Privacy Policy
Effective
You are about to hand us your wedding contracts, before you have paid us anything and before you know whether you ever will. Those are private documents with your name, your money, and your vendors in them. Here is exactly what happens to them — including if you never become a customer, which is the outcome for anyone whose documents do not add up to enough to be worth buying a plan for.
The short version
- We do not sell your documents or disclose them to vendors or advertisers. We share data only with service providers required to operate Wedding Remedy, under contractual restrictions.
- We use them for one purpose: your own analysis, and the Recovery Plan built from it if you decide to buy one.
- No card details are collected to upload or to be analysed. We hold no payment method for someone who has not bought anything.
- Contributing to the de-identified, aggregated benchmark data is opt-in. The box starts unchecked and stays unchecked unless you check it.
- We hold raw uploads for no longer than 90 days after a plan is delivered. If you are never charged, read “How long we keep things” below — there is a gap there we would rather name than hide.
- You can ask for a copy of what we hold, ask us to correct it, or tell us to delete it, at any time — customer or not.
What exists today
Not built yet. Wedding Remedy has not launched, and no real couple’s contracts have been through the upload, storage, and analysis described here. Some visitors will only ever meet the estimate quiz, which collects what you type into it, the email address you give to see the estimate, and the advertising parameters described below. Everything this page says about uploaded documents describes how they are built to be handled — written to be judged before you hand us anything, not reported after the fact. When any of it changes, so does the effective date above. The full list of what is and is not live is on one page, so you can see the bottom of it.
What we collect
- Your estimate quiz answers
- Roughly when the wedding is, the state it is in, your target budget and what you project spending, what you have already paid or committed, guest count, which categories you have signed or are still deciding, and whether you have documents to hand. While you are answering, these sit in your own browser’s local storage; they reach us only when you ask for the estimate. They contain no name and no free text.
- Your email address
- How we send your estimate, your sign-in link, what we found in your documents, and — if you buy — your receipt and your plan. Nothing works without it.
- The documents you upload, and what we extract from them
- Contracts, quotes, invoices, and vendor emails — whatever you choose to give us — plus the figures, dates, vendor names, and clauses our pipeline pulls out of them, and the findings and scripts built from those figures.
- Your order record, and a payment record only if you bought
- An order record exists from the moment you upload: it is what your documents and your analysis hang off. A paymentrecord — amount, status, refunds — exists only if you accepted a quote. If you never did, there is nothing here at all, because nothing was charged. Card details are handled entirely by our payment processor and never reach our servers; where there is a payment, we store the processor’s identifiers for it so we can issue a refund if one is owed.
- How you found us
- Campaign parameters (UTM tags), the ad click id that rides along in the link you clicked, the ad platform’s browser id from its own cookie, which landing page you arrived on, and which creative brought you. Our attribution record is deliberately fenced: it may hold marketing metadata and may not hold budgets, vendor names, contract text, findings, quiz answers, guest count, or location. That fence is enforced in code, not by good intentions.
- Messages you send us
- Support email, and whatever you tell us in it — including anything you quote from your own contracts.
- Technical data
- Ordinary server request data: IP address, user agent, and the page requested, plus error reports when something breaks. Used to keep the site up, to rate-limit public endpoints against abuse and double-submits, and to debug. We do not build an advertising profile from it.
- An internal event log
- An append-only record of what happened to an order — documents received, analysis run, figure shown or threshold missed, and then paid, delivered, or refunded if it got that far — with timestamps. It holds identifiers and statuses, not document contents. It is how we can answer “so what actually happened to my order” honestly, including for an order where nothing was ever charged.
Why we process it
- To analyse your documents and work out whether there is enough in them to be worth a plan — the part we do before any money is discussed.
- To produce your Recovery Plan and the scripts that go with it.
- To deliver it to you and to support you afterwards.
- To take payment if you accept a quote, and to issue refunds, including automatic ones.
- To keep the accounting and tax records a business is required to keep.
- To keep the service working and safe: rate limiting, abuse prevention, error monitoring, and debugging.
- To measure whether our advertising pays for itself, in the narrow way described below.
- To improve the benchmark data other couples see — only if you opted in.
We do not use your documents, your figures, or your findings to train anyone’s general-purpose models, and we only use providers whose terms prohibit them from doing so with your content.
