Skip to content
KinrelicEvery story, a family relic

Legal

Privacy Policy

Last updated: August 2, 2026

This policy is written in plain language and kept accurate to what the app actually does. If anything here is unclear, email info@kinrelic.com and we will explain it.

What this covers

This policy describes how Kinrelic ("we," "the app") handles information for the family workspaces, stories, recipes, photos, and recordings you and the people you invite create here.

What we store

  • Account info: name, email or phone, and how you sign in.
  • Family content: recordings, photos, transcripts, translations, recipes, comments, and the people/relationships you add — everything a family chooses to preserve.
  • Workspace and membership records: who's in a family workspace, their role, and invitation history.
  • Billing records, handled by our payment processor — we do not store card numbers.
  • An audit log of sensitive actions (who did what, when) for accountability.

Where it lives

Original recordings and photos are stored as immutable files in encrypted object storage with short-lived, signed access links — never a public URL. Everything else lives in an encrypted database. A workspace is private by default: only invited members can see it.

When we look inside your account

Sometimes the only way to fix a problem you've reported, or to help you set something up, is to see your account the way you see it. When that happens:

  • We open a support session that expires automatically after an hour, and we have to write down why we opened it.
  • It is read-only unless we deliberately enable changes — for example because you've asked us to set something up for you.
  • You can see it. Every support session appears in your own activity log, with the reason and the time. You do not have to take our word for it.
  • We never sign in as you. Anything we do is recorded as us, so your family's history never shows you doing something you didn't do.

We don't browse accounts out of curiosity, and we don't use what we see for anything but helping you.

Automated processing

Transcription, translation, and handwriting recognition (for recipe cards) are performed by third-party providers when configured. Only the specific recording, text, or image being processed is sent — never your whole workspace — and results are stored back in your workspace, not retained by us for any other purpose. Where a provider offers it, we prefer processing that is not used to train the provider's models.

Who processes your data (sub-processors)

To run the app we use a small set of vetted providers. They only ever receive the data needed for their specific job, and only when that feature is enabled for this deployment:

  • Speech-to-text: Deepgram (or another transcription provider) — the audio being transcribed.
  • Translation & text features: Anthropic (Claude) — the transcript or text being translated, summarized, or corrected (fixing misheard names and places), split into chapters, or turned into follow-up questions.
  • Reading handwriting: Anthropic (Claude) — a photo of a handwritten recipe card, when you ask us to type it up for you.
  • Media storage: Cloudflare R2 (or S3-compatible storage) — your recordings and photos, encrypted.
  • Database & hosting: the platform this deployment runs on (e.g. Render).
  • Sign-in: Clerk — your login identity.
  • Email: Resend — to send invites, reminders, and codes.
  • SMS & phone calls: Twilio — to send codes and to place recorded interview calls.
  • Payments: Stripe — billing only; we never see your card number.
  • Error monitoring: Sentry — diagnostic error reports, no family content.
  • Site & product analytics: PostHog — funnel counts (visits, signups, purchases) always, without a cookie; on our public marketing pages, only if you agree, also basic visit analytics (pages viewed, roughly where from, device type). Never once you are signed in.
  • Advertising measurement: Meta (Facebook) — only on our public marketing pages, only if you agree, and never once you are signed in. Meta receives that a visit or sign-up happened; it never receives family content.

Several of these providers are based in the United States, so enabling them may involve an international transfer of the specific data sent for processing. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards such as the providers' Standard Contractual Clauses. A data processing addendum (DPA) is available to business customers on request.

Cookies, analytics and advertising measurement

Inside the app we use only essential cookies — the ones needed to sign you in and keep your session secure. Our product analytics (how many people record a story, upgrade, and so on) run server-side, without a cookie, even for signed-out visitors. So once you're signed in, nothing else tracks you and there is nothing further to consent to.

On our public pages only — the homepage, pricing, guides and similar — we may also load, with your agreement, PostHog's browser analytics (to see how many people visit, roughly where from, and on what device — no session recording, no individual profile) and the Meta (Facebook) advertising pixel (to tell whether our ads reach people who are actually looking for something like this). Either sets a cookie; PostHog tells us a page was viewed, Meta tells it that a visit or a sign-up happened.

  • Neither loads until you say yes. We ask once, and nothing is requested from either before you agree — not even downloaded, let alone run. Declining is one tap and exactly as easy as accepting.
  • Neither runs inside your archive. The moment you sign in, neither is on the page at all. No vendor is ever told which stories, recordings, people or recipes you look at, or that you looked at anything.
  • You can change your mind at any time, using the control below.

Biometric information (faces & voices)

Some features work with biometric information. Photo face tagging can detect and group faces so you can find who's in a picture, and voice features can recognise a storyteller's voice across recordings to label who is speaking. Where face detection is enabled, we ask for per-person consent before it runs, and any face or voice data derived for matching is used only inside your workspace to power those features — never sold, never used to identify strangers, and never used to train anyone's models. You can turn these features off and delete the derived data at any time. Some regions (for example, Illinois' BIPA and the EU's GDPR) treat face and voice data as sensitive and require explicit consent — by enabling these features you confirm you have that consent for the people involved.

