মূল কনটেন্টে যান

Privacy Policy

Effective date: July 18, 2026 · Last updated: September 24, 2026

Template notice — legal review required before launch

This document is a plain-English template prepared to describe how Kunbaa is intended to work. It is not legal advice and has not yet been reviewed by a qualified lawyer. A licensed legal professional must review and adapt it for each jurisdiction where Kunbaa launches before it is relied upon.

Kunbaa is operated by Vritul Pty Ltd, a company registered in Australia ("Kunbaa", "we", "us", or "our"). Kunbaa is a family-first, private social platform that helps families build a private family tree, preserve photos, videos, documents, recipes, and stories, chat and call with relatives, coordinate events and tasks, receive AI-written family digests, and, if you choose, connect an AI app you already use to your Kunbaa account. This Privacy Policy explains what personal information we collect, how and why we use it, when we share it, how long we keep it, how we protect it, and the rights and choices available to you.

1. Summary of key points

  • Family data is private and family-scoped. Content you add to a family space is shared with the relatives you invite and choose, not with the public.
  • We do not sell your personal information and we do not use private family content to target advertising.
  • Kunbaa's own AI writes digests, and nothing else. Kunbaa periodically writes you a short recap of the family updates you missed. Kunbaa starts it, it is read-only, it is limited to the family content your own account is already permitted to see, and it reaches you as a notification or in a weekly email. It is written with AI only if you allow it, and you can change that at any time (Section 9). Kunbaa still has no AI chat, no AI voice, and no screen of its own that accepts a prompt.
  • You can connect an AI app you already use — only if you choose to. Nothing is connected unless you create an access token on kunbaa.com and give it to an app you pick. That app can then read the categories of family data you allowed, in every family you belong to, and can create things in Kunbaa only after you confirm each one. Kunbaa never connects an app on your behalf, and the app — not Kunbaa — decides which AI provider sees what it reads. See Section 9.
  • You have control. You can access, correct, export, and delete your information, manage permissions and consent, and contact us with any privacy request.
  • We operate globally. We aim to align with the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and the Australian Privacy Act and Australian Privacy Principles.

2. Scope and our role

This policy applies to Kunbaa websites, mobile apps, and related services, including public marketing pages and signed-in product areas.

Signed-in product areas include family trees, member profiles, memories, posts, announcements, comments, reactions, chat, calls, events, tasks, invites, imports of a family-tree file or a chat export, family digests, connected apps, billing, and account settings.

For most personal information about our account holders, Vritul Pty Ltd is the data controller (under the EU and UK GDPR), the business (under the CCPA/CPRA), and the responsible entity (under the Australian Privacy Act). When a family administrator organises a family space and invites members, they and Kunbaa may share responsibility for how information within that space is handled; Kunbaa remains responsible for the platform, and members remain responsible for the content they choose to add.

3. Information we collect

We collect the following categories of personal information:

