I Do · Legal

Privacy Policy

Last updated: July 2026

SR Studio Apps Ltd (“we”, “us”), trading as I Do, operates the wedding planning application accessible at say-ido.co.uk and via our mobile web app (together, the “Service”). This policy explains what personal data we collect, how we use it, and your rights.

By using the Service you agree to this policy. If you do not agree, please do not use the Service.

01

Who we are

SR Studio Apps Ltd, a company registered in England and Wales (company number 17330448), trading as “I Do”. We are the data controller for personal data processed through the Service.

Contact us at any time: privacy@say-ido.co.uk

02

What data we collect

We collect the following categories of personal data:

Account data

Your email address and authentication credentials, provided when you create an account. We use Firebase Authentication to manage sign-in securely.

Wedding planning data

Information you enter into the Service, including your name, your partner’s name, wedding date, venue, supplier details and their contact information, guest list, budget, planning sessions, mood board, and any documents you share with Iris.

This data is held in two places. It is stored in Firestore (Google Cloud), which is the live working store that keeps the Service responsive and keeps you and your partner in sync. If you connect Google Drive, a durable copy of your core planning record — your budget, guests, planning sessions, mood board, suppliers, and couple details — is also written to the Iris HQ folder in your own Google Drive, which you own and control. If you do not connect Drive, your data remains in Firestore only.

Guest data

To help you plan, we hold information about your wedding guests — names, contact details, RSVP responses, and, where guests provide them, dietary requirements, allergies, and accessibility needs. Some of this may constitute health-related information.

Guests provide this directly when they reply to your invitation, or you enter it on their behalf. We process it only to produce your guest list, seating plan, and catering summaries. We do not use it for any other purpose, we never share it with third parties beyond the processors listed in Section 10, and we never contact your guests for our own purposes. A guest may exercise any of the rights in Section 9 by contacting us directly.

Email you send to your wedding address

Your wedding is given its own private email address at say-ido.co.uk, unique to you and shared with your partner. Nothing reaches Iris unless you send it there — by copying her into a supplier thread, by forwarding a thread that already exists, or by setting a rule in your own mail client that redirects supplier messages to that address. We hold no permission to read your mailbox, and we never have. Iris is simply a recipient, exactly as a human planner would be.

When mail arrives at that address we process and store its contents: the message body, the subject, the sender’s name and email address, and any attachments. Attachments are held briefly by Cloudflare while they are processed, and then filed into your Iris HQ folder if you have Drive connected. We use this to build your supplier threads, to extract quotes, contracts, prices and dates, and to draft replies for you.

This means we hold personal data about your suppliers, who are not our users. We process it only to run your wedding admin. We never contact them for our own purposes, we never use it for marketing, and we never share it beyond the processors listed in Section 10. A supplier may exercise any of the rights in Section 9 by contacting us directly.

Replies Iris drafts for you

Iris drafts replies to your suppliers in your own voice. Opening a draft opens a compose window in your own mail app with the message already written — you read it, change whatever you like, and send it yourself. We hold no permission to send email on your behalf, and the Service never sends mail as you. Because it goes from your own account, it lands in your own Sent folder and the supplier replies to you.

Google account data (only if you connect Google services)

Connecting Google services is entirely optional. The Service works without it. If you choose to connect, we request the following, and nothing more:

We hold no permission to read your email. Your wedding has its own email address; mail reaches Iris only because you send it to her — by copying her in on a supplier thread, forwarding a thread that already exists, or setting your own mail client to redirect supplier messages to that address. We never hold a key to your inbox.

We store an encrypted OAuth refresh token in our secure database so the Drive and Calendar integrations persist across sessions. Tokens are encrypted at rest using AES-256-GCM and are never transmitted to third parties.

Where you plan your wedding with a partner, one Google connection is shared between you both, so that the Service holds a single record of your wedding rather than two divergent ones. Either of you may disconnect it at any time.

Documents you share with Iris

When you share a document (an invoice, quote, or contract) with Iris via the app or via your phone’s share sheet, its content is sent to Google Gemini for structured extraction. Gemini returns structured data — supplier name, amount, date — which we store in your account. The document itself is stored in your Iris HQ Drive folder if you have Drive connected.

