Your privacy in brief
- We never sell your data, never use it for advertising, and never train AI on your content.
- Living people are private by default; only people in your family, within your sharing settings, can see your content.
- Face recognition is off until you switch it on for yourself, and you can switch it off again at any time.
- Your family content stays in the EU, with a handful of named providers.
- You can request export or erasure and exercise your GDPR rights; lawful retention of shared content and necessary transaction evidence is assessed separately.
- Mollie independently controls payment services; privacy acknowledgement is separate from optional processing consent.
This summary is for orientation only and is not legally binding; the full policy below governs.
This policy explains how beinand staging ("we", "us") processes personal data when you and your relatives use our private family network, in line with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Who is responsible
In short: we run and secure beinand staging; your household decides what to record about people, and we share responsibility for that.
The controller is , (VAT ). For any data-protection matter — including to exercise your rights, withdraw consent, or request our processor list or transfer safeguards — contact us at hello@beinand.app. Full operator details are in our Imprint. We have not appointed a Data Protection Officer.
For the family content you and your relatives create, we act as a joint controller with your household (Art. 26 GDPR) in respect of the functions we organise. In essence: we are responsible for hosting and storage, security, the visibility engine, retention and for answering your data-subject requests; your household (represented by its founder/owner) is responsible for the accuracy and lawfulness of the content it enters about people. You can exercise your rights against us directly (Art. 26(3) GDPR); where needed we route a request to the right place. We are the sole controller for your account, billing, security and operational logs. The essence of the arrangement is summarised here; the full terms are available on request.
2. What data we process
In short: your account, family content, photos and service data; purchases also produce payment and contract evidence.
- Account data: name, email address, language preference, password hash, two-factor/passkey credentials, sessions.
- Family-tree & wiki content: names, dates, places, relationships, stories, notes and documents about you and your relatives — living and deceased.
- Photos and their metadata. When you select a photo, we read its embedded EXIF data to pre-fill the capture date and, if present, the GPS coordinates of where it was taken; you can confirm, change or clear these before saving, and the place name is a free-text field you type yourself. If you save coordinates, they are stored with the photo and visible to the same household members who can see the photo. To share less, remove location data from a photo before uploading, or simply clear the suggested coordinates. We read only what we need for these features (data minimisation, Art. 5(1)(c) GDPR). Where face detection is enabled, we locate faces and store rectangular regions so members can select a person manually; this step does not create identity faceprints. Separately, where enabled, we also process biometric face data (a mathematical face template) used to recognise people.
- Special categories of data (Art. 9 GDPR) that family records can contain — for example religion, health (including cause of death), ethnic origin or relationships.
- Usage & technical data needed to run and secure the service (log files, device/browser data, and push-notification subscriptions you opt into — you can turn push notifications off again at any time under Settings, or in your browser or device settings).
- Payment and contract data: If you buy a pass, upgrade or gift code, we process your name and email address, order reference, selected plan, amounts and currency, payment status and provider reference, receipt and refund records, declared country and available country evidence, service dates, and the legal documents, product descriptions and early-start request recorded with the order. We do not store your card number or full bank-account details. Withdrawal and cancellation declarations contain the information you submit, including any cancellation reason; we record their receipt time and technical abuse-prevention data.
3. Why we process it, and our legal bases
In short: to give you the service, on the legal grounds the GDPR requires for each purpose.
- To provide the service (your account, the app's features) — performance of a contract, Art. 6(1)(b).
- We process your own uploads as necessary to provide the family-network service you requested, Art. 6(1)(b). Information about other living people requires its own legal basis; your account or payment does not make them parties to your contract. The rules for relatives' data and special-category data in this section continue to apply.
- Data about living relatives entered by other members — our and the family's legitimate interest, Art. 6(1)(f). Our specific interest is operating the family-history service our members signed up for and keeping the shared tree accurate, connected and useful; the family's interest is preserving its shared history. We carried out a balancing test (a legitimate-interests assessment), which we make available on request; this basis does not extend to making anyone's data public, and you can object at any time (section 10).
- Face recognition (biometric data) — your explicit consent, Art. 9(2)(a). It is off by default and opt-in per person; we only compute and store a face template for the deceased or for a living person who has switched recognition on for themselves. A non-biometric alternative (manual tagging) is always available, and you can withdraw at any time, after which we delete your template.
- The Health feature (your medical history) — your explicit consent, Art. 9(2)(a). It is entirely opt-in: you record your own blood type, allergies and conditions and share them only with the close family circle you choose; partner-guest accounts never see them. You can change the audience or delete the record at any time, and withdrawing consent deletes it. You may also record the known medical history of deceased adult relatives (the deceased are outside the GDPR, Recital 27); we do not aggregate or infer health conditions across the family.
