CherishVow

Privacy Policy

Last updated: July 21, 2026

Who We Are

CherishVow (“we”, “us”, or “our”) is the data controller for the personal data processed through this website and service. If you have questions about this policy or how we handle your data, contact us at support@cherishvow.com. For users in the European Economic Area or the United Kingdom, our EU representative can be reached at the same address.

What Data We Collect

We collect the photos you upload (bride and/or groom reference photos), your email address, and session metadata such as scene selections, generation preferences, and payment history. We also store AI-generated portraits and quality-control metrics associated with your account.

Sensitive and Biometric Data

The reference photos you upload contain facial images. Depending on your jurisdiction, facial images used to identify an individual may be classified as biometric data or a special category of personal data. We process this data only to generate the portraits you request and to perform automated quality checks. We do not use your photos or facial data to train AI models, create facial recognition databases, or build profiles for any purpose other than delivering your portraits.

How Photos Are Stored

Uploaded and generated photos are stored in a private Cloudflare R2 bucket located in the United States. All database records (including metadata and embeddings) are encrypted at rest via Neon PostgreSQL. Generated photos expire after 7 days and are automatically removed from storage.

Third-Party Processors

We work with a small set of processors to operate the service. Each processor handles data only as needed to provide its function:

  • Clerk — authentication and user identity.
  • Stripe — payment processing.
  • Cloudflare R2 — photo storage and CDN.
  • Neon — database hosting.
  • Atlas Cloud — AI image generation. Your uploaded photos are transmitted to this provider solely to generate your portraits.
  • Resend — transactional email.
  • Sentry — error monitoring.

AI Training

We never use your uploaded photos, face data, or generated portraits to train AI models. Your images are processed only to create the portraits you request.

Data Retention

  • Generated portraits expire after 7 days and are automatically deleted.
  • Face embeddings extracted during photo validation are purged 30 days after your session is completed.
  • Reference photos and session metadata are retained until you delete your account.
  • Payment and tax records are retained for 7 years after a transaction to comply with legal and accounting obligations.

Security

We use industry-standard safeguards to protect your data, including encryption in transit (TLS), encryption at rest for database records, access controls for our infrastructure, and private object storage with presigned URLs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Data Breaches

In the unlikely event of a personal data breach, we will notify affected users and relevant regulators as required by applicable law, including without undue delay under GDPR where feasible.

Cookies

We use essential cookies required for authentication and security (provided by Clerk). With your consent, we also use optional analytics cookies to understand how the service is used. We do not use advertising or cross-site tracking cookies. You can accept or decline optional cookies at any time via the consent banner. Our site does not respond to “Do Not Track” browser signals because we do not share data with third-party advertisers.

Legal Basis & International Transfers

If you are in the EU/EEA or UK, we process your data on the following legal bases: performance of a contract (creating and delivering your portraits), your consent (optional analytics and marketing), legitimate interests (service security and improvement), and legal obligations (payment and tax records). Your data may be processed in the United States and other countries where our processors operate. For transfers from the EU/EEA and UK, we rely on the European Commission’s Standard Contractual Clauses supplemented by appropriate technical safeguards, including encryption.

Your Rights

You have the right to access, export, correct, and delete your personal data at any time. Use the Export and Delete options in your Account Settings, or contact us at support@cherishvow.com. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.

US State Privacy Rights

If you are a resident of California or another US state with a consumer privacy law, you have the right to know what personal data we collect, to request deletion of your data, to opt out of the sale or sharing of your personal data, and to non-discriminatory treatment for exercising your privacy rights. We do not sell or share personal data for cross-context behavioral advertising. To exercise your rights, contact us at support@cherishvow.com.

Children's Privacy

CherishVow is not directed at children under 18, and we do not knowingly collect personal data from children. Photos of minors may only be uploaded by a parent or legal guardian who has the authority to provide consent on behalf of the minor. If you believe we have collected data from a child without appropriate consent, please contact us so we can delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

If you have any questions about this Privacy Policy, please reach out to support@cherishvow.com.