← Vowlist Security
Short and honest. Last updated: August 2026.
What we do
- HTTPS everywhere, with HSTS. Every page and every API call is encrypted in transit; browsers are told never to try plain HTTP.
- No passwords. You sign in with a one-tap email link that works once and expires in 60 minutes. Nothing to leak, nothing to reuse from another site.
- Unguessable links. Your RSVP page lives at a 26-character random address (about 128 bits of randomness); each household's private link adds its own random id. Guest pages are never listed, never indexed, and carry no login.
- Guests give us nothing to protect. We collect no guest emails, phone numbers or addresses — names and answers only, entered by you. Guest pages carry no ads and no third-party trackers (measured 0 on August 2026).
- Text is text. Everything a guest types is rendered as plain text — never as HTML — and CSV exports neutralise spreadsheet formulas, so a mischievous "guest note" can't run code in your browser or your spreadsheet.
- Payments never touch us. Stripe hosts the checkout; we see a payment confirmation, not your card.
- Small surface. Rate limits on every public form, a strict Content-Security-Policy, and a codebase small enough for one person to read end to end.
Where your data lives
On Cloudflare's network (application and database), with Stripe for payments and Resend for transactional email. The full list is in the privacy policy. Backups are Cloudflare's; there is no copy on anyone's laptop.
Found something?
Email hello@getvowlist.com with "security" in the subject. Good-faith reports get a fast, grateful reply and a fix — no legal threats, no bounty programme, no drama.