What happens to your documents
An uploaded file goes into private storage that is not publicly listable and is not linked from anywhere. An automated pipeline reads it and pulls out the figures, dates, and clauses that matter. Those extracted numbers are what become your analysis, and your plan if you buy one.
People on our side can open a document when there is a reason to: you have written to support about your order, or a run has failed and we are working out why. Access is limited to the people who need it for one of those reasons. It is not something anyone browses.
We do not send your documents, or anything taken from them, to your vendors. We do not contact your vendors at all. Every message in your plan is one you send yourself, from your own address.
If you are never charged
We analyse first and only ask for money if we found enough to be worth it, so some of the people whose contracts we hold will never be customers. It would be easy to treat their documents as less theirs. We do not.
- Nothing about the handling changes. Same private storage, same limited access, same providers, same refusal to send anything to your vendors.
- No card details are collected to reach that point, so there is no payment method held for you and nothing to cancel.
- The analysis we did at our own cost is not sold, licensed, or handed to anybody as a lead. Your figures are not shopped around to vendors, planners, or anyone else.
- The benchmark contribution stays opt-in and works exactly as described below, whether or not you ever pay us.
- Every right in the list further down — access, correction, deletion, a portable copy — is yours on the same terms as a paying customer’s. We do not have a slower queue for people who did not buy.
We will email you about your own analysis, because that is what you gave us an address for. Marketing email is a separate thing and every one of those carries an unsubscribe link that works.
Who else processes your data
We do not sell your documents or disclose them to vendors or advertisers. We share data only with service providers required to operate Wedding Remedy, under contractual restrictions. Each of the following is a role, and each role sees only what that role needs:
- Payment processor — runs checkout and refunds, and holds the card details we never see. Involved only if you accept a quote, and then gets your email and the amount. Never sees your documents.
- Cloud database and file storage — where your order record, your uploaded files, and your plan live. Technically holds everything; contractually processes it only on our instructions.
- Email delivery — sends your estimate, receipt, sign-in link, plan, and support replies. Gets your email address and the contents of those messages.
- AI document processing — reads your documents to extract terms and to draft your plan. Gets the document contents. Contractually barred from using them to train models.
- Concierge assistant — answers your questions about your finished plan. Gets your plan and what you type into it, for as long as it takes to answer. Contractually barred from using either to train models. Your conversation is not stored: it lives in your browser tab and is gone when you close it.
- Error monitoring — records technical errors so we can find and fix them. Gets stack traces and request metadata, not your documents.
- Hosting and content delivery — serves this site and runs our server code. Sees ordinary request data, including your IP address.
- Advertising platform — receives only the conversion signal described in the next section. Never receives documents, extracted figures, findings, vendor names, wedding dates, or budget amounts.
None of these providers is permitted to sell your data or to use it for their own purposes. If we change who does one of these jobs, the role list above stays true; if we add a new kind of processing, this page changes first.
Advertising, attribution, and your hashed email
If you arrive from an ad, we store the campaign parameters alongside your record so we can tell which advertising is worth paying for. When you ask for an estimate, and again if you buy, we tell the advertising platform that the event happened. What goes with it is limited to:
- Your email address, scrambled first with a one-way hash, so the platform can match its own record without receiving the address itself.
- The click id and browser id that platform issued in the first place, and the value of the purchase if there was one.
- Your IP address and browser user agent, in the clear. The platform requires them to match the event to the same device. We are naming this plainly rather than leaving it under “analytics”.
- Which page or offer the event was about, and our own advertising metadata: the landing-page variant under test and the id of the ad creative you clicked. That is our information about our own marketing, not information about you.
- How far through the five questions you got — the step number, how many steps there were, and which step it was. Not your answers.
- Identifiers for the estimate, the order and the plan, and for a delivered plan whether it went by email or the portal, and for a refund which of our stated reasons it was. The identifiers are random and mean nothing outside our own database.
That list is the whole list, and it is the same list our code enforces: a single array names every field that may leave, a type error stops a new one being added by accident, and a test fails the build if this page and that array ever disagree.
