Privacy Policy
Last updated: September 24, 2026
1. What we collect
- Account data — email address, display name, and sign-in provider (Email/Password or Apple), managed by Firebase Authentication.
- Content — event details you enter (titles, dates, locations, host names), photos you choose to upload for a design, generated designs, and share-link settings.
- RSVP data — when you respond to an invitation: your response, name, guest count, the names of any additional guests you list, and an optional message. This is shared with the event host.
- AI assistant chats — if you use the AI assistant, your messages are processed by our AI text provider (Google) to answer you, and the conversation history is stored with your account until you delete it or your account.
- Guest list data — if a host sends email invitations, the guest email addresses the host provides, a per-guest invitation link, delivery status, and whether the invitation was opened. Hosts must have their guests' permission to invite them (see our Terms).
- Purchase data — subscription and credit-pack status via Apple and RevenueCat. We never see your payment card details.
- Usage and device data — basic diagnostics, view counts on invitation links, abuse-prevention signals (e.g. Firebase App Check tokens), and a push-notification device token if you enable notifications.
2. How we use it
- To provide the Service: generate designs, host invitation pages, and deliver RSVPs to hosts — including an occasional email summary of new RSVPs sent to the host's account email address.
- To process prompts with our AI providers (text and image generation).
- To screen prompts and requests with our AI providers for safety and third-party-rights issues before generating.
- To manage credits, subscriptions, and fraud prevention.
- To respond to support requests and review content reports.
We do not sell your personal information.
Usage analytics (in the app)
To see where the app is hard to use, the app can send anonymous usage events to Google Analytics for Firebase: which screens and steps you reach (for example "paywall shown" or "design delivered"), your plan type, app language, an app-install identifier, and an approximate country derived from your IP address. It never includes what you type, your photos, your designs, your name, or your email, and it is not linked to your Inviti account. It is not used for advertising or cross-app tracking, and we have turned off Google's ad features and data sharing. Events are kept for 2 months.
In the European Union, the EEA, the United Kingdom, Switzerland, Turkey, and Brazil, usage analytics is off unless you switch it on. Elsewhere it is on by default. You can change it at any time in the app: the You tab → Share anonymous usage data.
3. Service providers
We rely on a small set of processors: Google Firebase (authentication, database, cloud functions), Apple (payments), RevenueCat (subscription management), Vercel (website hosting), Cloudflare (image storage, delivery, and message queueing), Resend (transactional email delivery — sign-in codes, invitation and RSVP summary emails), Google Gemini, the AI provider that processes the prompts and photos used to generate designs, and Google Analytics for Firebase (anonymous app usage statistics, only when usage analytics is on). We share only what is needed to produce your result.
4. Invitation links
Invitation pages are reachable by anyone with the link unless the host marks the link private. A public link also includes a preview image of the invitation hosted on our CDN so link previews work in messaging and social apps — anyone with the link can see it. Invitation pages are excluded from search-engine indexing. Hosts can disable or expire links, or make them private, at any time; each of these removes the public preview image, and a disabled link also removes the page.
5. If you received an invitation
If a host invites you by email, they gave us your address so we could send you their invitation. We use it only to deliver that invitation, and to show the host your RSVP — never for marketing. Hosts can remove replies from their own guest list. To be removed from an event's guest list, reply to your host or email support@getinviti.com and we will remove your details.
6. Data retention and deletion
Your data is kept while your account is active. Photos you upload for a design are stored in a temporary bucket and deleted automatically within 24 hours of processing; generated designs are kept until you delete them. You can delete your account in the app (the You tab → Delete Account) or by emailing support@getinviti.com; this removes your profile, designs, and share links within 30 days, except records we must keep for legal, accounting, security, or fraud-prevention purposes. To stop repeat abuse of introductory offers and allowances, we keep a one-way cryptographic hash derived from your account ID and email after deletion — it cannot be turned back into your email address. If you RSVP'd to someone else's event, your response is anonymized on deletion: your name and message are removed, and only the headcount remains for the host.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Contact us and we will help.
8. Children
The Service is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes
We may update this policy. Material changes will be announced in the app or by email.
10. Contact
Privacy questions: support@getinviti.com · See also our Terms of Service.