- Other special-category data in records (e.g. health, religion) — only on the basis of explicit consent or another Art. 9(2) condition. Please do not enter sensitive data about living people who have not agreed to it; where such data is entered without a valid basis, we will restrict or erase it on request or objection.
- Security, abuse prevention and logging — our legitimate interest in a safe service, Art. 6(1)(f).
- We record which version of the terms you accepted and which privacy notice you acknowledged, and when. These records document the contractual agreement and the information supplied to you. Acknowledging the privacy notice is not consent to all processing described in it.
- Optional processing that relies on consent, including the relevant health and biometric features, has separate choices and records. Accepting the terms or acknowledging this notice does not grant those permissions.
- We process purchases, payments, refunds and contractual declarations to perform the purchase contract, Art. 6(1)(b) GDPR. We retain required tax and accounting records to meet legal obligations, Art. 6(1)(c). Evidence retained beyond a statutory requirement must be necessary for establishing, exercising or defending claims, based on our legitimate interest under Art. 6(1)(f); section 9 explains the periods. You may object to processing based on legitimate interests.
The table below summarises how we use the main categories of data. It is a quick reference only; the binding detail is in sections 2, 3 and 9.
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, email, language, password hash, 2FA/passkey, sessions) | Create and run your account; sign-in security | Contract, Art. 6(1)(b); security, Art. 6(1)(f) | While your account exists; purged 30 days after deletion |
| Terms acceptance (version, time) | Document the contractual agreement | Contract, Art. 6(1)(b); accountability, Art. 5(2) | With the account; purchase evidence follows its separate schedule |
| Privacy acknowledgement (version, time) | Document the notice supplied and acknowledged; not blanket processing consent | Transparency and accountability, Arts. 5(2), 12–13; keeping this evidence requires approved Art. 6 grounds | With the account; purchase evidence follows its separate schedule |
| Optional processing consent and withdrawal | Document specific choices for health or biometric processing | Applicable consent basis; Art. 7 accountability and Art. 9 requirements | Account records are removed on account deletion; withdrawal stops the relevant processing and deletes health records or face templates |
| Family-tree & wiki content about you | Record and share your requested family content | Contract, Art. 6(1)(b); other people and special categories need their own basis | Lawfully retained shared contributions may remain identifiable; erasure/restriction assessed separately |
| Data about living relatives entered by others | Keep the shared family tree accurate and connected | Legitimate interest, Art. 6(1)(f) (LIA on file; right to object) | While the household exists; erased/restricted on request or objection |
| Photos & their metadata (capture date, place, GPS coordinates) | Show and organise your requested uploads | Own uploads: contract, Art. 6(1)(b); other living people need their own basis; Art. 9 where applicable | With the photo; erasure rights apply. Future cold-storage/inactivity rules are not operating yet (section 9) |
| Biometric face data (face template) | Store faceprints from confirmed person tags (opt-in); automatic identity suggestions are unavailable | Explicit consent, Art. 9(2)(a) | Until you withdraw consent; then the template is deleted |
| Health feature (blood type, allergies, conditions) | An opt-in family medical-history record, shared only with your close circle | Explicit consent, Art. 9(2)(a) | Until you withdraw consent or delete it; then it is deleted |
| Other special-category data in records (e.g. health, religion) | Family history records | Explicit consent or another Art. 9(2) condition | While the household exists; restricted/erased on request |
| Usage & technical data (logs, device/browser, push subscriptions) | Run and secure the service; deliver notifications you opt into | Legitimate interest, Art. 6(1)(f); consent for push | Security/abuse logs up to 12 months; push until you turn it off |
| Payment and purchase evidence (section 2) | Perform purchases/refunds; statutory records; necessary claims evidence | Contract, Art. 6(1)(b); legal duty, Art. 6(1)(c); justified claims, Art. 6(1)(f) | Proposed: ten years after the end of the payment year; bookkeeping generally seven years, OSS ten years; approval and field-level justification pending (section 9) |
| Contractual declarations (statement, submitted contract reference, cancellation reason, receipt time, matching values) | Receive and resolve withdrawal/cancellation; necessary claims evidence | Contract, Art. 6(1)(b); applicable duty, Art. 6(1)(c); justified claims, Art. 6(1)(f); sensitive reasons need specific assessment | Linked: approved evidence period; unmatched/rejected: proposed three years after receipt year-end. Structured-field clearing leaves identifying text; redaction or justified retention pending (section 9) |
4. Is providing data required?
In short: name and email are required for an account; an optional purchase also needs transaction-specific billing information.
Your account data (name, email) is necessary to create and operate your account — without it we cannot provide the service. A purchase is optional but requires the billing information necessary for that transaction. Profile content, photos, turning on face recognition and any sensitive entries are voluntary; not providing it only means reduced functionality, with no other consequence.
