← Back to home

Privacy Policy

Last updated: September 30, 2026

1. Introduction

Mitra Planner, operated by Yudaina (VAT BE 0728.505.731) ("we", "us", "our"), operates the website mitraplanner.com and the Mitra Planner mobile app (together, the "Service"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Information You Provide

  • Account information — email address, display name, and password when you register. If you sign in via a third-party provider (e.g. Google), we receive your name and email address from that provider.
  • Wedding data — guest lists, vendor contacts, budget details, event schedules, seating plans, task lists, and wedding website content that you enter into the Service.
  • Uploaded content — images and files you upload, such as decor inspiration photos, website images, and payment documentation.
  • Communications — messages you send to us via email or through the Service, including support requests and content reports with the reported image reference and any explanation you provide.

Information Collected Automatically

  • Log data — IP address, browser type, operating system, referring URLs, pages viewed, and timestamps.
  • Device information — device type, screen resolution, and language preferences.
  • Error and performance data — technical log messages, error details, stack traces, timestamps, and diagnostic context to help us maintain and improve the Service. Diagnostic context may include account or wedding identifiers; these records are not necessarily anonymous.

Mobile App

  • Contacts — with your permission, you can select a contact to prefill vendor details. The app uses the selected contact's name, phone number, and email address; it does not import your entire address book. Selected details are saved to your workspace when you save the vendor.
  • Photos and documents — images and files you choose to upload are stored to provide features such as profile photos, decor boards, stationery, vendor documents, and support attachments.
  • Push notifications — when you grant notification permission, we register a device-specific push token and platform information on your account to deliver notifications. You can revoke notification permission in your device settings.
  • Biometric app lock — if you enable biometric unlock, your operating system performs fingerprint or facial authentication. We do not receive or store your biometric templates.
  • Offline storage — wedding data and pending changes are cached on your device so supported features work offline. Signing out clears the app's query cache and pending mutation queue. Copies you export or save outside the app must be removed separately.
  • App updates — the app checks Expo's update service for compatible frontend updates. These requests can include technical app, operating-system, and update identifiers.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Create and manage your account
  • Authenticate your identity and control access to wedding workspaces
  • Send transactional communications such as invitations, notifications, and password resets
  • Process your requests, including AI-powered content generation
  • Monitor and analyse usage trends to improve the Service
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

We do not sell or rent your personal information. The native mobile app does not display advertising. The website and native mobile app do not use Meta Pixel.

4. Third-Party Services

We share information with service providers as needed to operate the Service. Their applicable service and data-processing terms govern this processing. Some providers also process technical or account information for their own security, legal, or service-improvement purposes, as described in their privacy policies.

Google

If you choose to sign in with Google, we receive your name and email address from Google. If you connect Google Calendar to sync meetings, we read your calendar events (title, time, attendees, and meeting link) solely to detect meetings involving your couple client and display them in that wedding's Meetings tab, and — only when you choose to schedule or edit a meeting from within Mitra Planner — we create or update the corresponding event on your Google Calendar. If you connect Google Drive to export documents, we create files and folders in your Drive only where you direct us to; we cannot see or access any other files in your Drive. You may disconnect either integration at any time from the relevant page, which immediately removes our stored access.

Pinterest

If you connect your Pinterest account, we request read-only access to your boards and pins. We use this access solely to allow you to browse and import pin images into your wedding moodboard. When you import pins, the images are copied to our storage — we do not maintain a persistent connection to your Pinterest account data. Your Pinterest credentials are stored securely on our servers and are never exposed to your browser. You may disconnect your Pinterest account at any time, which immediately removes your stored credentials.

Canva

If you connect your Canva account, we request access to create and manage designs, view your design library, and read your basic profile (display name) — solely to let you create, import, and edit Canva designs for your wedding stationery (invitations, signage, and similar) from within Mitra Planner. Design preview thumbnails are copied to our storage so they display reliably in your stationery checklist, since Canva's own preview links expire after a short time; we do not otherwise store or alter the underlying design content, which remains in your Canva account. You may disconnect your Canva account at any time, which immediately revokes our access and deletes your stored Canva credentials. Disconnecting removes our API access — it does not delete stationery items or designs you've already added to your wedding plan.

