Zaffa

Privacy Policy

Last updated 3 October 2026

What Zaffa is

Zaffa is a wedding-invitation and guest-management service. It pairs an iOS app for couples with a web invitation that guests view by link. A Custom GPT — “Zaffa: Wedding Planner” — can also read and update a couple’s wedding through the same API. This policy covers all three.

What we collect

  • Account. Your email address, used to send the one-time login code.
  • Wedding details. Couple names, date, venue, invitation sections (welcome message, photos, registry, accommodation), theme choice, and any palette overrides.
  • Guests. Names, phone numbers, RSVP status, plus-one details, meal preferences, table assignments, and any custom answers a guest provides.
  • RSVP submissions. What each guest replied, with the name, phone, and email they typed when responding.
  • Photos. Any images you upload for the invitation. Stored in Supabase Storage. A photo you attach in the chat is kept in a private bucket and reachable only through short-lived signed links until you place it on your invitation; only then does it become public like your other invitation photos.
  • Ask Zaffa conversations. The messages you and the assistant exchange in the chat, the proposal cards it made, and how each turn ended — kept so that a reload keeps the thread. Stored with your wedding and removed with it; nothing in a saved conversation is applied to your invitation without your approval.
  • Product analytics. On Zaffa’s own product and dashboard pages we use Google Analytics 4 to understand aggregate product use, and Microsoft Clarity to see how pages are used (click and scroll heatmaps, and replays of anonymous sessions). You can turn this off at any time with the preference at the bottom of this page. Text inside your dashboard is masked in your browser before Clarity sees it. We do not send invitation links, guest names, email addresses, wedding IDs, RSVP answers, or free-text content to either service.
  • Purchase records. When you buy Premium or a web address, we record the checkout and its outcome — started, paid, declined or expired — with the amount, the currency and the bank’s reason code, never card details, as part of providing and accounting for the paid service. This record is kept regardless of the optional analytics choice below; it is not analytics and is never shared with Google, Microsoft or TikTok.
  • Advertising measurement. On Zaffa’s own marketing pages we use the Meta pixel and the TikTok pixel to measure how our ads perform, and we may confirm a completed sign-up or purchase to Meta and TikTok from our server. To match it to an ad click we may send a one-way encrypted (hashed) form of your email address — never the address itself. You can turn this off at any time with the preference at the bottom of this page. This never runs on guest invitation pages, guest camera pages, or inside the Zaffa iOS app, and we do not send guest names, invitation links, wedding IDs, RSVP answers, or free-text content to Meta or TikTok.

What we do not collect

  • No tracking pixels or third-party analytics on the public invitation page.
  • No location data.
  • No payment information — Zaffa does not process payments.
  • No data from guests beyond what they submit through the RSVP form.

Where it lives

Data is stored on Supabase, hosted in their managed cloud, with row-level security so couples can only see their own wedding row. Photos sit in a Supabase Storage bucket. The web invitation runs on Vercel. Unless you turn it off, aggregate usage data is processed by Google Analytics and Microsoft Clarity, and advertising measurement by Google Ads, Meta and TikTok.

The AI features

Zaffa has AI helpers inside the product: the Ask Zaffa assistant, the writing and translation helper on the content editors, the “draft my invitation” wizard, the theme suggestion, and the guest-list import. When you use one, what you typed is sent to a company that runs the model which answers. Every one of them is reached through OpenRouter, with the same data restriction.

The Ask Zaffa assistant, the “draft my invitation” wizard, the theme suggestion and the guest-list import are all answered by GLM-5.3-Flash, a model built by Z.ai, reached through OpenRouter. OpenRouter is a router: it does not run the model itself, it forwards the request to one of a number of independent hosting companies and returns the answer. OpenRouter’s privacy policy states that it does not use inputs or outputs for model training, and also that some model providers may. So Zaffa sends every AI request — not only the assistant’s — with routing restricted to providers that do not collect data beyond serving the request.

The writing helper — including “Write it for me” and “Write it with AI” in the guided steps — is answered first by gpt-oss-120b, an open-weight model published by OpenAI and run by an independent hosting company (Cerebras or Groq when available, otherwise another host OpenRouter offers), reached through OpenRouter with the same restriction. OpenAI itself does not receive the request. If that model cannot answer, GLM-5.3-Flash answers instead.

What each feature sends. The assistant can read your wedding content and your guest list — guests’ names, their RSVP status, meal notes and table — to answer questions like “who hasn’t replied?”. The writing helper sends the wording you are working on, with your couple names and venue for context; the “draft my invitation” wizard sends the answers you give it, with the same context; the theme suggestion sends the style you describe and the list of available themes. The guest-list import sends the column headings of your spreadsheet (and any title lines above them), a summary of each column and a few sample rows — which can include names and phone numbers. The rows themselves are read by Zaffa’s own code, and the model only confirms which column is which.

Two things we will not claim, because neither company states them: a retention period for what any of these features sends, and the identity of the specific host that answers any one request.

These features are optional. If you would rather no wedding or guest data went to an AI provider, don’t use them — everything in Zaffa can be written, imported and managed by hand, and nothing is sent unless you ask for it.

The ChatGPT integration

“Zaffa: Wedding Planner” is a Custom GPT that authenticates to Zaffa with OAuth (a one-time code sent to your email). Once signed in, it can read and write only your wedding — the same data the iOS app can. Messages you send to the GPT are processed by OpenAI under their own privacy terms; the wedding data the GPT reads is sent from Zaffa’s API to OpenAI as part of the conversation.

Retention

We keep wedding data while your account is active. If you ask us to delete your wedding, we remove the wedding row, all guests, RSVP submissions, and uploaded photos within 30 days. Email us at info@getzaffa.app to request deletion.

Sharing

We do not sell data. We share data with the infrastructure providers above (Supabase, Vercel, Stripe for payments, OpenRouter and its hosting providers when you use any AI feature, OpenAI when you use the GPT) as needed to run the service — and, unless you turn it off, with Google Analytics, Google Ads, Microsoft Clarity, Meta and TikTok to measure our own marketing pages and ads.

Your rights

You can ask us at any time for a copy of your data, to correct it, or to delete it. Email info@getzaffa.app and we’ll respond within 30 days.

Analytics and advertising measurement:

Children

Zaffa is intended for adults planning a wedding. We don’t knowingly collect data from anyone under 16.

Changes

If this policy changes meaningfully, we’ll update the date at the top and, where we can, let you know in-app.

Contact

info@getzaffa.app — for any privacy question, data request, or concern.