Privacy policy
This privacy policy applies to the FamilyStories app (iPhone and iPad), to answering questions through a guest link in the browser, and to our website familystories.love (together, the "Services").
This is the complete English version of this privacy policy.
Last updated: · Version: 2026-09-09
Show the contents of this privacy policy
1. The essentials at a glance
Your family stories belong to your family. These are the key points:
- Stories, answers, voice recordings, and photos are end-to-end encrypted. Only you and the people you authorise can read, listen to, or view them. Not even we can do that.
- Account, purchase, reminder, and technical operational data, as well as voluntary feedback, are not end-to-end encrypted. We process them only for the functions and purposes described here.
- Voice recordings are turned into text exclusively on your family's devices.
- We do not sell data, show advertising, create advertising profiles, or use your data to train AI models.
- You can delete your account in the app and contact support@familystories.love about your privacy. Sections 11 and 12 explain retention, deletion, and your rights.
2. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
FamilyStories UG (haftungsbeschränkt)
Gewalterberg 1
45277 Essen
Germany
Represented by the managing director: Vedad Taranin
Email: support@familystories.love
Data protection at FamilyStories is owned at leadership level. For anything related to data protection, you can reach us at the email address above.
3. Scope and definitions
- "App" means the FamilyStories app for iPhone and iPad.
- "Guest link" means a private link that lets an invited family member answer questions directly in the browser, without the app and without an account.
- "Family circle" means the shared, encrypted space in which a family collects its stories and synchronizes them between the members' devices.
- "Website" means familystories.love and its information pages.
4. End-to-end encryption: what we cannot see
Your family content is encrypted on your device before it reaches our servers. The keys remain on your family's devices or in the privately shared guest link. We do not possess these keys.
End-to-end encrypted content includes in particular:
- Answers to questions (text)
- Voice recordings and their transcripts
- Photos
- Family-tree details such as names, dates of birth, family relationships, and photos
- Labels, descriptions, and questionnaire details held within an individual story
- Custom questions and edited question texts
- Answers and recordings submitted through guest links
Not even FamilyStories can read, listen to, view, or decrypt your family content. This also applies to guest-link answers and family circles with email reminders. Keep your devices and private links safe: without the keys, we cannot recover lost content for you either.
The account, reminder, feedback, purchase, and operational data that we need to run the service is not end-to-end encrypted. This includes in particular your profile name, optional date of birth, email address, membership and activity details, and account and device identifiers. We describe this data completely in section 5.
5. What data we process and why
5.1 Account and sign-in
To create an account, we process your email address. You can sign in in one of the following ways:
- with a sign-in code sent to your email address,
- with your Apple account ("Sign in with Apple"), in which case we receive your email address or a relay address provided by Apple, plus an identifier,
- with your Google account ("Sign in with Google"), in which case we receive your email address, an identifier, and, depending on your approval, profile details such as your name and profile image from Google.
We also store your chosen profile name, an optional date of birth, your language, and account and device identifiers. We use these details to display and operate your account, assign you within family circles, communicate in the right language, and synchronize your devices securely. Sign-in is handled technically by our processor Supabase (section 9). The legal basis is Art. 6(1)(b) GDPR (performance of a contract).
Your email address and a profile name are required for the account. Providing your date of birth is optional.
When you sign in with Google, Google's sign-in library may also process a user identifier and the IP address. Google may use the IP address to estimate the device's general location for fraud prevention. We receive neither the IP address nor that location from Google. Google acts as an independent controller for this sign-in process.
5.2 Your family content
We do not claim ownership of your family content or use it for our own purposes. We store it only in encrypted form to synchronise and preserve it within your family. The legal basis is Art. 6(1)(b) GDPR.
Some optional question areas expressly concern health, spirituality or religion, and social or political beliefs. This may include, for example, blood type, allergies, or health conditions. You decide whether to select such an area and which questions to answer; none of this information is mandatory. It remains end-to-end encrypted as family content and is not analysed by us. Please share information about other living people only when you are entitled to do so and with due regard for their privacy.
5.3 Voice recordings and transcription
When you answer a question with a voice recording, the app accesses the microphone with your permission. The recording is encrypted on your device and synchronized end-to-end encrypted like all other content.
Converting speech to text happens exclusively on your family's devices, using the device's speech recognition or a locally downloaded recognition model. There is no cloud transcription. Neither the recording nor the transcript ever reaches a speech recognition service outside your family's devices.
5.4 Photos
When you add photos to answers, the app accesses the images you select, with your permission. Photos are also encrypted on your device before they are stored or synchronized.