Retention and destruction. We keep face and voice matching data only while the feature is enabled and the workspace is active, and we permanently destroy it when you turn the feature off, delete the person or media, delete the workspace, or within 3 years of the person's last interaction with the feature — whichever comes first. We never sell, lease, or otherwise profit from biometric information.

Genetic information (DNA)

If you choose to import a DNA summary (ethnicity estimate and match list from a service like Ancestry, MyHeritage, or 23andMe), we store only that summary — never your raw genetic data. Genetic information is a special category of data; we use it only to show ancestry inside your family workspace, we never sell or share it, and you can delete it at any time from the person's DNA page.

Children's information

Kinrelic is intended for adults to preserve their family's history; account holders must be adults (18 or older). Families naturally record and add information about children (photos, birthdays, stories). That content stays private to your workspace and is treated with the same care as everything else — never sold, never advertised against. If you record or add a child, do so with the agreement of their parent or guardian, and a workspace owner can remove any content about a child on request. We do not knowingly let a child create their own account, and we do not knowingly collect information directly from children.

Recording other people

Kinrelic is built to preserve storytellers' and relatives' own words. Please only record someone with their knowledge and agreement, and give them the same control over their stories that you'd want over yours. If someone asks to have a recording of them removed, the workspace owner can delete it.

Phone calls and text messages

If you enable the optional phone interviewer or SMS reminders, Kinrelic may call or text the storytellers you choose, using an automated system, at the numbers your family provides — you confirm you have their permission to be contacted this way. Interview calls begin with a spoken notice that the call is being recorded, so the storyteller can decline by hanging up. Message frequency varies; standard message and data rates may apply. Reply STOP to any text to opt out, or HELP for help. You can also turn calls and texts off per person in their profile.

Information about other people

A family archive is inherently about other people — relatives living and passed. When you add or record someone, you're responsible for having a lawful basis to do so (their agreement, or your own family/household relationship). For that content we act on your behalf as a processor: it stays private to your workspace, we don't use it for our own purposes, and if a person asks, the workspace owner can correct or remove information about them. If you received a request about your data in a family's workspace, contact that workspace's owner, or us.

People who have passed

Much of a family archive honors people who have died. We treat their stories, photos, and recordings with the same privacy as everyone else's. Their recordings are always played back exactly as they were recorded — we never synthesise anyone's voice, living or dead. An optional feature that would have answered questions in a passed person's words is not currently offered; if we ever bring it back, we will describe precisely what it does before anyone can switch it on, and it will require a recorded consent basis.

Automated features and AI

Transcription, translation, handwriting recognition, story suggestions, and the optional "ask a relative" feature are automated aids that work on the specific content you give them. They don't make decisions that have legal or similarly significant effects about anyone, and we don't use your family's content to train anyone's general-purpose models. You can review, edit, or turn off these features, and originals are always kept unaltered underneath.

What we don't do

  • We never sell your data.
  • We never use your family's stories, photos, or recordings to train machine-learning models.
  • We don't run any third-party advertising or tracking inside the app itself — not on a single signed-in page. On our public marketing pages we may use browser analytics and an advertising pixel, and only with your agreement (see Cookies above).
  • We don't share workspace content with anyone outside the workspace you control.

Your rights

We process your data to provide the service you asked for (our contract with you), to keep it secure, and — for the optional AI features — on the basis of the consent you give by enabling them. Depending on where you live (for example under the EU/UK GDPR or California's CCPA/CPRA), you have the right to access, correct, delete, and export your data, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these yourself from Settings (export and account deletion), or email us. We do not sell or share your personal information, and we will never discriminate against you for exercising a privacy right.

Your controls

  • Export everything, any time, from Settings — a complete copy of your family's data.
  • Delete individual items; they wait in Trash until you restore them. Nothing is removed on a timer — when you want something gone for good, the account owner can delete it forever from Trash, which erases the file itself immediately.
  • Delete your account from Settings — this revokes your access everywhere and anonymizes your personal details (name, email). We keep a non-identifiable placeholder only where it's needed to preserve the authorship of stories other family members created, so their archive stays intact. If you're the sole owner of a workspace others still use, you'll be asked to transfer ownership first so the family doesn't lose access to their own archive.
  • Control who can see each story — visible to the whole family, or just to you.

Retention

We keep your data as long as your workspace is active. Deleted items are recoverable for a configurable window (30 days by default) before permanent removal. Audit log entries are kept longer for accountability, per the retention period configured for this deployment.

Security and data breaches

We protect your data with encryption in transit and at rest, signed short-lived links for media, and workspace isolation so one family can never see another's. No system is perfectly secure, but if a breach ever affects your personal data, we'll notify affected users and any regulators as required by law, without undue delay.

Who we are, and questions

Kinrelic is the data controller for your account and workspace data. For anything about this policy or your data, contact the family workspace owner, or reach us at privacy@kinrelic.com. We'll always try to resolve concerns directly; if you're in the UK/EEA you also have the right to lodge a complaint with your local data protection supervisory authority.