A ceremony stores its title, categories, and the display names of whoever joins it. Nominations and ballots are stored against a guest id so we can enforce one vote per guest per category and stop self-voting, but that id is never joined back to a display name anywhere results are shown, including to the host. We do not require a guest email address to join, nominate, or vote.
We set a small session cookie so a guest’s browser stays recognized as “joined” for that ceremony, and a separate one for a host’s dashboard session. Neither is used for advertising or cross-site tracking, and neither outlives the ceremony they belong to.
We do not run analytics or advertising scripts on any guest or host page, and we do not load any third-party script or asset in your browser. Payment, when a host purchases a Ceremony Pass or Pro, is handled entirely by our merchant of record; we never see or store card numbers.
A ceremony’s data is not deleted automatically today: a completed ceremony and its categories, nominations, ballots, and guest list stay stored so the host can keep returning to it. Self-service deletion is planned alongside host accounts. Until it ships, a host can write to hello@yearlies.app to request their ceremony’s data be removed, and we do it by hand.