This Privacy Policy explains what information Your Smart Invite App ("the App", "we", "us", "our") collects, how it is used, who it is shared with, and the choices available to you. It was generated from a direct audit of the app's source code, Android manifest, Firebase configuration, and third-party integrations as they exist today. It does not describe hypothetical or planned features.
If you do not agree with this Policy, please do not use the App.
The App is developed and operated by Lalitha Balamurugan ("Developer"), contactable at support.yoursmartinvite@gmail.com.
The App uses Google Firebase as its backend infrastructure. Firebase is operated by Google LLC / Google Ireland Limited and acts as our data processor.
When you create an account (via country code + mobile number + OTP) and complete your profile, we collect:
| Data | Required? | Notes |
|---|---|---|
| Mobile phone number | Yes | Used as your login identity via Firebase Phone Authentication (OTP). Cannot be changed after account creation. |
| Title, first name, last name | First name required | Displayed to hosts/guests you interact with. |
| Email address | Optional | Not used for login; contact purposes only. |
| City, country | Country required, city optional | Free-text profile fields. |
| Preferred language | Optional — default English | Controls the language of the app UI (English / Tamil / Telugu). |
We do not collect a profile picture, date of birth, gender, payment/billing information, or government ID of any kind. The App does not currently process payments in-app.
If you host an event ("invite") in the App, we collect and store:
If you choose to invite guests from your phone's address book, the App requests access to your device contacts (READ_CONTACTS permission) so you can search and select recipients. Contact names and numbers are read on your device only to populate the picker; only the phone numbers of people you actually select and send an invite to are transmitted to our servers and stored as guest records tied to that event.
Some events have an optional feature, enabled by the Developer per-event, that lets a host share event photos and lets guests find photos they personally appear in without the host having to manually sort or tag anything. This feature has two independent parts:
When a guest submits a selfie, it is sent to Amazon Web Services (AWS) Rekognition, a facial-analysis service, which computes a mathematical representation of the face (a "face vector") and stores it in a Rekognition collection scoped to that one event only. The selfie image itself is discarded immediately after this step — it is never stored by us, in Firebase or anywhere else.
When the host chooses to process their Drive photos, each photo is analyzed by AWS Rekognition to detect faces and compare them against the face vectors of guests who have opted in. Only guests who explicitly submitted their own selfie can ever be identified this way. Other people who happen to appear in a host's event photos — other guests who didn't opt in, photographers, staff, bystanders — are detected only transiently during this comparison and no face data about them is ever stored, by us or in the AWS Rekognition collection.
A host can delete this feature's data for their event at any time (the in-app "Unlink Folder" action), which deletes the AWS Rekognition face collection for that event and resets every guest's opt-in status. There is currently no separate automatic expiry beyond this host-triggered deletion — see the retention flag in Section 10.
| Data | Source | Purpose |
|---|---|---|
| Crash reports, non-fatal error logs, stack traces | Firebase Crashlytics | Diagnosing bugs and app stability |
| Device model, OS version, app version | Firebase Crashlytics (bundled automatically) | Same as above |
| Push notification token (FCM token) | Firebase Cloud Messaging | Delivering notifications about invites, RSVPs, and reminders to your device |
| IP address | Implicit in all network requests (Firebase, map tiles) | Standard request routing/security; not stored as a distinct profile field by us |
We do not use Firebase Analytics, Google Analytics, Firebase Remote Config, or any advertising/analytics SDK. No advertising identifier, browsing history, or cross-app activity is collected.
| Permission | Why the App requests it |
|---|---|
INTERNET | Required for all communication with Firebase and other cloud services. |
CAMERA | Scanning guest QR codes for entry check-in and scanning invite QR codes; capturing a selfie for the optional, opt-in Event Photos face-search feature (see Section 2.4). |
READ_CONTACTS | Lets a host search their phone's contact list to select invite recipients (see 2.3). Before this permission is requested, the App shows an in-app explanation of why contacts access is needed. |
POST_NOTIFICATIONS | Required on Android 13+ to show push notifications (RSVP updates, reminders, event changes). |
The App does not request the SMS-sending permission. To share an invite, the App opens your device's default messaging app with the invite text pre-filled, addressed to the contact the host selected — the host reviews and taps Send themselves. The App never sends a message on its own, and does not read, store, or have access to your messages or messaging history.
