Privacy Policy

Effective: August 22, 2026
Developer: Sergio Romano
Contact: support@tiedinbloom.com

Tied in Bloom keeps your full wedding plan on your own devices and in your private iCloud. The optional Wedding Team feature sends a limited, team-safe subset to a developer-operated Supabase service so you and one invited co-planner can work on it together. This policy explains both boundaries.

1. Summary

For Apple's App Privacy disclosure: information processed only on your device or in your private iCloud database is not collected by this developer. Beginning with version 1.7, if you use Wedding Team sharing or Seating Studio commerce, the limited information processed by Supabase is collected for App Functionality and is linked to your Wedding Team account. The categories prepared for the version 1.7 App Privacy submission are Name, User ID, Other User Content, Purchase History, Coarse Location, and Other Diagnostic Data. It is never used for tracking or advertising. Until Apple approves version 1.7 and its updated disclosure, the live App Store page may describe the currently released version. Apple separately processes App Store, iCloud, and device-service information under Apple's own policies.

2. What the app processes

Depending on what you enter or import, the app may process:

The private-planner groups above stay on your device and in your private iCloud. Wedding Team identity, collaboration, publication, commerce, safety, and service-security data reaches the developer-operated service only when the related feature is used.

3. On-device storage, widgets, and iCloud

The app stores your wedding data locally using Apple's Core Data framework. A small snapshot needed for the home-screen widgets is kept in an Apple App Group on your device so the widgets can show the countdown, RSVP totals, and upcoming tasks.

When you are signed in to iCloud and iCloud is available, Apple's CloudKit syncs the app's records through your private iCloud database. Apple, not the developer, runs iCloud and handles that data under the agreements and privacy terms tied to your Apple Account. The developer has no administrative dashboard and no server access to read your private CloudKit records.

4. Wedding Team

Wedding Team is optional and off until you turn it on.

Who can be in a Team. A new Team has one owner and one invited co-planner. Older Helper or Viewer records may remain readable and removable for compatibility, but neither role can be newly invited.

Signing in. Wedding Team uses Continue with Apple to create a Team identity with Supabase, and requests your full name. If Apple provides it, the app uses it as your Team profile name. If you are accepting an invitation, the name you enter becomes your membership and profile name. If Apple provides no name and you have no prior profile, the service uses a generic label.

What is sent. When an owner creates a Team, the app sends a Team title derived from the partner names, the wedding date, and an opaque identifier that links the Team to the private wedding. The service also processes internal user identifiers, membership and role, invitation state, team-safe tasks and notes, and any seating or wedding-day copy the owner chooses to publish.

A published seating copy includes the plan, venue and table labels chosen for publication, table layout details, guest display names, internal identifiers, and each published guest's table and seat placement. A published wedding-day copy includes event titles, times, public locations, team-safe notes, and internal event identifiers.

What is never sent. The Wedding Team service does not receive your budget, deposits, installments, payment due dates, private checklist notes, vendor pricing, guest phone numbers, email addresses, postal addresses, dietary information, save-the-date or invitation dates, RSVP reply dates, guest tags, guest private notes, full guest records, or unpublished working seating layouts. Please do not put private or sensitive information into team-safe task notes or published display names.

Invitations. The owner shares a private tiedinbloom.com/join/ link through the standard system share sheet. The invitation secret lives in the URL fragment, is single-use, expires, and is not sent to the website server during normal link navigation. You choose the messaging app or service that carries it. Tied in Bloom does not upload your contacts and does not store the recipient's email address or phone number.

Legacy iCloud sharing. If you created a Plan Together iCloud share in an earlier version, that existing share may still give the invited person access to your full private plan. The owner can end that access and the participant can leave it. The app no longer creates new full-plan iCloud invitations.

Service security. Supabase and its network providers may process and retain limited technical request information, such as IP address, IP-derived approximate city, region, country, postal code and coordinates, request time, route and protocol, limited client information, response status, latency, and security metadata, to authenticate requests, prevent abuse, diagnose failures, and operate Wedding Team. This approximate location comes from the network request, not the device's precise Location Services. These records are retained only for the provider's active operational period and any longer period reasonably necessary to resolve a security or abuse incident or comply with law. They are not used for advertising or tracking.

