Privacy Policy
Last updated: Aug 13, 2026
1. Data controller
The controller of the database is the operator of ydw.app. You can reach them about anything concerning your personal data at contact@ydw.app.
2. Legal framework
This policy is governed by Uruguayan Law No. 18.331 on the Protection of Personal Data and Habeas Data Action and its implementing decree, by articles 37 to 40 of Law No. 19.670, and by Decree No. 64/020. The supervisory authority is the Personal Data Regulatory and Control Unit (URCDP).
3. What data we process
About your account: email, display name and preferred language. If you sign in with Google, we receive your email, your name and your account identifier from Google; never your password.
About your wedding: the couple's names, date, RSVP deadline, currencies and exchange rate, per-person prices, budget, expenses, payments and due dates, vendors, tables and checklist.
About your guests — people other than you, whose data you enter: name, group, relation, guest type, email, phone, plus-one, dietary restrictions, RSVP status, any message they leave when confirming, and the date they replied. Dietary restrictions can reveal health or belief information, so we treat them with particular care: they are never used for anything other than showing them to you and are never shared beyond what section 6 describes.
Files you upload: images or PDFs of payment receipts, and reference photos for the dress designer. They are held in private buckets reachable only by the members of that wedding.
Purchases: Mercado Pago payment identifier, amount, currency, status and date. Your card details never enter YDW: the charge happens entirely inside Mercado Pago's checkout.
AI usage: a log of which feature ran, when, how many tokens it consumed and with what outcome. It is what enforces the usage caps.
4. Why we use them, and on what legal basis
- Performance of the contract: providing the service — storing your data, computing your figures, sending the invitations you ask for, unlocking Premium after payment.
- Consent (art. 9, Law 18.331): the consent you give expressly when creating your wedding, by ticking the acceptance box for these documents. You can withdraw it at any time by deleting your account.
- Legitimate operational interest: security, abuse prevention, enforcement of usage caps, and backups.
- Ad measurement: knowing whether a visit that arrived from one of our ads went on to create an account or buy Premium, with exactly the scope and the limits set out in section 8.
There is no advertising inside YDW, we do not sell your data, and we do not disclose it to third parties beyond the processors listed below. The only thing shared for an advertising purpose is the measurement in section 8, which includes neither your name, nor your email, nor anything about your wedding, and which you can block from your browser without losing any feature.
5. Your guests' data
Your guests' data is entered by you, and in doing so you represent that you are entitled to and that you will inform them. We process it on your behalf and for the sole purpose of organising that wedding.
Each guest receives a personal RSVP link. That page shows only their own card — never the list — and links to this policy, so they know who processes their data and how to exercise their rights. A guest can write to us directly at contact@ydw.app or ask the couple who invited them.
The RSVP audit records what the guest answered and when. We do not record their IP address or their browser.
6. Processors and international transfers
We work with the following providers, each with access only to what its function requires (art. 23, Law 18.331):
- Supabase — database, authentication and file storage. This is where your data lives.
- Cloudflare — application runtime, delivery network and technical request logs.
- Google — two separate functions. To authenticate you, only if you choose "Continue with Google". And, through Google Ads, to measure whether a visit that arrived from one of our ads went on to create an account or buy Premium; exactly what is sent is in section 8.
- Resend — delivery of invitation emails to the guests you choose, with their name, their address and their link.
- Mercado Pago — the Premium charge. It receives your email and the amount; we receive back the payment identifier and its status.
- Anthropic — the language model behind the assistant, guest import, receipt reading, seating proposals and the drafting of invitations, speeches and vows.
- OpenAI — the image model behind the dress designer.
These providers run servers outside Uruguay, so your data may be processed abroad under the contractual and technical safeguards each of them offers. We use no other provider. The only measurement we do is the Google Ads one described in section 8: there are no analytics tools, we do not track you across sites, and we do not sell your data to anyone.
7. Exactly what is sent to the AI models
AI features run only when you ask for them, and each one sends the least it needs:
- Assistant and seating proposals: your guests' name, group, relation, guest type, RSVP status, covers, table and dietary restriction, plus your budget and payment figures. A guest's email, phone, plus-one name and RSVP link are never sent — that exclusion is fixed in the code and covered by an automated test.
- Guest import: the text you paste, exactly as pasted.
- Receipt reading: the receipt image or PDF you upload.
- Invitations, speeches and vows: the couple's names, the date, the venue and whatever instructions you write.
- Dress design: the reference photos you upload and your form preferences.
Under Anthropic's and OpenAI's policies in force for their programming interface, content sent through it is not used to train their models.
8. Cookies and ad measurement
Strictly necessary cookies: the session cookie that keeps you signed in, and the language cookie that remembers whether you chose Spanish or English. There are no analytics cookies — we do not measure how you move around the site.
Advertising. We promote YDW with Google Ads. To know which ads are worth anything, the public pages and the application load the Google tag, which stores a cookie holding the identifier of the click you arrived from and tells Google if you later create an account or buy Premium. What Google receives is that click identifier, an internal reference whose only purpose is to avoid counting the same event twice — your user identifier, or the payment number — and, for a purchase, the amount charged. It never receives your name, your email, or any data about your wedding or your guests.
That tag is not loaded on the invitation pages: someone opening an RSVP link is a guest of yours who did not arrive from an ad, so there is no reason to give them an advertising cookie.
For visits from the European Economic Area, the United Kingdom and Switzerland the tag starts with storage denied, so no advertising cookie is stored there. From anywhere, you can block or delete these cookies in your browser settings, and turn off ad personalisation in your Google ad settings. Blocking them changes nothing about how the application works.
9. Security
All traffic is encrypted in transit (HTTPS). Isolation between weddings is enforced in the database itself through row-level policies, so a query can only reach rows of a wedding you belong to. Receipts and photos live in private buckets under the same rule. Passwords are stored hashed by the authentication provider and never in plain text.
No system is infallible. Should a security breach significantly affect your data, we will notify the data subjects and the URCDP in accordance with Decree 64/020, within 72 hours of becoming aware of it.
10. Retention
We keep your data for as long as your account exists. You can delete it at any time from Settings: deletion is immediate and removes your user, your profile, the weddings you own with all their content, and the associated files. Transaction records remain with Mercado Pago under its own policies and statutory periods, over which we have no control. Our operational backups rotate and expire on short cycles.
11. Your rights
As a data subject you have the rights of access, rectification, updating, inclusion and deletion (arts. 13 to 16, Law 18.331). Exercising them is free.
- Access, rectification and updating: you can exercise most of these yourself inside the application, by editing your data.
- Deletion: from Settings, with "Delete my account", or by writing to contact@ydw.app.
- For any request by email we reply within the statutory deadlines, after reasonable verification of your identity.
If you believe your rights have not been honoured, you may complain to the URCDP and bring the habeas data action provided for in Law 18.331.
12. Minors, changes and contact
The service is directed at people aged 18 or over. If we identify an account belonging to a minor, we delete it.
We may update this policy; the date of the version in force is shown at the top of this page and material changes are announced inside the application. For any question, write to contact@ydw.app.
See also the Terms and Conditions. This document was originally written in Spanish; in the event of any discrepancy with this English translation, the Spanish version prevails.