Privacy Policy

    Last updated: June 2026

    This Privacy Policy explains how we — MYFAMBLISS GROUP LTD, the operator of EventBliss — collect, use, share and protect your personal data when you use our app (iOS and Android), our website event-bliss.com and the EventBliss marketplace. It also explains your rights under the EU General Data Protection Regulation (GDPR). EventBliss is built to be privacy-friendly: we process only what is needed to run the service, we do not sell your data and we do not show third-party advertising.

    1. At a Glance

    • We only process the data needed to run EventBliss — your account, your events and, if you buy Premium, your purchase data.
    • Our database, authentication and file storage run on Supabase in the EU (Frankfurt, Germany).
    • Payments are handled by Apple, Google and Stripe — we never see or store your full card details.
    • AI features (receipt scanner, planning assistant, read-aloud) only transmit data while you actively use them — and never for advertising purposes.
    • We do not sell personal data and we do not use third-party advertising or tracking networks.
    • You can delete your account at any time in the app (Profile → Settings → Delete account) — see 'Account Deletion'.

    2. Controller

    Controller within the meaning of Art. 4(7) GDPR for all processing described in this policy is: MYFAMBLISS GROUP LTD is a company registered in the Republic of Cyprus. "EventBliss" is a brand and product of MYFAMBLISS GROUP LTD. We have not appointed a data protection officer, as we are not legally required to do so; for all privacy matters you can reach our team directly using the contact details below.

    MYFAMBLISS GROUP LTD

    Gladstonos 12-14, 8046 Paphos, Cyprus

    Reg. No. HE 473088 · VAT ID CY60165018Q

    info@event-bliss.com

    3. What Data We Process

    Depending on how you use EventBliss, we process the following categories of personal data. We collect them directly from you, from your device, or they arise from your use of the service:

    Account data
    Display name, email address, password (stored only as a salted cryptographic hash by our authentication provider), profile picture, language and notification preferences. If you sign in with Apple or Google, we receive your name (or a pseudonym), your (relay) email address and a technical account identifier from that provider.
    Event content
    Everything you and your guests create inside an event: event name, type, dates, location, guest list, tasks, schedules, polls and votes, chat messages, photo gallery uploads, expense entries and game results. Event content is visible to the other participants of that event.
    Purchase and payment data
    Your subscription status (Free, Premium, Lifetime), product identifiers, transaction and purchase tokens from Apple or Google, and — for web purchases — the data processed via Stripe (amount, currency, payment method type, last four card digits). Full card numbers are processed exclusively by the payment providers and never reach our servers.
    Receipt photos (expense scanner)
    If you use the receipt scanner in the expense feature, the photo you take and the recognised data (merchant, amount, date) are processed to pre-fill the expense entry. See 'Recipients and Processors' for the OCR provider involved.
    Usage data
    Which features you use and basic interaction events (e.g. event created, game started), crash reports and performance diagnostics. We use this to keep the app stable and to improve it — not to build advertising profiles.
    Device and log data
    IP address, device model, operating system and version, app version, browser type, time stamps of requests and — if you enable notifications — your push token. Server logs are kept for security and troubleshooting.
    Location data (optional)
    Only when you use map features (e.g. picking an event location): the map section you view and, if you grant the system permission, your approximate device location for centring the map. We do not create movement profiles and we do not track your location in the background.
    Read-aloud / audio (optional)
    When you use the read-aloud (text-to-speech) feature, the text to be spoken is transmitted to our speech provider to generate the audio. We do not access or record your microphone for this feature.

    4. Purposes and Legal Bases (Art. 6 GDPR)

    We process your data only for the following purposes and only on these legal bases:

    Providing the EventBliss service: your account, event planning and collaboration, synchronisation across devices, marketplace bookings and customer support.

    Legal basis: Art. 6(1)(b) GDPR — performance of the contract (our Terms of Service).

    Processing purchases and subscriptions (Premium, Lifetime, marketplace bookings), issuing receipts and preventing payment fraud.

    Legal basis: Art. 6(1)(b) GDPR; for tax and commercial record-keeping additionally Art. 6(1)(c) GDPR.

    AI-supported features: receipt text recognition (OCR), the AI planning assistant and text-to-speech output. Data is transmitted to the providers listed under 'Recipients and Processors' only at the moment you actively use the feature.