AI Services

If you use AI-powered content generation features (such as decor moodboard image generation), your prompt and the event's decor notes are sent to the configured AI provider to generate content. These inputs may contain information you choose to enter, so avoid including personal or sensitive information. We do not include Google Workspace integration data in these creative prompts.

Any raw or derived user data we receive from Google Workspace APIs (such as Google Calendar) is used solely to provide the features described in this policy — such as the Meetings sync feature above. We do not use this data, and do not permit any AI provider we integrate with to use this data, to train, develop, or improve artificial intelligence or machine learning models, whether generalized or product-specific. Our use of data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Email Delivery

We use a third-party email service to send transactional emails such as team invitations, couple invitations, and password resets. Recipient email addresses are shared with this provider solely for the purpose of delivering these messages.

Hosting, Diagnostics, and Mobile Delivery

We use Supabase for authentication, database storage, and uploaded files, and Vercel to host the web service. Better Stack processes technical logs and diagnostic context when logging is enabled. Expo provides mobile update delivery and push delivery, and Google Firebase Cloud Messaging delivers Android notifications. Push delivery providers process device tokens and notification payloads, which may contain wedding-related information displayed in the notification. These services receive the data needed to operate their respective features.

Mapping Services

We use third-party mapping services for address lookup and map display features. Address queries are processed through our servers — API credentials are not exposed to your browser.

5. Cookies and Similar Technologies

We use cookies and similar technologies for authentication and preferences. These include:

  • Authentication cookies — to keep you signed in and maintain your session.
  • Preference cookies — to remember your settings, such as your role and selected workspace.

You can control cookies through your browser settings, but disabling essential cookies may prevent you from using the Service.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls limiting data visibility to authorised users, and regular security reviews.

While we strive to protect your information, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.

If you believe you've found a security vulnerability in the Service, please report it to security@mitraplanner.com rather than disclosing it publicly. Full details are published at /.well-known/security.txt.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. We respond to account-deletion requests within 30 days and explain the deletion process and any information retained for legal obligations or legitimate dispute resolution. Better Stack technical logs are retained for seven days. Supabase backups are retained on a rolling seven-day basis, so deleted data may remain in existing backups until those backups expire.

Wedding data is retained to provide the workspace until its owner requests deletion. Account deletion and wedding deletion are separate operations: an owner must delete or transfer owned weddings before using self-service account deletion. Contact support for help removing associated uploaded files and personal data, including records in workspaces managed by another owner.

You can request deletion of your Mitra Planner account and associated personal data at mitraplanner.com/delete-account, including without access to the app. The app also provides account deletion in the Account screen and a deletion-request link in Settings. If you own a wedding workspace, the self-service flow requires you to delete or transfer it first; contact support if you need assistance. Account deletion affects both web and mobile access. Shared wedding records managed by another owner may remain available to that owner; contact us about personal data in those records. We will explain any legally required retention when processing your request.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data.
  • Portability — request a machine-readable export of your data.
  • Objection — object to processing of your data in certain circumstances.
  • Withdrawal of consent — withdraw consent at any time where processing is based on consent (e.g. third-party integrations).

To exercise any of these rights, please contact us at support@mitraplanner.com. We will respond within 30 days.

You may also complain to your local data-protection authority, including the Belgian Data Protection Authority.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer your data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable law.

10. Children's Privacy

Service accounts are not intended for individuals under the age of 16. Wedding organisers may enter information about guests, including children, when planning an event. Organisers are responsible for having an appropriate basis to provide this information and limiting it to what is needed. Contact us about a child's personal data or an account created by someone under 16.

11. Public Wedding Websites

If you publish a wedding website through the Service, the content you add (text, images, event schedules) will be publicly accessible at the URL you configure. You may enable password protection to restrict access. RSVP submissions from visitors are stored within your wedding workspace and are subject to this Privacy Policy.

12. Links to Other Websites

The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policy of any third-party site you visit.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by email.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Yudaina (trading as Mitra Planner)
VAT: BE 0728.505.731
Email: support@mitraplanner.com