Privacy policy
This privacy policy applies to the FamilyStories app (iPhone and iPad), to answering questions through a guest link in the browser, and to our website familystories.love (together, the "Services").
This English version is provided for your convenience. The German version is the legally binding one.
Last updated: July 5, 2026
1. The essentials at a glance
FamilyStories is built so that your family stories belong to your family. Before you read on, here are the principles we work by:
- Everything your family creates (answers, voice recordings, photos, the names of the people telling their stories) is end-to-end encrypted. We cannot read it, listen to it, or view it. Not even if we wanted to, and not even in response to a government request.
- Voice recordings are turned into text exclusively on your family's devices, never in the cloud.
- The app contains no advertising, no tracking SDKs, and no third-party analytics tools.
- We do not sell data. We share data only with the technical service providers needed to run the Services, and only to the extent described here.
- We collect only what is required to operate the Services: essentially your email address for signing in and technical metadata for encrypted synchronization.
- Invited relatives who answer through a guest link in the browser need no account and give us no personal data. Their answers are end-to-end encrypted too.
The details are in the sections that follow.
2. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
FamilyStories UG (haftungsbeschränkt)
Gewalterberg 1
45277 Essen
Germany
Represented by the managing director: Vedad Taranin
Email: support@familystories.love
We are not required to appoint a data protection officer under Art. 37 GDPR. Nevertheless, data protection at FamilyStories is owned at the leadership level: our managing director is a certified data protection officer. For anything related to data protection, you can reach us at the email address above.
3. Scope and definitions
- "App" means the FamilyStories app for iPhone and iPad.
- "Guest link" means a private link that lets an invited family member answer questions directly in the browser, without the app and without an account.
- "Family space" means the shared, encrypted space in which a family collects its stories and synchronizes them between the members' devices.
- "Website" means familystories.love and its information pages.
4. End-to-end encryption: what we cannot see
Everything your family creates in FamilyStories is encrypted on your device before it reaches our servers. The keys needed for this are generated on your family's devices and never leave them unencrypted. Our servers store only encrypted data packages that cannot be read without your family's keys.
End-to-end encrypted content includes in particular:
- Answers to questions (text)
- Voice recordings and their transcripts
- Photos
- Names and details of the people telling their stories, including the information from the setup questionnaire
- Custom questions and edited question texts
- Answers and recordings submitted through guest links
The practical consequence: we can neither view this content nor recover it if your family loses access. We also cannot hand it over to third parties, because we cannot decrypt it ourselves.
What is not end-to-end encrypted are the few account and operational data we need to run the service. We describe these completely in section 5.
5. What data we process and why
5.1 Account and sign-in
To create an account, we process your email address. You can sign in either:
- with a sign-in link sent to your email address (magic link),
- with your Apple account ("Sign in with Apple"), in which case we receive your email address or a relay address provided by Apple, plus an identifier,
- with your Google account ("Sign in with Google"), in which case we receive your email address and an identifier from Google.
We also store the language you have chosen so that sign-in emails arrive in your language. Sign-in is handled technically by our processor Supabase (section 9). Purpose: providing your account and linking your devices. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Your email address is the only mandatory piece of information: without it, we cannot provide an account. Everything else you enter in the app is voluntary.
5.2 Your family content
All content listed in section 4 is encrypted on your device and stored on our servers only as encrypted data packages, so that it can be synchronized between your family's devices and is not lost if a device is lost. We process this content exclusively as ciphertext that is unreadable to us. Purpose: synchronization and backup within your family. Legal basis: Art. 6(1)(b) GDPR.
5.3 Voice recordings and transcription
When you answer a question with a voice recording, the app accesses the microphone with your permission. The recording is encrypted on your device and synchronized end-to-end encrypted like all other content.
Converting speech to text happens exclusively on your family's devices, using the device's speech recognition or a locally downloaded recognition model. There is no cloud transcription. Neither the recording nor the transcript ever reaches a speech recognition service outside your family's devices.
5.4 Photos
When you add photos to answers, the app accesses the images you select, with your permission. Photos are also encrypted on your device before they are stored or synchronized.
5.5 Family space, invitations, and synchronization (technical metadata)
For encrypted synchronization to work, our servers process some technical metadata:
- pseudonymous account and device identifiers as well as the public keys of your devices,
- which accounts belong to a family space and the permissions granted there (for example, who may invite members),
- timestamps, version counters, and the size of encrypted data packages,
- the status of invitation codes and guest links (but not their secret components).
