How we handle your data

Effective 2026-05-13 · last updated 2026-08-04 · subject to RA 10173 (Philippines Data Privacy Act)

Data Protection Officer

Setnayan’s Data Protection Officer is reachable at iscasasolaii@gmail.com. Reach the DPO for requests under RA 10173 (access, correction, blocking, erasure, complaints, NPC inquiries). We respond within 15 business days.

Regulatory posture

Setnayan is operated by SETNAYAN SOFTWARE DEVELOPMENT SERVICE, a sole proprietorship registered with the Department of Trade and Industry under that business name (registered 2026-06-25, national scope). Because a sole proprietorship has no legal personality separate from its proprietor, the Personal Information Controller under RA 10173 is the proprietor, who also holds the Data Protection Officer function directly and is reachable at iscasasolaii@gmail.com. BIR registration is under the proprietor’s existing TIN. NPC registration will be filed under this business name.

Cross-border data transfers — Singapore (Supabase, our database, which is also where any biometric face vector is stored), the APAC region (Cloudflare R2, our media storage, which holds photos, videos, and the selfie image you upload if you enrol a face), United States (Anthropic Console for Setnayan AI), and United States (Google LLC, when you connect the optional Google Drive or YouTube integrations) — are subject to RA 10173 § 21 and the provider’s adequacy commitments. We do not run servers of our own; every location above is a third-party provider, and none of them is in the Philippines — no Setnayan data is stored on Philippine soil. Third-party identity-verification providers (such as Persona, Veriff, or Onfido) are not currently active — the integration is a stub with no personal data flowing to them; we will update this policy before any such provider begins processing your data.

Self-declared information (and what we verify)

Setnayan is a self-service platform, and most of what we hold about an account is self-declared — you provide your profile, your event details, the vendors you name, and your story yourself. We do not require a government ID and do not independently verify that this information is accurate; you control it and are responsible for keeping it correct. You can view, correct, or delete it at any time from your profile or the relevant event page.

We verify identity only where this notice says so. The main case is vendor identity verification: a vendor shown as verified has had that credential checked separately. (Third-party identity-verification providers are not yet active — see “Regulatory posture” above.)

Where content involves other people — for example a photo, likeness, or detail you upload about a guest or a third party — we rely on the uploader’s confirmation that they have the right to share it, together with the event’s own consent controls (such as guest photo consent and couple approval for any public showcase, described below). This does not change the separate, explicit consent we require before processing biometric face data or other sensitive personal information covered in their own sections.

What we collect

  • Account info — email, password (hashed), display name, optional phone + profile photo URL
  • Event data you create — guest lists, vendor records, budget items, schedule, mood-board palettes
  • Messages you send via the in-app chat
  • Payment metadata — order amounts, reference codes, channel, your screenshot if you upload one
  • Anonymized product analytics — page views, button clicks, funnel events (via PostHog · no personal identifiers · opt-out available in your profile)
  • Error reports — uncaught exceptions + their stack traces sent to Sentry so we can fix bugs; no message bodies, payment details, or guest data are included
  • Automatic — IP address (truncated to first 3 octets for QR scan events), browser user-agent, timestamps

Device identifier (fraud prevention)

To keep our marketplace safe from fake accounts and coordinated abuse, we may record a hashed identifier for the device you sign in from — a random value stored in your browser, one-way hashed on our servers (we never store the raw value). Where active, we use it only to detect fraud and duplicate/sock-puppet accounts.

  • It is not a behavioral or biometric fingerprint and uses no third-party tracking service — it identifies a browser, not your activity.
  • We never use it for advertising, personalization, or tracking you across other websites, and we never sell or share it.
  • Legal basis: our legitimate interest in preventing fraud and protecting our vendors (RA 10173 § 12). The hash is pseudonymous, included in your data export, and deleted when you delete your account.

Biometric data (facial recognition)

Certain optional features — such as automatically matching you to event photos so your tagged pictures reach you — can process facial-geometry data derived from a selfie you choose to provide (a “face vector”, a mathematical representation of facial features). You might be offered enrollment when you RSVP, from a guest photo page during the event, or at an on-site check-in — and it is always your choice. We process this sensitive personal information only:

  • with your explicit, opt-in consent, recorded with a timestamp when you enroll;
  • for adults 18 and older only (enrollment is not offered to minors); and
  • scoped to a single event — your face vector is never reused across events and never sold or shared for advertising.

You may withdraw consent at any time, which permanently deletes your face vector and enrolled selfie. If you never enroll a selfie, we collect no biometric data about you.

A single, account-wide face profile that would carry across your events is not active — it is turned off pending our Data Protection Officer’s review. Until it is enabled and separately disclosed here, all face matching stays scoped to the one event you consented to.