    Legal basis: Art. 6(1)(b) GDPR — the feature is part of the service you request. Where required, we additionally ask for your consent (Art. 6(1)(a) GDPR).

    Push notifications about your events (e.g. new messages, tasks or schedule changes).

    Legal basis: Art. 6(1)(a) GDPR — your consent via the system permission dialog; revocable at any time in your device settings.

    Security and abuse prevention: server logs, rate limiting, fraud detection, defence against attacks and enforcement of our Terms.

    Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, trustworthy platform.

    Compliance with legal obligations, in particular statutory retention periods for transaction and accounting records.

    Legal basis: Art. 6(1)(c) GDPR.

    5. Recipients and Processors

    We share personal data only with the following recipients, only to the extent necessary, and — where they act as our processors — on the basis of data processing agreements pursuant to Art. 28 GDPR. Apple, Google, Stripe and Spotify act (partly) as independent controllers for their own services.

    Supabase

    Database, authentication and file storage — the technical backbone of the app

    Location: EU (Frankfurt, Germany)Safeguards: Processor; DPA pursuant to Art. 28 GDPR; data hosted in the EU

    Vercel

    Hosting and content delivery of the website event-bliss.com

    Location: USA / global edge networkSafeguards: DPA with EU Standard Contractual Clauses (SCCs); EU-U.S. Data Privacy Framework

    Stripe

    Payment processing for purchases on the website (cards, Apple Pay, Google Pay, SEPA)

    Location: EU / USASafeguards: DPA with SCCs; certified under the EU-U.S. Data Privacy Framework

    Apple

    In-app purchases on iOS, Sign in with Apple, push notifications (APNs)

    Location: USASafeguards: Independent controller for purchases; EU-U.S. Data Privacy Framework

    Google

    In-app purchases on Android (Play Billing), Google Sign-In, push notifications (FCM), Google Maps

    Location: USASafeguards: Independent controller for purchases; SCCs; EU-U.S. Data Privacy Framework

    RevenueCat

    Subscription management and validation of in-app purchases (receives a pseudonymous user ID and purchase tokens)

    Location: USASafeguards: Processor; DPA with SCCs

    OpenAI

    Receipt OCR — receipt photos are transmitted for text recognition when you use the expense scanner

    Location: USASafeguards: Processor; DPA with SCCs; API data is not used to train models

    OpenRouter

    AI assistant — your input text is transmitted to generate planning suggestions

    Location: USASafeguards: Processor; DPA with SCCs

    Mistral AI

    Text-to-speech — generates the audio for the read-aloud feature

    Location: EU (France)Safeguards: Processor; DPA pursuant to Art. 28 GDPR

    Spotify

    Music playback SDK — only if you use the OHRWURM music game and connect your own Spotify account

    Location: EU (Sweden)Safeguards: Independent controller; Spotify's own privacy policy applies

    Mapbox / Google Maps

    Map display — your IP address and the requested map tiles are transmitted when a map loads

    Location: USASafeguards: DPA with SCCs; EU-U.S. Data Privacy Framework (Google)

    Chatbase

    Support chatbot on the website; processes the messages you enter in the chat

    Location: USASafeguards: DPA, SCCs

    ALL-INKL.COM (SMTP)

    Delivery of transactional and notification emails (e.g. booking confirmations, newsletter confirmation)

    Location: EU (Germany)Safeguards: DPA (Art. 28 GDPR)

    6. International Data Transfers

    Where recipients are located outside the European Economic Area (in particular in the USA), we ensure an adequate level of data protection through: (a) the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR) for certified providers, and (b) the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) including supplementary measures where required. Copies of the relevant safeguards are available on request via the contact details below.

    7. Storage Periods

    We store personal data only for as long as necessary for the respective purpose or as required by law:

    Account data
    Stored for as long as your account exists and deleted when you delete your account.
    Event content
    Deleted when you delete the event or your account; residual copies are removed from encrypted backups within 30 days.
    Payment and transaction records
    Retained for 6 years after the end of the relevant financial year, as required by the Cyprus Companies Law and tax legislation.
    Server and security logs
    Automatically deleted or anonymised after 30 days, unless a specific security incident requires longer retention.

