Privacy Policy

Privacy Policy

Last updated: December 2026

Your account

Creating an event requires an account, using your email and password, Google sign-in, or your phone number, handled by Firebase Authentication. We store whichever identifier you sign in with (email or phone number) to identify which events belong to you. We never see or store your password, and phone sign-in works via a one-time SMS code — we never see that code either. If you sign in with your phone number, Google's reCAPTCHA is used to confirm you're not a bot before the code is sent.

If you're signed in when you open someone else's invitation link, we remember that you viewed it so it appears under "Invited" on your Profile page — this happens automatically and isn't shared with the host beyond what your RSVP already tells them.

What we collect

When you create an event, we store the details you enter: host and family name, event type, date, venue, location, your phone number and an event-day point of contact if you add one (both shown to guests so they have someone to reach with questions), and any optional links you add (photo/video, Google Drive album, UPI handle).

When a guest submits an RSVP, we store their name, dietary preference, party size, and optionally an email address or phone number if they choose to provide one.

If a host adds gifts to a registry, we store the product link, name, price, and photo they provide. If a guest checks off a gift as bought, or logs a Shagun payment, we store the name and amount they enter — this is self-reported by the guest, not verified against any bank, UPI app, or retailer.

Where it's stored

Event and RSVP data is stored in a Firebase Firestore database. We do not sell or share this data with third parties. Event links are not indexed or discoverable — only people with the exact link can view an event or its RSVPs, and only the host who created an event can edit or delete it.

Photo & video uploads

Pre-event photos and videos a host uploads, and photos guests add to the Memory Vault, are stored by Cloudinary, a media hosting service, and served from Cloudinary's servers when anyone views an event. We don't send guest or RSVP data to Cloudinary — only the media file itself.

AI features

If a host uses the AI invitation writer, the event type, host/family name, venue, location, and date are sent to Groq's API (or, as a backup if Groq is unavailable, OpenRouter's API) to generate invitation text. No guest or RSVP data is sent to any AI service.

Third-party links

Ceremoniz links out to Google Maps for directions, WhatsApp for sharing, UPI apps (GPay, PhonePe, Paytm, and others) for Digital Shagun payments, gift registry links a host adds (Amazon, Flipkart, Myntra, or elsewhere), and any photo/video or Google Drive links a host adds. Payments made through a UPI app happen entirely within that app — we never see or handle payment details ourselves. These services have their own privacy policies, which we don't control.

No ads, no tracking

Ceremoniz does not run advertising and does not use analytics or tracking cookies beyond what's needed to operate the app.

Deleting your data

Hosts can delete an event at any time from "My Events," which removes its data. Guests who want an RSVP removed can ask the event host to do this, or contact us directly. To delete your account and email address entirely, contact us at the email below.

Contact

Questions about this policy: adityakukreti8@gmail.com