Safety reports and blocking

If you use Report & Remove or Report, Block & Leave, the service processes the Team identifier, the reporter's and reported person's user and membership identifiers, the reported person's display name and role, the reason you select, any details you add, and technical request and result information. This is used to validate the action, prevent replay or misuse, record the report, and enforce removal or blocking within that Team. Reports are not shown to the other person. A report is not an emergency or customer-support channel. Reports enter a safety review process, but the queue is not monitored in real time, and no individual reply or particular outcome is guaranteed.

If you use Report shared content or Hide & Report, the service stores the Team and content identifiers, your selected reason and optional details, local suppression state, revision and editor attribution, and an exact snapshot of the reported Team title, member name, task, publication, table, seat, or event needed to identify what was reported. This evidence is private and is not shown to the reported person.

An owner who reports someone removes them from the Team and blocks their return while the block stands. A co-planner who reports someone blocks that person within the Team and leaves it. When someone is removed, leaves, or loses access, the app clears locally cached Team snapshots and widget data.

Tied in Bloom is not an emergency service. Contact local emergency services when immediate help is needed.

5. Contacts and file imports

When you choose From Contacts, Apple's out-of-process picker lets you select specific people. The app receives only the selected contact's first and last name, the organization name if no personal name is set, and, when available, the first postal address. It does not request broad address-book access, does not scan your contacts, and does not receive phone numbers, email addresses, birthdays, photos, or other fields.

When you choose a CSV or text file, the app reads that file on your device to create guest records. The source file is not uploaded to the developer.

6. Notifications

If you enable reminders and grant notification permission, the app schedules local notifications on your device for incomplete checklist items and unpaid budget installments with due dates. Wedding Team participants can also opt in to local assignment and due-soon reminders. Delivery is best effort, so the in-app checklist, payment calendar, and Assigned to you view remain the sources of truth.

Apple's iCloud sync sends the app silent background notifications so your data stays current across your devices. Those come from Apple, carry no visible alert, and are part of how CloudKit works.

The developer does not send marketing or promotional notifications, does not operate its own push service, and does not receive the content of your reminders.

7. Exports and the share sheet

The app can create guest-list, budget, day-plan, and seating-chart files on your device. Guest and budget exports can include the mail milestones, tags, deposits, installments, and due dates you recorded. Text and CSV exports are written to the app's temporary directory, which iOS manages. When you open the share sheet, you choose the destination. The receiving app, service, person, or organization then handles that file under its own terms. The developer does not receive a copy.

Review exports before sending them. They may contain personal or financial information about you, your guests, or your vendors.

8. Subscriptions and purchases

Core Wedding Team access for the owner and one invited co-planner is free. Beginning with version 1.7, once Apple approves the subscriptions and makes them available, the owner can buy an auto-renewable subscription that unlocks additional seating plans, ready-made layouts, saved and comparison designs, the polished Seating Book, and new publications. An invited co-planner does not subscribe and is never asked to buy anything.

Apple's App Store and StoreKit process the purchase, renewal, restoration, and any refund under Apple's terms. The developer never receives your payment card details, billing address, or Apple Account password.

See the Terms of Use for the subscription length, price, renewal, and cancellation terms.

While your Wedding Team account exists, the Wedding Team service stores a minimal commerce record to keep paid features working across your devices and to prevent one purchase being shared between unrelated accounts: Apple's original transaction identifier and transaction identifier, the product identifier, whether the transaction is from the production or sandbox environment, the current subscription state and renewal state, related lifecycle dates, an opaque token derived from your Continue with Apple identity, and a link to your Wedding Team user record.

The service does not store your raw Continue with Apple subject identifier or your Apple Account email for this purpose, and it does not store what you paid.

9. Information received outside the app

If you email support or send TestFlight or App Store feedback, the developer may receive what you choose to provide: your email address, your message, attachments, screenshots, and any diagnostic details Apple supplies. This is used to answer you, troubleshoot, prevent abuse, and comply with law. Please do not include wedding plans or other sensitive information unless it is needed to help you.

Support email is handled by an email service provider. Apple may also give the developer aggregate App Store performance information and user-authorized crash or diagnostic reports. The app contains no analytics or tracking SDK.

10. Disclosure, sale, and advertising

The developer does not sell your wedding data, does not share it for cross-context behavioral advertising, does not use it to profile you, and does not display advertising.

The developer may disclose support correspondence only where reasonably necessary to provide support, protect rights and safety, prevent fraud or abuse, comply with law or legal process, or complete a business transfer subject to appropriate privacy protections.

11. Retention and deletion

Your private wedding. It stays on your device and in iCloud until you delete it, subject to Apple's iCloud retention, backup, and sync behavior.