5.5 Family circle, invitations, and synchronization (technical metadata)
For encrypted synchronization to work, our servers process some technical metadata:
- pseudonymous account and device identifiers as well as the public keys of your devices,
- which accounts belong to a family circle and the permissions granted there (for example, who may invite members),
- when you deliberately open a family circle in the foreground, so that we can apply the retention periods described in section 11 reliably,
- timestamps, version counters, and the size of encrypted data packages,
- the status and technical identifiers of invitations and guest links, never their secret decryption keys.
This metadata contains no content. It is required to deliver changes to the right devices, enforce permissions, and prevent abuse. Legal basis: Art. 6(1)(b) GDPR.
When the app starts, it may use Expo to check for and download an app update suitable for your device. This involves technically necessary connection and update data, including the IP address, platform, app and runtime versions, release channel, and identifiers of the offered and installed update. The purpose is to provide the current app version securely, not advertising or ad measurement. The legal bases are Art. 6(1)(b) and (f) GDPR.
5.6 Purchases and subscriptions
Purchases are handled through the Apple App Store. Apple processes payment details such as your credit card number; we do not receive them.
We use RevenueCat to manage and restore purchases. The data processed includes a pseudonymous identifier linked to your account, product, purchase times, transaction and subscription status, purchase history, and technical details such as device type and operating system. RevenueCat also processes the necessary purchase receipts. We use this to assign purchases to your family circle, enable restoration, prevent purchase fraud, and analyse purchase history for operational purposes. The legal bases are Art. 6(1)(b) GDPR for purchase management and restoration, and Art. 6(1)(f) for fraud prevention and operational analytics.
Deleting your account does not cancel your Apple subscription. In our own systems, we keep a minimal deletion and purchase record to assign later restorations securely. Limited billing data also remains where necessary. These records contain pseudonymous identifiers or their hashes, timestamps, and, where applicable, transaction identifier, product, Store environment, and purchase status. They contain no email address, name, family content, key, or signed Apple receipt.
During a restoration you request, we temporarily process old and new purchase identifiers and the necessary transaction details. Transfer data that is no longer needed is removed after completion. The legal bases are Art. 6(1)(b) and (f) GDPR. Retention follows section 11; where necessary, we handle purchase-data deletion requests together with the service providers involved.
5.7 Reminders
Story reminders are scheduled server-side as one shared setting for the relevant story and synchronized between the app and the guest-link browser. We process activation and confirmation status, cadence, local time, time zone, end date, next due time, technical versions, and delivery status. These details contain no story, question, or answer. Purpose: providing the scheduling and delivery that was explicitly requested. Legal basis: Art. 6(1)(b) GDPR.
For push notifications, we store a push token for each signed-in device together with platform, app version, selected app language, and technical delivery information. Expo and Apple Push Notification service (APNs) process the token and the deliberately content-minimized notification for delivery. Push is voluntary and can be disabled in the device settings. The notification contains no story, question, email address, or personal message.
For email reminders, we process the recipient address, language, schedule, confirmation and stop status, and an optional personal message. Addresses and messages are encrypted on the server, but are not end-to-end encrypted: we and Postmark need to read them for delivery. Please do not include private family content or secrets here. The email contains no private answer link and cannot open one; the invited person uses the link privately shared by their family to answer. External recipients must first confirm reminders by email (Art. 6(1)(a) GDPR). Every reminder email lets them stop the entire shared reminder, including any push channel.
5.8 App protection with Face ID or Touch ID
If you enable the optional app protection, the app uses your device's biometric features. Biometric data stays on your device and is handled by the operating system. We receive no biometric data; the app receives only the local confirmation.
5.9 Security and abuse prevention
When the app or the browser communicates with our servers, your device's IP address is processed temporarily for technical reasons in order to answer the request. It is not stored permanently together with your account.
To protect against abuse (for example, mass guessing of links or automated sign-in attempts), we limit how often requests can be made. For this, we process the IP address of the request in the form of a cryptographic hash (SHA-256). We do not store the IP address itself. The hash entries serve abuse detection only and are kept only as long as needed for that purpose. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, abuse-free operation).
5.10 Feedback in the app
When you send feedback in the app, we process the category, message, optional attached images, account and feedback identifiers, language, platform, app and operating-system versions, and timestamps. Location and other EXIF metadata are removed from images before upload.
Feedback is not end-to-end encrypted because our team needs to read it. Supabase stores it with access controls in Frankfurt. Please include only the information we need to handle your request. Internal notifications through Postmark contain neither your feedback text nor images or links to them.
