Both families. Their own lists.
Her parents run her side, his parents run his, and neither sees the other's list.

Four roles, named plainly.
Owner and Bride and Groom see everything. A Parent sees and edits their own side. A Family Helper sees only the family group you assign.
Nobody except the owners can delete an event or change who has access.

Enforced in the database, not hidden in the interface.
Visibility is applied in every query and again by Postgres row-level security. The app connects as a non-privileged role, so a bug in one layer cannot leak the other side's list.
No certifications are claimed here. The detail is on the security page.
How we protect it →
Common questions.
Can my mother add guests without seeing the groom's list?
Yes. Invite her as a Parent with the bride's side as her scope. She sees and edits that side only.
Can a helper delete an event by accident?
No. Only owners can delete events or change access. Helpers work inside the group you give them.
Does family access cost extra?
No. Access for both families is part of the free tier.