    8. Cookies and Local Storage

    EventBliss uses only technically necessary cookies and local storage entries: your login session, your language selection and interface preferences (e.g. theme). Legal basis: Art. 6(1)(f) GDPR or — for storage covered by the ePrivacy rules — strict necessity to provide the service you request. We do not use third-party advertising or cross-site tracking cookies. Should an optional, non-essential technology be introduced in the future, we will ask for your consent first (Art. 6(1)(a) GDPR). The support chat (Chatbase) only loads once you actively start it — no connection to Chatbase is made before that.

    9. Push Notifications

    We send push notifications (e.g. new chat messages, tasks or schedule changes in your events) only if you allow them in the system permission dialog. Delivery is handled by Apple (APNs) on iOS and Google (FCM) on Android, which receive a technical push token for your device. You can revoke your consent at any time: on iOS under Settings → Notifications → EventBliss, on Android under Settings → Apps → EventBliss → Notifications — or simply disable individual notification types directly in the app.

    10. Purchases, Subscriptions and Payment Data

    In-app purchases (iOS/Android): Premium subscriptions and the Lifetime purchase are processed by Apple (App Store) or Google (Google Play) as independent controllers. We receive confirmation of the purchase and pseudonymous transaction data, but no payment details. RevenueCat validates purchases and manages the subscription status on our behalf. Web purchases: On event-bliss.com payments are processed by Stripe. Stripe processes your payment details in accordance with payment regulation; we only receive the result, the amount and a reference. We never store full card numbers; statutory retention duties apply to transaction records (see 'Storage Periods').

    11. Account Deletion

    You can delete your account directly in the app at any time: Profile → Settings → Delete account. This permanently deletes your account data and the events you own; copies in encrypted backups are purged within 30 days. Data subject to statutory retention duties (e.g. payment records, see 'Storage Periods') is blocked from any other use and deleted once the retention period expires. Alternatively, you can request deletion by emailing support@event-bliss.com from your account email address. Note: subscriptions purchased via Apple or Google must be cancelled separately in your App Store / Google Play subscription settings — deleting your account does not cancel them automatically.

    12. Your Rights (Art. 15–21 GDPR)

    You have the following rights regarding your personal data. To exercise them, an informal email is sufficient — we respond within one month at the latest (Art. 12(3) GDPR):

    Right of access (Art. 15 GDPR)
    You can request confirmation of whether and which data we process about you, and obtain a copy of that data together with the information listed in Art. 15.
    Right to rectification (Art. 16 GDPR)
    You can have inaccurate data corrected and incomplete data completed — most account data can be edited directly in the app.
    Right to erasure (Art. 17 GDPR)
    You can request the deletion of your data; the easiest way is the in-app account deletion (see 'Account Deletion').
    Right to restriction of processing (Art. 18 GDPR)
    In the cases listed in Art. 18 (e.g. while the accuracy of contested data is being verified), you can require us to restrict processing.
    Right to data portability (Art. 20 GDPR)
    You can receive the data you provided in a structured, commonly used, machine-readable format. Download it directly in the app under Profile → Settings → “Export my data”, or request the export by email to support@event-bliss.com.
    Right to object (Art. 21 GDPR)
    You can object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. We will then stop processing unless compelling legitimate grounds prevail.
    Right to withdraw consent (Art. 7(3) GDPR)
    Where processing is based on your consent (e.g. push notifications), you can withdraw it at any time with effect for the future.

    Right to lodge a complaint (Art. 77 GDPR): You may complain to a data protection supervisory authority, in particular in the EU member state of your habitual residence or place of work. The authority responsible for us is the Commissioner for Personal Data Protection of the Republic of Cyprus, 1 Iasonos Street, 1082 Nicosia, Cyprus — dataprotection.gov.cy.

    13. Children and Minors

    EventBliss is not directed at children. Creating an account requires a minimum age of 16 (or the lower age your member state has set for information society services, but never below 13). We do not knowingly collect personal data from children below this age. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

    14. Data Security

    We protect your data with technical and organisational measures pursuant to Art. 32 GDPR: TLS encryption for all data in transit, encryption at rest for the database and file storage, row-level security so that every user can only access their own events, role-based access controls for our team, the principle of least privilege for service keys, and regular review of our security measures. No system is 100% secure, but we work continuously to keep the risk as low as possible.

    15. Changes to this Privacy Policy

    We update this policy when our service, our providers or the legal situation change. The current version with the date stated above always applies; material changes will be announced in the app or by email. Earlier versions are available on request.

    16. Contact

    For any privacy questions or to exercise your rights, contact us at:

    info@event-bliss.com