1. Who the controller is
The data controller is VowlYou. For any question about personal data, write to [email protected].
Last updated: September 28, 2026
This policy explains what personal data VowlYou processes, why, on what legal basis, for how long, and what rights you have under Regulation (EU) 2016/679 (GDPR) and Romanian law.
The data controller is VowlYou. For any question about personal data, write to [email protected].
Account data: name, email, password (stored only as a bcrypt hash) or your Google account identifier if you sign in with Google. Event data: title, date, venue, budget, vendors, tasks and uploaded files. Guest data entered by the organizer: name, email, phone, group, party size and RSVP answers (menu, allergies, transport, accommodation, message). Payment data: billing is handled by Stripe; VowlYou never sees or stores card details. Technical and security data: IP address, browser type and access logs, used to protect against abuse. Text entered in the AI generator and messages sent to support.
Performance of a contract (Art. 6(1)(b) GDPR): creating and running your account, providing the app's features, account emails and support. Legal obligation (c): invoicing and keeping accounting records. Legitimate interest (f): platform security, preventing fraud, spam and automated attacks (attempt limits, anti-bot checks), improving the service. Consent (a): analytics cookies; you can withdraw it at any time from “Cookie settings” without affecting earlier processing.
For guest data added to an event, the event organizer is the controller and VowlYou acts as a processor (Art. 28 GDPR): we process that data only to generate personal RSVP links, display the invitation and pass responses to the organizer. The organizer is responsible for having a legal basis to provide it. Guests can exercise their rights with the organizer or with us at [email protected], and we will forward the request to the organizer.
When you use the AI generator, we send OpenAI (the model provider) only the preferences you write and the data the invitation needs: displayed names, event type, date and venue. Under OpenAI's API terms this data is not used to train models and may be retained by the provider for up to 30 days for abuse monitoring. Please don't include sensitive data about yourself or others in your preferences. The result is only a design proposal you can edit; we make no automated decisions with legal effects on you.
We use providers (processors) bound by data processing agreements to run the service: the application hosting and database provider, Stripe (payments and invoicing), Google (Sign in with Google and, only with your consent, Google Analytics), OpenAI (AI generator), Cloudflare (Turnstile anti-bot check) and the transactional email provider. We never sell personal data or use it for advertising. We disclose data to authorities only when the law requires it.
Some providers (e.g. Stripe, Google, OpenAI, Cloudflare) may process data in the United States. Transfers rely on the EU-US Data Privacy Framework adequacy decision for certified providers, or on the European Commission's standard contractual clauses together with additional safeguards.
Account and event data: while your account is active; after an event or account is deleted, data is removed within 30 days (backups within 90 days). Invoicing records: 10 years, as required by accounting law. Security logs: up to 90 days; anti-abuse counters: up to 24 hours. Support messages: up to 2 years. For the AI generator we keep only usage (token counts and cost), not the text you entered, except for variants you choose to save.
You have the right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, objection to processing based on legitimate interest, and the right to withdraw consent at any time. You can delete events directly in the app; to delete your account or exercise other rights, write to [email protected]. We reply within one month. You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro.
We use encrypted connections (HTTPS), passwords stored only as hashes, role-based access for every event, sign-in attempt limits and anti-bot protection. RSVP links are unique and hard to guess; don't share them publicly.
VowlYou accounts are for people aged 16 or older. Data about minor guests may only be entered by the organizer, under their responsibility.
We may update this policy. Material changes will be announced by email or in the app before they take effect, and the last-updated date is shown above.