Optional personalization & family details

Some Setnayan features let you add details that are optional and that you choose to provide. Several of these are sensitive personal information under RA 10173, so we process them only with your consent, record a timestamp when you provide them, and let you remove them at any time. You never have to provide any of these to use Setnayan.

  • Profile personalization — your religion, civil status, and gender, if you add them, so we can tailor suggestions and salutations. Reference-only and always optional.
  • Family details — dependents (which may include a child’s name, birth date, sex, and religion) and godparents (name and email), if you choose to track family milestones such as upcoming christenings or godchild reminders. Data about a minor is provided by you as the responsible adult, on that basis.
  • Event honoree details — for some event types (for example a christening or a gender reveal) the person the event is for is not the account holder; the details you enter about them — which may include the celebrant’s first name (“Para kanino?”), a child’s birth date and gender, or an expected due date — are stored as part of your event. The celebrant’s first name is used only to keep their celebrations organized; it is never shown on public pages or to vendors.
  • Guest RSVP details — when your guests reply we store what the event needs, which may include meal or dietary preferences. Because dietary information can imply health or religious observance, we treat it as sensitive and use it only to run your event.

You can view, correct, or delete any of these from your profile or the relevant event page; removing them deletes the underlying data.

Your connection tree (limited pilot)

Setnayan is piloting a connection tree — a record of how the people around an event are related. It has three layers: family, ritual (ninong and ninang), and friends. It is entirely optional, and you never have to add anyone to use Setnayan.

  • Nothing is recorded about someone without an account. During the pilot a connection can only be stored when both people have a Setnayan account. That way both of you can see it, answer it, and delete it. You cannot add someone who has not signed up.
  • The other person has to agree. When you say how you are related to someone, that stays a request until they confirm it. Until then it counts as nothing, and it is not shown as a relationship anywhere.
  • Only the person a claim is about can answer it. You cannot confirm a connection you proposed yourself — that is enforced by the database, not just by the interface.
  • Drafts are private to you. If you are still working out your tree, a draft is visible only to you. The other person is never shown a claim you have not sent.
  • Requests do not linger. A request nobody answers, and a connection that is declined, are both deleted after 30 days.
  • Wider family words are worked out, not stored. Terms like lolo, lola, tito, tita, pinsan and pamangkin are calculated from the connections you and others have confirmed. We do not keep a separate record of them.

You can remove any connection you created at any time, and either person can decline one. Deleting your account removes your side of every connection.

This feature is a limited pilot while our filing with the National Privacy Commission is being completed. We have kept it deliberately narrow for that reason — both-parties-only, consent before anything counts, and short retention.

Gift-receiving details (Pabuya)

If you set up Pabuya (digital gift-giving), you can display your own gift-receiving details to your guests — for example a GCash, Maya, bank, or PayPal handle and a receiving QR image. This is your own information, shown to your guests at your choice.

Setnayan never holds, moves, or records the transfer of any money. We store only the receiving details you enter so we can display them — there is no wallet, balance, or transaction ledger. You can edit or remove these details at any time, and they are deleted with your event.

Photos and videos — location data and guest capture

When photos and short clips are captured at an event (for example through Papic, our in-app camera feature), the original file can carry the device metadata a camera normally records, which may include the GPS coordinates of where the shot was taken. Originals are stored privately in our object storage for the couple.

We strip location from what leaves the app. When a photo is downloaded or shared out, we remove its EXIF/GPS metadata first so the copy you send does not reveal where it was taken; if that strip cannot complete for a given file, we drop the file rather than release a location-bearing original. (Short video clips are shown and shared as a re-encoded web copy that is produced without the capture device’s location or other embedded metadata; the couple’s own full-resolution clip originals stay private in our storage and keep whatever the camera recorded.)

Guest capture is consent-gated. If you take photos as a guest, a photo only becomes eligible for the couple’s public showcase when two gates are met: you opt in at capture time (off by default, never pre-checked) and the couple approves it. You can leave the opt-in off and still have your photos delivered privately to the couple.

The shared pool: other guests at the same event can see your shots. When the host turns on the shared pool for their event, the photos and clips guests capture there become visible to the other signed-in guests of that same event — not only to the couple, and not to the public or to anyone outside the event. Only the compressed web copies are shared, only after they pass the automatic screening that runs on every capture, and the sharing never crosses events: a pool is scoped to the one celebration. Guests can also link themselves to a photo they appear in. If you would rather your shots went only to the couple, ask the host to leave the shared pool off for their event, or capture without it.

FaceBlock. A guest who does not want to appear on an event’s live photo wall can turn on FaceBlock. We then generate a server-side copy with detected faces blurred into the pixels and only that blurred copy may be projected — the wall fails closed, so if the safe copy is not ready the photo is withheld. You can opt out of the live wall this way at any time.