  • Account details such as name, the preferred name you choose to be shown to your family, email address, phone number, profile photo, preferred language, time zone, sign-in method, account status, and display preferences. Where we offer relationship names in another language, the words shown beside each relative are worked out on your device from the family tree; the only thing we store is the language you chose.
  • Your date of birth, which we ask for once after sign-in and use to confirm that you meet the 18-and-over account requirement described in Section 15. If the date you enter is under 18 we do not store it — the account is blocked instead.
  • Family tree and relationship data you choose to add, including relatives' names, relationships, family roles, birth, marriage, death and other life dates (including a record that a relative has passed away with no date), places, nicknames, and profile details — including information about relatives who do not have a Kunbaa account. For members who have joined, this also includes their access level in the family and the permissions a family administrator has set for them.
  • Files you choose to import, where we make that available: a family-tree file in GEDCOM format exported from another genealogy product, or a chat export made by WhatsApp. The file is read in your browser or on your device and is not uploaded to Kunbaa or kept by us. What reaches Kunbaa is what is needed to place people on your tree: from a GEDCOM file, the names, dates, places, and family links it contains, so they can be matched against the people already on your tree and — only when you confirm — written to it; from a WhatsApp export, only the names you confirm and the relationship you chose for each. No message, photo, or phone number from a chat export is sent to or stored by Kunbaa; a phone number is shown on your screen only as a reminder of who someone is. Nothing from either file is kept unless you confirm it, and what you confirm becomes ordinary family-tree data under this policy.
  • Memories and media you upload, including photos, videos, documents, recipes, voice notes, posts, announcements, comments, reactions, and stories, together with any captions, tags, and metadata (such as timestamps) attached to them, and the audience you chose for a post — everyone in the family, your extended family, or your household.
  • Messages, calls, and notifications, including chat messages, reactions, read receipts, push tokens, call signaling metadata (such as who is calling whom and call start and end times), timestamps, thread identifiers, and delivery information needed to provide the feature. Where we make it available, this also includes the membership of the family groups Kunbaa maintains in chat — a household, a set of siblings, or an extended family — which is worked out from the relationships recorded on your family tree and kept in step with it, rather than chosen by hand. The content of your private messages is used to deliver and secure your conversations, not to profile you for advertising.
  • Invite and contact details you choose to use, such as selected phone numbers, emails, or share links for inviting relatives.
  • Location information only where you choose to share it, in Family Safety or in a chat. Nothing is collected until you start sharing, and there are three ways to share. A timed live share — for 15 minutes, 1 hour or 8 hours — keeps updating your position until the time you chose, even when you switch apps or lock your phone: about every 15 to 30 seconds on a 15-minute or 1-hour share, whether or not you move, and every few minutes on an 8-hour share. While a timed share runs, your iPhone shows its blue location indicator in the status bar and Android shows a notification. On Android it keeps running even if you swipe Kunbaa away; on iPhone, force-closing Kunbaa pauses updates until you open it again. It uses the same “while using the app” permission as the next level, never asks for “Always”, and ends on its own. While using collects your device location while the app is open and in use, refreshed every few minutes, until you turn it off. Always — on iPhone only in this release, which you enable separately, after an in-app explanation and your phone’s own “Always” permission prompt — also collects your position about once an hour, and when you move a meaningful distance, while the app is closed or not in use, so the family members you choose can see where you are. You can stop any of them at any time in the app, and turning off Kunbaa’s location permission in your device settings stops any further collection. A share in Family Safety is seen only by the family members in your sharing audience; a live location you share into a chat is seen only by the people in that chat.
  • Digest content and metadata — the family content your own account is already permitted to see, which Kunbaa sends to its AI provider to write your periodic digest, together with the summary produced for you and the delivery records for it. Kunbaa does not collect AI prompts or AI voice recordings, because Kunbaa has no prompt or voice surface of its own. If you connect an AI app (Section 9), anything you type into that app is received by the app and its provider, not by Kunbaa.
  • Connected-app access records, only if you connect an AI app to your account: the name you give each access token, the permissions you chose for it, a short display prefix of the token, and when it was created, last used, expires, or was revoked. For each request a connected app makes we record the time, which token was used, which family and tool it concerned, how long it took, and whether it succeeded or why it was refused, plus running request counts used for rate limits. We keep only a one-way hash of the token itself, never the secret, and we do not keep the family content those requests returned. A change an app proposes is held for up to five minutes so you can confirm it; if you do not, it expires. We also keep a running count of the events created through connected apps each calendar month, to apply the monthly allowance described in Section 9, and — when a proposed change fails the automated content check described there — a record that it was refused, with the category, the time, and your account and family identifiers, but never the text itself.
  • Billing data from payment providers, such as checkout session identifiers, subscription status, plan selection, trial and renewal dates, invoices, country, tax information, and high-level payment metadata. For a plan bought on kunbaa.com this comes from Stripe. For a plan bought in an app store, where we make that available, it comes from Apple or Google by way of RevenueCat and is limited to the purchase record — which product, whether it is active, when it renews or lapses, and an opaque transaction identifier — because the store, not Kunbaa, is the merchant. If an App Store subscription reaches you through Apple's Family Sharing, the record we receive is the same kind; it does not identify the relative who bought it or include their payment details. We do not store full card numbers in either case; card details are handled by the payment processor or the store.
  • Device, security, and usage data such as IP address, approximate location inferred from network data, browser and device type, app version, operating system, logs, crash details, fraud signals, referral parameters, and consent preferences.
  • Support and feedback information when you contact us, respond to us, report content, or request account help.