Payment data

If you purchase a subscription or pass, payment is processed by Stripe. We never see or store your card details. We hold a record of what you purchased and when.

Usage and technical data

Standard technical data including your browser type, device type, and IP address, collected automatically when you use the Service. We use this for security and to diagnose errors.

03

How we use your data

We use your personal data to:

We do not use your data to serve advertising. We do not sell your data. We do not use your data to train AI models.

04

Legal bases for processing

Under UK GDPR we rely on the following legal bases:

05

Google API services — limited use disclosure

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, in relation to the Drive and Calendar scopes:

You can revoke our access to your Google account at any time by visiting myaccount.google.com/permissions and removing “I Do” from the list of connected apps. Doing so will disconnect these services from the Service but will not delete your I Do account or planning data.

06

AI processing

Iris — our AI wedding planning assistant — is powered by Google Gemini.

We do not use your conversation data, your documents, or your email content to fine-tune or train any AI model.

What Iris remembers, and how

So that Iris does not ask you the same thing twice, the Service keeps a memory of your planning. After a conversation, a short summary of the exchange is written to a private .iris folder inside your Iris HQ folder, in your own Google Drive. Overnight, two automated jobs tidy that memory: one promotes summaries into a longer-term record, and one asks Gemini to look across many conversations at once for through-lines a single exchange cannot show — that you keep returning to a particular idea, or that a decision was reached over several messages rather than announced in one.

Facts produced that way are inferred, not confirmed. They are marked as such, and Iris hedges when she uses them. Anything you tell her directly, or confirm by filing it yourself, is marked confirmed. Where a newer fact contradicts an older one, the older is marked superseded rather than deleted. Low-value inferred material is moved to an archive after eighteen months; decisions and anything you confirmed are never aged out.

These overnight jobs are switched on when you connect Google Drive, and they run only for couples who have connected it. If you never connect Drive, no memory folder is created and these jobs do not run for you. Everything Iris has remembered is a readable file in your own Drive, and you may ask us to correct or delete any of it under Section 9.

07

Data storage and security

Your data is stored in the following systems:

OAuth tokens are encrypted at rest using AES-256-GCM. All data is transmitted over TLS. Access to production systems is restricted.

We follow reasonable security practices but no transmission or storage method is completely secure. If you believe your account has been compromised, contact us immediately at privacy@say-ido.co.uk.

08

Data retention

We retain your account and planning data for as long as your account is active. If you request deletion of your account, we will delete your data from our systems within 30 days, except where we are required to retain it by law.

If you disconnect Google Drive, we delete the stored OAuth refresh token from our systems and, on a best-effort basis, revoke it directly with Google, so that our access ends immediately rather than merely being unused. Your Iris HQ folder remains in your own Google Drive. It is yours; we do not delete it, and you may keep, export, or remove it at any time, independently of us. This is deliberate: your wedding record should outlast your relationship with us.

Email you have sent to your wedding address — the message records, supplier threads, and the data extracted from them — is retained for as long as your account is active, and deleted with it. Attachments staged with Cloudflare are removed once they have been processed and filed.

Guest and supplier data is deleted when the couple’s account is deleted, or sooner on request.

09

Your rights

Under UK GDPR and the Data Protection Act 2018, you — and any guest or supplier whose data we hold — have the right to:

To exercise any of these rights, email privacy@say-ido.co.uk. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data correctly.

10

Third parties

We use the following third-party services to provide the Service:

We do not sell your personal data to any third party. We do not share your data with any third party for their marketing purposes.

11

International transfers

Some of our processors are based outside the UK. Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as appropriate.

12

Cookies

We use cookies and similar technologies for authentication (session tokens) and to remember your preferences. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but some features of the Service may not function correctly without them.

13

Children

The Service is intended for adults aged 18 and over. We do not knowingly collect personal data directly from children under 18. Where a couple includes a child in their guest list, we hold only the information the couple provides for the purposes of seating and catering. If you believe we hold a child’s data inappropriately, contact us and we will delete it promptly.

14

Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service. The date at the top of this page shows when the policy was last updated.

15

Contact

For any privacy-related questions, requests, or complaints:

SR Studio Apps Ltd

Company number 17330448

privacy@say-ido.co.uk