Privacy policy
A wedding workspace holds unusually personal things - what you're spending, who you've fallen out with, who eats what. This is what we do with it, in plain words.
Last updated 3 September 2026
1. Who this covers
DoDeewane is a planning workspace for multi-day and destination weddings, operated by <registered legal entity>, <registered business address>. This policy covers the website at do-deewane.com and the app behind it. Writing to admin.dodeewane@gmail.com reaches the people responsible for it.
Where the law calls someone the controller of personal data, that is us for your account, and it is you for the guest list and vendor details you put into your wedding — see section 8.
2. What we collect
Your account
- Your name and email address, always.
- A phone number and profile photo, if you choose to add them.
- Either a password — stored only as a bcrypt hash, never as text we can read — or, if you signed in with Google, the account identifier Google gives us. Never both unless you set a password yourself.
- The role you picked when you signed up (bride, groom, wedding planner, vendor, family, guest). It decides which part of the product opens for you.
What you put into a wedding
Everything you or your collaborators enter: functions and venues, budgets, payments and vendor contracts, guest lists and RSVPs, seating plans, hotel and travel arrangements, tasks, schedules, mood boards, registry and gift records, packing lists, and any files you upload — contracts, quotes, images and PDFs among them.
Records the app keeps by itself
- An activity log of significant changes inside a workspace — who changed what and when — so a team of a dozen people can tell what happened.
- Your conversations with the AI assistant, kept so a thread still reads as a conversation when you come back to it.
- Single-use password-reset and invitation tokens. Only a SHA-256 hash of each is stored, so a copy of our database cannot be used to replay one.
- Ordinary server logs, which include IP addresses, for security and debugging.
3. What we do not do
There is no advertising on DoDeewane, and no advertising network is given anything. We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising — which under laws such as the CCPA is also a kind of “sale”, and we do not do that either.
There are also no analytics or product-telemetry trackers in this app. No Google Analytics, no advertising pixel, no session recorder, no third-party script watching what you click. If we ever add measurement, it will be named in this section before it runs.
4. Cookies
DoDeewane sets two cookies, both strictly necessary, and no others. Neither is used to profile you, and there is nothing here to opt out of because there is nothing optional.
| Cookie | What it is for | Lifetime |
|---|---|---|
ddw_session | Keeps you signed in. A signed token holding your user id and nothing else — no name, no email, no role. | 7 days |
ddw_oauth | Set only while a Google sign-in is in flight, to confirm the reply came back to the same browser that started it. | 10 minutes |
Both are httpOnly, so page scripts cannot read them, and both are Secure in production.
5. Signing in with Google
Using “Continue with Google” is optional — email and a password work just as well. If you use it, we ask Google for three things and nothing else: a stable account identifier, your email address, and your display name. Those correspond to the openid, email and profile scopes, all of which Google classes as non-sensitive.
We do not request, receive or hold access to your Gmail, Drive, Calendar, Contacts, photos or anything else in your Google account. We do not receive your Google password. We keep no long-lived Google token: the sign-in is verified once and then it is our own session cookie that keeps you logged in.
DoDeewane’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. That data is used only to sign you in and identify your account — never for advertising, never sold, and never handed to anyone except the providers in section 6.
You can disconnect DoDeewane at any time from your Google account permissions. Doing so stops future Google sign-ins; it does not delete your DoDeewane account — for that, see section 10.
6. Who else touches your data
We keep the list short on purpose, and everyone on it is a supplier acting on our instructions, not a partner we share data with for their own ends.
| Provider | What for | What reaches them |
|---|---|---|
| Microsoft Azure | Hosting and the database | Everything, at rest and in transit — this is where the app runs |
| Sign-in, and destination autocomplete | For sign-in, section 5. For autocomplete, the place name you type into a destination field — nothing about you or your wedding | |
| OpenAI | The AI features in section 7 | Only the text or file involved in the specific request you made |
| Our email provider | Sign-up confirmations, password resets, invitations | The recipient’s name and address, and the message itself |
An exchange-rate service is also called for currency conversion. It receives currency codes only — no personal data of any kind.