4. How we collect information

  • Directly from you when you create an account, add content, invite relatives, message, call, purchase a plan, connect an AI app, or contact support.
  • From other family members who may add information about you to a shared family space, such as your name, your place in the family tree, or a photo of you — including from a family-tree file or a chat export a relative chose to import and confirmed (Section 3).
  • From a file you choose to import, read where you chose it; the file itself is not uploaded, and only what you confirm is written (Section 3).
  • Automatically through your device and browser as you use Kunbaa, including usage, diagnostic, and security data.
  • From service providers such as payment, sign-in, analytics, and infrastructure partners, consistent with this policy and their terms.

5. Device permissions and biometrics

Kunbaa may ask for permission to access device features such as photos, camera, microphone, contacts, notifications, clipboard, local files, or biometric unlock. We use these permissions only for the feature you choose to use, and you can change them at any time in your device settings. When you import a family-tree file or a WhatsApp chat export, your browser or phone asks you to choose the file; Kunbaa reads it there and does not upload it (Section 3).

Camera and microphone access may be used for chat attachments, profile updates, and family voice and video calls. Call audio and video are sent between the people on the call and are not recorded or stored by Kunbaa. Call signaling metadata helps connect and end calls, but Kunbaa is not an emergency calling service.

Location permissions are opt-in. Kunbaa requests foreground (“while using the app”) access the first time you share your location — by turning on Family Safety sharing or by starting a live location share in a chat — and requests background (“Always”) access only if you choose the Always level on iPhone, after showing you what will be collected and how often. A timed live share never needs “Always”: it runs on the while-using permission, keeps updating in the background only until the time you chose, and your phone shows that it is running. Background collection under Always is limited to roughly hourly updates plus movement of a meaningful distance. Location is never used for advertising and never sold, and Family Safety location is never visible outside your family space. You can pause or stop sharing, and revoke the permission, through the app or your device settings. Location sharing may be hidden or unavailable in some release profiles.

While sharing is on, we keep your most recent shared position so the people you chose can see it on the Live Map, and turning sharing off clears that stored position. A timed share also ends by itself: the moment its time is up, your position is hidden from everyone else — even if your phone is switched off or has no signal — and the stored position is deleted within about an hour. Signing out of Kunbaa ends the live location shares started on that phone, the same as stopping them; if the phone cannot reach us at that moment, they end at their set time instead. Turning off Kunbaa’s location permission only stops your phone sending new positions: until the share ends or you stop it, the people you shared with can still see the last position it sent. A live location you share into a chat is seen only by the people in that chat, never by someone you have muted or who has muted you, and anyone removed from the chat stops receiving it. When a chat share ends — at its time, when you stop it, or when you are removed from the chat — its position is no longer shown, and the chat keeps only a note that you shared your live location and when, never where you were. If your family has saved places, we also keep a short log of arrivals and departures at those places — these are the entries behind alerts such as “Ella got home”. That log is kept for 7 days and then deleted automatically; it is visible only to the family members you share your location with; it is deleted as soon as you turn sharing off; and it is deleted with your account. When a timed share ends by itself, your entries in that log are hidden from everyone else at the same moment and are deleted on the same 7-day clock at the latest. Location is never used for advertising and is never sold or shared with third parties for their own purposes.

