Privacy policy
This policy explains what personal data Toast collects, why, who we share it with, how long we keep it and the rights you have. It applies to everyone who uses Toast: speakers, the friends who send them stories, and members of a Wedding party room.
Who is responsible for your data
Toast is run by Relay Labs Limited, a private company limited by shares, registered in Ireland, company number 807438. Registered address: 35 Lower Sherrard Street, Dublin 1, D01 T6N7, Ireland.
We are the controller of your personal data under the General Data Protection Regulation (GDPR). You can reach us at [email protected].
What we collect
- Your account: your email address, and the sign-in codes and links we send to it. You can start a speech without an account; what you write is then linked to a guest session in your browser until you confirm an email.
- Your speeches: the names of the couple, the wedding date, your role, the answers you give to our questions, every draft and version, your edits and your print settings.
- Story Harvest: the stories your friends send you, with each contributor's name and how they know the couple, their voice notes if they record one, and the transcript of each voice note. With each story we also keep a hashed (scrambled) form of the sender's IP address, which we use to limit abuse.
- Wedding party rooms: the couple's names and date, each member's display name and role, the speeches members bring into the room, the running order and the story clash labels.
- Payments: what you bought, the amount, the VAT, the currency, the date, the time you accepted the no refunds waiver and Stripe's reference for the payment. Stripe handles your card. We never see or store your card details.
- Technical data: your IP address and browser details when you sign in, short records we use to limit abuse (for example how many emails were sent to an address in the last hour), and error reports when something breaks.
Why we use it, and on what legal basis
- To provide Toast to you under our contract with you (the Terms of use): your account, your speeches, the drafts we write with AI, Story Harvest, Wedding party rooms, downloads, reminder emails and purchases.
- With consent: a friend who sends a story agrees that it is shared with the speaker and processed by AI to help write the speech. A room member who pastes or uploads a speech agrees that we check it with AI for clashes with the other speeches. You can withdraw consent at any time by writing to us; this does not affect what was done before.
- For our legitimate interest in keeping Toast safe and working: limiting abuse, scanning uploaded files for malware, and fixing errors.
- To meet our legal obligations: keeping payment records for at least six years, as Irish law requires.
We do not sell your data, we do not use it for advertising, and we do not use your speeches or stories to train AI models.
What other people can see
Your speeches are private to you. A friend's story is seen by the speaker it was sent to, not by the couple. In a Wedding party room, the other members see your display name, your role, your speech's title and length, and its place in the running order. They see the text of your speech only if you switch on "Let the room read my speech", and they can never change it. A story clash label is shown only to the two members it involves.
Who we share it with
We use these service providers to run Toast. Each one processes data only on our instructions and only for the service it gives us.
- Anthropic: writes and rewrites drafts, checks drafts for lines that might not suit the room, tags and summarises friends' stories, and checks room speeches for story clashes.
- OpenAI: turns voice notes into text.
- Stripe: takes payments.
- Plunk: sends our emails, such as sign-in codes, reminders and story notifications.
- Hetzner: hosts Toast and stores voice notes, in the European Union.
- Sentry: collects error reports, set up to leave out personal details such as IP addresses.
- ClamAV: scans uploaded files for malware. It runs on our own server, so files are not sent anywhere else to be scanned.
Anthropic and OpenAI are based in the United States. When your data leaves the European Economic Area, we rely on the safeguards the GDPR requires, such as the European Commission's standard contractual clauses.
How long we keep it
- Your account, speeches, answers, drafts and Story Harvest stories: while your account exists. They are deleted when your account is deleted.
- Voice notes: deleted 90 days after the wedding, or 12 months after they were sent if no wedding date is set. The written story and the transcript of the voice note are kept with the speech. Voice notes are also deleted when you ask us to, or when the speaker's account is deleted.
- The hashed IP address kept with a friend's story: kept with the story, and deleted with it.
- Speeches in a Wedding party room: deleted 30 days after the room closes. While payments are not switched on, rooms stay open until their last member leaves. If you leave a room, or are removed from it, you can still read your own speech there for 30 days, or until the room closes on schedule if that comes first. Your speech is deleted 30 days after you left or were removed.
- Wedding party rooms with a payment: when anyone paid for a seat, we keep the room record (the couple's names, the date, and the members' display names and roles) for as long as we keep the payment records. The speeches in the room are still deleted as above, and a member who deletes their account is removed from the room record.
- Payment records: kept for at least six years, as Irish law requires. When you delete your account, we remove their link to your account, your speech and your wedding date. We keep the amount, the VAT, the date, what was bought and Stripe's reference for the payment. Because Stripe's reference stays, these records are pseudonymised, not anonymous: we keep no link to you, but Stripe holds its own records of the payment.
- Records we use to limit abuse: deleted after 7 days. The IP address and browser details kept with a sign-in: deleted when you sign out, or 7 days after the sign-in expires. Uploaded files are scanned and read, then discarded straight away; we keep only the text you chose to add.
- Copies in our backups are deleted within 30 days.
Your rights
Under the GDPR you have the right to:
- get a copy of the personal data we hold about you
- have data corrected when it is wrong
- have your data deleted, including your account
- receive the data you gave us in a format you can take elsewhere
- object to how we use your data, or ask us to limit it
- withdraw a consent you gave
You can delete your account yourself: open Account, then Delete my account.
To use any of these rights, email [email protected] from the address on your account. We answer within one month. If you are not happy with our answer, you can complain to the Data Protection Commission, Ireland's supervisory authority (www.dataprotection.ie), or to the data protection authority where you live.
Contact
Relay Labs Limited, 35 Lower Sherrard Street, Dublin 1, D01 T6N7, Ireland. Email: [email protected].
When we change this policy, we change the date below. If a change affects you in a significant way, we tell you by email first.
Last updated 2 October 2026