We use feedback for support, troubleshooting, and improving the app. The legal basis is Art. 6(1)(b) GDPR for contract-related requests, and otherwise our legitimate interest under Art. 6(1)(f) GDPR.
5.11 Support
When you contact us by email, we process your email address and the content of your message in order to answer your request. Legal basis: Art. 6(1)(b) GDPR, and for general inquiries Art. 6(1)(f) GDPR.
6. Answering and reminders through a guest link in the browser
A family member can create a private guest link from the app and send it, for example, to grandma. The invited person then answers the questions directly in the browser. The following applies:
- No account and no sign-in are needed. During ordinary reading and answering, we collect neither the invited person's name nor their email address nor any other account data. We process an email address only if that person voluntarily sets up an email reminder.
- The secret part after the # character stays in the browser. It is not sent to our servers or the email provider, including when setting up a reminder.
- Answers and voice recordings are encrypted in the browser before they reach our servers. Here too, we store only encrypted data packages.
- Unsent answer drafts and the chosen display language are stored only locally in the browser (localStorage). A reminder save not yet confirmed by the server is stored in IndexedDB, encrypted with a key derived from the private link, until the server confirms it or you clear browser data. These technically necessary storage operations are based on Section 25(2)(2) of the German TDDDG.
- For reminders, you can select an authorised person in the family circle or an external email address. The member picker shows only the necessary display names, not account email addresses. External addresses first receive a confirmation email. Other reminder data is processed as described in section 5.7.
- The guest pages contain no cookies, no analytics tools, and no tracking.
- For abuse prevention, we process hashed IP addresses when a link is opened and when answers are submitted, as described in section 5.9.
The legal basis for processing when answering through a guest link is Art. 6(1)(b) GDPR with respect to the person answering (providing the answering feature) and otherwise Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the family circle).
Good to know: anyone who has the complete link can read and change the answers given through that link. The link should therefore be treated like a key and shared only with the person it is meant for. The link can be renewed in the app at any time; the old link then becomes invalid.
7. Website
When you visit familystories.love, our hosting provider Vercel (section 9) processes the technically necessary connection data (in particular IP address, time of access, page requested, browser type) in server logs in order to deliver the website and ensure its security and stability. Legal basis: Art. 6(1)(f) GDPR.
For audience measurement, we use Vercel Web Analytics. It may process the timestamp, page URL and route, referrer, filtered query parameters, location derived from the IP address, browser and operating-system versions, device type, and analytics-script version. The tool works without cookies or cross-device tracking. Visits are evaluated only in aggregate and are not tied to a person or stored IP address. The daily identifier derived from the request expires after 24 hours, so no lasting profile or cross-session browsing history is created. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly audience measurement).
The website sets no advertising or tracking cookies. The guest link pages are fully excluded from audience measurement.
If you sign up for the one-time message announcing the app launch, we process your email address, selected language, and sign-up time solely to send that requested message. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time by emailing support@familystories.love. We delete the entry after sending the message or an earlier withdrawal, unless a legal obligation requires otherwise.
We store technically necessary settings in cookies and your browser's local storage for the language you expressly select. They are used only to display the website in that language and avoid showing the language selector again after you have made a choice. The basis for this storage is section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG).
8. Legal bases at a glance
- Art. 6(1)(b) GDPR (performance of a contract): account, synchronization, family circle, explicitly configured reminder scheduling, purchases, support and feedback related to your account.
- Art. 6(1)(f) GDPR (legitimate interests): general feedback and improvement of the app, security and abuse prevention including purchase fraud, operational analysis of purchase history, server logs, and privacy-friendly website audience measurement.
- Art. 6(1)(a) GDPR (consent): an external email reminder starts only after confirmation through the email sent to you and can be stopped through every reminder email. The website launch message is also based on your consent. Independently, you control device permissions for the microphone, photo selection, and notifications in your device settings.
- Art. 6(1)(c) GDPR (legal obligation): retention where required by law (for example, tax-law obligations relating to purchase records).
9. Recipients and processors
We use the following service providers. Before engaging them and throughout the relationship, we check that they process personal data under the same or equivalent safeguards. Where they act as our processors, agreements under Art. 28 GDPR are in place.
Supabase Inc. (USA)
Data hosted in Frankfurt am Main, Germany (AWS, region eu-central-1). Purpose: account and sign-in, database, preparation of email, server functions, reminder scheduling, push-token management, storage of feedback.
Processes: email address, profile name, optional date of birth, language setting, account and device identifiers, membership and activity details, technical metadata (section 5.5), reminder schedule and status, push token, hashed IP addresses, encrypted data packages, server-side encrypted reminder addresses and messages, email address and language for the one-time launch message, and the readable feedback data and images described in section 5.10.
AC PM LLC (USA), provider of Postmark
Purpose: sending transactional email, in particular sign-in and reminder emails and internal feedback notifications.
Processes: recipient address and email content. Reminder email may also include schedule details and an optional personal message, but never the guest-link fragment. For feedback, this is limited to the category, an opaque feedback identifier, image count, technical information, and timestamps. It never includes the feedback message, account identifier, images, or signed links to them.
650 Industries, Inc. (USA), provider of Expo
Purpose: providing app updates and technically relaying voluntary push notifications to Apple Push Notification service (APNs).
Processes: connection, platform, app, runtime, channel, and update identifiers needed for updates, as well as the device push token and the content-minimized notification. The notification is processed only for delivery and contains no family story, question, email address, or personal message.
Cloudflare Inc. (USA)
Purpose: storage for encrypted voice recordings and photos (R2).
Processes: exclusively end-to-end encrypted media files and technical object metadata (for example, size).
RevenueCat Inc. (USA)
Purpose: purchase and subscription management and restoration, fraud prevention, and operational analysis of purchase history.
Processes: a pseudonymous identifier linked to the account, product and subscription status, purchase times, purchase history, purchase receipts, and technical details such as device type and operating system.
Apple Inc. (USA)
Purpose: app distribution, payment processing, optional Sign in with Apple, and delivery of voluntary push notifications through APNs.
Apple processes payment data as an independent controller; with Sign in with Apple, we receive an email address or relay address and an identifier. For push, Apple processes the device token and content-minimized notification.
Google LLC (USA)
Purpose: optional Sign in with Google and fraud prevention.
When you sign in, we receive an email address, an identifier, and potentially profile details such as your name and profile image. Google's sign-in library may also process a user identifier and the IP address and use it to estimate the device's general location. We receive neither the IP address nor that location from Google. Google processes the sign-in as an independent controller.
Vercel Inc. (USA)
Purpose: hosting the website, cookieless audience measurement.
Processes: connection and server-log data, plus the aggregated page-view, referrer, location, browser, operating-system, and device data described in section 7.
We otherwise disclose personal data only when legally required. We cannot disclose family content in readable form because we do not possess its keys.
10. Transfers to third countries
Your account and operational data and stored feedback data are held in Supabase's Frankfurt region. End-to-end encrypted media files are held in Cloudflare R2 with an EU data location. Some of our service providers are based in the USA or may access systems as part of support and operations. Where personal data is transferred to the USA in this context, we rely on adequacy decisions of the EU Commission (in particular the EU-US Data Privacy Framework, where the provider is certified) and on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
You can request a copy of the safeguards we use by emailing support@familystories.love.
To send transactional email and internal feedback notifications, Postmark (AC PM LLC) processes the minimized data listed in section 9 in the USA. Feedback images, signed links to them, and the secret guest-link fragment are not transferred to Postmark. For app updates and voluntary push notifications, Expo (650 Industries, Inc.) processes the necessary technical data, and APNs relays the content-minimized notification through Apple. The safeguards described in the preceding paragraph apply to these transfers.
Your family content is also unreadable to these service providers because it is end-to-end encrypted.
11. Storage and deletion
- Account: you can delete your account in the app settings immediately or after 30 days. Normal app access ends immediately in either case. You can cancel a scheduled deletion until final processing, but not an accepted immediate deletion. Final deletion removes account data, sign-in, device associations, keys, and personal recovery data. The limited purchase records described in section 5.6 remain to the extent explained there.
- Family content: contributions in a continuing family circle remain encrypted there; references to your account and devices are anonymised. Your own family circle is transferred to an active member with administrator rights or, if there is none, deleted together with its encrypted content and media.
- Free family circles: within 1 GB of storage, they remain available while an active member deliberately opens the circle or explicitly chooses to keep the archive. Six months without such use starts a six-month warning period. The online archive may be deleted no earlier than twelve months in total. Deliberate use resets the period. Background synchronisation does not count as use; your account and other family circles are unaffected.
- After Premium, Family, or trial access expires, the free allowance applies. Above 1 GB, new media uploads wait; existing content remains readable, downloadable, exportable, and deletable. Twelve continuous months above the limit starts a further six-month warning period. Online media may be deleted no earlier than eighteen months in total; text, transcripts, account, and family circle remain.
- After an additional storage package expires, storage above the remaining allowance has a six-month grace period. Restoring sufficient storage or reducing usage below the limit ends this state. Active Premium, Family, trial, Lifetime, and storage entitlements are exempt from plan-related inactivity deletion. Before plan-related deletion, we recheck current entitlements, usage, and protective conditions.
- The free and plan-related deletion periods above are not currently applied automatically. Reaching a deadline alone does not currently delete content. Before activation, we will provide the planned warnings and options to keep or export content.
- Reminders: stopping a reminder ends further deliveries but does not automatically delete the encrypted address, personal message, and configuration. This data may remain to keep the reminder safely stopped and allow a later setup that is deliberately confirmed again. It is removed when the email channel is fully removed or the related story, family circle, or account is deleted, unless a legal obligation requires otherwise. You can request earlier deletion at support@familystories.love.
- Notification device identifiers are disabled or removed on sign-out, account deletion, or proven permanent invalidity. Hashed IP addresses used to prevent abuse are retained only for the short rate-limiting windows and then deleted.
- Feedback: attached images are deleted within 90 days, and the message and other feedback data within twelve months. Incomplete submissions are removed within 24 hours after their reservation expires. Account deletion or a valid request for earlier erasure removes the associated data sooner, unless a legal obligation or overriding retention reason applies.
- Email records: our delivery records for successful feedback notifications are deleted within 30 days. Postmark may retain the email content it processes and related activity data for up to 45 days.
- Website: runtime logs from our website functions are retained for one hour under our current Vercel plan. This period does not apply to all of the provider's security and operational data; those are subject to the retention periods necessary for their respective purposes. Launch notification entries are deleted after the message is sent or consent is withdrawn earlier, unless a legal obligation requires otherwise.
- Purchase data remains for as long as necessary for contract handling, renewals, refunds, secure restoration, preventing duplicate assignment, or legal obligations. The minimal record of a deleted account may remain even without a known purchase assignment while restorable purchases could still be presented later. For Lifetime, this may be a long period.
- You can delete local data by removing the app or clearing browser data. An encrypted reminder request in the browser that has not yet been acknowledged remains until server confirmation or until browser data is cleared.
12. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time, on grounds relating to your particular situation.
An informal email to support@familystories.love is enough to exercise your rights. To protect your account, please write to us from the email address linked to your account.
We cannot read or export your encrypted family content for you. You can view, change, export, and delete it directly in the app. For account, reminder, and other data we can read, you can exercise your rights through our contact address.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (www.ldi.nrw.de); you can also contact the supervisory authority where you live.
13. Responsibility within your family
Your family decides whom to invite and what content to share. Please respect other people's privacy and keep guest links confidential. We remain responsible for the processing by our Services described here; any household exemption that may apply to family members' private activities does not change this.
Permissions within the family circle control who can read and edit stories. The shared family tree is visible and editable by all members. We cannot retrieve copies that have already been downloaded or exported to other people's devices.
14. Children and teenagers
FamilyStories is intended for families. The legal age limits and consent requirements where you live apply to its use. Where required by law, a parent or legal guardian must consent to or be involved in use of the service and the processing of personal data.
Children can contribute family stories together with their parents or legal guardians. The privacy rules described here also apply to them. If you are a parent or guardian with questions or a request to delete a child's data, you can reach us at support@familystories.love.
15. Data security
In addition to end-to-end encryption, we protect your data through, among other things:
- modern, vetted encryption schemes for content and key material,
- storage of device keys in your device's protected key store,
- transport-encrypted connections (TLS) for all communication,
- server-side access controls and permission checks for every request,
- rate limiting and further safeguards against abuse.
No system can guarantee absolute security. On our servers, your family content remains encrypted and unreadable without your family's keys.
16. No advertising, advertising profiles, or AI training
We do not show advertising, sell personal data, or share it for advertising purposes. We do not create advertising profiles or make automated decisions within the meaning of Art. 22 GDPR. Family content and account, reminder, feedback, purchase, and operational data are not used to train our own or third-party AI models.
17. Changes to this privacy policy
We update this privacy policy when our Services or the legal requirements change. You can always find the current version in the app and on our website. If the changes are significant, we will additionally inform you in the app or by email.
18. Contact
For questions about data protection, you can reach us at:
FamilyStories UG (haftungsbeschränkt)
Gewalterberg 1
45277 Essen
Germany
Email: support@familystories.love