Zaffa
Privacy Policy
Last updated 3 October 2026
What Zaffa is
What we collect
- Account. Your email address, used to send the one-time login code.
- Wedding details. Couple names, date, venue, invitation sections (welcome message, photos, registry, accommodation), theme choice, and any palette overrides.
- Guests. Names, phone numbers, RSVP status, plus-one details, meal preferences, table assignments, and any custom answers a guest provides.
- RSVP submissions. What each guest replied, with the name, phone, and email they typed when responding.
- Photos. Any images you upload for the invitation. Stored in Supabase Storage. A photo you attach in the chat is kept in a private bucket and reachable only through short-lived signed links until you place it on your invitation; only then does it become public like your other invitation photos.
- Ask Zaffa conversations. The messages you and the assistant exchange in the chat, the proposal cards it made, and how each turn ended — kept so that a reload keeps the thread. Stored with your wedding and removed with it; nothing in a saved conversation is applied to your invitation without your approval.
- Product analytics. On Zaffa’s own product and dashboard pages we use Google Analytics 4 to understand aggregate product use, and Microsoft Clarity to see how pages are used (click and scroll heatmaps, and replays of anonymous sessions). You can turn this off at any time with the preference at the bottom of this page. Text inside your dashboard is masked in your browser before Clarity sees it. We do not send invitation links, guest names, email addresses, wedding IDs, RSVP answers, or free-text content to either service.
- Purchase records. When you buy Premium or a web address, we record the checkout and its outcome — started, paid, declined or expired — with the amount, the currency and the bank’s reason code, never card details, as part of providing and accounting for the paid service. This record is kept regardless of the optional analytics choice below; it is not analytics and is never shared with Google, Microsoft or TikTok.
- Advertising measurement. On Zaffa’s own marketing pages we use the Meta pixel and the TikTok pixel to measure how our ads perform, and we may confirm a completed sign-up or purchase to Meta and TikTok from our server. To match it to an ad click we may send a one-way encrypted (hashed) form of your email address — never the address itself. You can turn this off at any time with the preference at the bottom of this page. This never runs on guest invitation pages, guest camera pages, or inside the Zaffa iOS app, and we do not send guest names, invitation links, wedding IDs, RSVP answers, or free-text content to Meta or TikTok.
What we do not collect
- No tracking pixels or third-party analytics on the public invitation page.
- No location data.
- No payment information — Zaffa does not process payments.
- No data from guests beyond what they submit through the RSVP form.
Where it lives
The AI features
The Ask Zaffa assistant, the “draft my invitation” wizard, the theme suggestion and the guest-list import are all answered by GLM-5.3-Flash, a model built by Z.ai, reached through OpenRouter. OpenRouter is a router: it does not run the model itself, it forwards the request to one of a number of independent hosting companies and returns the answer. OpenRouter’s privacy policy states that it does not use inputs or outputs for model training, and also that some model providers may. So Zaffa sends every AI request — not only the assistant’s — with routing restricted to providers that do not collect data beyond serving the request.
The writing helper — including “Write it for me” and “Write it with AI” in the guided steps — is answered first by gpt-oss-120b, an open-weight model published by OpenAI and run by an independent hosting company (Cerebras or Groq when available, otherwise another host OpenRouter offers), reached through OpenRouter with the same restriction. OpenAI itself does not receive the request. If that model cannot answer, GLM-5.3-Flash answers instead.
What each feature sends. The assistant can read your wedding content and your guest list — guests’ names, their RSVP status, meal notes and table — to answer questions like “who hasn’t replied?”. The writing helper sends the wording you are working on, with your couple names and venue for context; the “draft my invitation” wizard sends the answers you give it, with the same context; the theme suggestion sends the style you describe and the list of available themes. The guest-list import sends the column headings of your spreadsheet (and any title lines above them), a summary of each column and a few sample rows — which can include names and phone numbers. The rows themselves are read by Zaffa’s own code, and the model only confirms which column is which.
Two things we will not claim, because neither company states them: a retention period for what any of these features sends, and the identity of the specific host that answers any one request.
These features are optional. If you would rather no wedding or guest data went to an AI provider, don’t use them — everything in Zaffa can be written, imported and managed by hand, and nothing is sent unless you ask for it.
The ChatGPT integration
Retention
Sharing
Your rights
Analytics and advertising measurement: