Privacy policy
Effective 1 October 2026
ChairPlanner (chairplanner.com) is a seating planner for weddings and events, run by wondertroy, an independent developer based in Australia. This policy explains what information is handled when you use it, and the choices you have. Questions or requests: privacy@chairplanner.com.
Two ways to use ChairPlanner — your choice
Offline, with no account
The default. Your events, guests, tables and plans are stored only in your browser on your device. They aren’t sent to us, and no account or email address is needed. This is how ChairPlanner works unless you choose otherwise.
With an optional account
If you choose to sign in — for example to keep chosen events in sync across your devices — we store a small amount of account information. In events you save to the cloud, names and personal details are end-to-end encrypted: only you can read them, not us. The seating layout is stored without names (details below).
You can stay offline-only forever, sign in later, move individual events in or out of the cloud, or delete your account at any time. Deleting your account never deletes the events stored on your devices.
Using ChairPlanner offline
- Your event data is kept in your browser’s storage (IndexedDB) on that device. We don’t receive it. Clearing your browser’s site data deletes it, so export a
.chairplanfile if you want a backup. - Website hosting. Cloudflare hosts and protects the site. Like any website, delivering a page involves standard request information such as your IP address, browser type and the address requested. Cloudflare may keep this briefly in operational and security logs.
- Analytics. We use Cloudflare Web Analytics to count page views. It doesn’t use cookies and isn’t used to track you across sites.
- Share links. A plan shared as a link carries the plan inside the link itself (after the
#), not on our servers. Anyone with the link can open the plan, and the link stays wherever you paste it (chats, browser history). - AI assistant connector. If you use ChairPlanner from an AI assistant, the assistant sends the plan details it has chosen (such as guest names, tables and seating rules) to our server so we can check them and return an import link. We don’t store those details. Your conversation is handled by your AI provider under its own policy.
If you create an account
Only if you choose to sign in, we handle the following.
- Email address — to sign you in. Our database stores it only in encrypted form, plus a one-way keyed fingerprint used to find your account. The encryption key is kept separately from the database, so a copy of the database alone wouldn’t reveal email addresses. Unlike your cloud saves, though, this isn’t end-to-end encrypted: we hold that key and can decrypt your email address when needed — to send sign-in codes and, if needed, important messages about your account, its security, or changes to this policy. We don’t send marketing.
- Sign-in codes — sent by email through Cloudflare Email Service, stored only in hashed form, and valid for 10 minutes.
- Sessions — when you sign in, a secure cookie keeps you signed in for up to 30 days of inactivity. We store a session record with the IP address and browser details from when it was created, to protect your account. Signing out deletes that session.
- Passkeys — if you add one, we store its public key and a label such as “iPhone · Safari”. Your fingerprint, face or device PIN never leaves your device.
- Sign in with Google — if you choose it, Google tells us your email address and an account ID. We ask Google for nothing else (no name, photo or contacts), keep no Google access tokens, and store the email address encrypted like any other. Google’s own privacy policy covers its side.
- Abuse protection — the sign-in form uses Cloudflare Turnstile, which checks signals from your browser to tell people from bots. We also keep short-lived request counters by IP address, and a 24-hour log of sign-in emails sent, stored only as keyed fingerprints, to stop spam and abuse.
What’s encrypted in cloud saves
- Only events you choose are saved to the cloud. Everything else stays offline.
- Encrypted in your browser before upload, with keys that are unlocked only by your passkey or your recovery code, so we can’t read them: the event’s name and date; guests’ names, email addresses, phone numbers, dietary requirements, tags, parties and song requests; the names of layouts, tables and plans; and seating-rule notes and relationship labels.
- Stored readable, so we can check that saves are valid, keep your devices in sync and apply free-account limits: the shape of the event, without names. That’s random IDs for each guest, table, plan and layout; table shapes, sizes and positions; which guest ID sits in which seat; the type and priority of seating rules and relationships between guest IDs (for example, “guest 7 must sit next to guest 12”); and each guest’s role (such as bride or groom) and RSVP status. None of this contains names or other free text, so on its own it doesn’t say who anyone is.
- We also see when each part was last changed and how much you’ve saved.
- You can turn on Redact sensitive info for an event, which leaves guests’ email addresses, phone numbers and dietary requirements out of its cloud copy entirely. Redacted details stay on the device where you entered them and can’t be recovered from the cloud.
- Because we can’t read the encrypted parts, we can’t reset your recovery code. If you lose every passkey and your recovery code, they can’t be decrypted (copies on your devices are unaffected).
Short links and QR codes
- With a cloud account, you can share a read-only view of an event saved to the cloud as a short link or QR code. A share doesn’t store a copy of your event: it holds only the keys needed to read what you chose to share, locked with a key that’s in the link itself (after the
#) or derived from an access code you send separately, and protected again with a key kept on our servers. We can’t read what it shares. - When someone opens it, we send only the parts it allows (for example one plan, without dietary notes or relationships), and their browser decrypts them. It shows your event as it is now, so it stays up to date as you edit.
- Anyone who has the full link (or the link and its access code) can open it without an account. Shares are view-only unless you include the full event, which also lets them import a copy. Redact sensitive info is on by default and leaves out contact details, dietary notes, tags, rule notes and relationship labels.
- We store each share’s settings, its locked keys, its creation and expiry dates, and how many times it’s been opened (used to limit repeated attempts). You can revoke a share at any time: it stops working straight away and the event’s keys are replaced, so a revoked link can’t read anything newer. Moving the event out of the cloud or deleting your account revokes all its shares. Copies people have already imported stay with them.
Information about your guests
Seating plans usually include information about other people, such as names and dietary requirements. Please only add what you need for your event. Offline, it stays on your device; in the cloud, names and details are end-to-end encrypted and only readable by you and the people you share with, and the seating layout uses random IDs instead of names.
Who processes data, and where
ChairPlanner runs on Cloudflare, which hosts the site, the sign-in service and the account database, sends sign-in emails and provides Turnstile. The account database is located in Cloudflare’s Oceania region, but Cloudflare’s network operates worldwide, so requests may be processed in other countries. Cloudflare acts on our behalf under its own privacy and security commitments. Sign-in emails may instead be sent through Resend, which receives your email address only to deliver the code. If you choose Sign in with Google, Google handles that step and knows you signed in to ChairPlanner. We don’t sell personal information, show ads, or use advertising or tracking cookies.
Cookies and browser storage
- Your events and settings are kept in your browser’s storage on your device.
- If you sign in, essential cookies keep you signed in, plus short-lived ones while you use a passkey or Google sign-in. ChairPlanner sets no other cookies.
- Cloudflare may use strictly necessary cookies or similar technology for security and bot protection.
Keeping and deleting your information
- Account information is kept until you delete your account.
- Delete account (on your account page) removes your account, sessions, passkeys and all cloud saves and shares from our database straight away. Database backups may keep them for up to 30 days before they’re gone for good.
- Events on your devices are removed by deleting them in ChairPlanner or clearing your browser’s site data.
Your rights
You can ask to access, correct or delete the personal information we hold about you, and ask questions about how it’s handled, by emailing privacy@chairplanner.com. Most of this you can also do yourself on your account page. Because names and details in cloud saves are end-to-end encrypted, we can’t provide them, but you can see and export everything in the app.
If you’re not happy with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, if you’re in the EU or UK, your local data protection authority.
Children
ChairPlanner isn’t intended for children under 16, and we don’t knowingly create accounts for them.
Changes to this policy
If this policy changes, we’ll update this page and its effective date. If you have an account and the change is significant, we’ll also let you know by email.
Contact: privacy@chairplanner.com · See also our terms of use.