Privacy

What JoinMe stores, and for how long.

JoinMe collects what an invite needs to work and nothing else. This page describes the data the app actually holds, where it is stored, who can reach it, and when it is deleted.

What a guest gives

When you RSVP to an invite, JoinMe stores the answers you type: your name, your response (yes, maybe, no, or waitlist), how many people you are bringing and their names if you add them, and — only if you fill them in — your email address, your phone number, dietary notes, a message to the host, and your answers to the host’s own questions. If the host runs a date poll, potluck, song requests, or a photo album, whatever you submit there is stored with the event too. If the host checks you in on the day, the time is recorded.

An email address is used for two things: sending you a confirmation with a link to edit your own reply, and sending a single reminder about 24 hours before the event. It is not used for anything else and it is not sold or shared.

What a host gives

Creating an invite needs a JoinMe account: a name, an email address, and a password. The password is never stored in readable form. Account email is used for verification, password resets, and notifications about your own events — a message each time someone RSVPs, for example. Everything you enter about an event (title, description, date, place, cover image, questions, agenda, links) is stored so the invite page can render it.

Who can see it

  • The host of an event sees every reply to that event, including the optional email addresses and phone numbers guests leave.
  • Guests see the public invite page. Which guest names are shown there is the host’s choice.
  • A public event is listed in the JoinMe directory and in the sitemap. A private event is not, and its page asks search engines not to index it.
  • Host manage links and guest edit links contain a secret token. They are served with noindex and no-referrer headers so the token is never leaked to another site or to a search index — but anyone holding the link can use it, so treat it as a password.
  • Guest-uploaded photos stay pending and are visible only to the host until the host approves them.

Where it is stored

JoinMe runs on Cloudflare. Pages are served from Cloudflare Workers, event and guest data is stored in Cloudflare D1, and uploaded cover images and guest photos are stored in Cloudflare R2 and served from this domain. Email is sent through Cloudflare Email Service from no-reply@joinme.rsvp. Cloudflare is the only third party involved in running the site.

Tracking

There are no advertising trackers, no third-party analytics and no cross-site cookies. The app sets a session cookie once you sign in, and stores your light/dark theme preference in your own browser. Each invite page keeps a simple view counter — a number on the event, with nothing about who viewed it.

How long it is kept

An event expires when it is over. Ninety days after that, a scheduled job permanently deletes the event and everything attached to it: RSVPs, plus-ones, date polls and votes, potluck sign-ups, song requests, invitations, and uploaded photos and cover images. A host can delete an event sooner from the manage page, which removes its guest data and stored images immediately. A guest can change their own reply — including to a no — at any time from the edit link in their confirmation email, and a host can remove a guest from the guest list.