Use Settings → Start fresh → Erase everything to delete a wedding you own and its connected private records. If it has a legacy Plan Together share, the app first revokes non-owner access. If it has a Wedding Team, the app first closes that Team through the service so your co-planner loses access. It then deletes the private wedding locally and through CloudKit. If any of those steps cannot finish safely, the app keeps the wedding and reports the partial state so you can retry.

Deletion is saved locally and sent to iCloud through CloudKit. Other devices and iCloud may need time to catch up. An invited co-planner cannot delete the owner's wedding from inside the app. Copies someone already exported, screenshot, or recorded are outside the app's control.

Deleting the app removes its local container but may not delete records already in iCloud, and those records can return after reinstalling. Use Start fresh before uninstalling if you want an owned wedding removed from iCloud.

Temporary exports may remain until iOS clears the app's temporary storage or the app is deleted. Copies you saved or shared must be deleted from wherever you sent them.

Your Wedding Team account. Use Wedding Team → Account & deletion to delete it. Owners permanently close Teams they own. Co-planners leave their membership, and tasks they created are removed. Memberships, team-safe tasks, invitations, publications, cached snapshots, and widget data are deleted or made inaccessible as applicable. Your private iCloud wedding is not deleted. The app also asks Apple to revoke its Continue with Apple authorization.

Deleting your Wedding Team account does not cancel or refund an App Store subscription. Cancel renewal in your Apple Account subscription settings.

Supabase may keep deleted hosted records in restricted service backups under its active backup configuration. Those records are not available through the app and remain only for the provider's normal backup lifecycle or longer when reasonably necessary for a security incident or legal obligation.

Commerce records. Deleting your Wedding Team account removes its owner-linked commerce records from the Wedding Team service. It does not cancel or refund the App Store subscription. If you later create a new account with Continue with Apple, the app can ask Apple to verify an eligible subscription again and create the minimum new records needed for paid feature access. It cannot restore a deleted Team or deleted Team content.

Person safety reports. Raw person-report details are retained only while needed to review the report, enforce a block, prevent replay or abuse, protect the service, or comply with law. They are removed or redacted after those operational and legal needs end. Unresolved, pending-preservation, security-relevant, or legally held reports remain longer. Limited non-content integrity proof, membership history, and Team block state may remain after raw report details are removed.

Content reports. Exact reported-content snapshots, revision and editor attribution, review records, and related integrity evidence currently remain until an approved deletion or redaction lifecycle is active. This evidence can remain after the underlying Team content or Wedding Team account is deleted and may be kept longer where required by law. Deleting an account does not bypass a legally required hold.

Support email. Kept only as long as reasonably necessary for support, security, recordkeeping, or legal obligations, then deleted or de-identified.

12. Your choices and requests

You can:

The developer cannot access, correct, export, or delete private wedding data that exists only on your device or in your private iCloud database. Those controls are in the app and in Apple's settings. The in-app account deletion control deletes the Wedding Team account and Team content described above.

Depending on where you live, privacy law may give you additional rights. The developer will honor applicable rights for information the developer actually holds, and will not treat you differently for exercising them.

13. Security

The app relies on iOS security, Apple's CloudKit protections, encrypted HTTPS, Supabase authentication, and server-side authorization that limits what each role can read or change. No method of storage or transmission is perfectly secure. Keep your device and Apple Account secure, use a passcode and two-factor authentication, share only with someone you trust, and keep your own backup of anything you cannot afford to lose.

14. Children

The app is a general-audience planning tool and is not directed to children under 13. The developer does not knowingly collect personal information from children through the app. Adults should avoid entering a child's personal information without the authority and a good reason to do so.

15. International processing

Apple, Supabase, and the developer's email provider may process information in countries other than your own, under their own terms and privacy policies. The developer's handling of support correspondence takes place in the United States.

16. Changes

This policy may change when the app's features or legal requirements change. The effective date above will be updated. Material changes will be communicated through the app, the App Store listing, or this page where reasonably appropriate.

17. This website

The Tied in Bloom website is informational. It has no developer-added account system, forms, advertising, analytics, or tracking cookies. It is hosted by Netlify, which may process technical request information such as IP address, browser type, requested page, and date and time in order to deliver, secure, and operate the hosting service, under Netlify's own terms.

If analytics, forms, purchases, or other website features are added later, this policy will be updated before they go live.

18. Contact

Sergio Romano
Email: support@tiedinbloom.com