Privacy
What this site stores, for how long, and who else gets to see it. The short version: as little as possible, and you can delete all of it yourself.
What is stored when you build an invitation
Everything you type into the builder: the sender name and the name of the person you are inviting as you enter them, the headline, the message, the sign-off, the place, a practical note, the proposed times and, if you give one, an e-mail address for the notification.
Photos and the voice note are stored in the same database as the invitation itself. They are not uploaded anywhere else and not passed on.
What you say about how the two of you stand and where it might go only feeds the wording suggestions in the builder. None of it appears on the invitation.
What is stored when somebody answers
The answer, the chosen time, an optional note and the moment it arrived. On a shared link, also the name the person replying types in themselves.
Anyone who chooses to leave an e-mail address when replying gets a private link to their own answer and can change it later. That stores the address and a random identifier. Without an address none of this happens.
Opening an invitation increments a counter and records when it was first opened. No IP addresses and no device information are stored.
Cookies and local storage
One cookie, mmm_locale, remembers the chosen language. It holds nothing but de or en and exists only to make the site work.
On an invitation sent to several people, your browser notes locally that this device has already replied. That stays on the device and is never transmitted.
There is no analytics, no tracking, no ad network and no embedded third-party content.
Who else sees anything
If a notification address is set, the e-mail provider Resend delivers one message and processes that address and the contents of that mail.
The status page offers prepared search links to OpenStreetMap, OpenTable, Booking.com and Google Maps. Those are ordinary links: the provider learns something about you only once you click one. Nothing flows before that.
The calendar file is generated on this server. No third party is involved.
The basis for all this
Building an invitation forms a contract of use. The processing needed for it rests on Article 6(1)(b) GDPR, performance of a contract. Without the details you enter there is no invitation.
An invited person's answer rests on the same basis: they open a page that was sent to them and answer a question. Leaving an e-mail address when answering is optional and rests on consent, Article 6(1)(a) GDPR, which can be withdrawn at any time by deleting the answer through the personal link.
No legitimate interest under (f) is claimed for advertising or analytics, because neither happens here.
Who processes on our behalf, and where
The application and the database are run by the providers named in the legal notice, acting as processors under Article 28 GDPR. A data processing agreement is in place with each of them.
Those providers are based in the United States, so a transfer to a third country takes place. It rests on the European Commission's standard contractual clauses and, where the provider is certified, on the EU-US Data Privacy Framework. Despite those safeguards, access demands by US authorities cannot be ruled out.
Anyone who wants to avoid that can run this software on European servers instead. It requires nothing that is unavailable there.
Vercel Inc., USA (Anwendung); Neon, USA (Datenbank)
How long any of it stays
A published invitation is reachable for 30 days by default. After that the link shows a short note instead.
You can delete it yourself at any time, through the private status link you received when you published. That removes the message, the photos, the voice note and every answer from the database for real, not just from the screen.
Your rights
You can ask what is stored about you and request correction, deletion or restriction of processing. For deletion the status link is the fastest route; for anything else a message to the address in the legal notice is enough.
You also have the right to lodge a complaint with a data protection supervisory authority.
This text describes what the software actually does. It is not a substitute for legal review.
