Privacy Policy — Your Smart Invite

Effective date: 20-July-2026  |  Last updated: 26-July-2026 (Section 11.2)

This Privacy Policy explains what information Your Smart Invite App ("the App", "we", "us", "our") collects, how it is used, who it is shared with, and the choices available to you. It was generated from a direct audit of the app's source code, Android manifest, Firebase configuration, and third-party integrations as they exist today. It does not describe hypothetical or planned features.

If you do not agree with this Policy, please do not use the App.

Geographic scope. The App is developed, operated, and marketed for users located in India. It is not directed at, marketed to, or intended for use by individuals located outside India, and we do not knowingly offer the App to residents of the EEA, UK, California, or any other jurisdiction outside India. This Policy is written with that India-focused user base in mind. If you nonetheless access or use the App from outside India, you do so on your own initiative; this does not itself make the App "directed at" your jurisdiction, but you remain responsible for confirming the App is lawful for you to use where you are located.

1. Who We Are

The App is developed and operated by Lalitha Balamurugan ("Developer"), contactable at support.yoursmartinvite@gmail.com.

The App uses Google Firebase as its backend infrastructure. Firebase is operated by Google LLC / Google Ireland Limited and acts as our data processor.

2. Information We Collect

2.1 Personal information you provide directly

When you create an account (via country code + mobile number + OTP) and complete your profile, we collect:

DataRequired?Notes
Mobile phone numberYesUsed as your login identity via Firebase Phone Authentication (OTP). Cannot be changed after account creation.
Title, first name, last nameFirst name requiredDisplayed to hosts/guests you interact with.
Email addressOptionalNot used for login; contact purposes only.
City, countryCountry required, city optionalFree-text profile fields.
Preferred languageOptional — default EnglishControls the language of the app UI (English / Tamil / Telugu).

We do not collect a profile picture, date of birth, gender, payment/billing information, or government ID of any kind. The App does not currently process payments in-app.

2.2 Information about the events you create and the guests you invite

If you host an event ("invite") in the App, we collect and store:

Important — data about non-users: Guest phone numbers are personal data of people who may never install the App themselves. By inviting someone, you (the host) represent that you have the right to share their contact number with us for the purpose of sending them an invitation. The App does not independently verify this.

2.3 Contacts on your device

If you choose to invite guests from your phone's address book, the App requests access to your device contacts (READ_CONTACTS permission) so you can search and select recipients. Contact names and numbers are read on your device only to populate the picker; only the phone numbers of people you actually select and send an invite to are transmitted to our servers and stored as guest records tied to that event.

2.4 Event Photos — optional selfie-based photo search ("Find My Photos")

Some events have an optional feature, enabled by the Developer per-event, that lets a host share event photos and lets guests find photos they personally appear in without the host having to manually sort or tag anything. This feature has two independent parts:

When a guest submits a selfie, it is sent to Amazon Web Services (AWS) Rekognition, a facial-analysis service, which computes a mathematical representation of the face (a "face vector") and stores it in a Rekognition collection scoped to that one event only. The selfie image itself is discarded immediately after this step — it is never stored by us, in Firebase or anywhere else.

When the host chooses to process their Drive photos, each photo is analyzed by AWS Rekognition to detect faces and compare them against the face vectors of guests who have opted in. Only guests who explicitly submitted their own selfie can ever be identified this way. Other people who happen to appear in a host's event photos — other guests who didn't opt in, photographers, staff, bystanders — are detected only transiently during this comparison and no face data about them is ever stored, by us or in the AWS Rekognition collection.

A host can delete this feature's data for their event at any time (the in-app "Unlink Folder" action), which deletes the AWS Rekognition face collection for that event and resets every guest's opt-in status. There is currently no separate automatic expiry beyond this host-triggered deletion — see the retention flag in Section 10.

Biometric data note: a face vector is treated as biometric/sensitive personal data in several jurisdictions (e.g. the EU GDPR's "special category data," Illinois' BIPA, India's DPDP Act). This section describes what the App's code actually does today; it is not a substitute for jurisdiction-specific legal review of the disclosure and consent language before this feature is relied upon at scale — see the Appendix.

2.5 Information collected automatically

DataSourcePurpose
Crash reports, non-fatal error logs, stack tracesFirebase CrashlyticsDiagnosing bugs and app stability
Device model, OS version, app versionFirebase Crashlytics (bundled automatically)Same as above
Push notification token (FCM token)Firebase Cloud MessagingDelivering notifications about invites, RSVPs, and reminders to your device
IP addressImplicit in all network requests (Firebase, map tiles)Standard request routing/security; not stored as a distinct profile field by us

We do not use Firebase Analytics, Google Analytics, Firebase Remote Config, or any advertising/analytics SDK. No advertising identifier, browsing history, or cross-app activity is collected.

3. Android Permissions Requested — and Why

PermissionWhy the App requests it
INTERNETRequired for all communication with Firebase and other cloud services.
CAMERAScanning guest QR codes for entry check-in and scanning invite QR codes; capturing a selfie for the optional, opt-in Event Photos face-search feature (see Section 2.4).
READ_CONTACTSLets a host search their phone's contact list to select invite recipients (see 2.3). Before this permission is requested, the App shows an in-app explanation of why contacts access is needed.
POST_NOTIFICATIONSRequired on Android 13+ to show push notifications (RSVP updates, reminders, event changes).

The App does not request the SMS-sending permission. To share an invite, the App opens your device's default messaging app with the invite text pre-filled, addressed to the contact the host selected — the host reviews and taps Send themselves. The App never sends a message on its own, and does not read, store, or have access to your messages or messaging history.

The App does not request location permissions. A venue "location picker" lets you manually drop a pin on a map or search an address — this does not read your device's GPS location (see Section 6).

The App does not declare broad photo/media-library permissions in its manifest; photo selection for invitation templates uses the Android system picker and scoped-storage APIs, which do not require a standing storage permission on modern Android versions.

4. Firebase Services Used

ServicePurpose
Firebase AuthenticationPhone number + OTP login.
Cloud FirestoreStores user profiles, invites, guest records, RSVP data, activity logs, and app-wide theme settings.
Firebase Cloud StorageStores invitation background templates, host-uploaded custom templates, and localization (language) files.
Firebase Cloud Messaging (FCM)Push notifications for invite updates, RSVP confirmations, and reminders.
Cloud Functions for FirebaseServer-side logic: sending reminders, generating delegate check-in sessions, and processing guest QR scans.
Firebase CrashlyticsCrash and non-fatal error reporting.
Firebase HostingHosts the web landing page and the browser-based "delegate" QR scanner page used by non-app-installed event staff.

Not used: Firebase Analytics, Firebase Remote Config, Firebase App Check (not yet enabled — see Section 9), Firebase Realtime Database, Firebase In-App Messaging, Firebase A/B Testing.

5. Third-Party Services We Use

ServiceProviderWhat is sharedPurpose
OpenStreetMap tile serversOpenStreetMap FoundationYour device's IP address, when map tiles are requestedRendering the venue-location map picker
Google Maps (web link only)Google LLCThe address/coordinates you chooseOpens maps.google.com in the browser/Maps app when you or a guest taps a venue link — no API key or data feed, just a URL
Google FontsGoogle LLCYour device's IP address, when a font not yet cached is requestedLoading decorative fonts used in invitation designs
Device OS geocodingApple / Google (on-device)Coordinates/address text you searchConverting a typed address into map coordinates and back — this does not access your device's live location
Amazon Web Services (AWS Rekognition)Amazon.com, Inc.A guest's selfie (transiently, discarded after processing — see Section 2.4) and photos from a host's shared Google Drive folder (read-only, for face-matching analysis only)Powers the optional, opt-in Event Photos face-search ("Find My Photos") feature
Google DriveGoogle LLCThe contents of a Drive folder a host explicitly shares with our backend service accountLets a host's own event photos be analyzed for the Event Photos feature without us storing photo files on our own infrastructure

We do not integrate any advertising network, analytics SDK, social-media SDK, or data broker.