This metadata contains no content. It is required to deliver changes to the right devices, enforce permissions, and prevent abuse. Legal basis: Art. 6(1)(b) GDPR.
5.6 Purchases and subscriptions
Purchases are handled through the Apple App Store. Payment details (for example, your credit card) are processed exclusively by Apple; we never receive them.
To manage purchases, we use RevenueCat (section 9). RevenueCat receives a pseudonymous user identifier and purchase-related information (for example, the product purchased, the time of purchase, subscription status) so that purchases can be linked to your family space and, for example, restored. Legal basis: Art. 6(1)(b) GDPR.
5.7 Reminders
If you turn on reminders, they are scheduled locally on your device. No push tokens are sent to us or to third parties; the reminder feature works without any server.
5.8 App protection with Face ID or Touch ID
If you enable the optional app protection, the app uses your device's biometric features. Biometric data stays entirely on your device with Apple; we receive neither biometric data nor the plain result, only the local confirmation.
5.9 Security and abuse prevention
When the app or the browser communicates with our servers, your device's IP address is processed temporarily for technical reasons in order to answer the request. It is not stored permanently together with your account.
To protect against abuse (for example, mass guessing of links or automated sign-in attempts), we limit how often requests can be made. For this, we process the IP address of the request in the form of a cryptographic hash (SHA-256). We do not store the IP address itself. The hash entries serve abuse detection only and are kept only as long as needed for that purpose. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, abuse-free operation).
5.10 Support
When you contact us by email, we process your email address and the content of your message in order to answer your request. Legal basis: Art. 6(1)(b) GDPR, and for general inquiries Art. 6(1)(f) GDPR.
6. Answering through a guest link in the browser
A family member can create a private guest link from the app and send it, for example, to grandma. The invited person then answers the questions directly in the browser. The following applies:
- No account and no sign-in are needed. We collect neither the invited person's name nor their email address nor any other account data.
- The secret part of the link (after the # character) is, for technical reasons, never sent to our servers. It is the key the browser uses to decrypt the questions and encrypt the answers.
- Answers and voice recordings are encrypted in the browser before they reach our servers. Here too, we store only encrypted data packages.
- Unsent drafts and the chosen display language are stored only locally in the browser (localStorage). This storage is strictly necessary for the feature being used (Section 25(2)(2) of the German TDDDG). It is not transmitted to us and can be removed by clearing your browser data.
- The guest pages contain no cookies, no analytics tools, and no tracking.
- For abuse prevention, we process hashed IP addresses when a link is opened and when answers are submitted, as described in section 5.9.
The legal basis for processing when answering through a guest link is Art. 6(1)(b) GDPR with respect to the person answering (providing the answering feature) and otherwise Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the family space).
Good to know: anyone who has the complete link can read and change the answers given through that link. The link should therefore be treated like a key and shared only with the person it is meant for. The link can be renewed in the app at any time; the old link then becomes invalid.
7. Website
When you visit familystories.love, our hosting provider Vercel (section 9) processes the technically necessary connection data (in particular IP address, time of access, page requested, browser type) in server logs in order to deliver the website and ensure its security and stability. Legal basis: Art. 6(1)(f) GDPR.
For audience measurement, we use Vercel Web Analytics. This tool works without cookies and without cross-device tracking; visits are counted only in aggregate using a short-lived identifier derived from the request, without building lasting profiles. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly audience measurement).
The website sets no advertising or tracking cookies. The guest link pages are fully excluded from audience measurement.
8. Legal bases at a glance
- Art. 6(1)(b) GDPR (performance of a contract): account, synchronization, family space, purchases, support related to your account.
- Art. 6(1)(f) GDPR (legitimate interests): security and abuse prevention, server logs, privacy-friendly audience measurement on the website.
- Art. 6(1)(a) GDPR (consent): you grant system permissions such as microphone, photo selection, and notifications through your device's dialogs; you can revoke them at any time in your device settings.
- Art. 6(1)(c) GDPR (legal obligation): retention where required by law (for example, tax-law obligations relating to purchase records).
9. Recipients and processors
We use the following service providers. Contracts under Art. 28 GDPR are in place with all processors.
Supabase Inc. (USA)
Data hosted in Frankfurt am Main, Germany (AWS, region eu-central-1). Purpose: account and sign-in, database, delivery of sign-in emails, server functions.
Processes: email address, language setting, technical metadata (section 5.5), hashed IP addresses, encrypted data packages.
Cloudflare Inc. (USA)
Purpose: storage for encrypted voice recordings and photos (R2).
Processes: exclusively end-to-end encrypted media files and technical object metadata (for example, size).