What is never sent, to any advertising platform, at any point: your documents or anything extracted from them, your vendors’ names, your wedding date, your budget figures, your guest count, the financial qualification bucket produced by your answers, whether we recommended buying a plan, your findings, and any conclusion in your plan. An allowlist in our code rejects those fields before a payload can leave, and a browser is never trusted to report a purchase — only our payment processor’s verified webhook is.
We do not sell your personal information. Some state laws treat a conversion signal like the one above as “sharing” or as targeted advertising. We treat it that way for the purpose of your rights below wherever you live, so you never have to work out which law applies to you.
Cookies and what is stored in your browser
- Your quiz answers, in local storage, so a refresh does not lose your progress. Clearing site data removes them.
- Our own attribution record, in local storage: the campaign parameters and click ids described above, and nothing about your wedding.
- Your free wedding starter, saved in local storage when you choose “Save on this browser.” It stays on that browser until you clear it or clear site data. It does not sync between devices. Bringing it into the paid shared plan and saving there stores it with your order, visible to people with access to that plan.
- A session cookie for the portal, to keep you signed in after you follow your sign-in link — which is how you upload, before there is any question of paying.
The site does not load the advertising platform’s browser script. The limited server conversion signals described above remain separate from your planning notes.
Benchmark data is opt-in, de-identified, and aggregated
Knowing what other couples actually pay is the most useful thing in a plan. It only exists because people choose to contribute. That choice is a checkbox, unchecked by default. Ignoring it is a complete answer and changes nothing about what you receive.
If you do check it, this is precisely what happens:
- We strip your name, your email, your vendor’s name, your dates, and the document itself. What is left is a category, a rough location, a guest-count bucket, and a price.
- A figure only becomes visible to another customer once at least 5 separate orders sit in the same category-and-metro cell. Under 5, the cell stays dark and nobody sees anything from it.
- Because of that floor, a single vendor’s pricing is never surfaced to another customer. A benchmark is always a group, never a quote.
- We call this de-identified and aggregated rather than anonymous. The difference matters: we hold the link between a contribution and the order it came from, which is how we can remove yours when you ask.
Withdrawing consent. Tell us at any time and we delete your contribution — same route as the deletion request below, and no explanation needed. Deleting your data removes it too. What we cannot do is reach into a PDF another couple already downloaded, so a withdrawal applies to every benchmark computed from that point on.
How long we keep things
- Raw uploaded documents, when a plan was delivered: no more than 90 days after delivery
- That is the limit for active copies, whether or not you ask. A scheduled sweep finds orders delivered longer ago than that and deletes the files themselves, then records the deletion — in that order, so a row can never say “deleted” next to a file that still exists. The plan you already have does not depend on them.
- Encrypted recovery backups: seven days
- We keep encrypted database and file snapshots in a private GitHub repository’s recovery artifacts for seven days. A snapshot may retain a copy after it has been removed from the active service, until that backup expires. These copies are restricted to recovery work and are not used for planning, advertising or model training. Before a restored snapshot returns to service, deletion requests received after the snapshot must be applied again.
- Raw uploaded documents, when you were never charged: until you ask
- Here is the honest version, because it is not what you would assume. That scheduled sweep is keyed to delivery: it looks for orders that received a plan. An analysis that ended without one — we found less than the threshold, or you never took up the quote — is not picked up by it today, so those uploads are not on an automatic clock. They stay until you ask us to delete them, and that request is honoured within 30 days and removes the files for good. Extending the sweep so it covers an analysis that never became an order, on the same 90-day outer limit measured from the end of the analysis, is on the build list. Until the code does that, this page will not claim it does.
- Your plan and sign-in link: until 60 days after your wedding date
- Then the link stops working. If you bought a plan, download the PDF and keep your own copy.
- Your order record
- Email, dates, and status — plus amounts if you bought something. Where there was a payment, it is kept while we need it for accounting and tax records. Where there was not, there is no accounting record to keep and deletion removes it.
- Support messages
- Kept while your order is open and for a period after it, so a later question does not start from nothing.
- Your benchmark contribution, if you made one
- Kept until you withdraw it or ask for deletion.
- The internal event log
- Append-only by design, so nobody can quietly rewrite the record of what happened to an order. It holds identifiers, statuses, and timestamps rather than document contents.
- Unsubscribe records
- If you unsubscribe, we keep the fact that you did. It is the only way to be sure we do not email you again.
