This document is a draft pending legal review and does not yet constitute Eventyno's final legal terms. Draft version: 2026-10-04-v1-draft
Eventyno Security
Document version: 2026-10-04-v1-draft Effective date: 2026-10-04 (draft; becomes effective only when published as final)
We take the security of your events, photos, and personal information seriously. This page explains in plain language how we protect it and how to tell us about a problem. No online service is perfectly secure. We work to reduce risk, but we cannot promise that information will never be accessed, altered, lost, or disclosed.
How we protect information
- Encrypted connections. Eventyno is served over HTTPS, and connections to our database, storage, and payment providers are encrypted in transit.
- Access rules in the database. Data lives in a managed database with row-level access rules, so the application can only read or change the records a given person is allowed to see. Passwords are never stored by us in readable form; our authentication provider stores a one-way hash.
- Browser protections. Pages are served with a Content Security Policy that limits which scripts, frames, and connections a page may use, and with HSTS, clickjacking and content-type protections, and a restrictive referrer policy. State-changing requests from other websites are rejected.
- Unlisted means unlisted. "Anyone with the link" events use long random addresses and cannot be listed or searched through our public interfaces. Who follows whom is visible only to the people involved.
- Accounts need an acceptance record. The database itself refuses to let an account with no recorded Terms/Privacy acceptance or no known age create or change content, even if someone calls our public API directly.
- Map keys stay on the server. Map and place requests go through Eventyno's servers, so the map provider's key is never sent to your browser.
- Private media with short-lived links. Photos and videos are stored in private storage and delivered through signed links that expire.
- Payment details stay with Stripe. Eventyno never receives or stores your full card number.
- Rate limits and abuse controls on sign-in, RSVPs, reports, and other public actions.
- Separation of duties. Administrative tools are separate from the consumer product and available only to authorized staff. Privileged credentials are kept on the server and are never sent to your browser.
- Minimizing data. We collect only what the product needs, and we strip location metadata from uploaded photos.
- Monitoring and updates. We review logs for abuse and security issues and keep our software and dependencies updated.
What you can do
Use a strong, unique password and keep your email account secure, because password resets go there. Sign out on shared devices. Be careful what you make "Public," and remember that "Anyone with the link" events are unlisted but not password-protected. Do not put sensitive personal information on event pages or RSVP forms.
Reporting a vulnerability
If you believe you have found a security vulnerability in Eventyno, please email support@eventyno.com with enough detail to reproduce it. Please give us reasonable time to fix it before sharing it publicly, do not access or change other people's data, do not degrade the Service, and do not test with real users' accounts. We will review reports in good faith. We do not currently run a paid bug-bounty program.
If something goes wrong
If a security incident affects your personal information, we will investigate, take steps to contain it, and notify affected people and the authorities as the law requires.
