Privacy Policy
Effective August 13, 2026
This Privacy Policy explains how Kali Artistry ("Kali Artistry," "we," "our," or "us") handles information when you use Madali, our mobile app for coordinating small celebrations, and the Madali marketing website.
Information we collect
- Account information. If you sign in with Google or Apple, we receive identifiers those providers make available, such as your email address, display name, and Firebase user ID. Madali does not offer password/email sign-in. If you continue without an account, Firebase creates an anonymous user ID.
- Terms acceptance. Before you enter Madali, we record the version of the Terms you accepted, the server time of acceptance, and that the acceptance came from the Madali app. This record is linked to your Firebase user ID and is used to provide the service and document compliance.
- Celebration content. We store information you or other participants enter, such as celebration titles, schedules, participant names and roles, invite codes, and announcements.
- Event photos and Google Drive connection. When a host enables event photos, authenticated participants may take or choose photos in Madali. Photos are optimized on the participant's device and streamed through Madali's protected upload service into a private folder created in the host's Google Drive. Madali stores upload metadata, including the event, uploader, file name, optimized size, timestamps, status, and Google Drive file reference, but does not retain a permanent copy of the media in Madali or Firebase Storage. The host may select photos for a shared in-app guest gallery.
- Google Drive authorization. A host who connects Google Drive grants the limited
drive.filepermission, allowing Madali to manage only files and folders it creates or that the host explicitly opens with Madali. The host's authorization credentials are encrypted server-side. - Safety reports and blocks. If you report content or a participant, we store your selected reason, optional details, identifiers for the celebration and people involved, and a protected copy of relevant reported content so Kali Artistry can review it. If you block someone, we store that choice privately for the celebration so their announcements and related alerts can be hidden from you.
- Device and notification information. We process device identifiers, device and app details, and a Firebase Cloud Messaging token so we can operate the app and send celebration notifications.
- Usage, approximate location, and diagnostics. Firebase Analytics processes app interactions and related usage information. Firebase Analytics and Firebase Remote Config may infer an approximate country or region from a masked Internet Protocol address to provide analytics, configure app behavior, and protect the service; Madali does not request your device's precise location. Firebase Crashlytics and related Firebase session services process crash logs, session identifiers, diagnostics, device type, operating system, app version, and performance or quality metadata so we can understand and improve reliability.
- Optional website guide analytics. The two comparison guides offer a clear choice before loading Google Analytics. If you choose Allow, the linked Madali Analytics property receives a standard page-view event with the guide's canonical path, page title, and one fixed article identifier. It also receives an event when you choose a marked guide or App Store call to action, using only fixed article and button identifiers. Google Analytics may process basic browser and device information, a first-party analytics cookie, and an approximate region derived from your Internet Protocol address. We do not send form entries, names, email addresses, invitation or celebration details, URL query strings, referrer URLs, or a Madali user ID. Advertising storage, Google signals, and ad personalization remain disabled. If you continue without analytics, the Google tag is not loaded and no analytics request is sent. Your choice is stored locally in your browser so the guides can remember it.
- Purchase information. RevenueCat processes purchase receipts, product identifiers, transaction and subscription status, and an app user identifier to provide and restore Madali Lifetime or Pro access. Apple or Google processes payment details; Madali does not receive your full payment-card number.
How we use information
We use information to provide and sync the service, authenticate users, record acceptance of the current Terms, enable collaboration and notifications, process private event-photo uploads and galleries, configure app behavior, process and restore purchases, review safety reports, enforce our Terms, protect users and the service, troubleshoot problems, measure feature and comparison-guide use, and improve Madali.
How information is shared
Celebration content is shared with people who join that celebration according to their role. A participant can see only their own photo-upload records unless the host selects photos for the shared guest gallery; the host can see all uploads for the event. We also use service providers that process information on our behalf: Google Firebase and Google Analytics (Authentication, Firestore, Cloud Functions, Cloud Messaging, Analytics, Remote Config, Crashlytics, and related session services), Google Drive, RevenueCat, Apple, and Google Play. Their processing is governed by their own terms and privacy policies.
We do not sell personal information. Madali has no advertising and does not track you across other companies' apps or websites. We may disclose information if required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.
Storage, security, and retention
Madali is offline-first, so celebration data may be stored on your device and synchronized with Google Firebase. Photo uploads are temporarily processed on the device and by the protected upload service, then stored in the host's Google Drive. Temporary processing files are removed after an upload attempt. Information is encrypted in transit using HTTPS/TLS, and Drive authorization credentials are encrypted at rest. No system is completely secure, but we use reasonable administrative and technical safeguards.
We retain account, celebration, and photo metadata while needed to provide Madali or until it is deleted. Media stored in a host's Google Drive remains under that host's control and is not automatically deleted from Google Drive when a Madali account or event is deleted. After account deletion, planning changes you made in a celebration owned by someone else may remain so that the event team's shared plan still works, but those changes will no longer be linked to your account.
We may retain a minimal, server-only deletion marker containing your former Firebase user ID solely for security and abuse prevention and to stop a stale signed-in session from recreating the deleted account. The marker does not contain your profile or celebration content. We may also retain protected safety or moderation records, including a snapshot of reported content and the identifiers needed to investigate or prevent abuse, even if the original announcement or an involved account is later deleted. Limited information may otherwise remain in backups or as required by law. Apple, Google, or RevenueCat may retain purchase records, and aggregated or de-identified analytics may be retained longer.
Your choices and deletion
You may use Madali without providing an email address by choosing "Continue without account." You can control notification permission in your device settings. On either comparison guide, use Analytics choices in the footer to allow or withdraw optional guide measurement. Withdrawing changes the stored choice, disables analytics storage, and removes Madali's first-party Google Analytics cookies from that browser.
You can permanently delete your Madali account in the app by opening Home → Settings (gear icon) → Delete account. Deletion removes your Firebase authentication account and profile, celebrations you own and their content, updates you sent, memberships, notification tokens, access and identity links in shared celebrations, and local Madali account data from that device, subject to the narrow retention described above. If deletion cannot be completed in the app, follow the alternative request instructions on Madali's account-deletion page or email support@madalievents.com.
Children
Madali is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us so we can delete it.
International use
Kali Artistry is based in the United States. If you use Madali elsewhere, your information may be processed in the United States and other locations where our service providers operate.
Changes to this policy
We may update this policy as Madali changes. We will update the effective date on this page and provide additional notice when appropriate.
Contact
Kali Artistry
Email: support@madalievents.com
See also the Madali Terms of Service.