Location information is provided on a best-effort basis and cannot be guaranteed to be accurate, complete, current, or continuously available. GPS signal, device settings, connectivity, and other factors can delay, omit, or misplace a location, and a shared location may be out of date. Family Safety and the Live Map are convenience features, not a substitute for direct contact or professional monitoring. Kunbaa is not an emergency, security, or safety-monitoring service. In an emergency, or if you believe someone is at risk, call your local emergency number and rely on official emergency services — do not rely on Kunbaa location data.

Biometric matching, such as Face ID or fingerprint unlock, is handled by your device operating system. Kunbaa does not receive or store your fingerprint or face scan.

If you allow contact access on mobile, Kunbaa uses selected contact details to help you invite relatives. We do not publish or harvest your address book.

6. How we use information

  • To create, secure, and maintain your account and family space.
  • To provide family trees, member profiles, memories, posts, announcements, chat, calls, events, tasks, invites, and notifications.
  • To deliver media, generate thumbnails, sync content across devices, and keep the family archive usable.
  • To write and deliver the periodic family digests described in Section 9, from the family content each member is already permitted to see.
  • To serve the family data you have allowed to an AI app you connect, as described in Section 9, and to secure, rate-limit, and log that access.
  • To process sign-in codes, account recovery, support requests, invitations, service notices, and important product updates.
  • To process subscriptions, invoices, refunds where required, tax-related information, storage limits, and billing support.
  • To keep Kunbaa reliable and secure, detect abuse, prevent fraud, troubleshoot errors, enforce our terms, and protect users.
  • To understand public website performance, improve accessibility and product quality, and measure marketing only where permitted by law and your consent choices.
  • To comply with legal obligations and protect users, families, rights, property, and Kunbaa.

8. Family-scoped and private by default

Kunbaa is private by default. Content you add to a family space is shared with the relatives you invite and the members who already have access, according to your family workspace settings and the actions you take. It is not published to the open internet, indexed by search engines, or made available to people outside your family space by us.

Within a family space you can narrow a post further. When you post you choose whether it reaches everyone in the family, your extended family (two generations up and down from you, and their partners), or your household (your parents, partner and children), as those relationships are recorded on the family tree. The audience is applied on our servers to every place the post can appear — the wall, the feed, the media library, comments, reactions, and mentions — on the app and the website alike, so a relative outside it never receives the post. Family administrators also set each member's access level and permissions (posting, adding people to the tree, messaging); those control what a member can do, not what they can see. The family groups Kunbaa maintains in chat are read from the tree in the same way: who is in a household, a set of siblings, or an extended-family group follows the relationships recorded on the tree, is limited to relatives who have joined your family space, and changes only when the tree does.

If you connect an AI app to your account (Section 9), that app receives the family data you allowed it to read. That is a choice you make and can undo at any time; Kunbaa does not connect anything on its own.

We do not sell your personal information, and we do not use private family content — your family tree, private messages, private posts, private media, events, tasks, or the digests we write for you — to target advertising to you or anyone else. Any advertising is limited to public marketing pages, as described in our Ads & Monetization Policy.

9. AI-written family digests and connected AI apps

Two different things in this section involve AI, and they are not the same. The first is Kunbaa's own AI, Kunbaa AI, which writes family digests. The second is an AI app you already use, which you can choose to connect to your Kunbaa account. Kunbaa runs the first; you run the second.

Kunbaa's own AI: family digests

Kunbaa's own AI does one thing: it writes family digests. These are short, periodic recaps of the family updates a member missed — new posts and announcements, photos and videos added to the family archive, upcoming birthdays and events, and family tasks involving them — delivered as a notification or in a weekly email. Kunbaa starts them; you do not ask for them. Kunbaa has no conversational assistant, no AI voice, and no screen of its own that accepts a prompt, so Kunbaa does not collect AI prompts, AI chat transcripts, or AI voice recordings. Digests are included for every account at no cost, and nothing AI-related is sold.

To write a digest, we send the family content and metadata needed to summarise it to our AI infrastructure providers (such as OpenAI or other large-language-model providers accessed through our AI gateway). A digest is permission-scoped: it is written only from what the signed-in member's own account is already allowed to see, through the same access rules that apply to them, and nothing more. It is also read-only — Kunbaa's AI never posts, comments, messages anyone, creates events or tasks, or changes the family tree. The only way anything AI-related creates something in Kunbaa is through an app you connected yourself, and only after you confirm each item, as described below.

Private family content is not used for third-party ad targeting or to train public, general-purpose AI models. We do not permit our AI providers to use your family content to train their general-purpose models. We record usage and related metadata to apply rate limits, prevent abuse, control cost, and keep the feature reliable. These commitments bind the providers Kunbaa chooses for its own digests; they cannot bind the provider behind an app you connect, as explained below.

Safety layers on Kunbaa's own AI. Every request Kunbaa's own AI makes runs behind a fixed safety instruction placed above all family content, so nothing a member wrote can change how the model is told to behave; the content sent in and the text that comes back are both passed through an automated moderation check; and if that check cannot run, the digest is not written rather than written unchecked. These layers have no opt-out. Kunbaa's AI does not generate sexual content, violence, hate or harassment, self-harm content, or content that sexualises minors, and a blocked request is recorded as a category and an identifier only, never as the words themselves.

You choose whether AI writes your digests. Kunbaa asks before its AI writes any digest for you. After you finish setting up, the Kunbaa app and kunbaa.com show a one-time permission prompt, "AI family digests", with two answers: "Allow AI summaries" and "No thanks". Until you allow it, nothing is sent to an AI provider to write a digest for you. If you allow it, Kunbaa sends the text of recent family updates you can already see — posts and comments, events, birthdays, and tasks, with the names of the people in them — to OpenAI, our AI provider. Photos, videos, chat messages and locations are never sent (a photo's caption is text and can appear in a comment). OpenAI uses that text only to write your summary and to run a safety check on it, and does not use it to train its models; under its API terms OpenAI may keep it for up to 30 days to monitor for abuse, then deletes it.

If you choose "No thanks", or later turn the setting off, it applies to your account in both directions: no digest is written for you with AI — you still get your updates, just without AI — and nothing you post is sent to AI for anyone's digest, including a relative who allowed it. Closing the prompt without answering is not a yes; nothing is sent and you will be asked again later. You can change your choice at any time in Settings: on kunbaa.com under Profile, Preferences, "AI family digests", and in the Kunbaa app under Settings. A change applies to digests written after it. We keep a record of your answer — allowed or declined, when, on which surface, and which version of this notice you saw — so that every part of Kunbaa follows it, and we ask again only if what we send or who we send it to changes.

Digests reach you as notifications and in a weekly email, so declining the notification permission means no digest notifications will arrive. The family updates a digest summarises stay readable in the app either way.

Connected AI apps: an app you choose

What a connected app is. A connected app is a third-party AI app that supports the open Model Context Protocol (MCP) — for example a desktop AI assistant or an AI coding tool such as Claude Desktop or Cursor — that you authorise to read, and with your confirmation act on, your Kunbaa data. Kunbaa is not affiliated with, does not select, and does not control any of these apps or the AI providers behind them. Kunbaa does not offer this by default and never connects an app on your behalf. Nothing is connected until you sign in on kunbaa.com or in the Kunbaa app, open Connected apps in your account, create an access token, give it a name, choose exactly which permissions it carries and how long it lasts (no more than 90 days), and give that token to the app you chose. The token is shown to you once; Kunbaa keeps only a one-way hash of it, and you can revoke it at any time from either place. This feature may be hidden or unavailable in some release profiles.

Where the AI runs. The reasoning happens in the app you connected, on its AI provider and under your agreement with that provider — not on Kunbaa. Kunbaa does not send your prompts, the app's questions, or your family data to any AI model provider of its own for this feature. The one automated step Kunbaa performs itself is the content check described below.

An automated content check before anything is stored. Before Kunbaa stores a change a connected app proposes — the title, description, place, and any other text it sends — that text is run through an automated content check: OpenAI's moderation service — one of the AI providers the commitments earlier in this section cover — receives the text for that classification only and returns a verdict. A proposal that fails the check is refused and never stored, and neither is the text; Kunbaa keeps only the refusal record described in Section 2. If the check cannot run, the proposal is refused rather than stored unchecked; creating the item yourself in the app is not affected.

A monthly allowance for AI-created events. On the Free plan, a connected app can create one event a calendar month on your behalf — counted in UTC, at the moment you confirm the proposal, and shown on the Connected apps page as what is left this month. Kunbaa Plus, whether you subscribe or a relative's plan covers your family, removes the limit. A proposal that is refused or that you do not confirm is never counted, and adding events yourself in the app is not limited or counted.

What a connected app can read. Exactly the categories you allowed when you created the token, and nothing you did not. In plain words, the categories are: your family's name and summary counts; the family tree, the people in it, and how they are related; family archive entries — the titles, descriptions, dates, places, tags, and people attached to your family's photos, videos, and stories; posts and announcements on the family wall; events; tasks; goals, where those features are available to your account; your own history with Kunbaa's assistant, if you have one; and Kunbaa's help articles, which contain no family data. Within those categories the app sees only what your own account is already permitted to see, under the same access rules that apply to you — which includes content other relatives shared with you, such as their posts and the memories they added. A token works in every family your account belongs to, not just one: if you are a member of two family spaces, an app holding your token can read the allowed categories in both. Think about that before you connect an app if you belong to a family space whose members would not expect it.

Family chat is not included. A connected app cannot read your family's chat messages in this release, and no token permission for chat is offered. Chat is your relatives' words as much as yours, and a connected app would pass those words to an AI provider your relatives never chose. If a chat permission is offered in the future, this policy will say so first, and it will not be on unless you deliberately turn it on.

What a connected app can change: nothing on its own. With the matching permission, an app can propose a new event, task, post, goal, or family-tree person. A proposal is not a change. Kunbaa holds it for up to five minutes and creates the item only if you confirm that specific proposal in the app; if you do not, it expires and nothing happens. Kunbaa creates the proposal it stored when you approved it, not something the app sends back afterwards, so an app cannot alter what you confirmed. The item is recorded as created by you, and it needs the same family role a person would need — a member whose family role is view-only cannot create events, tasks, posts, goals, or tree people through a connected app either. No connected app can send messages, comment, delete anything, invite anyone, start a call, or change privacy or family settings, and there is no voice access.

Where the data goes. When a connected app makes a request, Kunbaa sends the data that app is allowed to read to that app, over the encrypted connection you set up. That app — not Kunbaa — may then send it to its own AI model provider, under your agreement with that provider. Kunbaa has no agreement with, does not select, does not pay, and cannot control that provider. Once the data has left Kunbaa, the app's and its provider's privacy policies and terms govern what happens to it, including where in the world it is processed; the transfer safeguards in Section 12 do not cover it. Kunbaa labels everything it returns to a connected app as family content to be read rather than as instructions to be followed, but Kunbaa cannot control how the app or its AI actually behaves. The commitments earlier in this section — no training on family content, no advertising use — apply to the providers Kunbaa uses for its own digests only; they cannot apply to a provider you chose.

Your relatives are not asked. When you connect an app, your relatives are not asked for their consent; the app sees what you can see. Use connected apps in a way that is consistent with what your family expects of you, and do not connect an app you would not trust with your family's information. Section 3 of our Terms of Service applies.

Your controls. On the Connected apps page on kunbaa.com, and on the Connected apps screen in the Kunbaa app, you can see every token you have created, the permissions it carries, when it was last used, and how many AI-created events are left this month, and you can revoke any token at any time. Revoking takes effect on the token's next request. Every token expires on the date you chose when you created it, which can be no more than 90 days after creation; to keep using an app after that, you create a new token. Deleting your Kunbaa account revokes all of its tokens. Revoking a token stops future access; it does not remove anything the app or its provider already received. Kunbaa limits how many requests a token and an account can make per minute and per day, logs access as described in Section 3, may revoke tokens or suspend a connected app for security or abuse, and may turn the connected-apps feature off for everyone at any time. Kunbaa never shares your token secret with anyone and never shows it again after creation; if you lose it, revoke it and create a new one.

Please check AI-generated output before sharing it or relying on it, especially for health, legal, financial, safety, emergency, or sensitive family matters. AI output can be incomplete, inaccurate, or unsuitable for your situation. This applies equally to a Kunbaa digest and to anything an app you connected produces from your family data.

10. When we share information

  • With relatives, family admins, and invited participants according to your family workspace settings and the actions you take.
  • With apps and AI assistants you connect, as described in Section 9. Kunbaa sends them only the categories you allowed, at your request. They are not Kunbaa's service providers; what they do with the data is governed by their own policies and your agreement with them.
  • With service providers and sub-processors who help us operate Kunbaa, under contracts or equivalent safeguards appropriate to their role.
  • With our payment provider (Stripe) and tax or fraud-prevention partners when you buy or manage a paid plan on kunbaa.com — or, where we make in-app purchase available, with the app store that bills you and with RevenueCat, which records that purchase so your plan works across your family's devices.
  • With legal authorities, regulators, or professional advisers when required by law or reasonably necessary to protect people, rights, safety, property, or Kunbaa.
  • In connection with a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate safeguards and notice where required.
Provider category
Purpose
Amazon Web Services (AWS)
cloud hosting, media and database storage, messaging, push delivery infrastructure, logging, and infrastructure security
Vercel
public website hosting, web content delivery, deployment operations, and aggregate public-site performance measurement
Expo, Apple, and Google
mobile app distribution, push notification delivery, app diagnostics, and storefront operations
Stripe
checkout, subscriptions, invoices, tax, fraud checks, and payment method management for plans bought on kunbaa.com
Apple and Google (app store billing)
processing and managing a subscription bought inside the mobile app, where we make that available. They are the merchant for that purchase: they take the payment, hold the payment details, and tell us only that a subscription exists, which plan it is for, and whether it is active
RevenueCat
recording app-store purchases and keeping your Kunbaa entitlement in step with the store that billed you. It receives the purchase and subscription records the store sends, and an anonymous identifier for your account — never your payment details
OpenAI and other AI infrastructure providers
generating the periodic family digests Kunbaa writes for you, from the family content your own account is already permitted to see. These are Kunbaa's providers for Kunbaa's own AI only; an AI app you connect (Section 9) uses its own provider, which is not a Kunbaa service provider
Vritul's own mail service on Amazon SES, and communication providers
sign-in codes, account messages, invitations, service emails, and support communication
Google (Firebase Analytics and Google Analytics)
pseudonymised usage measurement. The mobile app sends a copy of its sanitised product-usage events to Google Analytics through Google's Firebase Analytics SDK, and the public website reports to Google Analytics after you accept optional cookies. Google receives event names and properties, device and app metadata, a random app-instance identifier it generates, and coarse account-level attributes such as plan tier and family role — never your name, email, Kunbaa account or family identifiers, message or media content, precise location, or private family content. Details and the opt-out are in Section 11
Google, Facebook, and advertising providers
optional sign-in, public-page advertising, consent management, and campaign attribution

We do not sell your personal data or share it for cross-context behavioural advertising. Private family content is not used for third-party ad targeting.

11. Cookies, analytics, ads, and public pages

We use essential technologies to keep Kunbaa working. On public pages, we may use optional analytics, advertising, attribution, and consent tools where permitted by law and your choices. We request consent before loading non-essential cookies in regions where consent is required, and you can revisit your choice through the cookie settings control on the site.

