Privacy Policy
Family.Reunions.app
Effective Date: [DATE]
Last Updated: [DATE]
1. Introduction
Family.Reunions.app ("the Service," "we," "us," or "our") is operated by [COMPANY LEGAL NAME] ("the Company"). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, who we share it with, and the rights you have with respect to it.
Family.Reunions.app is a private, invitation-only platform designed to help families gather online, share memories, and maintain connections between events. Access to every family space requires explicit approval by a family administrator — no one can join a family simply by signing up. We recognize that families will share sensitive personal content — including photographs, relationship data, and information about children and elderly relatives — and we have built the Service with privacy as a foundational principle.
By creating an account or using the Service, you agree to the practices described in this Privacy Policy.
2. Who This Policy Applies To
This policy applies to:
- Independent account holders (age 13 and over) who register directly or through a supported OAuth provider
- Guardian-linked minor accounts (under age 13) created and managed by a parent or legal guardian who is a verified family member — see Section 9
- Event guests with limited, event-scoped access
- Visitors to our public-facing pages
Family.Reunions.app is designed for whole-family participation, including children. Children under 13 may have their own accounts on the Service, but only through the guardian-linked account process described in Section 9. OAuth sign-in (Google, Apple) is available for independent accounts only and is not used for guardian-linked minor accounts.
3. Information We Collect
3.1 Account Information
When registering with email and password:
- Email address
- Password (stored as a cryptographic hash — we never store your plain-text password)
- Display name
- Date of birth (collected on first sign-in to confirm age eligibility)
When registering or signing in with Google OAuth:
We receive from Google the following information associated with your Google account:
- Email address
- Display name
- Profile photo URL
- A unique Google account identifier
We do not receive your age, phone number, or any other data from Google beyond the above. We store the Google account identifier to link your Family.Reunions.app account to your Google account for future sign-ins.
When registering or signing in with Sign in with Apple:
We receive from Apple the following information:
- Email address (which may be a private relay address of the form
abc123@privaterelay.appleid.comif the user chooses to hide their real email) - Display name (only on first sign-in; Apple does not re-send this on subsequent authentications)
- A unique Apple account identifier
We do not receive your age or any other data from Apple beyond the above. We store the Apple account identifier as the canonical identifier for your account. If you sign in with Apple and choose to hide your email, your Apple account identifier — not your email — is used to recognize your account on future sign-ins.
When a parent or guardian creates a guardian-linked minor account:
In addition to the child's display name and a parent-set username and password for the child's account, we collect and log:
- The parent or guardian's authenticated user ID (establishing their verified identity within the family space)
- An explicit consent declaration, timestamped and linked to the parent's account
- The child's date of birth (confirming minor status)
- The IP address at the time of consent, retained as part of the consent record
All account types: We collect date of birth on first registration or first sign-in for age verification purposes. For OAuth sign-ins, this is collected during the onboarding step that follows the initial OAuth authentication, since OAuth providers do not share age data with us.
3.2 Profile Information
When a profile is completed, users (or a parent on behalf of a minor) may provide:
- Full name and nickname
- Profile photo and banner image
- Birthday and age-display preference
- Biography and personal notes
- Physical location (city, state, country)
- Geographic coordinates (latitude and longitude) for the family map feature
- Contact information, including phone number and address
- Emergency contact details
- Social profile links
- Relationship references to other family members (spouse, parents, children)
All profile fields are optional unless otherwise noted. Sensitive fields — including phone number, physical address, and emergency contact information — are not visible to event guests by default and are subject to the account holder's own privacy settings. For guardian-linked accounts, profile visibility settings are managed by the parent or guardian.
3.3 Family and Relationship Data
As part of the family tree, directory, and family unit features, we store:
- Family membership records (which family spaces you belong to and your role within each)
- Relationship data connecting you to other family members
- Ancestor profiles, including names, dates, places, biographical notes, and memorial content
- Family unit groupings (household associations)
- For guardian-linked accounts: the link between the child account and the parent or guardian account
3.4 Family Media
When you or other family members upload content, we store:
- Photos (JPEG, PNG, GIF, WebP)
- Videos (MP4, WebM, OGG)
- Audio clips (MP3, WAV, OGG)
- Other family artifacts you choose to upload
- Metadata associated with uploaded media, including captions, tags, associated people, capture dates, and geographic locations
Images are stored in Backblaze B2 cloud object storage and delivered via TwicPics (our content delivery network). See Section 6 (Third-Party Services) for details.
3.5 Communications
We store the content of room chat messages (persistent per room), direct messages between family members, and event announcements created by organizers or administrators. These are accessible to family members according to role-based permission settings. For guardian-linked accounts, parents and guardians may review their child's messages and activity.
3.6 Calendar and Event Data
We store events you create or are invited to (including titles, descriptions, dates, and times), RSVP responses, and calendar entries including birthdays, anniversaries, and in-person events.
