Privacy at Happily
Privacy Policy
This draft explains what Happily collects, why we use it, who can see it, and the choices available to you wherever you use the service.
Last updated 16 August 2026
Who is responsible
Clevero AB provides Happily and is responsible for the personal data described here. Contact us at support@usehappily.love for privacy questions or requests.
Data we collect
- Account information: your name, email address, profile image, sign-in identifier, and the Apple or Google sign-in method you choose.
- Event and membership information: event title, people named in the event, dates, time zone, venue, invite link or code, display names, roles, and membership status.
- Content and interactions: photos, videos, captions, guestbook messages, reactions, upload details, reports, and moderation decisions.
- Purchase information: the Event Pass product, transaction and receipt identifiers, store, status, and purchase time. Payments are handled by Apple or Google together with our purchase-management provider; Happily does not receive your full payment-card details.
- Device and service information: local session credentials, push token when you enable notifications, basic app/device information, and technical request data such as IP address that our hosting and security providers process when you connect.
- Support communications: the email address, message, and attachments you send when you contact us.
How and why we use data
Depending on where you live, our legal bases include performing our agreement with you, our legitimate interests in operating and protecting Happily, your consent for optional permissions or communications, and compliance with legal obligations.
- Provide the event gallery, uploads, sharing, sign-in, purchases, exports, notifications, and support you request.
- Attribute contributions, enforce event roles, prevent abuse, investigate reports, secure private media, and keep the service reliable.
- Reconcile purchases, refunds, and entitlements and meet accounting, legal, and store obligations.
Who receives data
We use a small number of service providers only to run Happily: a sign-in provider, an application database provider, an EU media-storage provider, an email delivery provider, a notification delivery provider, a purchase-management provider, and hosting and security providers. We name our current providers on request. Our application database provider processes application records and technical metadata in the United States, including account references, event and membership details, display names, captions and messages, upload metadata, interactions, moderation records, purchase-entitlement metadata, and service request data. Private photo and video file bytes are stored with our EU media-storage provider and served through the Happily media service.
When hosting-reminder email is enabled, our email delivery provider receives the event owner’s email address, event title, and hosting end date to deliver the reminder, and stores related email metadata, delivery logs, and API records in the United States. Apple, Google, and our purchase-management provider process purchase and entitlement data, and our notification delivery provider processes optional push delivery. Providers may also process limited technical data where they operate, subject to applicable contracts and transfer safeguards.
We do not sell personal data or use your event content for advertising. We may disclose information when law requires it, to protect people or the service, or as part of a business transaction with appropriate safeguards.
Who can see event content
Happily events are not intended to be public, but anyone who receives a valid event link or code may be able to join. Event members can see shared content and contributor display names. Event hosts control invitations, roles, review settings, visibility, reports, and removal of members or content. Keep event links within the invited group.
Storage and retention
Media is stored privately with our EU media-storage provider. Event records are kept for the hosting period shown in Happily: free events currently remain hosted for 90 days after the event, while an Event Pass includes 24 months. At expiry the event is archived and scheduled for permanent deletion. Owners can delete an event sooner.
Account data is kept while the account is active. Push tokens remain until opt-out or invalidation. Short-lived upload and access credentials expire automatically. After account deletion, some purchase-ledger and moderation records may remain for accounting, refunds, fraud prevention, safety, disputes, or legal obligations. We keep them only while the applicable purpose or obligation requires them; an active legal hold may delay removal of affected data.
Those retained records are pseudonymous, not anonymous. They may keep unsalted, deterministic SHA-256 digests derived from internal account or member IDs and provider transaction, lifecycle, event, report, reason, status, resolution, and timestamp fields, which can remain linkable within our systems. We remove direct account and membership references, contact details, contributor display names, and free-text report details from these retained records.
Deletion and your choices
Owners can export event data in the app and can permanently delete an event. Signed-in users can permanently delete their account in the app; see the Delete account page for the exact path and an email route if you cannot access the app.
Account deletion removes events you own and your contributions to every other event, including uploaded photos and videos, captions, guestbook messages, and reactions. Private media objects are permanently removed from storage. It also removes your account records, push tokens, export links, memberships, and sign-in identity. Access is revoked when deletion starts; background removal is retried after technical failures and is not treated as complete until the sign-in provider confirms that the identity is gone.
The narrowly retained pseudonymous purchase and moderation records described above can remain linkable through hashed references or transaction, event, and report identifiers. We keep them only where, and only while, the stated accounting, refund, fraud-prevention, safety, dispute, legal-obligation, or legal-hold purpose applies.
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, withdraw consent, and complain to your local data-protection authority. Contact us to exercise a right; we may need to verify your identity.
Security, children, and changes
We use access controls, scoped credentials, private object storage, and encryption in transit. No online service is completely risk-free, so please avoid sharing highly sensitive content.
Happily is not directed to children who cannot legally consent to use an online service in their country. A parent or guardian can contact us about a child’s data.
We may update this policy as the service or law changes. We will update the date above and give additional notice where required.