Privacy Policy
Draft pending legal review.
This policy explains how CurV LLC(“Adélie”, “we”) collects, uses, and protects personal data when couples use Adélie to plan their wedding. Contact: privacy@askadelie.com. Postal address: 418 Broadway STE N, Albany, NY 12207, USA.
Information we collect
Account and profile information you provide (names, wedding details, budget, to-dos); the content of emails you send, receive, forward, or CC through your Adélie wedding inbox; and usage data (see Cookies and analytics).
Data from third parties
Adélie ingests email from your wedding vendors. That mail contains vendor personal information (names, email addresses, quotes, scheduling) that the vendor provided to you, not to Adélie directly. We process it to extract tasks, quotes, and dates for your wedding, as described here (GDPR Article 14).
How we use your information
To operate the wedding inbox and command center: organizing vendor threads, extracting structured details, drafting replies you approve, and tracking budget and to-dos.
Lawful basis
We rely on: performance of our contract with you (operating the service); your consent (non-essential analytics; and explicit opt-in consent for special-category data extraction and saving — see Special-category data below); and our legitimate interests (securing and improving the service, server-side product analytics that are pseudonymous and cookieless), balanced against your rights (see Your rights below).
Service notifications
We send two types of notification email to the primary address on your Adélie account:
- Approval nudge — a plain-text email when Adélie has prepared a reply or budget update awaiting your approval. Legal basis: performance of our contract with you (operating the approval queue is a core service function, Article 6(1)(b) GDPR).
- Weekly digest— a brief Monday summary of Adélie’s activity for your wedding. Legal basis: our legitimate interests in keeping you informed of the service’s work (Article 6(1)(f) GDPR), balanced against your rights. You may object at any time via the unsubscribe link in any digest email (GDPR Article 21).
Both types include a working unsubscribe link. Clicking it stops all Adélie notification emails to that address. Unsubscribed addresses are retained on a suppression list to honour the opt-out (legal-obligation basis, Article 6(1)(c) GDPR; Article 17(3)(b)) and are not removed by the account-erasure control in settings.
Unsubscribe links include your email address in encoded form so the link self-authenticates; our hosting provider (Vercel — see Subprocessors) logs these requests as part of normal access logging. The unsubscribe page loads no third-party resources.
AI processing
Adélie is an AI co-pilot. Replies, summaries, extractions, and planning suggestions are AI-generated using Anthropic’s models. Separately, the content of your emails is embedded (converted into a numeric representation) using OpenAI, via the Vercel AI Gateway with zero data retention enforced on every request, to power search in Adélie’s chat (see Subprocessors). Alongside each numeric representation we also store the corresponding excerpt of your email text, so that a search result can show you the passage it came from. Those excerpts are held in your workspace, are included in any access or deletion request you make, and are deleted when the message or vendor they came from is deleted. A human approves every outbound email before it is sent.
Automated processing
We use automated processing to extract structured details from your email and to suggest drafts, tasks, and budget figures. These suggestions do not produce legal or similarly significant effects without your review — you approve outbound mail and can edit or delete any extracted figure (Article 13(2)(f); no Article 22 solely-automated decision-making).
Vendor directory
Adélie maintains a directory of wedding vendors and venues to help couples discover options. Directory entries hold public business information only — business name, category, general location, public contact channels (website, phone, public social handles), and a public description. Each field is sourced either from the business’s own public website or a public business listing, and we keep a record of where each field came from. Directory entries are never built from the content of your emails or any other couple’s private correspondence.
Because the directory is more useful when it reflects what couples actually find helpful, we also keep anonymous aggregate usage signals: how many couples have engaged with a listing, and how many have engaged with a particular venue-and-vendor pairing. These signals are counts only — we never store or expose which couple engaged with which vendor, and low-volume counts are not shown until enough couples contribute to keep any individual couple’s activity unidentifiable.
Our lawful basis for maintaining the directory and its aggregate usage signals is legitimate interest: the underlying data is public, we publish no individual couple’s activity, and we weigh this against vendors’ interests in how their public information is used. A business that wants to be removed from the directory can contact privacy@askadelie.com; removal excludes the business from all directory results and from any further research, permanently.
Special-category data
Wedding planning can involve special-category data (Article 9) — for example dietary needs, accessibility requirements, or religious and cultural ceremony details. Adélie extracts and saves these details only with your explicit opt-in consent; the opt-in is off by default and offered at onboarding. You can grant or withdraw this consent at any time in Account settings. Withdrawing consent stops future extraction and saving of special-category details; details already saved are not deleted automatically — use the Delete my data control in Account settings to request full erasure (see Your rights). We keep these details out of logs and telemetry.
Retention
We retain your data for the life of your account and delete it on request or on account deletion (see Your rights). Operational logs and queue payloads are short-lived.
Subprocessors
We share data with the following subprocessors, each under a data-processing agreement:
- Anthropic — AI model provider (drafting, extraction over email). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- OpenAI — AI model provider (embedding of vendor-email content for RAG chat, via Vercel AI Gateway, zero data retention enforced per-request). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Resend — Inbound + outbound email delivery. United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Clerk — Authentication + organization (wedding workspace) management. United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Neon — Managed Postgres database (couple + vendor data). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Vercel — Application hosting + serverless compute + blob storage + AI Gateway (routes embedding requests to OpenAI). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Upstash — Redis + job queue (QStash) infrastructure. United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- PostHog — Product analytics (consent-gated for EU). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Sentry — Error monitoring (errors-only, PII-scrubbed). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
- Stripe — Billing + payments (Phase D). United States. Transfer basis: EU-US Data Privacy Framework or Standard Contractual Clauses (to be verified, #195).
Cookies and analytics
Non-essential analytics (PostHog) load only after consent for visitors in the EU/EEA; you can change your choice at any time. Errors-only, PII-scrubbed crash monitoring (Sentry) runs under legitimate interest. Server-side product analytics are pseudonymous and cookieless.
We set the following first-party cookies:
- adelie-consent— Stores your analytics consent choice (“accept” or “reject”). Functional. 1-year expiry.
- adelie-region— Stores your detected region (“eu” or “row”) to apply the correct consent rules. Functional. Session expiry.
- adelie-ref — Referral/attribution cookie that records the marketing source (?ref= parameter) when you first visit. Analytics category; set only when analytics consent has been granted. 90-day expiry.
- adelie-signup-tracked — Analytics (once-guard) that prevents the signup analytics event from firing more than once per browser. Set only when analytics consent has been granted. 1-year expiry.
Your rights
You have the right to access, correct, export (portability), and erase your data, to restrict or object to processing, and to withdraw consent — including opting out of analytics — at any time. EU/EEA and UK residents may also lodge a complaint with a supervisory authority (a data protection authority). California residents have the right to know, delete, and opt out of sale/sharing (we do not sell personal data). To exercise any right, contact privacy@askadelie.com, or use the export and delete controls in your account settings.
How third parties exercise their rights
If you are a vendor (or other third party) whose personal data reached Adélie through a couple’s inbox, you can request access or erasure of that data by contacting privacy@askadelie.com; we handle these requests manually.
Changes
We will update this policy as the service evolves and note material changes.