3.7 Location Data
We store geographic coordinates (latitude and longitude) if a user voluntarily adds their location to their profile for the family map feature. Providing location data is entirely optional. For guardian-linked accounts, location data may only be added by the parent or guardian.
3.8 Presence and Activity Data
To support real-time "who is online" indicators, we briefly record when you were last active, which area of the platform you are currently using, and event-scoped presence information. Presence data is transient and expires automatically within minutes of inactivity.
3.9 Device and Technical Data
We automatically collect IP addresses (in server access logs), browser type and version (via standard HTTP headers), and application errors and stack traces (for debugging). Camera and microphone preferences are stored in your browser's local storage and are never transmitted to our servers. See our Cookie and Session Notice for details.
We do not use technical data to build advertising profiles or to track users across other websites or services.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate identity (including via Google OAuth and Sign in with Apple) and maintain logged-in sessions
- Display profiles, presence, and family content to authorized family members
- Enable video meetings, room chat, direct messaging, and other communication features
- Power the family directory, family tree, calendar, and family map
- Deliver invitation and magic-link authentication emails
- Detect and diagnose technical errors and performance problems
- Maintain consent records for guardian-linked minor accounts
- Enforce our Terms of Service and Acceptable Use Policy
- Comply with applicable legal obligations, including responding to lawful legal process
We do not sell personal information. We do not use personal information for advertising.
5. Information Shared Within Your Family Space
Family.Reunions.app is built around private, family-scoped spaces. By default, profiles and content are visible only to verified members of a family. Event guests have a narrower, event-scoped view and cannot access general family content.
Family administrators can view and manage membership, roles, and administrative data for their family space. An audit log of administrative actions is retained and accessible to family administrators. Parents and guardians can view the activity and profile of their linked child accounts.
6. Third-Party Services
We rely on the following third-party service providers to operate the Service. By using Family.Reunions.app, you acknowledge that your data may be processed by these providers in accordance with their own privacy policies.
6.1 Google OAuth (Sign in with Google)
If you choose to sign in using your Google account, your authentication is handled by Google LLC. We receive your name, email address, profile photo, and unique Google account identifier. Google's privacy policy governs the authentication process on Google's side: https://policies.google.com/privacy. We do not receive your Google password or any data beyond what is listed in Section 3.1.
6.2 Apple Sign In
If you choose to sign in using your Apple ID, your authentication is handled by Apple Inc. We receive your name (on first sign-in only), email address or relay address, and unique Apple account identifier. Apple's privacy policy governs the authentication process on Apple's side: https://www.apple.com/legal/privacy/. We do not receive your Apple ID password or any data beyond what is listed in Section 3.1.
6.3 Jitsi Meet
Video rooms are powered by Jitsi Meet. When you join a video room, your audio, video, and any shared screen content are processed by Jitsi's infrastructure. Jitsi Meet is operated by 8x8, Inc. Their privacy policy: https://www.8x8.com/privacy-policy.
Implementation note: If you subsequently deploy a self-hosted Jitsi instance, update this section to reflect that video data is processed on your own infrastructure.
6.4 Backblaze B2
Photos and images are stored in Backblaze B2 cloud object storage. Backblaze's privacy policy: https://www.backblaze.com/company/privacy.html.
6.5 TwicPics
Images are delivered through TwicPics, a content delivery and image optimization service. TwicPics' privacy policy: https://www.twicpics.com/privacy.
6.6 YouTube
When family members share content via YouTube links, those videos are embedded from YouTube's servers. Embedded YouTube players are subject to Google's privacy policy: https://policies.google.com/privacy. We do not upload content to YouTube on behalf of users.
6.7 Email Delivery
We use an SMTP email service to send transactional emails, including magic-link authentication emails and family invitations. Email delivery logs may be retained by our email provider consistent with their terms of service.
6.8 Hosting
The Service runs on servers operated by OVHcloud. OVHcloud's privacy information: https://www.ovhcloud.com/en/personal-data-management/.
7. Data Retention
We retain personal data for as long as an account is active or as needed to provide the Service. Specifically:
- Account data is retained until the account is closed.
- OAuth identifiers (Google or Apple account IDs) are retained as long as your account exists and are removed upon account closure.
- Profile and family content is retained for the lifetime of the family space.
- Room chat and direct messages are retained until deleted by an authorized user or until the family space is closed.
- Presence data expires automatically within minutes of inactivity.
- Parental consent records for guardian-linked accounts are retained for the lifetime of the child's account and for a reasonable period thereafter, as required to demonstrate compliance with applicable law.
- Server access logs (including IP addresses) are retained for [30 / 60 / 90] days. (Choose and confirm.)
- Error reports are retained until administratively resolved or cleared.
