Legal
Privacy Policy
Last updated: July 20, 2026
What this covers
This policy describes how Kinrelic ("we," "the app") handles information for the family workspaces, stories, recipes, photos, and recordings you and the people you invite create here.
What we store
- Account info: name, email or phone, and how you sign in.
- Family content: recordings, photos, transcripts, translations, recipes, comments, and the people/relationships you add — everything a family chooses to preserve.
- Workspace and membership records: who's in a family workspace, their role, and invitation history.
- Billing records, handled by our payment processor — we do not store card numbers.
- An audit log of sensitive actions (who did what, when) for accountability.
Where it lives
Original recordings and photos are stored as immutable files in encrypted object storage with short-lived, signed access links — never a public URL. Everything else lives in an encrypted database. A workspace is private by default: only invited members can see it.
When we look inside your account
Sometimes the only way to fix a problem you've reported, or to help you set something up, is to see your account the way you see it. When that happens:
- We open a support session that expires automatically after an hour, and we have to write down why we opened it.
- It is read-only unless we deliberately enable changes — for example because you've asked us to set something up for you.
- You can see it. Every support session appears in your own activity log, with the reason and the time. You do not have to take our word for it.
- We never sign in as you. Anything we do is recorded as us, so your family's history never shows you doing something you didn't do.
We don't browse accounts out of curiosity, and we don't use what we see for anything but helping you.
Automated processing
Transcription, translation, and handwriting recognition (for recipe cards) are performed by third-party providers when configured. Only the specific recording, text, or image being processed is sent — never your whole workspace — and results are stored back in your workspace, not retained by us for any other purpose. Where a provider offers it, we prefer processing that is not used to train the provider's models.
Who processes your data (sub-processors)
To run the app we use a small set of vetted providers. They only ever receive the data needed for their specific job, and only when that feature is enabled for this deployment:
- Speech-to-text: Deepgram (or another transcription provider) — the audio being transcribed.
- Translation & text features: Anthropic (Claude) — the transcript or text being translated, summarized, or corrected (fixing misheard names and places), split into chapters, or turned into follow-up questions.
- Reading handwriting: Anthropic (Claude) — a photo of a handwritten recipe card, when you ask us to type it up for you.
- Media storage: Cloudflare R2 (or S3-compatible storage) — your recordings and photos, encrypted.
- Database & hosting: the platform this deployment runs on (e.g. Render).
- Sign-in: Clerk — your login identity.
- Email: Resend — to send invites, reminders, and codes.
- SMS & phone calls: Twilio — to send codes and to place recorded interview calls.
- Payments: Stripe — billing only; we never see your card number.
- Error monitoring: Sentry — diagnostic error reports, no family content.
Several of these providers are based in the United States, so enabling them may involve an international transfer of the specific data sent for processing. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards such as the providers' Standard Contractual Clauses. A data processing addendum (DPA) is available to business customers on request.
Cookies
We use only essential cookies — the ones needed to sign you in and keep your session secure. We don't use advertising or cross-site tracking cookies, and our product analytics run server-side without cookies, so there's no consent banner to click through.
Biometric information (faces & voices)
Some features work with biometric information. Photo face tagging can detect and group faces so you can find who's in a picture, and voice features can recognise a storyteller's voice across recordings to label who is speaking. Where face detection is enabled, we ask for per-person consent before it runs, and any face or voice data derived for matching is used only inside your workspace to power those features — never sold, never used to identify strangers, and never used to train anyone's models. You can turn these features off and delete the derived data at any time. Some regions (for example, Illinois' BIPA and the EU's GDPR) treat face and voice data as sensitive and require explicit consent — by enabling these features you confirm you have that consent for the people involved.
Retention and destruction. We keep face and voice matching data only while the feature is enabled and the workspace is active, and we permanently destroy it when you turn the feature off, delete the person or media, delete the workspace, or within 3 years of the person's last interaction with the feature — whichever comes first. We never sell, lease, or otherwise profit from biometric information.
Genetic information (DNA)
If you choose to import a DNA summary (ethnicity estimate and match list from a service like Ancestry, MyHeritage, or 23andMe), we store only that summary — never your raw genetic data. Genetic information is a special category of data; we use it only to show ancestry inside your family workspace, we never sell or share it, and you can delete it at any time from the person's DNA page.