Live video connections (calls and event cameras)

A few Setnayan features connect two devices directly to each other, so that live audio and video travel between them rather than through us. That is how a voice or video call inside a vendor conversation works; how a camera operator’s phone sends its feed to the couple’s Live Studio control room; how a guest who taps a side camera on an event page receives that angle (the operator’s phone sends it straight to them); and how the live demo on our homepage works.

A direct connection means each device learns the other’s IP address. An IP address is the number your internet provider gives your connection so that other computers know where to send data — it broadly indicates your provider and general area, not your street address. Two devices cannot send video straight to each other without each knowing where to send it, so on a direct connection the other person’s device receives your IP address and yours receives theirs. This is inherent to how direct video connections work everywhere on the internet; it is not something we add, and not something we can switch off while still offering the feature. Your device also briefly contacts a public address-discovery (STUN) server run by Google or Cloudflare to learn which address to advertise.

We do not store these addresses. To introduce the two devices to each other, Setnayan carries the setup messages between them, and those messages contain the candidate addresses — so the addresses do pass through our infrastructure in transit. We do not write them to our database, keep them in a log, or use them for anything else. What we do keep for each connection is whether it ended up direct or relayed and the general type of network path it used, so that we can size the relay costs described below; that record contains no IP address and none of the audio or video.

When a direct connection is not possible, media is relayed. Some networks — Philippine mobile data and shared venue or guest Wi-Fi especially — will not let two devices reach each other directly. Those connections instead route the audio and video through a relay server operated by Cloudflare, using short-lived credentials we issue for that one connection. The relay is transit, not storage: it forwards the stream, and Setnayan keeps none of it. On a relayed connection the two devices see the relay instead of each other.

Tapping a side camera creates a session for you. If you choose a side camera on an event page while signed out, we create an anonymous sign-in for your browser at that moment — a session identifier with no name, email, or password attached — because the connection can only be set up under a signed-in session. We create it only when you actually tap a camera, never merely for visiting the page.

Calls are never recorded. Setnayan does not record, store, or listen to the audio or video of a call. On a direct connection the media never touches our infrastructure at all; on a relayed connection it passes through the Cloudflare relay described above in transit only, and is not retained there or by us. We keep only the fact that a call took place on a conversation: who started it, whether it was voice or video, when it began, and when it ended.

Featuring your event on Setnayan’s own social channels

Setnayan may feature finished work from real events — such as a published event recap, or a consented artifact like an animated monogram, save-the-date, event website, or personal reel — on Setnayan’s own social channels (for example our Facebook, Instagram, or TikTok) to showcase what the platform makes. This is optional and governed by consent:

  • Per-artifact consent. A specific artifact is only eligible after you grant consent for that item, and you choose how you are credited — by first names only, or fully anonymously. You can revoke a consent at any time.
  • Recap re-posts are opt-out. For the automatic re-post of a published recap, we honor a one-tap opt-out on your recap manager; a recap is never composed for our social queue when you have opted out, and it is never posted at all if your event page is private.
  • After the event only. Featuring happens only after your event has taken place — never before or during it.
  • We never post your guest list, RSVP data, budget, chat history, or raw photo feed, and we never sell these artifacts.

Minors, dependents, and religious information

Where you optionally provide family details (see “Optional personalization & family details” above) — including a dependent’s information or a religion — we collect it only with your consent, as the responsible adult, and use it solely to run your events and reminders. Some of these features are still gated and not enabled by default. We never surface a minor’s details or anyone’s religion on a public page, in search, or in any social feature.

Samahan (groups)

You can create or join a samahan — a group you and your people name yourselves (a barkada, a clan, an org, anything). For each samahan we store only the group’s chosen name, an optional description, your role (organizer or member), and when you joined. We do not classify or categorize groups — the name is yours, and we attach no type, affiliation, or category to it. Your display name is visible to fellow members of the same samahan (that’s what a group is), and never to anyone outside it. Your memberships are included in your data export and are removed when you leave a group or delete your account.

What we do not collect

  • Precise location for advertising, profiling, or cross-site tracking (photo/clip GPS is described above and stripped from outbound shares)
  • Advertising identifiers, third-party cookies, or cross-site tracking signals
  • Stored IP addresses from live calls and camera feeds — the two devices exchange these to connect, and they pass through our signaling in transit, but we never log or keep them (explained under “Live video connections” above)

Vendor identity masking

When you chat with a Setnayan vendor, the vendor sees only your event display name and date — never your email or personal name unless you choose to share. This is a load-bearing product rule.

Vendor interest counts (what other couples can see)

When you save a vendor to your plan, or send that vendor an inquiry, for an event on a specific date, that action is counted toward an aggregate, de-identified number — how many other couples are interested in that vendor on that same date. Other couples planning that date can see that number next to the vendor.