Security, and what we are not claiming
In place today:
- The site is served over HTTPS with strict transport security, so a browser refuses to load it over plain HTTP, and with headers that block framing and content-type sniffing.
- Nothing in your browser talks to our database. Row-level security is enabled and forced on every table with no permissive policy for public or signed-in roles, so order data is reachable only through our own server code.
- Card details never reach our servers. Checkout runs on the payment processor’s own hosted page.
- Portal and plan routes are served with no-store caching and are excluded from search engines, so nothing behind your sign-in link is cached by an intermediary or indexed.
- Public endpoints are rate-limited.
Built in, but not yet tested by real traffic:
- Sign-in tokens are held as a hash. The database has no column for the value we email you, so a copy of it is not a set of keys.
- Uploads are constrained by file type, size, and count, and the same file uploaded twice is one document rather than two.
- Uploaded files go to storage that is not publicly listable and not linked from anywhere.
What we are not claiming: we have not commissioned an independent security audit, and this page does not claim encryption at rest, formal access logging of who opened which document, or any certification. Some of those are on the build list; none of them are true today just because a privacy policy would look better saying so. When one becomes true, this page will say it and the effective date will move.
Access, correction, deletion, and a portable copy
Write to help@weddingremedy.com from the address you gave us and say which of these you want. We do it within 30 days and write back to confirm. There is no form, no retention offer, and no phone call, and it makes no difference whether you ever paid us.
- Access — a copy of what we hold about you.
- Portability — that copy in a structured, machine-readable file rather than a screenshot.
- Correction — fix anything we have wrong, including a figure misread out of one of your documents.
- Deletion — remove your data.
- Withdraw benchmark consent — remove your contribution without deleting anything else.
- Unsubscribe — stop marketing email. We keep a suppression list so that it sticks, rather than relying on someone remembering.
What deletion removes: your uploaded documents, the figures extracted from them, your quiz answers, your plan, your attribution record, and any benchmark contribution.
What survives it: the append-only event log entries for that order, which hold identifiers and statuses rather than document contents; your unsubscribe record if you have one; and — only if you actually bought something — a minimal record that the purchase and any refund happened, because payment and tax rules require it and our payment processor keeps its own record regardless. If you were never charged, that last one does not exist for you.
We do not charge for any of this, we do not require an account to ask, and we do not make the service worse for people who exercise a right. If we ever refuse a request, we will tell you why and you can ask us to reconsider.
State privacy rights
Several U.S. states give their residents privacy rights — typically to access, correct, delete, and obtain a portable copy of personal data, to limit certain advertising uses, and to appeal a refusal. Rather than work out which of them applies to you, we extend the list above to every customer, wherever you live, on the same terms and at no cost.
Rather than print a list of statute names, this page describes the rights we honour, wherever you live, and how to use them. If a law where you live gives you a right this page does not name, write to us and we will honour it.
If something goes wrong
If we discover unauthorised access to your documents or your personal data, we will investigate and contain it first, then email the people affected without undue delay: what happened, what data was involved, what we have done, and what — if anything — you should do. Where the law requires us to notify a regulator, we will. We will not wait for a journalist to ask.
Automated processing
An automated pipeline reads your documents and drafts your findings, and an automated check decides what the finished plan may claim — which is to say, whether you are shown a figure and asked to pay at all, or told honestly that there is not enough there. That check is arithmetic on figures traced to your own paperwork, described in full on the How we count page — not a judgement about you as a person, and never a credit, insurance, or eligibility decision. If you think it got something wrong, a human will look.
Where your data is processed
Our providers run infrastructure in more than one region, and processing may happen outside the state or country you are in. We are not naming specific locations on this page until we have verified them in each provider’s contract, because a location claim that turns out to be wrong is worse than no claim at all.
Age
Wedding Remedy is for adults. Do not use it if you are under 18. We do not knowingly collect data from anyone under 18, and if we learn we have, we delete it.
Changes to this policy
If we change this policy, the effective date under the heading at the top of this page changes with it. If the change actually affects you, we will email you rather than quietly editing the page.
Questions
Write to help@weddingremedy.com. Support is answered by an assistant first, with a person stepping in when it needs one. Anything about deletion, access, or a mistake in your plan reaches a human.
See also our Terms of Service, our Disclaimer, and our accessibility statement.