This Privacy Policy ("Policy") explains how AppskKuber ("AppskKuber", "we", "our", "us"), an India-based developer, collects, uses, stores, transfers, shares and protects information when you use the Welvite Android application (package com.appskuber.welvite, the "App"), the invitation pages it publishes at https://invite.welvite.com (the "Pages") and our websites https://welvite.com and https://legal.welvite.com (together, the "Service").

Welvite does one thing: a host types the details of a family function, picks a design, and gets a link to an invitation page that guests open in a browser and reply on. Two kinds of people meet this Policy, and it speaks to both: hosts, who have an account and create invitations, and guests, who have no account and simply open a link. Section 6 is written for guests.

Quick summary. There is no advertising and we never collect an advertising identifier. We never sell personal data. A host’s invitation contains exactly what the host typed and the photos the host chose; it is public to anyone who has the link, and to nobody else. Guests who reply leave a name, an answer and a head count, which only the host sees; we store a truncated one-way hash of the network address to stop duplicate replies, never the address itself. Guest data is deleted together with the page. When a host asks the optional AI feature to write the card text, only the host’s one line, the names on the card, the occasion and the tone go to the model (Google Vertex AI); nothing is used to train it. New photos are screened for unsafe content by Google Cloud Vision at publish time. Everything a host has can be deleted from inside the App in three taps.

If you do not agree with this Policy, please do not use the Service and, if you have an account, delete it as described in Section 13. Using the Service after the Effective Date means you accept this Policy.

1. Definitions

Host
A person who uses the App to create, publish or manage an invitation. Making drafts needs no account; publishing, buying a level, AI writing and sending a report from the App need one.
Guest
A person who opens a Page through its link. Guests have no account.
Invitation
Everything a host enters for one function or set of functions: names, hosts’ and parents’ lines, wording, event titles, dates, times, venues, addresses, map links, notes, photos, template, music choice and languages.
Page
The public web page generated from a published Invitation, reachable only by its link (a short address containing a random part).
Reply
A guest’s answer on a Page: name, yes / no / maybe, number of people and, where the host asked, which functions.
Level
A one-time purchase (Silver, Gold, Diamond or Platinum) made through Google Play that lets you publish one Invitation and unlocks the features of that level for it.
Personal Data
Any information relating to an identified or identifiable natural person. “Personal information” under the CCPA and “personal data” under the DPDP Act and GDPR are read the same way here.
Processing
Any operation on Personal Data: collecting, storing, using, displaying, transferring, deleting.
Data Fiduciary / Controller
The entity that decides why and how Personal Data is processed. For the Service this is AppskKuber, except as explained in Section 6 for the content of a host’s guest list.

2. Scope & Applicable Law

This Policy applies to the App, the Pages and our websites. It does not apply to Google Play, WhatsApp, Google Maps or any other service a link may take you to; those have their own policies.

We comply with the Digital Personal Data Protection Act, 2023 (India) and the rules under it; the General Data Protection Regulation (EU) 2016/679 for users in the European Economic Area; the UK GDPR and Data Protection Act 2018 for users in the United Kingdom; the California Consumer Privacy Act as amended by the CPRA for California residents; and the Children’s Online Privacy Protection Act (US) as explained in Section 20. Where these laws differ, we apply the standard that protects you more.

3. About AppskKuber and Welvite

AppskKuber is an independent software developer based in Rewa, Madhya Pradesh, India (full details in Section 23). Welvite is published on Google Play for Android. There is no iOS app and no web creator at this time.

The App is meant for adults (18 and over) who are organising a family function. It is not directed to children.

4. Information We Collect from Hosts

4.1 Account information

DataWhenWhy
Your sign-in details, depending on the way you choose: Google: your Google account name, email address, profile photo address and Google account identifier; phone number: that number; email: your email address and a password, which Firebase Authentication keeps only as a salted hash (nobody at AppskKuber can read it)When you sign in, which is needed only to publish, to buy a level, to use AI writing or to send a report from the App. Before that, drafts stay on your phone and no account existsIdentifies you as the owner of your invitations and the levels you bought, lets you open them from another phone, and lets us verify a deletion or rights request
The sign-in code we text you (phone sign-in only)Each time you sign in with your phone numberProves the number is yours. Google sends the SMS for us through Firebase Authentication; the code expires within minutes and is not kept. Your operator’s normal SMS terms apply
Date and version of the Terms you accepted, and your app languageAt sign-inRecord that the content rules were accepted before publishing (Google Play’s user-generated content rules)

4.2 Invitation content

Everything you type into an Invitation and every photo you choose. Names and parents’ lines are Personal Data about you and the people on your card; venue addresses may be your home. You decide what to put on a card, and you are responsible for having the right to put other people’s names and photos on it.

