Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains what Elysia ("we", "us") collects, why, and what your choices are. It applies to hosts who create events and to guests who RSVP or upload to an event. Elysia is the data controller for host accounts, billing, and the operation of the Service. For the personal data inside an event — the guest list, RSVP replies, and guest uploads — the host who created that event decides what is collected and why and is the controller of it; we process it on that host’s instructions, as their processor, and delete it on the schedule in section 6. Hosts are responsible for having a lawful basis to contact their guests and to collect their details. You can reach us at support@elysiaevents.com. Elysia is operated by Michael Zaher, a sole proprietor registered in Israel.
1. What we collect
- Host accounts — email address, optional name, and authentication data managed by Supabase Auth (password hash or Google sign-in profile). We never see your password in plain text.
- Event data — event details, guest lists, RSVP responses (including plus-ones, children, and dietary notes your guests choose to provide), and seating plans.
- Guest uploads — the display name a guest types, the photos, videos, and audio they choose to upload, a hashed IP address, and the browser user-agent (used for abuse prevention and rate limiting).
- Payments — processed by Dodo Payments, our Merchant of Record and the system of record. We store the transaction reference, the product, and the amount. We never see or store card numbers.
- AI inputs — prompts (and, for restyling, the image being edited) that you submit to AI features, and messages you send to the support assistant.
- Design feedback — when you share a design for feedback, anyone with the link can see it and leave a comment with a name. The comments are kept with the design until you delete them, the design or the event.
- Technical logs — server logs needed to run and secure the Service.
- Product analytics — in your browser, on host and marketing pages only: the pages you view, linked to a random identifier and, once you sign in, to your account ID — never your name or email. It works without cookies and stores nothing on your device. Separately, our servers record a small number of key product milestones in a host’s event (for example, the first photo arriving, or a purchase completing) — even when a guest’s action is what triggers them — attributed only to the host’s account, never to a guest, and never with guest content or guest identifiers. Guest pages load no browser-side analytics, and guests are never identified.
- Invitation opens — for each event we keep a count, per day, of how many times its invitation and reply pages were opened, so the host can see how many guests opened their invitation. These are anonymous totals: no cookie or other device storage is used, and no IP address, user-agent, name or identifier is stored. Link-preview and search bots, the host’s own visits and events that are not live are not counted.
2. What we deliberately do not do
- No advertising or analytics trackers on guest pages — guests are not tracked across the web.
- By default we strip GPS coordinates from photo EXIF metadata before storing images. Hosts can change this per event.
- We never sell personal data, and we never use your media to train AI models.
3. Why we process data
We process personal data to provide the Service you or your host asked for (contract), to secure the Service and prevent abuse (legitimate interest), to understand in aggregate how hosts use the Service so we can improve it (legitimate interest), to comply with legal obligations such as tax records, and — for optional emails like product updates — with your consent, which you can withdraw in your account’s email preferences.
4. Cookies
Essential cookies: a host session cookie (authentication), a signed guest-session cookie scoped to the specific event a guest joined, a language-preference cookie, and a first-touch attribution cookie that remembers which campaign link brought a host to the site (30 days). The browser-based part of product analytics runs only on host and marketing pages, using no cookies or other device storage; the server-recorded product milestones described in section 1 use no cookies either.
Advertising measurement (marketing and host pages only, never guest event pages): we use the Meta Pixel and Meta Conversions API to measure whether our Facebook and Instagram ads lead to sign-ups and purchases. The pixel sets a first-party cookie and sends your IP address, browser information and the pages you viewed to Meta Platforms; on sign-up and purchase we also send a hashed (irreversible) form of your email address so Meta can match the conversion to the ad. In the EU/EEA, UK and Switzerland this runs only after you accept it in the consent banner; elsewhere it is based on our legitimate interest in measuring advertising, and you can opt out through your Facebook ad settings or by declining the banner. Guests are never tracked.
If you follow an Elysia link on an event page — the "Try Elysia free" card or the "Powered by Elysia" badge — we set one first-party referral cookie (elysia_ref) that lasts up to 30 days. It records only which event’s link you followed, not who you are, so that if you then create an account we can credit the host who introduced you. It is never shared with advertisers, and simply viewing a guest page does not set it.
5. Who processes data for us
We share personal data only with the processors needed to run the Service, under their data-processing terms:
- Supabase — database, file storage, and authentication (hosted in the EU by default).
- Vercel — application hosting; functions run close to the data.
- Dodo Payments — payment processing (Merchant of Record).
- Google — generation of AI images when you use the design tools; inputs are processed to produce your result.
- Recraft — background removal and vector ornaments when you use those tools; the photo or your description is sent to produce the result.
- Anthropic — the support assistant; your messages are processed to produce the reply.
- PostHog — product analytics: browser-based measurement on host and marketing pages only (EU region), plus server-recorded product milestones attributed only to the host’s account; the browser measurement script is never loaded on guest pages.
- Meta Platforms — advertising measurement on marketing and host pages (Meta Pixel and Conversions API), as described in section 4; never on guest pages.
We may also disclose data where required by law or to protect the rights, safety, or property of Elysia, our users, or the public.
6. Retention and deletion
Every event has a retention window, and it starts the day after the event date rather than on the day of purchase — so buying early never shortens it. If no event date is set, the window starts when the album is first used in earnest (5 uploaded items, or 250 MB) or 90 days after the event was created, whichever comes first. For an event created very far ahead of its date, the start is capped at 400 days after creation. Different kinds of data are then kept for different periods, all measured from that same start:
- Event media (photos, videos, audio) — 7 days on the free plan, 90 days on Pro, 1 year on Premium. The event is then archived, the host has 14 days to download everything as a single ZIP, and the media is permanently deleted.
- Guest upload identities — the display name a guest typed, the hashed IP address, and the browser user-agent are cleared when that event’s media is deleted.
- RSVP guest details — names, email addresses, phone numbers, and dietary or free-text notes are kept for 30 days on the free RSVP plan and 18 months on the paid RSVP plans, then irreversibly anonymised. Headcounts and the shape of the guest list remain; the personal details do not, and existing invite links stop working.
- Seating layouts — tables and seat assignments are deleted 5 years after the window starts.
- Host account data — kept until the host deletes their account, which permanently deletes their events and the associated data.
- Payment records — retained as required by tax and accounting law.
- Partner commission records — when a purchase was referred by one of our partners (a planner, venue or photographer), we keep the event name and the host’s email address alongside that commission as a financial record, for as long as the partner’s payout history must be retained under tax and accounting law — including after the event or the account is deleted.
- Live demo uploads — photos a visitor adds on the public demo page are visible only on that visitor’s own devices and to our support staff, and are deleted automatically: a scheduled job permanently removes every demo photo within one hour of upload, and if that job is delayed or interrupted, as soon as it next runs.
Hosts can delete an event, individual media items, or their whole account at any time from the dashboard, ahead of any of the periods above. Deletion and anonymisation are irreversible: once they run we cannot restore the data, so download anything you want to keep before your window ends. Backups are purged within 30 days of deletion. We may keep anonymised or aggregated data that can no longer be linked to you or your guests for as long as it remains useful.
7. Security
Data is encrypted in transit and at rest. Access to event data is enforced with row-level security; guest sessions use signed, HttpOnly cookies scoped to a single event; media uploads are verified server-side. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
8. Your rights
You can access, export, correct, or delete your personal data, object to or restrict certain processing, and withdraw consent at any time. Hosts can exercise most of these directly in the dashboard; for anything else, email support@elysiaevents.com and we will respond within 30 days. Guests can ask the event host to remove their content, or contact us directly — where we act as a processor for a host, we will pass the request to that host and help them answer it, and we will act on it ourselves where the law requires us to. Depending on where you live, you may also lodge a complaint with your data-protection authority.
9. Children
Host accounts are for adults (18+). Photos of children may appear in event albums; the host is responsible for having the appropriate consent from parents or guardians, and we remove such content promptly on a substantiated request.
10. International transfers
Primary data is stored in the EU. Some processors (for example Dodo Payments, Google, Anthropic, and Recraft) process data outside the EU, such as in the United States, under appropriate safeguards such as standard contractual clauses.
11. Changes and contact
If we make material changes to this policy we will notify hosts by email or in-app before the changes take effect. Questions or requests: support@elysiaevents.com.