being captured in recordings

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously review and improve our security practices.

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated policy on this page with a revised “Last updated” date
  • Notify you via email or through a prominent notice on the platform if the changes are significant

We encourage you to review this page periodically. Your continued use of Anvaya after a revised policy is posted constitutes your acceptance of the changes, except where consent is required under applicable law, in which case we will seek your consent before applying the changes to your data.

20. Contact Us & Supervisory Authorities

If you have questions about this Privacy Policy, wish to exercise your rights, or have concerns about how your data is handled, please contact us:

Privacy inquiries: privacy@anvaya.love

Legal inquiries: legal@anvaya.love

Company: Automorphism LLC, doing business as Anvaya

UK Supervisory Authority

Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113

EU Supervisory Authorities

A directory of EU/EEA data protection authorities is maintained by the European Data Protection Board: edpb.europa.eu/about-edpb/about-edpb/members_en