WUMM Privacy Policy
Last updated: September 12, 2026
WUMM ("we", "our") is a wedding planning app for couples, operated by BCD Inc. This policy explains what information we collect, how we use it, and the choices you have.
1. Information We Collect
- Account and sign-in information: email address, display name, profile image, Firebase user ID, and identifiers from the Apple, Google, or Kakao sign-in provider you choose
- Wedding planning, contact, and financial information: couple-link data, checklists, budgets and payment records, schedules and locations, guest names/contact details/RSVP/dietary restrictions/gift amounts, vendor contact details/addresses/costs, and invitation names/event details/bank-account notices
- User content: community posts, comments and images; invitation, thank-you card and guest-gallery photos; receipts, contracts and other uploaded files; reports and feedback
- Automatically collected information: app or installation identifiers and FCM token, app/iOS version and device model, screen and feature interactions, crash and diagnostic data, IP address, and network/browser information
- Public web pages: visits to public pages, including brand, app-download bridge, and invitation pages, generate Cloudflare request logs. On brand and app-download bridge pages, Meta Pixel PageView data may include browser/device information, IP address, and cookies or similar identifiers set by Meta.
2. How We Use Your Information
- Account management and identity verification
- Couple linking and data sharing between partners
- Storing and syncing wedding planning data and providing public invitations and guest galleries
- Providing community features and managing content
- Sending push notifications (Firebase Cloud Messaging)
- App analytics and public-invitation visit or campaign measurement
- Crash diagnostics, security, abuse prevention, and service reliability
- Extracting vendor fields from on-device OCR text through Workers AI
- Handling support requests and feedback
3. Sharing with Third Parties
We do not sell your personal information. We share data only with the service providers below, to operate the app:
- Google Firebase — Auth, Firestore, Storage, Cloud Functions, Analytics, Crashlytics, and Cloud Messaging provide authentication, storage and sync, server processing, analytics, crash diagnostics, and push notifications. Account data, user content, usage/device identifiers, and diagnostics are processed as needed for those features.
- Apple and Google — authenticate the social sign-in method you choose and process the provider identifier and any name, email, or profile information you authorize.
- Kakao — provides the Kakao sign-in method you choose and the place/address search API. Kakao processes the provider identifier and any name, email, or profile information you authorize for sign-in. For place/address searches, the search terms you enter and network request metadata accompanying the API request are sent to Kakao, which returns place names, addresses, and coordinates.
- Cloudflare Workers, R2, and Workers AI — host public invitation pages, store owner and guest photos, validate Firebase tokens, and extract vendor fields from receipt/contract text recognized on the device. Photos, recognized OCR text, IP addresses, and request metadata are processed as applicable. For place search, the Firebase UID is used only within Cloudflare for authentication and per-user rate limiting and is not sent to Kakao.
- Slack — receives in-app feedback and operational alerts for new fatal and non-fatal Crashlytics issues. Feedback includes the message, a one-way hashed user reference, app/iOS version, and device model; it does not include the user's email or display name. Issue alerts may include the platform, issue title or subtitle, app version, and a Firebase Console link.
- Meta Pixel — measures PageView and visit/campaign performance on public brand and app-download bridge pages. Meta may process browser/device information, IP addresses, and cookies or similar identifiers under its own policy.
Upcoming advertising feature
Starting with iOS 2.2.4 and Android 2.2.8, the home-screen banner uses Google AdMob and the User Messaging Platform (UMP). Ads are displayed depending on consent status, app usage conditions, and ad availability.
Google may process IP addresses (which may estimate approximate location), advertising/app/device identifiers, ad impressions and clicks, other interactions, device information, and diagnostics for advertising, analytics, and fraud prevention. WUMM does not put budgets, guest contacts, couple codes, invitation content, or uploaded documents into ad requests.
We display consent messages where required and request ads only when UMP permits requests. When a privacy-options entry is required, you can change your choices through Advertising privacy choices in Settings. Android advertising IDs can also be reset or deleted in device settings. We do not request iOS tracking authorization to access IDFA.
Google advertising policies and controls · Google Privacy Policy
4. Data Retention and Deletion
- When account deletion completes, we delete the account/profile, community posts, comments, and images authored by the departing user, shared files and photos uploaded by that user, and wedding-planning data for a couple with no remaining partner, except for minimum records required for law, security, or dispute resolution.
- If a linked partner remains, shared wedding-planning records may remain available to that partner. We replace the departing user's creator or uploader identifiers in retained joint records with a de-identified value and clear items assigned to that user. We also remove that user's identifiers and name from likes, views, and structured mentions in other users' community content, and remove the account link and access.
- After server data and external-storage deletion and de-identification succeed, the server deletes the Firebase Authentication account as its final server-side step. The callable reports success only after that deletion is confirmed. After confirmed success, the app only signs out locally. If an external-file or finalization step fails, the callable does not report success and the user can retry.
- At account deletion, we retain only a server-only Firebase UID deletion lock to prevent stale Firebase ID tokens from recreating the profile. It contains no profile or content fields, expires after 24 hours, and Firestore TTL normally removes the document within roughly another 24 hours.
- A retired public invitation URL slug is retained as a tombstone to prevent that URL from being reused. Invitation, couple, and account IDs are removed from the tombstone.
- Hashed slug-conflict diagnostic records that contain no raw identifiers are deleted after 30 days.
- Invitation cover, invitation-gallery, and thank-you-card photos uploaded by the invitation owner are scheduled for deletion seven days after the wedding, after a notice on day four.
- Guest-gallery photos are scheduled for deletion 31 days after the wedding.
- An invitation and guest gallery without a wedding date are retained until 180 days have passed since the latest invitation edit or guest-photo upload. We then notify the owner and allow at least three days before deleting both owner and guest photos and disabling the guest gallery. Invitation or gallery activity after notice, or setting or moving the wedding date, cancels the stale-inactivity notice and recalculates the retention schedule.
- Limited backups or security logs may remain under the operational or legal retention periods of Firebase, Cloudflare, Slack, and Meta.
5. Your Rights and Choices
- You may request access to, correction of, or deletion of your personal information
- You can edit your name and delete your account in the app's Settings
- You can turn push notifications off in iOS Settings and disable calendar sync in the app or revoke calendar access in iOS Settings.
- You may revoke Apple, Google, or Kakao access in the provider's settings. You must separately delete your WUMM account to delete WUMM-held data.
- You can limit Meta Pixel on public brand and app-download bridge pages through browser tracking protection or third-party cookie blocking.
- You may withdraw consent for optional processing or make additional privacy requests through the in-app Feedback menu. Withdrawing processing required to operate the account may require account deletion.
- Depending on where you live (for example, California), you may have additional rights under local privacy laws, including the right to know what personal information we collect and the right to request its deletion. We honor these requests for all users.
6. Children's Privacy
- WUMM is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.
7. Contact Us
- Company: BCD Inc.
- Contact: through the Feedback menu in the app
8. Changes to This Policy
- If we change this policy, we will notify you in the app or by email