- Audit logs of administrative actions are retained for [period].
When an account is closed, we will delete or anonymize personal account data. Content created within a shared family space may remain visible to other family members unless separately removed.
8. Your Privacy Rights
Depending on your location, you may have rights including access, correction, deletion, portability, restriction, and objection with respect to your personal data.
California residents (CCPA): You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of your personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
EEA and UK residents (GDPR / UK GDPR): You have rights under applicable data protection law, including the right to lodge a complaint with your local supervisory authority.
Requests on behalf of minors: A parent or guardian may exercise privacy rights on behalf of a child whose account they manage. We will verify the guardian relationship before acting on any such request.
To exercise your rights, contact us at [LEGAL CONTACT EMAIL]. We will respond within 30 days.
9. Children's Privacy and Guardian-Linked Accounts
9.1 Our Approach
Family.Reunions.app is designed for whole-family participation, and we want children to be full participants in family reunions — with their own presence, their own name on screen, and their own voice in the room. At the same time, we take children's privacy seriously and comply with the Children's Online Privacy Protection Act (COPPA) and applicable international children's privacy requirements.
Children under 13 may have accounts on the Service, but only through the guardian-linked account process described below. OAuth sign-in (Google, Apple) is not available for guardian-linked minor accounts. Children authenticate using a username and password set by their parent or guardian.
9.2 The Guardian-Linked Account Process
A child under 13 cannot self-register. Only a parent or legal guardian who is already a verified member of the family space may create a child account. The creation process:
- The parent or guardian initiates account creation from within their own authenticated account settings
- The parent or guardian provides the child's display name, a chosen username, and a password for the child's account
- The parent or guardian provides the child's date of birth
- The parent or guardian reviews and accepts a consent declaration stating: "I am the parent or legal guardian of this child. I consent to the creation of a Family.Reunions.app account for them and to the collection and use of their information as described in the Privacy Policy."
- The consent declaration is logged with a timestamp, the parent's user ID, the child's account ID, and the IP address at the time of consent
This process satisfies COPPA's verifiable parental consent requirement in the context of a private, invitation-only platform: the parent's verified family membership establishes their identity and their relationship to the family space, and their explicit in-session consent action creates a documented, auditable record.
9.3 What Guardian-Linked Accounts Can Do
Guardian-linked accounts are full participants in the reunion experience: they appear in rooms with their own name and camera, can send chat messages, and have their own profile visible to family members. Their capabilities are limited compared to adult accounts:
- They cannot create events
- They cannot send direct messages to event guests
- They cannot hold administrative roles
- Their profile visibility and privacy settings are managed by the parent or guardian
9.4 Parent and Guardian Controls
The parent or guardian account includes a "Managed accounts" section in settings where they can:
- View the child's profile
- Review the child's activity within the Service
- Update the child's profile, username, password, and privacy settings
- Suspend or delete the child's account at any time
9.5 Conversion at Age 13
When a guardian-linked account holder reaches age 13, the Service will present an option to convert the account to an independent account. Conversion requires the account holder to confirm their credentials and, if they choose, connect an OAuth provider or update their email address. The parental link is removed after conversion; ongoing parental access to account settings and activity is not retained unless the now-13-year-old chooses to share it.
9.6 No Self-Registration for Under-13s
We do not knowingly permit children under 13 to self-register or to authenticate via OAuth (which requires their own Google or Apple account, also restricted to 13+). If we discover that a child under 13 has created an account outside the guardian-linked process, we will suspend the account and contact the family administrator. Contact us at [LEGAL CONTACT EMAIL] if you believe this has occurred.
10. Security
We implement reasonable technical and organizational measures to protect personal data, including:
- HTTPS (TLS encryption) for all data in transit
- HTTP-only, cryptographically signed session cookies
- Secure OAuth state parameter handling using short-lived, single-use tokens
- Password hashing — we do not store plain-text passwords
- Role-based access controls limiting data visibility by permission level
- Audit logging for sensitive administrative actions
- Private-by-default family spaces with no publicly accessible content
- Consent logging for guardian-linked minor accounts
No system is perfectly secure. We encourage strong, unique passwords and prompt reporting of any suspected unauthorized access to [LEGAL CONTACT EMAIL].
11. International Data Transfers
The Service is hosted on infrastructure located in [confirm OVHcloud region]. If you access the Service from outside that region — including from EU or UK member states — your data may be transferred to and processed in a jurisdiction with different data protection laws. By using the Service, you acknowledge this. We process EU and UK residents' personal data on the basis of legitimate interests in providing a private family communication service, and we honor applicable data subject rights as described in Section 8.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date at the top of this page when we do. For material changes, we will notify family administrators by email or by a prominent notice within the Service at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
[COMPANY LEGAL NAME]
[Mailing address, if applicable]
[LEGAL CONTACT EMAIL]