Ceylon Wedding
Privacy Policy
Last updated: 7 July 2026
This Privacy Policy describes how Ceylon Wedding ("the app", "we", "us") handles personal information. Ceylon Wedding is operated by Roxy & Leam Nelson as a private wedding companion app.
1. What we collect
When you sign in to Ceylon Wedding, we collect the following information.
From your sign-in provider (Apple, Google, or Microsoft):
- Your name, or whatever name your provider passes through. Apple's "Hide My Email" relay may auto-generate one, in which case we'll prompt you to type your real name.
- Your email address (or relay address, if you used Apple's Hide My Email).
- A unique identifier from your sign-in provider.
Created by you in the app:
- Photos you upload to the wedding album, including any captions, EXIF metadata (capture time, GPS if your device included it), and people you tag.
- Messages you send to other guests (one-to-one or group threads).
- Comments and reactions on photos.
- Song requests and any comments on them.
- The Daily Word game scores.
- RSVP responses and dietary preferences.
- Profile photo, if you choose to upload one.
Generated by your device:
- Approximate location, used only to auto-tag photos you upload to the closest wedding event by time and proximity. You can disable location sharing for photos under your profile settings. Disabling it does not affect any other app feature.
- A push notification token, used to deliver messages, announcements, and access-approval notifications to your device.
- Basic crash and performance information, used to fix bugs.
We do not collect: payment information, contacts, browsing history outside the app, or any biometric data.
2. How we use your information
We use the information described above only for the following purposes:
- Running the app's features: showing you the wedding's events, your photos, messages, RSVPs, etc., and routing your contributions to the right surfaces.
- Matching you to the guest list: when you sign in, we compare your email against the wedding's invitation list. If you're matched, you get full access; if not, you're shown a "preview" experience and can request access.
- Sending notifications: new messages from other guests, photo comments, host announcements, access approvals, and the daily word puzzle.
- Improving photo organization: the app uses Anthropic's Claude AI to classify each uploaded photo into theme tags (couple, family, dance, food, etc.) so guests can browse the album by category. The thumbnail of your photo is sent to Anthropic over a secure connection during this classification, and Anthropic does not retain it after the response is returned. See Section 4 for details.
- AI features you actively use: the in-app translator, photo identification ("what's this?"), caption suggestions, and smart-reply suggestions all send their input to Anthropic's Claude API. These calls are transient — the input is processed and a response is returned, with no long-term storage on Anthropic's side.
- Operating the app safely: detecting bugs, banned users, or misuse.
We do not use your information for advertising, profiling, or sale to third parties.
3. Who can see your content
Ceylon Wedding is invitation-based. Once you're approved (by email match, host approval, or by being a host yourself), other approved guests can see:
- Your name and profile photo (in the guest directory and wherever your name appears).
- Photos you upload to the wedding album.
- Messages you send to threads they participate in.
- Comments and reactions you add to other guests' photos.
- Song requests you submit and your votes on others' picks.
Hosts (Roxy and Leam) and approved planners can additionally see RSVP status, dietary preferences, and arrival information you provide.
If you're in preview mode (signed in but not yet approved), you cannot post photos, send messages, or contribute to the wedding's data. Other users in preview mode cannot see your content either.
4. Third-party services we use
We use the following services to operate the app. Each is briefly described with a link to its own privacy policy.
Google Firebase (Google LLC) — handles sign-in, data storage (Cloud Firestore), file storage (Cloud Storage), serverless logic (Cloud Functions), and push notifications (Cloud Messaging). Data is stored in Google's asia-south1 (Mumbai) region. firebase.google.com/support/privacy
On Android, typing your hometown in the profile editor uses the device's built-in geocoding service (Google Play services) to suggest matching place names. Only the text you type is sent; no device location or location permission is involved.
Anthropic Claude API (Anthropic PBC) — processes AI-driven features: smart-album classification, translation, photo identification, caption suggestions, and smart-reply suggestions. Calls are transient; Anthropic's API does not retain the inputs after responding under our usage tier. anthropic.com/legal/privacy
Apple, Google, Microsoft (your sign-in provider) — handles the actual sign-in flow. We never see your password.
open.er-api.com — fetches currency exchange rates. We send no personal data to this service; only the currency codes you select.
iTunes Search API (Apple) — used to look up song preview URLs when you search the song-requests feature. We send only the song title and artist you typed.
We do not share your data with any other third parties.
5. Where your data is stored
- Personal data and photos are stored in Google Firebase, primarily in the
asia-south1(Mumbai) region. - Push notification tokens are stored on Google's Firebase Cloud Messaging service.
- Cached data (recent photos, messages, etc.) is stored locally on your device while the app is open. Clearing the app's data on your device clears this cache.
6. How long we keep your data
We keep your data for as long as the wedding event and its companion app are active. After the wedding (June 2026) and a 12-month retention window for guests who want to revisit photos and memories, we will delete or archive the wedding's data.
You can request deletion of your data at any time before then by emailing us (see Section 11).
7. Security
We protect your data with industry-standard measures:
- All data is transmitted over TLS (HTTPS).
- Firebase Security Rules restrict access to data based on your role (matched guest, host, or planner).
- Sign-in credentials are managed by your sign-in provider; we never see your password.
- We follow the principle of least privilege when granting host or planner access.
No system is perfectly secure. If you become aware of a security issue, please report it immediately to the contact below.
8. Your rights
You have the right to:
- Access the data we have about you. Most of it is visible in the app itself; for anything else, contact us.
- Correct any inaccuracies. You can update your profile in the app, or contact us for changes outside the profile.
- Delete your account and associated data. Contact us at the email below and we'll process the request within 30 days.
- Withdraw consent at any time. Sign out of the app and contact us if you want your data deleted.
- Disable location sharing for photos at any time via your profile settings.
If you're in the European Union, the United Kingdom, or California, you have additional rights under the GDPR, UK GDPR, or CCPA respectively. We honor those rights — contact us to exercise them.
9. Children
Ceylon Wedding is intended for guests of an adult wedding. We do not knowingly collect data from children under 13 (or under 16 in the EU). Wedding guests under that age should use the app only with the consent and supervision of a parent or guardian.
10. Changes to this policy
We may update this policy as the app evolves. If we make a material change (e.g., adding a new third party that processes your data), we will notify you in the app or by email. The "Last updated" date at the top of this page reflects when the policy last changed.
11. Contact us
For any privacy-related question, request, or concern, email: