Tenancy in the database
Every row carries a family id and Postgres row-level security refuses cross-family reads. The API role cannot bypass it.
Privacy
Private is a structure, not a setting. Here is what that structure is.

Every row carries a family id and Postgres row-level security refuses cross-family reads. The API role cannot bypass it.
Photos and recordings live in an S3-compatible bucket in Singapore. An EU bucket exists for families who ask before setup; the region is fixed at family creation.
JSON, CSV, and PDF from Settings › Export, any time.
Owner-only, type the family name, scheduled with a countdown every adult can see, cancellable until it runs.
Grandparent highlights and RSVP links expire on the schedule you set.
Each AI feature has its own switch. Names are pseudonymised before text leaves the server. Every call is logged with feature, model, and size, never the text.
No ads, no analytics SDKs, no data sales. Weather feeds receive a city, not family data.
Magic links and one-tap invites by default; an optional password. Rate limits on links. Sessions per device, revocable.
Settings › Privacy
Share-link expiry, the storage region, and the AI feature switches are on one settings page for the owner; the audit log is beside it.

FAQ
Structured data lives with the API. Media region is your choice. Ask hello@yearkeep.com for the current hosting details.
No.
Create the family and invite the other adult. Free during early access.