5. If a relative entered your data
In short: when someone adds you, you still have all your rights, and this is how we inform you.
Much of the information here is provided by one family member about another, rather than by you directly. Where we hold data about you that we did not receive from you, the categories are those listed in section 2, and the source is the relevant member of your family (and, in some cases, a genealogy file such as a GEDCOM that a member imported, which may itself draw on family documents or publicly accessible registers). We provide this Art. 14 GDPR information when you are invited or first contacted; where you have no account and cannot reasonably be contacted, the law (Art. 14(5)(b)) recognises that individual notice may not be possible, and this public policy serves that purpose. You have the same rights as everyone else (section 10).
6. Who can see your data
In short: only your family, within your sharing settings — never advertisers, and we never train AI on your content.
Family content is visible only within your household, and within it only to the people your sharing settings allow. Living people are private by default. We do not sell your data, not use it for advertising or profiling, and never train artificial-intelligence or machine-learning models on your content. Our staff access a household's data only where necessary to provide support or operate or secure the service.
If you import a family tree (a GEDCOM file), the same rule applies: each member sees only the relatives within their own view of the family, and the family-tree export is limited the same way — it never hands anyone records that are hidden from them. We do not retain the uploaded file itself once it has been imported; only the family records it created are kept, within your family's space.
7. Processors and recipients
In short: named processors help run the service; Mollie separately controls payment processing.
We use a small number of vetted service providers ("processors") under data-processing agreements (Art. 28 GDPR), each bound to act only on our instructions: Hetzner (hosting and database), Bunny.net (media storage and delivery, and encrypted backups) and Lettermint (transactional email delivery, hosted in the EU). For event locations we use OpenStreetMap (OpenStreetMap Foundation): we look up a place name's map coordinates from our server, and an event's map itself is loaded from OpenStreetMap only after you click to show it — so no map request (and no transfer of your IP address) leaves your browser unless you ask for the map. Biometric face matching runs on our own self-hosted software within our EU service environment (at Hetzner) and is not sent to any separate face-recognition vendor. A current list of processors, including those not named here, is available from the contact address above. We disclose data to authorities only where legally required.
Payments are handled by Mollie, our payment service provider. Mollie acts as an independent controller for its payment services, including payment execution, fraud prevention and its own legal obligations. We transmit the payment amount, currency, order reference and technical information needed to initiate and reconcile the payment. You provide the payment details required by your chosen method directly in the payment flow. Mollie returns payment status, references and available country evidence to us. We do not send family photos, stories, health records or the family tree to Mollie. Mollie's privacy statement.
8. Where your data is stored (international transfers)
In short: family content is hosted in the EU/EEA; payment processing can involve transfers outside the EEA.
We host and store family content within the EU/EEA. Some providers are companies based outside the EU or may provide support from outside the EEA; where any processing takes place in a third country without an EU adequacy decision, we rely on appropriate safeguards under Art. 46 GDPR — the European Commission's Standard Contractual Clauses (and, where a provider is certified, the EU-US Data Privacy Framework). You can obtain a copy of the safeguards from hello@beinand.app.
Family-content hosting does not describe all payment processing. Mollie may process payment data outside the EEA and describes its transfer safeguards in its privacy statement. The contracted Mollie entity and applicable safeguards require confirmation before publication.
9. How long we keep it
In short: account and family content follow their erasure processes; necessary payment evidence has separate retention periods.
- Account & content: while your account and household exist and the service is provided to you.
- Account deletion: deactivated immediately and irreversibly purged after a 30-day recovery window; shared contributions may remain only where their retention is lawful. Removing attribution does not necessarily remove personal information within them; we assess erasure or restriction separately. Necessary transaction evidence is retained separately as explained below.
- Household deletion: family-space deletion is a separate recovery and erasure process. Its safeguards and the existing empty-space purge must be reconciled before publication; necessary transaction evidence is retained separately.
- Data exports you request are deleted from our servers 24 hours after they are generated.
- Security & abuse logs: kept for up to 12 months, then deleted.
- Backups: encrypted, stored in the EU, and overwritten on a rotating cycle (within 30 days), so deleted data also disappears from backups within that window.
- Withdrawing face-recognition consent deletes your stored face templates.
Payment evidence and declarations
Our proposed retention schedule keeps paid purchase and refund records for ten years after the end of the payment year. The retained fields must be necessary financial, tax or contractual evidence. Austrian bookkeeping rules generally require seven years; records covered by the EU One Stop Shop (OSS) require ten years. Any retention beyond an applicable statutory duty requires a separate, documented justification for the claims-related purpose described in section 3.
Deleting your account or family space does not automatically delete necessary transaction evidence. The account-erasure process clears the separate billing-name and billing-email fields on purchases, and the separate name, email and IP-address fields on matched contractual declarations. It retains protected email-matching values and transaction evidence.