What is shared is the count, and only the count. Never your name, your account, your email, your event, your budget, your guest list, or any contact detail; never which couples they are; and never anything that would let another couple work out who you are. The count is computed on our servers from data no couple can read directly, and only the final number reaches the page. Vendors are not shown this count either.

Small numbers are suppressed. In the Marketplace’s “In demand right now” ranking, the number is only sourced from couples who actually inquired with the vendor (not from couples who merely saved them), and it is not shown at all unless at least three other couples have inquired for your date — so one couple’s planning is never exposed on its own. The count is also exact-date only: if your date is still a month or a year rather than a day, no count is computed and none is shown.

We never present this number as scarcity. Setnayan does not tell you a vendor is “almost gone” or that there are “only N slots left” — we do not hold a live capacity count, so any such claim would be invented.

You cannot switch this one off. There is no setting that removes your own inquiry from the counts other couples see. We are telling you plainly rather than leaving it unsaid: what leaves our servers is a number, at three or above, with nothing attached to it that points back to you — that is the protection, and it is the reason we consider the trade a fair one. If you would rather not be counted at all, not sending the inquiry is the only way.

Coordinators you invite (delegated access)

You can invite a coordinator to help plan your event. A coordinator is someone on your side — a planner, a family member, a friend — not a Setnayan employee. Before they get any access, they accept a consent screen that names exactly what they will be able to see and do: your guest list, seating, schedule, and your chats with vendors.

Two abilities are off by default and only turn on if you explicitly grant them: “Can finalize vendors” (lock in a vendor choice for you) and “Can handle payments” (complete an apply-then-pay checkout on your behalf). Even with the payments scope, Setnayan never holds, moves, or records the transfer of any money — the coordinator only prepares the same off-platform payment you would, and settlement happens directly between you and the vendor.

A coordinator can also draft schedule items privately and release them to you when ready; drafts stay hidden from you, your guests, and your vendors until the coordinator releases them.

On the day, a coordinator can post announcements your guests see. A day-of announcement (“dinner is moving up fifteen minutes”) is a short message, capped at 500 characters, that goes to everyone on that event — you, your guests, and your vendors — and it cannot be edited or unsent once posted. Only you and a coordinator you invited can write one, and every message records who sent it. Announcements never leave the event they belong to.

They also run a day-of requests desk. Requests raised during the event — a vendor asking for something, a change of plan on the floor — collect in one list the coordinator works through. It holds what a person wrote into the request and who raised it, stays scoped to that one event, and is deleted with it.

Lawful basis & your control. We process this on your consent (captured on that invite screen) and the planning contract (RA 10173 § 12(a) and § 12(b)). You can narrow or revoke a coordinator’s access at any time, and revoking it takes effect going forward. Objections go to our Help Center or our Data Protection Officer (above).

What we do not do here: a coordinator never receives your face or biometric data, and their access is scoped to the one event you invited them to — never across your other events.

Vendor AI assistant (automated replies)

A vendor may turn on a paid Vendor AI assistant for their own shop. When they do, it can read the messages in your chat with that vendor and your event brief (event date, guest count, budget per head, and venue) to answer common questions — and, if the vendor allows it, accept a booking request — automatically, on that vendor’s behalf.

You always see an automated message labelled “⚡ AI auto-reply”, so you know a person didn’t type it. The assistant is deterministic — it follows fixed rules and never invents answers or commitments — and it is single-tenant: it only ever acts for the one vendor whose chat it is in, and never reads across vendors or across your events.

Lawful basis & your rights. We process these messages on the basis of your own act of messaging that vendor (consent) and the couple–vendor relationship (contract). Because a machine, not a person, is replying, RA 10173 § 34 (automated processing) and § 16(c) (right to object) apply: you can always reach a human — every message you send still goes to the vendor, and nothing is hidden from them — and you may object through our Help Center or our Data Protection Officer (above).

What we do not do here: we never feed sensitive personal information — religion, civil status, family or dependent details, or biometric/face data — into the assistant, and it never has access to your guest list.

Vendor Deep Search (vendor business research)

Vendors can run Deep Search, a paid tool that uses AI to research their own business across public web sources — their own website, directory listings, and review sites — and builds a short summary the vendor reviews to fill in their Setnayan profile.

This is about the vendor’s business information. The research runs through Anthropic’s AI web search (United States; see Subprocessors below). We never send your guest list, your messages, or your personal data into it. Public pages the tool reads may incidentally mention other people (for example, the name on a public review); we keep only a structured business summary, not the raw pages, and delete it on a rolling 180-day basis.

Lawful basis. The vendor initiates it about their own business (consent + contract); for any incidental, already-public third-party content we rely on legitimate interest (RA 10173 § 12(f)), minimised to a business summary and short retention.