The App does not request location permissions. A venue "location picker" lets you manually drop a pin on a map or search an address — this does not read your device's GPS location (see Section 6).
The App does not declare broad photo/media-library permissions in its manifest; photo selection for invitation templates uses the Android system picker and scoped-storage APIs, which do not require a standing storage permission on modern Android versions.
| Service | Purpose |
|---|---|
| Firebase Authentication | Phone number + OTP login. |
| Cloud Firestore | Stores user profiles, invites, guest records, RSVP data, activity logs, and app-wide theme settings. |
| Firebase Cloud Storage | Stores invitation background templates, host-uploaded custom templates, and localization (language) files. |
| Firebase Cloud Messaging (FCM) | Push notifications for invite updates, RSVP confirmations, and reminders. |
| Cloud Functions for Firebase | Server-side logic: sending reminders, generating delegate check-in sessions, and processing guest QR scans. |
| Firebase Crashlytics | Crash and non-fatal error reporting. |
| Firebase Hosting | Hosts the web landing page and the browser-based "delegate" QR scanner page used by non-app-installed event staff. |
Not used: Firebase Analytics, Firebase Remote Config, Firebase App Check (not yet enabled — see Section 9), Firebase Realtime Database, Firebase In-App Messaging, Firebase A/B Testing.
| Service | Provider | What is shared | Purpose |
|---|---|---|---|
| OpenStreetMap tile servers | OpenStreetMap Foundation | Your device's IP address, when map tiles are requested | Rendering the venue-location map picker |
| Google Maps (web link only) | Google LLC | The address/coordinates you choose | Opens maps.google.com in the browser/Maps app when you or a guest taps a venue link — no API key or data feed, just a URL |
| Google Fonts | Google LLC | Your device's IP address, when a font not yet cached is requested | Loading decorative fonts used in invitation designs |
| Device OS geocoding | Apple / Google (on-device) | Coordinates/address text you search | Converting a typed address into map coordinates and back — this does not access your device's live location |
| Amazon Web Services (AWS Rekognition) | Amazon.com, Inc. | A guest's selfie (transiently, discarded after processing — see Section 2.4) and photos from a host's shared Google Drive folder (read-only, for face-matching analysis only) | Powers the optional, opt-in Event Photos face-search ("Find My Photos") feature |
| Google Drive | Google LLC | The contents of a Drive folder a host explicitly shares with our backend service account | Lets a host's own event photos be analyzed for the Event Photos feature without us storing photo files on our own infrastructure |
We do not integrate any advertising network, analytics SDK, social-media SDK, or data broker.
The App does not request or access your device's GPS/precise or coarse location, and no location permission is declared in the Android manifest. The event "location picker" lets a host manually search an address or tap a point on an OpenStreetMap map to set the venue — this is event metadata you choose to enter, not a reading of your device's position.
The App is a mobile application, not a website, and does not use cookies. It contains:
The Firebase Hosting web pages (yoursmartinvite.com) used for the invite landing page and delegate scanner also do not set tracking cookies.
We use collected information to:
We do not use your information for advertising, do not build behavioral profiles, and do not sell personal information.
Most of your profile fields (name, email, city, country, language) can be edited directly in the App's Edit Profile screen. Your mobile number cannot be changed, as it is your login identity.
The App has an in-app "Delete Account" action (Profile → Delete Account), which permanently and immediately deletes:
This action requires you to type a confirmation phrase before it proceeds, and cannot be undone. It only ever removes data you yourself own or control — never another host's event or another guest's own records. There is currently no separate, smaller action to remove just a single RSVP without deleting your whole account; if you only want to withdraw from one specific event you're attending as a guest, contact us at support.yoursmartinvite@gmail.com.