Children's information
Kinrelic is intended for adults to preserve their family's history; account holders must be adults (18 or older). Families naturally record and add information about children (photos, birthdays, stories). That content stays private to your workspace and is treated with the same care as everything else — never sold, never advertised against. If you record or add a child, do so with the agreement of their parent or guardian, and a workspace owner can remove any content about a child on request. We do not knowingly let a child create their own account, and we do not knowingly collect information directly from children.
Recording other people
Kinrelic is built to preserve storytellers' and relatives' own words. Please only record someone with their knowledge and agreement, and give them the same control over their stories that you'd want over yours. If someone asks to have a recording of them removed, the workspace owner can delete it.
Phone calls and text messages
If you enable the optional phone interviewer or SMS reminders, Kinrelic may call or text the storytellers you choose, using an automated system, at the numbers your family provides — you confirm you have their permission to be contacted this way. Interview calls begin with a spoken notice that the call is being recorded, so the storyteller can decline by hanging up. Message frequency varies; standard message and data rates may apply. Reply STOP to any text to opt out, or HELP for help. You can also turn calls and texts off per person in their profile.
Information about other people
A family archive is inherently about other people — relatives living and passed. When you add or record someone, you're responsible for having a lawful basis to do so (their agreement, or your own family/household relationship). For that content we act on your behalf as a processor: it stays private to your workspace, we don't use it for our own purposes, and if a person asks, the workspace owner can correct or remove information about them. If you received a request about your data in a family's workspace, contact that workspace's owner, or us.
People who have passed
Much of a family archive honors people who have died. We treat their stories, photos, and recordings with the same privacy as everyone else's. The optional "ask a relative" feature can answer in a passed person's voice using only their own recordings — it never invents facts — and it can only be enabled when an authorized family steward affirms consent on the family's behalf. A workspace owner can turn it off and delete it at any time.
Automated features and AI
Transcription, translation, handwriting recognition, story suggestions, and the optional "ask a relative" feature are automated aids that work on the specific content you give them. They don't make decisions that have legal or similarly significant effects about anyone, and we don't use your family's content to train anyone's general-purpose models. You can review, edit, or turn off these features, and originals are always kept unaltered underneath.
What we don't do
- We never sell your data.
- We never use your family's stories, photos, or recordings to train machine-learning models.
- We don't run third-party advertising or ad-tracking on this app.
- We don't share workspace content with anyone outside the workspace you control.
Your rights
We process your data to provide the service you asked for (our contract with you), to keep it secure, and — for the optional AI features — on the basis of the consent you give by enabling them. Depending on where you live (for example under the EU/UK GDPR or California's CCPA/CPRA), you have the right to access, correct, delete, and export your data, to object to or restrict certain processing, and to withdraw consent. You can exercise most of these yourself from Settings (export and account deletion), or email us. We do not sell or share your personal information, and we will never discriminate against you for exercising a privacy right.
Your controls
- Export everything, any time, from Settings — a complete copy of your family's data.
- Delete individual items; they're recoverable from Trash for a limited window, then permanently removed.
- Delete your account from Settings — this revokes your access everywhere and anonymizes your personal details (name, email). We keep a non-identifiable placeholder only where it's needed to preserve the authorship of stories other family members created, so their archive stays intact. If you're the sole owner of a workspace others still use, you'll be asked to transfer ownership first so the family doesn't lose access to their own archive.
- Control who can see each story — visible to the whole family, or just to you.
Retention
We keep your data as long as your workspace is active. Deleted items are recoverable for a configurable window (30 days by default) before permanent removal. Audit log entries are kept longer for accountability, per the retention period configured for this deployment.
Security and data breaches
We protect your data with encryption in transit and at rest, signed short-lived links for media, and workspace isolation so one family can never see another's. No system is perfectly secure, but if a breach ever affects your personal data, we'll notify affected users and any regulators as required by law, without undue delay.
Who we are, and questions
Kinrelic is the data controller for your account and workspace data. For anything about this policy or your data, contact the family workspace owner, or reach us at privacy@kinrelic.com. We'll always try to resolve concerns directly; if you're in the UK/EEA you also have the right to lodge a complaint with your local data protection supervisory authority.