Photos are picked through the Android photo picker, so the App never sees your gallery, only the images you select. They are resized and compressed on your phone (at most 1,600 pixels on the long side and about 400 KB) before upload. The App never reads your contacts, your location or your microphone.

Drafts are saved on your phone. Once you have signed in, they are also saved to your space in our database under your account identifier, so that they survive a reinstall and open on another phone. Nothing in a draft is visible to anyone but you until you publish.

4.3 Guest list

If you use personalised links, you type guest names (and optionally a group label) into a list. These names appear in the links you send and in the envelope on the Page. They are Personal Data about your guests, which you have chosen to share with them.

4.4 Replies received

Replies from your guests (Section 6) are stored under your Invitation and shown to you in the App, with per-event counts. From the Gold level up you can export them as a file; that file is created on your phone and is yours to handle lawfully.

4.5 Purchases

When you buy a level, Google Play processes the payment; we never see your card or UPI details. We receive and keep: the product bought, the Google purchase token and order number, the verification result and date, your account identifier and the Invitation the level was applied to. The App also sends Google Play a one-way hash of your account identifier (an “obfuscated account id”) so that a purchase can be matched to the buyer and not replayed on another account.

4.6 Technical information

5. What a Published Page Contains, and Who Can See It

Publishing turns your Invitation into a Page: an HTML document, a calendar file and a preview image (your cover photo with the names and date, shown by WhatsApp and other messengers when the link is shared). The Page shows every text field you filled in, your photos and the music you chose. At the Silver and Gold levels it also carries a small “Make your own invitation” link to our website.

A Page is public to anyone who has the link. It is not listed by search engines (every Page tells search engines not to index it) and the link cannot be guessed (it contains twelve random characters), but anyone a guest forwards the link to can open it. Do not put on a card anything you would not want a guest’s cousin to read.

Pages are served from Cloudflare’s network so they open quickly on slow connections. When you edit a published Invitation the same link shows the new content within a minute. You can take a Page down at any time from the App (the link then answers “this page has been removed”), and every Page expires on its own (Section 13).

6. Guests: What a Page Collects When You Open or Reply

If someone sent you a link to a Page, this section is for you. You do not need an account and the Page asks you for nothing unless you choose to reply.

6.1 Opening a Page

6.2 Replying

When you tap reply, the Page sends us:

DataWhyWho sees it
The name you typedSo the host knows who is comingThe host, in their App
Your answer (yes / no / maybe), the number of people, and which functions (if the host asked)The host’s head countThe host
Your browser languageTo word the confirmation on screenNobody; used once
A truncated one-way hash (SHA-256, first 12 bytes) of your network addressTo let you change your reply instead of creating a duplicate, and to stop one connection from flooding a Page with replies (at most three names per connection per Page)Nobody; it cannot be turned back into your address and is never shown to the host

Before a reply is accepted, Cloudflare Turnstile checks that it comes from a real browser and not a script. Turnstile is loaded only when you start to reply, and it processes browser signals under Cloudflare’s privacy policy; it does not show you puzzles or set tracking cookies.

6.3 Reporting a Page

The Report link at the bottom of every Page sends us the Page address, the reason you choose, any text you add and the same truncated hash of your network address (to limit repeat reports). We look at every report within 24 hours.

6.4 Who is responsible for your reply

The host decided to invite you and is the one who reads your reply; in the language of the DPDP Act and GDPR, the host is responsible for their guest list, and we process your reply on their behalf to deliver it and keep the Service safe. Your reply is deleted when the host deletes the Page and, at the latest, when the Page expires (Section 13). To have it removed earlier, ask the host or write to us (Contact, subject “Guest reply removal”).