If you were only ever invited as a guest and never created an account at all, you may request removal of your phone number from a specific invite by asking the event host, or by contacting us at the same address.
A durable, non-identifying record that a deletion was requested and completed (a timestamp and result counts — no name, mobile number, or email) is kept for compliance purposes, consistent with Section 10.
As described in the Geographic Scope note above, the App is not directed at, marketed to, or knowingly offered to individuals in the EEA or UK. The rights below are described for completeness, in case you access the App from the EEA/UK on your own initiative or this scope changes in the future: access your personal data; request correction or erasure; restrict or object to processing; request a copy of your data in a portable format; and lodge a complaint with your local data protection authority. Contact us using the details in Section 1 to exercise these rights.
Legal basis for processing: performance of a contract (providing the App's core functionality), consent (e.g. camera/contacts permission), and legitimate interest (crash diagnostics, security). Where the optional Event Photos face-search feature (Section 2.4) applies, the legal basis is your explicit consent — a guest's face vector is only ever created after they actively choose to submit a selfie past an in-app consent notice, and never as a byproduct of any other feature.
International transfers: your data is processed on Google Cloud/Firebase infrastructure — Firestore (multi-region: nam5, United States), Cloud Storage (US-EAST1), and Cloud Functions (us-central1) — all located in the United States, and (only for guests who opt in to the Event Photos feature, Section 2.4) AWS Rekognition in ap-south-1 (India). This is disclosed for transparency. GDPR's Standard Contractual Clauses requirement governs transfers out of the EEA/UK — since the App is not directed at, marketed to, or offered to individuals there (see the Geographic Scope note above), this requirement is unlikely to apply to the App's processing at all. Separately, India's own DPDP Act 2023 permits cross-border transfer of personal data by default, except to countries the central government specifically restricts by notification — no such restricted-country list has been notified as of this writing, so no additional transfer mechanism is currently required under Indian law either.
EU representative: given the App is not directed at EEA/UK users, an Art. 27 representative is unlikely to be required — [INFORMATION REQUIRED FROM DEVELOPER]: revisit this if the Geographic Scope above ever changes.
As described in the Geographic Scope note above, the App is not directed at, marketed to, or knowingly offered to California residents, and the Developer's operations are India-focused and very unlikely to meet CCPA/CPRA's revenue or user-volume applicability thresholds. The rights below are described for completeness: California residents have the right to know what personal information is collected, request deletion, correct inaccurate information, and opt out of the sale/sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. Contact us using the details in Section 1 to exercise these rights.
The App is a general-audience event-invitation tool (weddings, birthdays, and similar events) and is not directed at children. We do not knowingly collect personal information from children under 13 (or the relevant minimum age in your jurisdiction). The App does not collect date of birth and has no age-gating mechanism today. If you believe a child has provided us with personal information, contact us using the details in Section 1 and we will take steps to delete it. [INFORMATION REQUIRED FROM DEVELOPER]: confirm the intended Google Play "Target audience and content" declaration for this listing.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the App after changes take effect constitutes acceptance of the revised Policy.
Questions, requests, or complaints about this Policy or your data:
support.yoursmartinvite@gmail.com
Lalitha Balamurugan
B-15, Prakrti Flat, 367 100ft ByPass Road, Velachery, Chennai 600 042, India
The following items could not be determined from the source code and must be filled in before publishing. Nothing above assumes an answer to these — placeholders are marked inline.
context/user_deletion.md) but has not yet been deployed (firebase deploy --only functions:deleteUserAccount,firestore:rules) or tested against real data. Confirm it's deployed and working before relying on Section 11.2's description in a real submission.invite_guests record for a specific event, anytime, without going through a support request) was discussed 25-July-2026 as a good candidate to build — it's safe to self-serve since it only ever affects the requesting guest's own data. Not implemented yet; when it ships, this Policy should be updated to describe it as an in-app capability rather than an email request.