6. Location Data

The App does not request or access your device's GPS/precise or coarse location, and no location permission is declared in the Android manifest. The event "location picker" lets a host manually search an address or tap a point on an OpenStreetMap map to set the venue — this is event metadata you choose to enter, not a reading of your device's position.

7. Cookies, Advertising, and Tracking

The App is a mobile application, not a website, and does not use cookies. It contains:

The Firebase Hosting web pages (yoursmartinvite.com) used for the invite landing page and delegate scanner also do not set tracking cookies.

8. How We Use Your Information

We use collected information to:

We do not use your information for advertising, do not build behavioral profiles, and do not sell personal information.

9. How Your Data Is Stored, Transmitted, and Protected

10. Data Retention

11. Your Rights and Choices

11.1 Access and correction

Most of your profile fields (name, email, city, country, language) can be edited directly in the App's Edit Profile screen. Your mobile number cannot be changed, as it is your login identity.

11.2 Deletion

The App has an in-app "Delete Account" action (Profile → Delete Account), which permanently and immediately deletes:

This action requires you to type a confirmation phrase before it proceeds, and cannot be undone. It only ever removes data you yourself own or control — never another host's event or another guest's own records. There is currently no separate, smaller action to remove just a single RSVP without deleting your whole account; if you only want to withdraw from one specific event you're attending as a guest, contact us at support.yoursmartinvite@gmail.com.

If you were only ever invited as a guest and never created an account at all, you may request removal of your phone number from a specific invite by asking the event host, or by contacting us at the same address.

A durable, non-identifying record that a deletion was requested and completed (a timestamp and result counts — no name, mobile number, or email) is kept for compliance purposes, consistent with Section 10.

11.3 GDPR rights (users in the EEA/UK)

As described in the Geographic Scope note above, the App is not directed at, marketed to, or knowingly offered to individuals in the EEA or UK. The rights below are described for completeness, in case you access the App from the EEA/UK on your own initiative or this scope changes in the future: access your personal data; request correction or erasure; restrict or object to processing; request a copy of your data in a portable format; and lodge a complaint with your local data protection authority. Contact us using the details in Section 1 to exercise these rights.

Legal basis for processing: performance of a contract (providing the App's core functionality), consent (e.g. camera/contacts permission), and legitimate interest (crash diagnostics, security). Where the optional Event Photos face-search feature (Section 2.4) applies, the legal basis is your explicit consent — a guest's face vector is only ever created after they actively choose to submit a selfie past an in-app consent notice, and never as a byproduct of any other feature.

International transfers: your data is processed on Google Cloud/Firebase infrastructure — Firestore (multi-region: nam5, United States), Cloud Storage (US-EAST1), and Cloud Functions (us-central1) — all located in the United States, and (only for guests who opt in to the Event Photos feature, Section 2.4) AWS Rekognition in ap-south-1 (India). This is disclosed for transparency. GDPR's Standard Contractual Clauses requirement governs transfers out of the EEA/UK — since the App is not directed at, marketed to, or offered to individuals there (see the Geographic Scope note above), this requirement is unlikely to apply to the App's processing at all. Separately, India's own DPDP Act 2023 permits cross-border transfer of personal data by default, except to countries the central government specifically restricts by notification — no such restricted-country list has been notified as of this writing, so no additional transfer mechanism is currently required under Indian law either.

EU representative: given the App is not directed at EEA/UK users, an Art. 27 representative is unlikely to be required — [INFORMATION REQUIRED FROM DEVELOPER]: revisit this if the Geographic Scope above ever changes.