We will also disclose data where the law genuinely requires it, and if DoDeewane is ever sold or merged, your data may transfer to the buyer — who would be held to this policy until you are told otherwise, with enough notice to leave first.
7. The AI features
Several features send data to OpenAI to work: the planning assistant, contract and quote scanning, seating suggestions, timeline drafting, outfit try-on and the drinks suggester. Only what a given request needs is sent — asking the assistant about your guest list sends guest data; scanning a contract sends that document.
OpenAI processes this on our behalf under its API terms, which do not permit using content submitted through the API to train its models. Even so, treat these features as you would any outside service: if a document is too sensitive to leave your organisation, do not run it through the scanner.
These features are optional to operate and can be switched off entirely at the configuration level, in which case nothing is sent to OpenAI and the rest of the product works unchanged.
8. Guest, vendor and family details you upload
Most of the personal data in a wedding workspace is not yours — it belongs to your guests, your family and your suppliers. When you enter or import it, you decide what is collected and why, and we hold it for you. In data-protection terms you are the controller and we are your processor.
That puts a few things on you rather than on us:
- Having a proper basis for holding those details, and telling those people if your local law requires it.
- Being careful with dietary requirements in particular. A note like “no beef” or “coeliac” can reveal someone’s religion or health, which several laws treat as a special category needing extra care. Record what catering needs and no more.
- Handling requests that come to you from your own guests. If one reaches us instead, we will point them to you and help you answer it.
Everyone you add to a wedding sees only what their role allows. A vendor sees the functions they are booked for, not the budget; a guest sees their own invitation and travel, not the guest list.
9. Where your data lives, and how it is protected
The app and its database run on Microsoft Azure. Depending on the region a workspace is served from, data may be stored or processed in a country other than yours, including the United States. Where a transfer out of the UK or EEA needs a safeguard, we rely on the European Commission’s standard contractual clauses through our providers.
Practically, the protections are:
- Every connection is encrypted in transit, and the database requires TLS.
- Passwords are bcrypt hashes. Nobody at DoDeewane can read your password.
- Reset and invitation links are stored only as hashes, expire, and can be used once.
- What each person can see and do is enforced on the server against their role, not hidden in the interface.
No system is perfect, and we will not claim otherwise. If a breach affects you, we will tell you and the relevant regulator within the time the law allows.
10. How long we keep things, and how to be forgotten
A workspace is kept while the account it belongs to is open — weddings are planned over years, and a workspace that tidied itself away would be worse than useless. Server logs are kept for a short operational period. Expired reset and invitation tokens are discarded.
There is no self-service delete button in the app yet. Until there is, email admin.dodeewane@gmail.com from your account address and we will delete your account and its data within 30 days, other than anything we are legally required to keep. We would rather say that plainly than point you at a button that does not exist.
11. Your rights
Wherever you live, you can ask us to: give you a copy of what we hold about you; correct it; delete it; export it in a portable form; or stop a particular use of it. If you are in the UK, EEA or a US state with a privacy statute, those rights are legal entitlements rather than courtesies — and we do not charge for them or treat you differently for asking.
Send any of these to admin.dodeewane@gmail.com. We answer within 30 days, and we will verify that the request really comes from you before acting on it. If you think we have handled your data badly, you are entitled to complain to your data-protection regulator — though we would appreciate the chance to fix it first.
12. Children
DoDeewane is for adults planning weddings. It is not directed at children, and we do not knowingly create accounts for anyone under 18. Children often appear in a guest list — as a headcount, a meal and a seat — and that information is the couple’s to hold under section 8. If you believe a child has created an account, tell us and we will remove it.
13. Changes
When this policy changes materially, we will update the date at the top and tell account holders by email before it takes effect. Continuing to use DoDeewane after that means the new version applies. See also our terms of service.
Questions about anything on this page? Write to admin.dodeewane@gmail.com — a person answers.