6.5 If a Page asks you for money

A genuine Page never contains a payment button, a QR code, a form asking for an OTP or a password, or anything to download. The only outside links a Page can carry are a Google Maps link and a calendar file. If you see anything else, it is not a real invitation made with Welvite: close it and report it.

7. How We Use Information & Legal Bases

PurposeDataLegal basis (GDPR / UK GDPR) and DPDP ground
Create, save, publish and edit your Invitations; show you your Pages and RepliesAccount, Invitation content, RepliesPerformance of our contract with you (the Terms); DPDP: consent given when you use the Service for its stated purpose
Deliver a guest’s Reply to the host and prevent duplicates and floodsReply data, truncated address hashLegitimate interests of the host and of guests in a working reply system; DPDP: the purpose the guest volunteered the data for
Unlock and verify levels, handle refundsPurchase recordsPerformance of contract; legal obligation (tax and accounting records)
Write card text on your request (Section 8)Your one line, names, occasion, tonePerformance of contract (a feature you chose to use); you can simply not use it
Keep the Service safe: screen text and photos, act on reports, block abusive accounts, stop scamsInvitation content, photos, reports, account identifiersLegitimate interests of guests, hosts and the public; legal obligations under Google Play’s developer policies and Indian law
Tell you a reply arrivedNotification tokenConsent (you allow notifications after your first publish; withdraw any time)
Fix crashes and understand the funnel at an aggregate level (Section 17)Crash reports, a few counted eventsLegitimate interest in a working product
Answer your email, handle rights requests, comply with lawYour email and what you writeLegal obligation; legitimate interest

We do not use your data for advertising, profiling, automated decisions with legal effect, or any purpose not listed here.

8. AI Writing Feature

The App ships with a library of pre-written invitation texts in Hindi, Marathi and English in three tones. That library is not AI: it was written and checked by people. Optionally, under “Write it in my words”, you can type one line about what you want to say and receive two versions written by a large language model.

What is sent to the model: your line, the names on the card, the occasion and its title, the hosts’ line, the chosen tone and the language. What is never sent: dates, venues, addresses, phone numbers, map links, photos, guest lists or replies.

The model is Google’s Gemini, accessed through Google Cloud Vertex AI under Google Cloud’s data processing terms, which do not permit customer prompts to be used to train Google’s models. We do not store your prompts or the generated texts beyond counting how many tries you have used (before a level is bought: 1; Silver: 3; Gold: 5; Diamond and Platinum: 10 per invitation). A text you choose to use becomes part of your Invitation like anything else you type.

Generated text can be wrong or awkward; you see it before it goes on your card and can edit every word. Every result has a Report button, and we filter output for money, OTP, link and download words before showing it.

This feature is disclosed in the Google Play Data safety form as text sent to an AI provider.

9. Safety Screening of Text and Photos

When you publish, the text of your Invitation is checked by rules on our servers for the patterns of the “wedding invitation APK” scams: requests for money, UPI or OTP, links that are not Google Maps, download files and phone-number bait, plus a short list of explicit words. New photos are sent to Google Cloud Vision SafeSearch, which returns a rating for adult, violent and suggestive content and does not keep the image. If anything is flagged, the Invitation is not published, you are told in the App that it needs a human check within 24 hours, and we look at it. Photos that were already published are not screened again.

Reports from guests and hosts are read by a person. A Page that is a scam or breaks the content rules is taken down and the account blocked from publishing; the rules and your options are in the Terms.

10. No Advertising, No Advertising Identifier

The App shows no advertisements and contains no advertising SDK. It does not request or collect the Android Advertising ID; advertising-identifier collection and ad-personalisation signals are switched off in the App’s configuration. Pages carry no advertising and no third-party scripts. The small “Make your own invitation” link on Silver and Gold Pages leads to our website and sends nothing about the guest.

11. Levels & Payments

Levels are one-time purchases sold through Google Play Billing. Google LLC is the seller of record and processes your payment under the Google Privacy Policy and Google Play Terms of Service. We never receive your card number, UPI id or bank details. What we receive and keep is listed in Section 4.5. When Google refunds or voids a purchase, Google notifies us; the Invitation keeps any level it still holds, or its Page is taken offline and it returns to your drafts. There are no subscriptions and no auto-renewal.

