
Privacy Policy
What Lumielle collects
- Waitlist email. If you join the waitlist, Lumielle stores your email address so it can tell you when the service is available.
- Wedding photos. The private Original is the file supplied by the guest’s browser and can retain available metadata, such as capture time and device details.
- Optional first name. A guest may add an unverified first name for the couple’s Album. It is not shown on the live slideshow.
- Wedding and service data. Lumielle processes Wedding configuration, Organizer and Purchaser contact details, contribution status, moderation decisions, acceptance evidence, removal records, and operational diagnostics.
- Device-scoped access data. A browser receives a Wedding-specific device credential so the guest can resume delivery, view their own history, and remove photos without creating an account. Lumielle does not use it as a cross-Wedding identity.
Lumielle does not permit advertising trackers on guest or display surfaces.
How information is used and shared
Lumielle uses information to collect and verify Contributions, create safe display renditions, operate the live slideshow and private Album, build the Original Album, eligibility, support the Wedding, prevent abuse, troubleshoot failures, enforce policies, and comply with valid legal requests.
Delivered photos are retained in the private Wedding collection. People entrusted with a separate Wedding-scoped Album link can consume eligible metadata-stripped safe renditions, private optional first-name attribution, and eligible Originals through bounded ZIP parts or individually authorized downloads. The rendition view never labels a rendition as an Original, and no Album response exposes private object keys or Rehearsal photos. Eligible renditions may also be shown to people at the Wedding. Service providers process information only to operate Lumielle: Cloudflare hosts application, database, and private object-storage infrastructure and handles transactional email; Polar acts as merchant of record for purchases. Payment details are handled under Polar’s own privacy terms rather than stored by Lumielle.
Lumielle does not sell guest photos or personal information for advertising.
Retention and removal
Wedding photos are scheduled for removal 60 days after the Contribution window closes. Photos added through the guest link during rehearsal follow the same Wedding retention period. Photos in a previously issued, separate Rehearsal collection keep their original deletion schedule: 24 hours before the main collection opens. A confirmed guest Retraction removes the photo from the collection and Album immediately, updates connected displays promptly, and schedules all photo artifacts for purge within 24 hours. A minimal non-photo record may remain to prove the outcome.
Copies already downloaded by the Organizer or couple, photographed from a display, or otherwise outside Lumielle cannot be remotely deleted by Lumielle.
Your choices
- Choose Not now to decline without opening the camera or library.
- Do not contribute a photo you do not want used in the disclosed ways.
- Use Your photos — view or remove on the same browser to permanently remove an individual Contribution.
- Use the removal and content-reporting process if browser access is lost or for privacy, copyright, or illegal-content concerns.
Security and location
Lumielle uses scoped access credentials, private object storage, access controls, file verification, and metadata-stripped display renditions. No online service can guarantee absolute security. Lumielle’s infrastructure providers may process data in locations described in their policies.