RevenueCat Inc. (USA)
Purpose: managing purchases and subscriptions.
Processes: pseudonymous user identifier, product and subscription status, purchase timestamps.
Apple Inc. (USA)
Purpose: app distribution, payment processing, optional Sign in with Apple.
Apple processes payment data as an independent controller; with Sign in with Apple, we receive an email address or relay address and an identifier.
Google LLC (USA)
Purpose: optional Sign in with Google.
When you sign in, we receive an email address and an identifier; Google processes the sign-in as an independent controller.
Vercel Inc. (USA)
Purpose: hosting the website, cookieless audience measurement.
Processes: connection data of website visits (section 7).
Beyond that, we disclose personal data only when we are legally required to do so. Even in that case, we cannot hand over end-to-end encrypted content in plain text, because we cannot decrypt it.
10. Transfers to third countries
Your content and account data are stored in Frankfurt am Main (Germany). Some of our service providers are based in the USA or may access systems as part of support and operations. Where personal data is transferred to the USA in this context, we rely on adequacy decisions of the EU Commission (in particular the EU-US Data Privacy Framework, where the provider is certified) and on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
In addition: the most sensitive data, your family's content, is technically unreadable for every service provider thanks to end-to-end encryption, regardless of location.
11. Storage periods and deletion
- We store account and family data for as long as your account exists. You can delete your account completely at any time in the app settings. Upon deletion, all information about your account and your devices as well as all encrypted content and media files belonging to your account are permanently deleted from our servers.
- If you use the free mode or your premium access expires, the data stored on our servers is kept for a transition period of six months and then deleted automatically. The content stored locally on your devices is not affected.
- Abuse-prevention entries (hashed IP addresses) are kept only for the short time windows needed for rate limiting and are then deleted.
- Server logs of the website are deleted automatically by our hosting provider after a short time.
- We retain purchase-related data for as long as statutory retention obligations apply.
- Local data on your device (for example, drafts in the browser or downloaded recognition models) is deleted by you, by removing the app or clearing your browser data.
12. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time, on grounds relating to your particular situation.
An informal email to support@familystories.love is enough to exercise your rights. To protect your account, please write to us from the email address linked to your account.
One particularity follows from end-to-end encryption: we cannot provide information about the content your family has created and cannot export it for you, because we cannot decrypt it. Viewing, editing, exporting (for example, as PDF), and deleting this content is done directly in the app on your device.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (www.ldi.nrw.de); you can also contact the supervisory authority where you live.
13. Responsibility within your family
FamilyStories is intended for personal and family use. Which relatives are invited, which questions are asked, and what is shared within the family space is decided by the family members themselves; this use regularly falls under the so-called household exemption (Art. 2(2)(c) GDPR). We are the controller for the technical operation of the Services, not for the content family members share with each other. Please invite only people who agree to sharing their memories in the family space, and treat guest links confidentially.
Within a family space, permissions control who can see and edit which content: for each person telling their story, you can set which members may read their stories and which may edit them. The shared family tree is visible and editable for all members of the family space. These permissions apply within your family and are enforced on the server side; they do not change the end-to-end encryption towards us.
14. Children and teenagers
FamilyStories is made for families, and family stories thrive when generations come together. Children can therefore take part within a family space, for example by answering questions or telling their story through a guest link, provided their parents or guardians agree and accompany the use. We collect no account data from guest link participants (section 6).
Creating an account of your own and managing a family space is only allowed for people aged 16 or older. We do not knowingly collect account data from children under 16.
15. Data security
In addition to end-to-end encryption, we protect your data through, among other things:
- modern, vetted encryption schemes for content and key material,
- storage of device keys in your device's protected key store,
- transport-encrypted connections (TLS) for all communication,
- server-side access controls and permission checks for every request,
- rate limiting and further safeguards against abuse.
No system can guarantee absolute security. But the architecture of FamilyStories is built so that even if our servers were accessed, your family's content would remain encrypted and therefore unreadable.
16. No advertising, no profiling, no automated decisions
We show no advertising, build no usage profiles, and make no automated decisions within the meaning of Art. 22 GDPR. We do not sell personal data and do not share it for advertising purposes.
17. Changes to this privacy policy
We update this privacy policy when our Services or the legal requirements change. You can always find the current version in the app and on our website. If the changes are significant, we will additionally inform you in the app or by email.
18. Contact
For questions about data protection, you can reach us at:
FamilyStories UG (haftungsbeschränkt)
Gewalterberg 1
45277 Essen
Germany
Email: support@familystories.love