Clearing those fields does not remove names or other personal information contained in the declaration itself, the contract reference you entered or a cancellation reason. Before publication, a separate review procedure must ensure that unnecessary identifying text is redacted or erased and justified evidence is retained only for its approved purpose and period. Cancellation reasons can contain sensitive information and require a specific assessment. Retained matching values and identifiable declaration contents are not anonymous.
Declarations linked to a purchase follow the approved period for the evidence they contain. The proposed period for unmatched or rejected declarations is three years after the end of their receipt year, where necessary to document and resolve claims. A specific legal obligation or unresolved proceeding can require a longer period. The required operator procedure must review records when their justified retention ends and erase or redact them unless a documented exception applies.
This candidate schedule is not approved for publication. Field-level purposes and clocks, later refunds, exceptions, legal holds, sensitive declaration contents and a named operator with an executable monthly review procedure remain pending.
Future preservation and inactivity
We do not delete family content because a paid year ends. When neither a trial nor paid or complimentary coverage applies, the family space continues on Kostenlos. Its upload allowance is the free plan's storage plus permanent bonus storage. New uploads pause while that allowance is exceeded.
We plan to introduce cold storage for long-term preservation. Once available, after 12 months without paid coverage we may move original files above the applicable free allowance to cold storage in the EU. A display copy remains available, and letters and memorials remain immediately accessible. Every retained file, including display copies and immediately accessible content, keeps two independent copies throughout storage, migration and restoration.
Originals can be restored free of charge within 48 hours, or immediately when a paid year starts. This cold-storage service is not operating yet; until then, originals remain in their existing storage.
Future inactivity process
A family space is active when any joined member signs in or a paid or gifted year keeps it active. A sign-in by one member is enough; nobody has to upload something or pay to keep the family active.
After 3, 6 and 9 months without activity, we plan to send a friendly reminder. After 12, 18 and 23 months, every member receives a notice with an export link. After 12 months without activity, the photo library may move to cold storage. Only after 24 months without activity may original gallery photos and videos be deleted; their small previews remain.
The family space, tree, written contributions, letter pictures, voice notes and profile pictures are retained independently of that original-file deletion. An original shared across several family spaces is not deleted under this rule while any of those spaces remains active. Erasure requests, lawful removal and family-space deletion are separate processes; data-protection rights still apply.
The automated inactivity process is not operating yet. We will not delete originals under this rule before its notices and export safeguards are available.
Sign-ins by partner-guests count too. Paid or gifted coverage protects the space throughout that year; an allocated purchase also counts as activity. Trial and complimentary coverage do not count as paid years. An unredeemed gift code cannot keep an unidentified receiving space active.
10. Your rights
In short: you can access, correct, delete, export and object — and complain to the authority.
You have the right to:
- Access your data (Art. 15) — members can download a copy from settings; otherwise contact us;
- Rectification of inaccurate data (Art. 16);
- Erasure (Art. 17);
- Restriction of processing (Art. 18);
- Data portability (Art. 20); and
- Withdraw consent at any time, without affecting processing before the withdrawal (Art. 7(3)).
You also have the right to object (Art. 21 GDPR), at any time and on grounds relating to your particular situation, to our processing of your data that is based on legitimate interest (section 3) — after which we stop unless we show compelling legitimate grounds that override your interests.
To exercise any right, contact us at hello@beinand.app. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at).
11. Automated decisions
In short: nothing important about you is decided automatically; members choose who is tagged.
We do not make decisions with legal or similarly significant effects about you by automated means. Face detection finds boxes without identifying people. Members choose the person for a box; a manually selected whole-photo person tag may also be attached to the only face in a photo. Automatic identity suggestions are currently unavailable.
12. Children
In short: accounts are for adults aged 18 or older; adult relatives look after children in the tree.
You must be 18 or older to have an account. Children have no account of their own. They stay in the family tree as people added and looked after by adult relatives. Information about children is entered by adult relatives, who are responsible for it.
13. Deceased persons
In short: the GDPR does not cover the deceased, but living relatives keep their rights.
The GDPR does not apply to the personal data of deceased people, so we can record and recognise ancestors without their consent. Where information about a deceased person also reveals personal data about a living relative, that living person keeps their full rights under this policy.
14. Cookies
In short: only the essentials to sign you in — no tracking, no banner needed.
We use only strictly necessary cookies/local storage to sign you in and keep the app working (for example your session and security tokens) and to remember your language. We do not use advertising or third-party tracking cookies, so no cookie-consent banner is required.
15. Changes
In short: if this policy changes meaningfully, we will tell you in the app.
We may update this policy as the service evolves. We will post the new version here and, for significant changes, notify you in the app.