Anti-fraud & trust integrity

To keep our marketplace signals honest — reviews, ratings, badges, and “most-booked” counts — we run automated checks that detect and prevent manipulation, such as fake or duplicate accounts created to inflate a vendor’s reputation. To spot rings of accounts controlled by one person or household, we analyze signals we already hold (device and browser signals, the address on your account, and the payment-sender identity on your transactions) so duplicate reviews and bookings are counted once, not many times.

Lawful basis. We rely on legitimate interest (RA 10173 § 12(f)) — preventing fraud and protecting the integrity of the marketplace for couples and honest vendors. We use only data we have already collected for other purposes; there is no new collection for this.

Automated decisions & your right to object. At a high fraud-risk score a vendor’s listing may be automatically and reversibly hidden while we review — no data is deleted, and one review by our team reverses it. Permanent action (removing a vendor’s reviews or banning an account) is never automatic; it requires two separate team members to confirm. If you are a vendor affected by an automated suspension or enforcement action, you may object and request a review through our Help Center or by contacting our Data Protection Officer (above). These rights are under RA 10173 § 16(c) (right to object) and § 34 (automated processing).

What we do not do here:

  • We do not capture or use your IP address for this.
  • These groupings, signals, and scores are strictly internal — no couple or vendor can view them, and they are never sold, shared, used for advertising, or used to rank or promote vendors.
  • The evidence we store is non-identifying — counts and ratios, not your name, address, or raw identifiers.

Storyteller chapters — inquiry referrals and source labels

When you contact a vendor after tapping “Book through this chapter” on a storyteller’s public chapter, we record which chapter referred your inquiry so the vendor can honor the promo that chapter advertised and the storyteller’s public profile can show an aggregate count of inquiries their chapters have driven. We also label each inquiry with how it reached the vendor (for example: their website, a Setnayan recommendation, a storyteller chapter, an editorial feature, or a returning customer). These labels and the referral are visible only to you and the vendor on your conversation — they are never public. The only public figure derived from them is the storyteller’s aggregate “inquiries driven” number, which never identifies you, your event, or your conversation. Any discount is offered and settled by the vendor directly; Setnayan never handles the money.

Public Event Summary (post-event editorial)

If a host opts in, the event’s summary page at setnayan.com/{event-slug} transitions from invitation and day-of mode into a public editorial article 30 days after the event date. The page becomes publicly indexable on setnayan.com/realstories and discoverable by search engines.

Eight safeguards apply under RA 10173 § 16(e) right to object:

  1. Onboarding-time consent during signup with explicit T+30d disclosure.
  2. Phase 4 starts at T+1d in archive mode (public via slug only).
  3. Index inclusion auto-activates at T+30d unless the host opts out.
  4. Reminder email at T+27d (“Your wedding goes public in 3 days — preview and edit, or keep it private”).
  5. One-click opt-out from /dashboard/{eventId}/privacy removes the page from the index immediately.
  6. Pseudonymization option (full names, initials only, or pseudonym).
  7. Private-always field allowlist — guest list, RSVP data, budget figures, vendor chat history, day-of broadcast video, and raw photo feed never reach the public Summary.
  8. Right to redact any field, photo, vendor credit, or whole page at any time.

Per CLAUDE.md decision-log 2026-05-19 row 426.

Guest-written columns on an event page

If a host turns this on, guests can write a short message — a title and a few sentences — for the event’s page. A column you submit is published on the open web once the couple approves it, alongside a byline drawn from the name on the event’s guest list, and can be read by anyone who opens the page.

Nothing is published automatically. A column starts as a submission only. It reaches the page when two things happen: it passes the automatic screening applied to guest-written content, and the couple approves it. The couple can decline it, with a note back to you, and you can edit and resubmit.

You can take it down. Withdraw your own column at any time and it comes off the page. If your guest record is deleted, or the event is, your column goes with it. We record the moment you agreed to publication when you submit, so consent is never assumed.

How long we keep things

Different kinds of data have different lifespans, and two of them are set by law rather than by us. This is the whole schedule.

  • Photos and video — the full-resolution originals are kept for 6 months from the event’s first photo (never less than 3 months after the event ends), and are then replaced by a compressed copy. That compressed gallery stays online, free, for 5 years — we do not delete your photos. Past 5 years, keeping everything stored with us becomes a paid option; we will tell you the price well before then. If you connect Google Drive, every original is also saved to a folder you own, and that copy is yours to keep for as long as you want it.
  • Face-recognition data — for the one event only, and deleted the moment you withdraw your consent or ask us to remove it. We do not currently put an automatic end date on it beyond that.
  • Messages between a couple and a vendor 5 years after the event date.
  • Payments, receipts and official receipts 10 years. This one is a legal floor under BIR rules: we cannot delete these earlier, even if you ask.
  • Contracts and e-signatures 10 years, the prescription period under the Civil Code.
  • Your account and profile — for as long as the account is open. When you close it, a short 30–90 day tail, then permanent deletion.
  • Support tickets2 years after the ticket closes.
  • Error and usage logs90 days or less, and they carry no personal data by design.
  • The fraud-prevention device identifier — for the life of the account, and device records unused for more than 24 months are pruned.

