Privacy, in plain English
Last updated 2026-07-10.
What we collect
For hosts (signed-in users):your email address (for magic-link sign-in) and your display name. If you opt into “Let guests contact me,” the email and/or phone you provide are shown on the invite.
For guests: your first name and your RSVP response. No account needed. We set a long-lived device cookie (hearth_device) so we can recognize you when you return to the same invite — this prevents accidental double-RSVPs and lets you edit your response.
Optional guest info: when you RSVP, you may optionally provide an email (for reminders), a phone number (for day-of updates), dietary notes, or an ETA. Email and phone are stored in a separate locked table that only the host and our server can read — they are never exposed to other guests through the invite page.
Ticketed events (Bonfire): buying a ticket requires your name, email, and phone number. Waitlist sign-ups collect the same. If the host enables ticket transfers, claiming a transferred ticket collects your name and at least one of email or phone.
Event content:titles, dates, locations, cover photos, chat messages, shared photos, and collaborative “who’s bringing what” lists — whatever hosts and guests put in.
Push notifications:if you tap the bell icon to enable reminders, your browser’s push subscription endpoint is stored so we can deliver notifications. You can unsubscribe at any time through your browser settings, and we automatically remove subscriptions that stop working.
Cookies and local storage
We use exactly two cookies: a Supabase auth session cookie (for signed-in hosts) and a device token(for recognizing returning guests). Both are functional — we don’t use cookies for advertising or analytics.
What we don't do
No ads. No ad tracking. No third-party analytics (no Google Analytics, no Facebook pixel, no session replay, no fingerprinting). We do not sell or share your data with anyone except the service providers listed below — and each sees only the slice they need to do their job.
Service providers
Supabase — database and file storage (US region). Hosts your event data, RSVPs, photos, and chat messages.
Resend— transactional email (sign-in links, event reminders, update notices). Sees the recipient’s email address and the message content.
Vercel — web hosting and edge delivery. Serves the app; does not store your event data.
OpenStreetMap / Nominatim— address geocoding (turning an address into map coordinates). Only inputs that look like mappable places (street addresses, city & state) are sent; colloquial location names like “Grandma’s” stay local.
Upstash — rate limiting to prevent abuse. Sees anonymized request counters only; no names, emails, or event content.
Push services(Apple, Google, Mozilla) — if you enable push reminders, your browser’s own push service delivers the encrypted notification. This is standard web-push infrastructure; they don’t receive your event data.
That’s the complete list. When we add payment processing in the future, we will update this page before collecting any payment information.
Ephemerality is structural
Events are ephemeral by default. After an event ends, we keep it around for about 30 days so you can grab photos and look back — then it’s actually deleted: event details, RSVPs, guest contact info, chat, photos, all gone from our database and storage. We can’t leak what we’ve deleted.
Hosts can also archive or permanently delete their events at any time from the dashboard.
Your rights
See what we have — sign in, go to Account settings, and tap “Download my data.” You’ll get a JSON file with everything we store about you (events, RSVPs, photos, messages).
Delete your account — same page, one tap. We erase your account and everything tied to it: hosted events, RSVPs, photos, messages, contacts, payment records. Irreversible. You can also email us if you prefer.
Delete your RSVP— guests can remove themselves from any event (“Remove me” on the invite — including recurring and multi-day events), which erases their RSVP and any contact info they gave, immediately. When a host removes a guest from their list, that guest’s email and phone are erased right away too (the name stays briefly recoverable in case of an accidental removal, then goes with the event’s normal deletion).
Share links and tracking
Hosts can create tracked share links for their event. Each link has a unique token so the host can see which link a guest used to find the invite — useful for knowing whether the Slack post or the group text drove more RSVPs. These tokens do not identify you personally; they identify the link, not the clicker.
Children
Hearth isn’t for kids under 13. Don’t set up an account for a child.
Changes to this policy
If we change anything that affects what we collect or how we use it, we’ll email every host. Material changes go into effect 30 days after notice.
Contact
Questions, data requests, or deletion requests? Email hello@hearth.rsvp.