Skip to main content

Kept while it's needed. Gone when it isn't.

The simple version of our retention schedule. Exact legal periods are set with counsel — where the law requires us to keep something (like billing records), we say so instead of deleting for show.

Last updated: 26 September 2026

  • Your account and celebrations

    Kept while your account is active. Delete an invitation or your account and the personal data goes with it — guests, RSVPs, photos, and storage objects included.

  • Deactivated accounts

    Sign-in is disabled immediately. Remaining personal fields are purged automatically after a 90-day grace window; only an anonymous billing skeleton is kept.

  • Studio data

    Leads, clients, and studio invitations belong to the studio tenant and survive any single member’s departure or deletion. Studios manage their own retention.

  • Payments

    Transaction records are kept as billing evidence even after deletion, as the law requires for accounting. Full card details are never stored at all.

  • Photos and media

    Tied to the invitation or asset that owns them, and removed with it — photo blobs, prefixes, and private-bucket receipts included.

  • Analytics and diagnostics

    Collected only with consent. Withdrawing consent stops collection; deleting provider-side profiles on erasure is on the roadmap.

  • Audit and request records

    Privacy requests and security audit entries are kept for up to 3 years as the accountability trail for the actions themselves, then minimised. Exact periods are set with counsel.

Don't take our word for it.

Trigger the retention paths yourself: export your data today, or erase it and watch the confirmations land.