Where you can end something sooner, you can: withdrawing face recognition deletes that data immediately, withdrawing a column takes it off the page, and closing your account starts the tail above. The two 10-year items are the exception — those we are required to keep.

Your rights (RA 10173)

  • Right to access: download a JSON archive of your data anytime from your profile (served by our /api/profile/export endpoint). The export includes your face-enrollment consent records but not the raw face-vector embeddings themselves.
  • Right to withdraw biometric consent (face-forget): if you enrolled a selfie for photo matching, you can withdraw at any time; we permanently delete your face vector and enrolled selfie.
  • Right to erasure: the same profile page has an account-deletion action (type DELETE to confirm). When you request account deletion, our team reviews and permanently erases your personal data within one business day of the request — except records we are legally required to keep, such as tax and receipt records under BIR rules, which we retain for the required period and then delete. Because deletion is permanent and immediate upon processing, it cannot be undone once completed — please contact iscasasolaii@gmail.com before requesting if you are unsure.
  • Right to rectification: edit your personal info on the profile page.
  • Right to object: reach us at the help center to opt out of specific processing.

TikTok integration (Patiktok)

Couples on the Patiktok Personal tier connect their own TikTok account to Setnayan so Patiktok booth compilations can auto-post to the couple’s handle. Setnayan uses TikTok’s Login Kit and Content Posting API. The Setnayan tier does not require a couple-side TikTok connection — those compilations post to @SetnayanWeddings, our company-owned handle, using credentials Setnayan manages directly.

  • Scopes requested. Only user.info.basic, video.upload, and video.publish. We do not request access to your TikTok followers, drafts, messages, or analytics.
  • What we receive from TikTok. Your TikTok open ID (a stable per-app identifier), your union ID (if available), your display name / handle, an access token (typically valid 24 hours), and a refresh token. We do not receive your TikTok password.
  • How we use it. The access token is read only by our render worker, only to post one rendered compilation MP4 per booth-day on your behalf, with a caption you can configure. We do not browse, download, or modify any other content on your TikTok account.
  • Storage + scope. Tokens and the open ID are stored in patiktok_oauth_grants in our Supabase database (Singapore region · encrypted at rest), scoped to one specific Setnayan event. These credentials are never shared with vendors, other couples, or third parties. (That statement is about your TikTok credentials specifically — it is not a blanket claim that nothing you do on Setnayan is ever visible to another couple. For the one place where your planning activity feeds an anonymous count that other couples can see, see Vendor interest counts above.)
  • Retention. Grants are kept until you revoke them — from your Setnayan profile or from TikTok’s own app settings — or until you delete your Setnayan account. The moment you disconnect, we erase the stored keys rather than merely marking the connection ended. We do not delete connections on a timer: if you want one gone, disconnect it.
  • Revoking access. Two paths, either works immediately:
    • In Setnayan, open the Patiktok page and click Disconnect TikTok. We soft-revoke the grant locally.
    • In TikTok, go to Settings → Privacy → Manage apps and websites and remove Setnayan. We honor the revocation on the next render attempt.
  • Posts on your TikTok account. Once a compilation is posted to your account, the video is owned by you. Delete it from TikTok like any other video — Setnayan cannot delete posts on your behalf after they go live.

Google / YouTube data (Live Studio)

Live Studio is Setnayan’s live-broadcast feature. It is optional and off by default. When a host turns it on for an event, Live Studio uses YouTube API Services to set up and run that event’s live broadcast, and embeds the player on the event page. Single-camera streaming is free for any host; the multi-camera control room is a paid upgrade. Your use of YouTube is also governed by YouTube’s Terms of Service and the Google Privacy Policy.

Whose YouTube channel the broadcast runs on depends on how your event is set up.

  • You connect your own channel. You link your YouTube channel to Setnayan using Google’s standard sign-in, and the broadcast is created on your channel. This is the arrangement everything below describes — and the one you are in if Setnayan ever asked you to sign in to Google.
  • Setnayan supplies the channel. For events where Setnayan provides the channel, the broadcast is created on a YouTube channel Setnayan owns and operates, using a Google connection that belongs to Setnayan. You connect nothing, you are never asked to sign in to Google, and no Google data of yours reaches us at all. What this means for the recording is under “Recordings” below.

