Protection without the theatre.
Last updated: 26 September 2026
Sign-in you can trust
Google sign-in verified server-side on every request. Disabled or deactivated accounts are rejected, and sensitive admin actions re-check that sessions haven’t been revoked.
Studios kept apart
Every studio query is scoped to its own tenant. A studio member can only ever see their studio’s leads, clients, invitations, guests, files, and analytics — never another studio’s.
Guests see only the celebration
Public invitation pages serve a stripped-down view: password hashes and internal fields never leave the server, and password-protected invites ask search engines not to index them.
Payments stay with the specialist
Card and UPI details go directly to Razorpay over verified webhooks. Maṅgalya keeps only order IDs, amounts, and status — never full card numbers.
Uploads and errors handled carefully
Files pass central type-and-size validation; crash reports carry minimal identity and masked replays; analytics identifiers stop at your account — never your guests’.
Found something that looks wrong? Write to mangalya.app@gmail.com with “security” in the subject — it goes to the front of the queue, and we'll investigate under our incident-response process.
Security you can verify.
Download your data to see exactly what we hold, or file a request and watch it move through review to completion.