12. Third-Party Services & SDKs

ProviderWhat it does for the ServiceData involvedPolicy
Google Firebase (Google LLC)Sign-in (Authentication, including the SMS code for phone sign-in), database (Cloud Firestore, Mumbai region), photo storage (Cloud Storage), server code (Cloud Functions), notifications (Cloud Messaging), App Check, Crashlytics, AnalyticsAccount (incl. the phone number or email address you sign in with), Invitation content, photos, Replies, tokens, crash reports, counted eventsFirebase privacy
Google Play Services: Play Integrity, Google Sign-In, Play BillingDevice integrity, sign-in, purchasesDevice signals, Google account, purchase tokensGoogle privacy
Google Cloud Vertex AI (Gemini)Writes card text on request (Section 8)Your line, names, occasion, toneGoogle Cloud privacy notice
Google Cloud VisionSafeSearch rating of new photos at publish (Section 9)The photo bytes, not retainedSame
Cloudflare, Inc.: Workers, R2 storage, KV, TurnstileServes Pages, stores their files and view counts, checks replies are humanPage files and photos; visitor connection data as any website; reply and report requestsCloudflare privacy
WhatsApp and other apps you share toYou choose where to send the link; the message leaves your phone through that appThe link and the text you send; the messenger fetches the Page previewTheirs

We have no advertising networks, data brokers, social-media SDKs or analytics vendors other than those listed. We add a provider to this table before it starts receiving data.

13. Data Retention, Page Expiry & Account Deletion

DataKept until
Drafts in your accountYou delete them (My invitations → Delete draft) or your account
Invitations whose Page you took down or that expiredKept in your account, hidden from the list, until you delete your account
A published Page, its files and photos on CloudflareOne year after the last function, or until you take it down. After that the link shows a short notice page only
Guest Replies and guest listsDeleted with the Page: when you take it down, when it expires, and when you delete your account
Photos in our storageDeleted with the Page
Purchase recordsUp to three years for dispute handling and accounting; after account deletion they remain without your account identifier
ReportsUp to 24 months; after account deletion without your account identifier
Cloud Functions logs30 days
Crash reportsUp to 90 days (Crashlytics)
Support emailUp to 24 months, or sooner on request

Deleting your account (App → Settings → Delete account) immediately takes down every Page you published, deletes your photos from our storage and from Cloudflare, deletes every Reply and guest list, your Invitations, your profile, your notification tokens and your sign-in identity. It is permanent. Full details, including the email route if you cannot open the App, are at https://legal.welvite.com/delete-account.

14. Data Sharing & Disclosure

We share Personal Data only:

We do not sell Personal Data, and we do not “share” it for cross-context behavioural advertising in the meaning of the CCPA. We have not sold or shared Personal Data in the preceding 12 months.

15. International Data Transfers

Our database runs in Google Cloud’s Mumbai region (asia-south1). Photos and Page files are stored with Google Cloud and Cloudflare and served from Cloudflare’s worldwide network, so a copy of a Page may be cached in the country where a guest opens it. The AI writing and photo screening requests are processed by Google Cloud, which may use data centres outside India for them. For users in the EEA and UK, transfers to India and the US rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) that Google and Cloudflare incorporate in their data processing terms, with supplementary measures such as encryption in transit and at rest.

16. Push Notifications

After your first publish, the App asks whether you want to be told when a reply arrives. If you say yes, Android asks for the notification permission and we store a Firebase Cloud Messaging token for your device. Each notification contains the guest’s name and answer in your app language. You can turn notifications off in Android settings at any time; the token is deleted with your account. We send no marketing notifications.

17. Analytics & Crash Reports

In release builds of the App we collect, through Firebase Crashlytics, crash reports with the stack trace, device model, Android version, app version and a Crashlytics installation identifier that is not linked to your account. Through Firebase Analytics we count a handful of events to see whether the App works as a whole: invitation created (with occasion and language), invitation published (with tier and template), invitation shared (with the channel: WhatsApp, other app or copied link) and level purchased (with the product). Event parameters are categories only; no names, text, links or photos are ever sent. The Advertising ID is not collected (Section 10). Development builds send nothing.

Our websites and the Pages run no analytics at all.

18. Data Security

No system is perfectly secure. If a breach affects your Personal Data we will notify you and the relevant authority as the applicable law requires (for Indian users, as the DPDP Act and its rules prescribe; for EEA/UK users, within 72 hours of becoming aware where required).