When you connect your own YouTube channel

  • The permission we ask for. Exactly one: https://www.googleapis.com/auth/youtube. This is the narrowest permission Google offers that can create and run a live broadcast — the read-only YouTube permission cannot start one, and the two other permissions that could (“force-ssl” and “youtubepartner”) are wider, not narrower. Google describes it broadly, as managing your YouTube account — so the consent screen will tell you it covers more than we use. We ask for nothing else: no permission to upload videos, and no permission to read your Google email address or profile. Connecting YouTube tells us your channel’s ID, name, and picture. It does not tell us your Gmail address.
  • What we actually do with it. Six things, and nothing else: (a) read which channel you connected, so we can show you it is linked; (b) create the live broadcast for your event; (c) create the streaming slot it receives video on; (d) link those two together; (e) start the broadcast, check that video is arriving, and end it; and (f) afterwards, look up the replay of the broadcast we created, by its ID, so your event page can link to it.
  • What we do not do. We do not read, edit, or delete any other video on your channel. We do not read your subscribers, comments, playlists, watch history, or search history. We do not upload anything to your channel. We do not delete anything from your channel — including the broadcast we created.
  • Setnayan does not send your video to YouTube. Setnayan creates the broadcast and gives you a streaming address and key; your own streaming software sends the video to YouTube. No ceremony video passes through Setnayan on its way to your channel.
  • The broadcast is unlisted. Every broadcast we create is set to unlisted — it does not appear in YouTube search or on a channel’s public video list. Anyone who has the link, or your event page, can watch it. It is embedded on your event page using YouTube’s privacy-enhanced player, which sets no tracking cookies until someone presses play.
  • What we receive and store. A refresh token and a short-lived access token for the connection, the permission Google granted, your channel’s ID, name and picture, which Setnayan account completed the connection, and the IDs of the broadcasts we created. We never receive your Google password.
  • Where it is stored, and who can read it. In our Supabase database in Singapore, encrypted at rest by our hosting provider. The credential is readable only by our servers — it is never sent to any browser, including yours, and the database blocks browser-level accounts from reading it at all. No Setnayan screen displays it to our staff. Access to the underlying database is limited to the small team that operates Setnayan. A person only ever looks at your Google connection data where it is necessary for security purposes, to comply with applicable law, or where you have asked us to investigate a specific problem with your broadcast. Your streaming key is shown to you only when you ask to see it, and is never published on your event page.
  • How long we keep it. Until you disconnect it, until you delete your Setnayan account, or until you ask us to remove it. We keep the connection alive in the background — refreshing the access token automatically, including outside your event window — so it still works on the day and so we can resolve your replay afterwards. We do not currently delete the connection on an automatic timer after the event. If you ask us to delete the Google data we hold about you, we will do so within 30 days.
  • If you revoke access at Google. Our side notices on the next attempt and stops using the connection. Setnayan will show you that the connection needs reconnecting rather than behaving as though it still works.
  • How to disconnect. Two ways, either works:
    • In Setnayan, open the Live Studio page and click Disconnect YouTube. We mark the connection revoked so Setnayan stops using it, and we ask Google to cancel our access. That second step is best-effort — if the call to Google does not go through, we still stop using the connection on our side. If you want to be certain the access is gone at Google as well, remove Setnayan from your Google account permissions too.
    • In your Google account, go to Security → Third-party apps with account access and remove Setnayan.
  • If you delete your Setnayan account. We delete the Google connections our records attribute to your account. Where a connection was recorded before we started capturing which partner completed it, we leave it in place rather than risk deleting your partner’s credential — ask us and we will remove it. Deleting your account does not, by itself, call Google’s revoke endpoint, so if you want the access cancelled at Google too, remove Setnayan from your Google account permissions. Records of the broadcasts we created (their YouTube video IDs, timings, and streaming keys) are not removed by account deletion today; ask us and we will delete them.

Recordings

  • Setnayan does not keep its own copy of your broadcast. YouTube archives it, and Setnayan links to it.
  • If the broadcast ran on your own channel, the recording is yours. Edit or delete it in YouTube Studio like any other video. Setnayan does not delete or edit videos on your channel.
  • If the broadcast ran on a Setnayan channel, the recording is an unlisted video on a YouTube channel Setnayan owns. Setnayan keeps it and can remove it; you will not have YouTube Studio access to it. Setnayan gives you the watch link from your dashboard. Ask us and we will delete it.
  • Setnayan never deletes anything on YouTube automatically. Nothing disappears because an event ended.

Sharing, advertising, and AI. Setnayan’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell YouTube data, do not transfer it to anyone other than Google, do not send it to advertising networks or data brokers, do not use it for advertising or personalisation, and do not use it to train AI or machine-learning models. Your connection credential and your channel details are not shared with vendors, other couples, or any other Setnayan user. The one thing that is published is the broadcast itself — its link is embedded on your event page, which is public, so anyone with that page or the link can watch. That is what the feature is for, and you control it by choosing whether to go live. (This paragraph is about your YouTube connection, not about everything you do on Setnayan — your vendor shortlisting also feeds an anonymous count other couples can see, described under Vendor interest counts above.)

