LAST UPDATED 8 AUGUST 2026
Privacy policy
Planning a wedding means handing over your guest list — the names, the addresses, the people you love. So here is the plain version of what Vowbird keeps, why it keeps it, and how to make it go away.
The short version
- We collect what you give us to plan your wedding, and nothing else.
- We don’t sell your data, and we don’t sell your guests’. There are no ads in Vowbird and no third-party trackers on the site.
- If you connect your Google account, Vowbird asks for permission to send mail and nothing more. It cannot read your inbox.
- You can delete your wedding, your account, and everything in it, whenever you like.
Who we are
Vowbird is a wedding planning app at vowbird.ai. When this policy says “we” it means the people who make Vowbird, and when it says “you” it means the person with the account. Questions about any of this go to hello@vowbird.ai.
What we collect
- Your account. Your email address and your password, which is hashed by our authentication provider and never visible to us, plus sign-in timestamps.
- Your wedding. The names, the date, the venue, and whatever else you choose to fill in — including anyone you invite to plan alongside you.
- Your guests. Names, email and postal addresses, RSVPs, dietary notes, and any custom fields you add. This is information about other people, so it gets its own section below.
- Your stationery. The save-the-dates and invitations you upload or write, and a record of what was sent to whom and when.
- Early access signups. If you join the waitlist from this site, we store your email address and which page you joined from, so we can tell you when Vowbird opens.
- Ordinary server logs. Our hosting providers record IP addresses, browser type, and timestamps. We use those for security and debugging, not for profiling you.
Vowbird carries no advertising and no analytics trackers. We do not buy data about you from anyone else.
Your guests’ details
A guest list is information about people who never signed up for anything. We hold it on your behalf, to do the job you asked for — keeping the list, tracking RSVPs, and sending the stationery you tell us to send. We don’t use it for anything else, and we never contact your guests on our own account.
You are the one who decides what goes on the list, so you are the one responsible for having a good reason to hold it and to write to those people. If a guest asks you to remove them, you can delete them from the app outright; if they write to us instead at hello@vowbird.ai, we will pass the request on to you and act on it ourselves where the law asks us to.
Guests reach their invitation through a private link that contains a random token. Anyone holding that link can see that invitation, so treat it the way you would treat the invitation itself.
Connecting your Google account
Vowbird can send your invitations from your own email address, so they arrive from you rather than from a stranger. That is the only reason it ever asks to connect to Google.
The one permission we ask for is https://www.googleapis.com/auth/gmail.send — permission to send mail as you. It does not allow reading, searching, downloading, or deleting anything in your mailbox, and Vowbird never asks for a scope that would. If you sign in with Google, we also receive your email address and basic profile (openid, email) to identify your account.
Here is exactly what that connection does:
- What we send. Wedding stationery only — save-the-dates, invitations, RSVP reminders and replies — to recipients that come from your own guest list, either when you press send or on a schedule you set.
- What we store. An OAuth refresh token issued by Google, encrypted at rest, together with the Google address it belongs to. The token exists for one purpose: to send those messages. It is never shared with anyone, never used to train a model, and never used for advertising.
- What we keep afterwards. A record of which stationery went to which guest and when, so you can see the state of your mailing. The message content is your own stationery, which you had already given us.
- How to stop it. You can disconnect Google from your Vowbird settings at any time. That revokes the refresh token with Google and deletes our copy of it, so Vowbird immediately loses the ability to send. You can also revoke it yourself from your Google Account permissions page, with the same effect. Deleting your Vowbird account revokes it too.
Vowbird’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice that means we use Google user data only to provide and improve the sending feature you turned on; we do not transfer it to anyone except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition with your notice; we never use it for advertising; and no human at Vowbird reads it, except with your explicit permission, for security purposes, or where the law requires it.
Where your data lives
Vowbird runs on Vercel and stores everything in Supabase, a managed Postgres host. Every table is protected by row-level security, so a row belonging to your wedding can only be read by members of that wedding — not by other couples, and not by an unauthenticated request.
Traffic is encrypted in transit over HTTPS. Google refresh tokens are additionally encrypted at rest, on top of the storage encryption the database already provides.
Who else sees it
Only the companies that run the app for us, and only so far as they have to:
- Supabase — the database and the sign-in system.
- Vercel — hosting and delivery of the site itself.
- Google — only if you connect your Google account, and only to send the mail you asked for.
- Our email provider — for account mail we send you, like a password reset or a sign-in link from hello@vowbird.ai.
We do not sell, rent, or trade personal information, and we do not share it for advertising. We would disclose data if the law genuinely compelled us to, and if a court order allows us to tell you, we will.
Cookies
Vowbird sets session cookies so that you stay signed in between pages. That is all they do. There are no advertising cookies and no third-party tracking cookies on this site.
Keeping it, and deleting it
We keep your data for as long as your account exists. Within the app you can delete individual guests, stationery, or the whole wedding at any time.
To delete your account entirely, write to hello@vowbird.ai from the address you signed up with. We remove your account, your wedding, your guest list and any Google token within 30 days, and the token is revoked with Google straight away. Encrypted backups roll off on their own schedule within 30 days after that.
You can also ask us for a copy of what we hold about you, or ask us to correct it, at the same address. Depending on where you live you may have further rights over your data — we will honour them regardless of where you live, because the alternative is silly.
Children
Vowbird is for adults planning a wedding. It is not directed at children, and we don’t knowingly collect account data from anyone under 16. Guests of any age can of course appear on a guest list, because that is what a wedding is.
Changes to this policy
When this policy changes we update the date at the top. If a change materially affects what we do with your data — particularly anything to do with your Google account — we will email you before it takes effect.
Getting in touch
Questions, requests, or something here that doesn’t match what you see in the app: hello@vowbird.ai. Our terms of service cover the rest of the relationship.