19. Your Rights & Choices

19.1 Everyone

19.2 India (DPDP Act, 2023)

You have the right to access a summary of your Personal Data and of the processing, to correction and erasure, to grievance redressal through our Grievance Officer (Section 23), and to nominate a person to exercise your rights if you die or are incapacitated. Consent you have given may be withdrawn as easily as it was given: delete the data or the account in the App, or write to us.

19.3 EEA and UK (GDPR / UK GDPR)

You have the rights of access, rectification, erasure, restriction of processing, data portability (we provide your Invitations and Replies in a machine-readable format on request), objection to processing based on legitimate interests, withdrawal of consent, and the right to lodge a complaint with your supervisory authority (Section 23). We answer within one month, extendable by two months for complex requests, and we tell you if we extend.

19.4 California (CCPA / CPRA)

You have the right to know what personal information we collect, use and disclose (this Policy), to delete it, to correct it, to opt out of sale or sharing (we do none), to limit use of sensitive personal information (we collect none in the CPRA sense), and not to be discriminated against for exercising your rights. We do not use or disclose sensitive personal information for inferring characteristics. You may designate an authorised agent. We verify requests by matching the email address of your account; an account that signs in with a phone number only is verified by signing in with that number in the App (we never act on a number alone).

19.5 How to exercise rights

Email support@welvite.com with the subject Privacy Rights Request from the email address on your account. If your account signs in with a phone number only, include that number: we will ask you to confirm while signed in with it in the App, and most rights (seeing, correcting and deleting your data) you can exercise there directly. Requests are free; we may decline manifestly unfounded or repetitive ones, and tell you why.

20. Children’s Privacy

The App is for adults aged 18 and over and is not directed to children. We do not knowingly collect Personal Data from anyone under 18 (under 13 for the purposes of COPPA). Birthdays of children are frequently the subject of an invitation; the host, an adult, decides what to put on the card and is responsible for it. If we learn that a child has created an account, we delete it. A parent or guardian who believes a child has given us Personal Data can write to the Grievance Officer (Section 23).

21. Do Not Track Signals

Pages and our websites do not track visitors across sites, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We treat such signals as a confirmation of what we already do.

22. Changes to This Policy

We update this Policy when the Service changes, for example when a new provider is added (Section 12). The Effective Date and Version at the top change with every revision, and material changes are announced inside the App before they take effect. Earlier versions are available on request.

23. Contact & Grievance Officer

Data Fiduciary / Controller

AppskKuber
Rupesh Patel
5/50/1 Chanakyapuri Colony, Padra
Rewa – 486001, Madhya Pradesh, India
Email: support@welvite.com
Legal pages: https://legal.welvite.com
Developer: https://appskuber.com

Grievance Officer (DPDP Act, India)

Name: Rupesh Patel
Designation: Grievance Officer, AppskKuber
Address: 5/50/1 Chanakyapuri Colony, Padra, Rewa – 486001, Madhya Pradesh, India
Email: support@welvite.com
Subject line: Privacy Grievance
Response time: within thirty (30) days of receipt

If you are not satisfied with the Grievance Officer’s response, you may complain to the Data Protection Board of India once it is constituted and operational under the DPDP Act.

Privacy Rights Requests

For a request under any applicable law (DPDP, GDPR, UK GDPR, CCPA/CPRA or other), email
support@welvite.com
Subject line: Privacy Rights Request

Account Deletion

In the App: Settings → Delete account, immediate and permanent.
If you cannot open the App: email support@welvite.com with the subject Welvite account deletion request.
Full details: https://legal.welvite.com/delete-account

Supervisory Authority: EEA & UK

EEA and UK users may lodge a complaint with their local supervisory authority. EU authorities are listed at edpb.europa.eu/about-edpb/about-edpb/members_en; UK users may contact the Information Commissioner’s Office at ico.org.uk.

California Privacy Rights

California residents may submit verifiable requests by emailing support@welvite.com with the subject California Privacy Request, and may designate an authorised agent to act on their behalf.

This Privacy Policy is the entire statement between you and AppskKuber regarding the privacy of your Personal Data in the Welvite Service and supersedes any earlier privacy notice issued for it.