Setnayan’s Google Drive integration (Photo Delivery and Papic) is a separate connection, with a separate permission and separate credentials that never mix with this one. See the Google Drive section below.

Facebook Live. A host may also publish a Facebook Live link alongside the YouTube player on their event page. For this, Setnayan uses no Meta credentials of yours or of ours: the host pastes in a link they created themselves on their own Facebook account. Setnayan sends no video to Meta and receives no data back from Meta for your broadcast. Meta, not Setnayan, controls how long that replay lasts. (Separately, Setnayan does hold a credential for its own Facebook and Instagram pages — that is only for posting Setnayan’s own marketing, and is covered under “Featuring your event on Setnayan’s own social channels” above.)

Google Drive integration (Photo Delivery + Papic)

Couples who use Photo Delivery (vendor-released final wedding photos) or Papic (the V1.5+ camera mesh) connect a Google Drive account so Setnayan can write photos and videos into that Drive on the couple’s behalf. The connection uses Google’s standard OAuth sign-in. You can revoke it at any time from your Google Account permissions.

  • Scope requested. Only .../auth/drive.file — a narrow scope that restricts Setnayan to ONLY files and folders the Setnayan app itself creates in the Drive. We cannot see, read, edit, or delete any other files, folders, photos, or documents you already have in the Drive. We also never request .../auth/drive (full Drive access), .../auth/drive.readonly, or any other Drive scope.
  • What we receive from Google. A refresh token tied to the connected Drive account, the email address used to sign in, an access token (typically valid 1 hour), and the file/folder IDs of the items Setnayan creates. We do not receive your Google password and do not enumerate or index your existing Drive contents.
  • How we use it. For Photo Delivery (0009), we create one folder per event named after the wedding (for example, “Setnayan · Maria & Juan Wedding · 2026-10-24”) and the vendor’s release action writes the finalized photo set into that folder. For Papic (V1.5+), the camera-mesh capture pipeline writes event-day photos into a bootstrapped folder structure inside the same Drive. We never browse, modify, or delete any file we did not create.
  • Storage + scope. Tokens and the connected email + folder IDs are stored in oauth_grants in our Supabase database (Singapore region · encrypted at rest), scoped to one specific Setnayan event. These credentials are never shared with vendors, other couples, or third parties. (That statement is about your Google Drive credentials specifically — it is not a blanket claim that nothing you do on Setnayan is ever visible to another couple. See Vendor interest counts above for the one place where your planning activity feeds an anonymous count.)
  • Limited Use commitment. Setnayan’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never use your Drive data for advertising, never sell or transfer it, and never use it to train AI or ML models.
  • Retention. Grants are kept until you revoke them — from your Google account or from your Setnayan profile — or until you delete your Setnayan account. The moment you disconnect, we erase the stored keys rather than merely marking the connection ended. We do not delete connections on a timer: if you want one gone, disconnect it. The files Setnayan wrote to your Drive are not deleted by Setnayan when the grant ends — they remain in your Drive under your sole control.
  • Revoking access. Two paths, either works immediately:
    • In Setnayan, open the Photo Delivery or Papic page for your event and click Disconnect Google Drive. We soft-revoke the grant locally.
    • In your Google account, go to Security → Third-party apps with account access and remove Setnayan. We honor the revocation on the next write attempt.
  • Files in your Drive. Once a file is written to your Drive, it is owned by the Drive account that authorized the grant. Move, share, or delete it from drive.google.com like any other file — Setnayan cannot delete files on your behalf after the grant is revoked. Your use of Google Drive is also governed by the Google Privacy Policy.

Subprocessors

  • Supabase (database + auth · Singapore region)
  • Vercel (web hosting)
  • Cloudflare (CDN + R2 object storage · APAC region; also the relay server that carries live call and camera video when a direct connection is not possible — transit only, nothing stored)
  • Resend (transactional email)
  • Sentry (server-side error monitoring · stack traces only)
  • PostHog Cloud (product analytics — opt-out available in your profile)
  • Anthropic (AI features, including AI web research for the vendor Deep Search tool · United States · never trained on your data)
  • Suno (AI music generation for Pakanta and rendered videos · United States · no guest or personal data is sent)
  • Google (YouTube Data API — used for any event broadcast through Live Studio, under either the couple’s own connected channel or a Setnayan-held connection where Setnayan supplies the channel; Google Drive API — only for couples who use Photo Delivery or Papic and explicitly connect a Drive account via OAuth; Google’s public STUN server — contacted briefly by your device when starting a live call or camera connection, to discover its own network address)
  • TikTok (Personal-tier Patiktok only · for couples who explicitly connect their TikTok account via OAuth)

Contact

For privacy questions or RA 10173 requests, message us via the help center with subject “Privacy”. We’ll respond within 15 business days (usually much sooner).