11.4 CCPA/CPRA rights (California residents)

As described in the Geographic Scope note above, the App is not directed at, marketed to, or knowingly offered to California residents, and the Developer's operations are India-focused and very unlikely to meet CCPA/CPRA's revenue or user-volume applicability thresholds. The rights below are described for completeness: California residents have the right to know what personal information is collected, request deletion, correct inaccurate information, and opt out of the sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. Contact us using the details in Section 1 to exercise these rights.

12. Children's Privacy

The App is a general-audience event-invitation tool (weddings, birthdays, and similar events) and is not directed at children. We do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). The App does not collect date of birth and has no age-gating mechanism today. If you believe a child has provided us with personal information, contact us using the details in Section 1 and we will take steps to delete it. [INFORMATION REQUIRED FROM DEVELOPER]: confirm the intended Google Play "Target audience and content" declaration for this listing.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the App after changes take effect constitutes acceptance of the revised Policy.

14. Contact Us

Questions, requests, or complaints about this Policy or your data:

support.yoursmartinvite@gmail.com
Lalitha Balamurugan
B-15, Prakrti Flat, 367 100ft ByPass Road, Velachery, Chennai 600 042, India


Appendix — Information Required from Developer

The following items could not be determined from the source code and must be filled in before publishing. Nothing above assumes an answer to these — placeholders are marked inline.

  1. Account & data deletion — built, not yet deployed (26-July-2026): the in-app "Delete Account" flow described in Section 11.2 is code-complete (see context/user_deletion.md) but has not yet been deployed (firebase deploy --only functions:deleteUserAccount,firestore:rules) or tested against real data. Confirm it's deployed and working before relying on Section 11.2's description in a real submission.
  2. Planned feature, not yet built: a guest-facing "remove my RSVP" self-service option (delete your own invite_guests record for a specific event, anytime, without going through a support request) was discussed 25-July-2026 as a good candidate to build — it's safe to self-serve since it only ever affects the requesting guest's own data. Not implemented yet; when it ships, this Policy should be updated to describe it as an in-app capability rather than an email request.
  3. Play Console country/region targeting (action item, decided 25-July-2026): the Developer has decided the App targets India only (see the Geographic Scope note near the top of this Policy). This is currently only a policy statement — to make it technically real, configure Google Play Console → your app → Grow → Store presence → Countries/regions (or the current equivalent path) to restrict distribution to India only, so the App genuinely isn't offered elsewhere.
  4. Google Play "Target audience and content" declaration — confirm the intended age rating and audience setting in Play Console to align with Section 12.
  5. Payment processing — none exists in the app today; if/when a payment provider is integrated, this Policy must be updated with a new section covering payment data.
  6. Whether Firebase App Check will be enabled before or shortly after launch (affects the security posture described in Section 9, not the data-collection facts themselves).
  7. Google Cloud / AWS Data Processing Addendum — downgraded to optional, low priority (26-July-2026): previously listed as a required action item; on review, GDPR's Standard Contractual Clauses requirement only governs transfers out of the EEA/UK, and the App does not target users there (see Geographic Scope note). India's DPDP Act 2023 also permits cross-border transfers by default today (no restricted-country list has been notified). Confirming AWS Artifact / Google Cloud DPA status is therefore no longer a blocking item — revisit only if the Geographic Scope above ever changes to include EEA/UK users.
  8. Biometric data disclosure — legal review needed: Section 2.4 (Event Photos face search) was added 25-July-2026 based on a direct audit of the current implementation. Google Play's Data Safety form treats facial recognition as sensitive/biometric data and requires explicit disclosure; several jurisdictions (Illinois BIPA, India's DPDP Act, EU GDPR Art. 9) impose additional requirements on biometric data specifically. Have this section reviewed by counsel before relying on it, and update the Play Console Data Safety form to declare biometric data collection accordingly.