# Wendus privacy facts

> Wendus stores wedding event data on the user's device by default and does not transmit that event data to a developer-operated server.

Canonical policy: https://wendus.app/privacy

Last fact-checked: 2026-07-13. The canonical HTML policy controls if this summary and the policy differ.

## App data

Wendus can hold event details, guests and households, RSVP and invitation status, meals, dietary and accessibility notes, user-entered contact details, seating assignments and drafts, venue maps and sketch data, QR-pass and check-in records, local purchase-pass records, export history, backups, archives, and audit history.

The local SQLite event snapshot is encrypted with Apple platform cryptography and Keychain-backed keys. Imported venue-map files are protected local sidecar files. Portable `.wendusbackup` files contain the event snapshot and optional venue-map bytes and are encrypted with a key derived from a passphrase chosen by the user. Wendus cannot recover that passphrase.

## Sharing boundaries

Users can create local vendor CSV files, a master guest-list CSV, and an encrypted portable backup. Vendor export previews show their purpose, included and excluded fields, row count, and sensitive-field warnings. Venue Handoff transfers an encrypted, check-in-only packet between nearby Wendus devices and excludes phone numbers, email addresses, and venue-map data.

Copies a user saves or shares through Files, Messages, email, or another destination remain under that user's control. Deleting app-managed local event data does not delete copies that already left Wendus.

## Accounts, advertising, and cloud services

The app does not require guest or vendor accounts. It does not use advertising SDKs, app analytics SDKs, tracking domains, or live cloud sync. App Store payment details are handled by Apple.

## Website analytics

The public website wendus.app uses Google Analytics 4 and Cloudflare Web Analytics for aggregate traffic and page-performance measurement. These website services are separate from the app and do not receive wedding event data from Wendus.

## Retention choices

Post-event closeout can create an encrypted archive, purge sensitive fields while retaining operational counts, retain aggregates only, or delete app-managed local event data. The exact policy is published at https://wendus.app/privacy.
