Wedding ♥ Guestbook
SupportPrivacyTermsPortal
Legal

Privacy Policy

Last updated August 3, 2026

Wedding Guestbook is an iPad guest book and photo booth for weddings, made by KeyesCode (“we”, “us”). This policy explains what the app and this website collect, why, and how to get it deleted. We do not sell personal information, we do not use it for advertising, and we do not use your guests’ photos, notes, or voice messages to train machine-learning models.

The short version

  • The app works fully offline. Everything a guest creates is written to the iPad first, and stays there whether or not it ever reaches us.
  • Nothing is sent to our servers unless the couple (or their planner) creates an account and turns on cloud backup.
  • The couple owns their book. They can delete any individual entry, or delete their whole account from inside the app.
  • Payment is handled by Apple. We never see your card details.

Two kinds of people in this policy

Account holders are the couples, planners, and coordinators who buy the app, set up a wedding, and receive the finished book.

Guests are the people who walk up to the iPad at a reception and leave a memory. Guests have no account and are never asked to create one. The account holder is the one who decides what happens to guest content; we process it on their behalf.

What guests give us

When a guest signs the book, the app records only what they choose to create:

  • The name they type on the screen
  • A typed note, and the handwriting style they picked for it
  • A handwritten note or signature drawn with a finger or Apple Pencil, saved as an image
  • A photo, if they use the photo booth
  • A voice message, if they record one
  • The time the entry was made, and which iPad made it

That is the whole list. The app does not ask guests for an email address or phone number, does not read the iPad’s contacts or location, and contains no advertising or third-party tracking software.

Guest entries are saved on the iPad, in the app’s own storage. If the account holder has turned on cloud backup, entries are also uploaded to our servers so the couple can download their book later. If they have not, the entries never leave the device.

What account holders give us

  • Account details — email address, an optional name, and a password. Passwords are stored only as a bcrypt hash; we cannot read them.
  • Wedding details — the couple’s names, the wedding date, the welcome message, the chosen theme and colors, an optional cover photo, and any guest list that is imported.
  • Device details — a name for each iPad, an identifier the app generates for it, when it last synced, and how many entries it holds. This exists to answer one question honestly: “did everything from the reception actually make it to the cloud?”
  • Sync and usage events — a small log of app events tied to a wedding, used to show sync statistics in the app and the planner portal.
  • Purchase records — the App Store transaction identifier and product identifier for each wedding unlock, so we can confirm the wedding is paid for.

How we use it

  • To run the app: saving entries, syncing them, and building the PDF keepsake
  • To sign you in and keep your account secure
  • To verify your email address, reset a forgotten password, and send you service messages about your wedding
  • To confirm a wedding has been paid for and to restore purchases
  • To answer your support requests
  • To keep the service working and to diagnose faults — for example, spotting entries that failed to upload

We do not use any of it for advertising, we do not sell or share it for cross-context behavioral advertising, and we do not build profiles of your guests.

Who else touches your data

We keep the list of companies involved as short as we can. Each one handles a specific job and nothing more:

  • Apple — processes all in-app purchases. Apple tells us that a purchase happened; Apple does not give us your payment details.
  • RevenueCat — verifies App Store purchase receipts on our behalf. It receives the transaction identifier and an anonymous or account-linked user identifier.
  • Railway — hosts our servers, database, and file storage in the United States.
  • Resend — delivers transactional email such as verification and password-reset messages.
  • Google Analytics — measures traffic on this website only. It is not present in the iPad app. If you would rather not be counted, browser tracking protection or an ad blocker will stop it.

We may also disclose information if the law requires it, or to protect our rights or someone’s safety. If our business is ever sold or merged, this data may transfer with it, and this policy travels with the data.

Where it lives, and for how long

Backed-up entries are stored in a database and object storage hosted in the United States. Photos, drawings, and voice recordings are stored as files with unguessable identifiers.

  • While your wedding is active — we keep your wedding’s contents so you can download and re-download your book. There is no automatic expiry; a wedding is a keepsake, not a session.
  • When you delete an entry — it is removed from the iPad and, if it had been synced, from our servers.
  • When you delete your account — your account record is deleted immediately, and your weddings are detached from you at once and become unreachable to anyone. We erase their contents once a short recovery period has passed; that window exists only so a deletion made by mistake can be undone before the photos and voice notes of people who never had an account are destroyed. If you would rather we erase everything straight away, email us and we will.
  • When you delete the app — everything the app stored on that iPad goes with it. If those entries were never synced, they are gone for good.
  • Purchase records — we keep a minimal record of transactions for as long as tax and accounting rules require, even after an account is deleted.

Your choices and rights

  • Delete a single entry — open the gallery in the app, choose the entry, and delete it.
  • Delete your account and your weddings — in the app, open the setup screen (tap the book cover five times, then enter the admin PIN), sign in, and use Delete account. No email to us is required.
  • See or correct your information — most of it is editable in the app or the planner portal. For anything else, email us.
  • Get a copy — email us from your account address and we will send you what we hold.
  • Turn off cloud backup — sign out on the iPad. The app keeps working; it simply stops sending anything to us.

Depending on where you live, you may have additional rights — for example under the California Consumer Privacy Act (CCPA/CPRA) or the GDPR — to know what we hold, to have it deleted or corrected, to receive a portable copy, and not to be discriminated against for exercising those rights. We do not sell or share personal information, so there is nothing to opt out of. To exercise any right, email support@weddingsguestbook.com and we will respond within 30 days.

Guests, consent, and photographs

The account holder controls the iPad at their event, and is responsible for making sure guests know they are being photographed or recorded and are willing. We recommend a small sign near the book. Guests who would prefer their entry removed can ask the couple, who can delete it, or email us and we will pass the request along.

Children

The app is not directed to children, and accounts may only be created by adults. Children at a wedding may of course appear in a photo their family takes at the booth — that content belongs to the couple and is governed by the rest of this policy. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided us information, email us and we will delete it.

Security

Traffic between the app and our servers is encrypted with HTTPS. Passwords are hashed with bcrypt and never stored in the clear. Sign-in uses expiring tokens, and access to a wedding’s contents requires ownership of that wedding. No system is perfect, so please use a strong, unique password and tell us promptly if something looks wrong with your account.

Changes

If we change this policy we will update the date at the top, and for anything significant we will say so in the app or by email. Continuing to use the app after a change means you accept the updated policy.

Contact us

Wedding Guestbook is operated by KeyesCode. Questions, requests, or complaints: support@weddingsguestbook.com.

See also our Terms of Use and support page.

© 2026 Wedding Guestbook · KeyesCode
PrivacyTermsSupport