Privacy

A family tenant. No feed. No ads.

Private is a structure, not a setting. Here is what that structure is.

Create your familyRead the privacy policy

A small house-shaped box with a key.

Tenancy in the database

Every row carries a family id and Postgres row-level security refuses cross-family reads. The API role cannot bypass it.

Region choice

Photos and recordings live in an S3-compatible bucket in Singapore. An EU bucket exists for families who ask before setup; the region is fixed at family creation.

Export

JSON, CSV, and PDF from Settings › Export, any time.

Delete with a grace period

Owner-only, type the family name, scheduled with a countdown every adult can see, cancellable until it runs.

Expiring links

Grandparent highlights and RSVP links expire on the schedule you set.

AI switches and audit

Each AI feature has its own switch. Names are pseudonymised before text leaves the server. Every call is logged with feature, model, and size, never the text.

No third parties on child content

No ads, no analytics SDKs, no data sales. Weather feeds receive a city, not family data.

Sign-in without passwords

Magic links and one-tap invites by default; an optional password. Rate limits on links. Sessions per device, revocable.

Settings › Privacy

The switches, in one place

Share-link expiry, the storage region, and the AI feature switches are on one settings page for the owner; the audit log is beside it.

Privacy settings.

FAQ

Where is the database?

Structured data lives with the API. Media region is your choice. Ask hello@yearkeep.com for the current hosting details.

Do you train AI on our data?

No.

Run the day. Keep the year.

Create the family and invite the other adult. Free during early access.

Create your familyGuide: a family tenant