Privacy

If you host

Your account holds your email address and the invitations you make: what you described to the AI, the letter you wrote, the places, menus and times you offered, and the answers and photos your guests sent back. Only your own account can read them, and that is enforced by the database rather than by application code.

If you were sent an invitation

You do not need an account. The link you were sent is what lets you in: anyone holding it can open the invitation, so share it as carefully as its host did. What you do inside it is stored for the host to see — the name you give, the choices you make (a place, a dish, a time), whether you are coming, and any photo you take in the photo booth. Those photos are kept in private storage and shown only to the host and to people holding the same invitation link.

Your visit is also recorded as usage telemetry, exactly as it is for hosts — including your answers and your booth photos, your IP address and your device details. The full list is below.

What goes to Google

The invitation designer runs on Google's Gemini API: what a host types to describe the occasion is sent to Google, along with the invitation being edited. Real places are looked up with Google Places, from the area and preferences the host describes — never from a guest's location. If a host turns on the butler's voice, the butler's lines are spoken by Google's text-to-speech. A guest's answers and photos are not sent to Google.

Limits

The AI is paid for by the person running this site, so each account has a daily allowance for designing invitations and looking up places. The app tells you when you reach it.

Usage telemetry

To understand how Invite is used, it records what hosts and guests do here as telemetry. Specifically:

What we store

  • Your activity — which actions you take and when.
  • The content you process — for hosts, what you describe to the invitation designer and the invitations you write; for guests, the name you give, the choices you make and whether you are coming. Do not enter anything here you would not want stored, including passwords, secrets or personal documents.
  • Files you upload — photos taken in an invitation’s photo booth are stored in our private file storage.
  • Your network and device — your IP address, an approximate location derived from it, your browser and operating system, language, time zone, screen and window size, and similar technical details your browser exposes.
  • A device identifier — a random id kept in your browser’s storage so we can recognise return visits. It is also stored in a cookie so our servers can recognise the device. It is not tied to your name and clearing your browser storage resets it.
  • Page views via Vercel Web Analytics — the hosting platform records which pages are visited, referrers, and coarse device and country data. It sets no cookies and identifies a visitor only by a hash that changes daily, so it cannot follow you across days or sites.
  • Performance via Vercel Speed Insights — the hosting platform measures how quickly pages load and respond (Core Web Vitals), with the page, device type and country. It sets no cookies and does not identify you.
  • Your account — while you are signed in, telemetry recorded from this browser is also linked to your account (its id and email address), so we can see what one account did across devices. Deleting your account unlinks that telemetry but does not delete it: the records stay under the device identifier, without your account or email. To have them removed as well, ask separately (below).
  • Support access — to diagnose a problem, the operator can sign in to your account and see the app as you see it, without learning or changing your password. Each access is time-limited and logged, and does not sign you out anywhere else. Nothing done during it is recorded as your telemetry.
  • Feedback you send — your bug reports, feature requests and replies are stored linked to your account, so the maintainer can answer them on your Requests page, and each new report is also emailed to the maintainer. Deleting your account unlinks them but does not delete them.

How long we keep it

Stored data is retained indefinitely unless you ask us to remove it.

Requesting deletion

To have your data deleted, use the feedback button in the app (the message reaches James Argarin) and mention your device identifier if you have it. We will remove the associated records.

Deleting your account

A host can delete their invitations from the account page, and with them every guest answer and booth photo they collected — immediately and permanently. Your hive sign-in itself stays, because it is shared with the other apps on this site. Usage telemetry is unlinked from your account but not deleted — see above for how to have it removed.

Home