Inside the app and signed-in areas we use our own product analytics to understand how features are used so we can improve Kunbaa. These measurements are privacy-preserving: identifiers are one-way hashed, and we record only pseudonymised activity (for example that a screen was opened or a call was started) — never your names, message content, photos, precise location, or private family content. We do not sell this data and do not share it with advertisers or data brokers.

Google Analytics (Firebase). The mobile app also sends a copy of the same events to Google Analytics through Google's Firebase Analytics SDK, so that app and website usage can be read together in one report. What Google receives is narrower than our own pipeline: the pseudonymous event name and its properties (for example that a screen was opened or a call was started, and which feature or screen it concerned), the app release it came from, and the device and app metadata the Firebase SDK collects on its own — device model, operating system and app version, approximate country inferred from the network, and a random app-instance identifier that Google generates; and a few coarse account-level attributes with no identifier in them: whether you are signed in, your plan tier, your role in the family, whether Kunbaa AI is enabled, and which billing rail and interval your family uses. Google never receives your name, email, Kunbaa account or family identifiers, message content, photos, precise location, or private family content. The app does not collect the advertising identifier, does not use Google's advertising features, and grants Google analytics storage only, with ad storage and ad personalisation switched off. Google processes these events as our service provider under the Google Analytics terms and keeps them for the retention period we set in Google Analytics, currently 14 months. On the website, Google Analytics loads only after you accept optional cookies and follows your cookie and consent choice.

Turning it off. In the mobile app, the switch under Settings → “Share pseudonymised usage data” is on until you turn it off. Turning it off stops both our own product analytics and the Google Analytics copy on that device, and discards anything our own pipeline has buffered but not yet sent; it does not delete events Google already received, which expire under the retention period above. On the web, analytics follows your cookie and consent choice and is sent only after you accept optional cookies.

Public pages may include Google AdSense or similar advertising in the future. Signed-in family trees, private chats, private posts, private media, private events, private tasks, billing screens, and family admin areas are not ad inventory.

Private family content is not used to personalize third-party ads. Read more in our Ads & Monetization Policy.

12. International transfers

Kunbaa is operated from Australia and uses global infrastructure and service providers. Your information may be processed in countries other than where you live, including Australia, the United States, and other locations where our providers operate. These countries may have data-protection laws that differ from those in your country.

When we transfer personal information internationally and the law requires it, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and additional technical and organizational measures intended to protect the information. You may contact us for more information about these safeguards. These safeguards cover Kunbaa and its service providers. Data that an AI app you connected receives (Section 9) is processed wherever that app and its provider operate, under their policies, not under these safeguards.

13. Security

We use technical and organizational measures intended to protect Kunbaa, including account verification, access controls, encryption of data in transit, private media delivery patterns, scoped, expiring, and revocable access tokens for connected apps, logging, monitoring, and abuse-prevention controls. Secrets are stored in managed secret stores rather than in application code.

No online service can guarantee perfect security. You should use a secure email account, protect your device, use a strong and unique password or secure sign-in method, and invite relatives carefully when sharing sensitive family information. If we become aware of a personal data breach that is likely to create a risk to you, we will notify you and the relevant regulators as required by applicable law.

14. Retention and deletion

We keep personal information for as long as reasonably necessary to provide the service, maintain family spaces, support users, comply with law, prevent abuse, resolve disputes, and maintain backups. When we no longer need information, we delete it or de-identify it.

Retention periods vary by data type. For example, we keep account and family content while your account is active; we keep billing and tax records for the period required by law (often up to seven years); and we keep security and diagnostic logs for a shorter period. Backups are purged on a rolling schedule after deletion. Connected-app records (Section 9) follow the same pattern: a token record is kept while the token is valid and for a short time after it expires or is revoked so it still appears in your list; request counters expire with their rate-limit window; an unconfirmed proposal expires after five minutes; and request logs follow the security-log period. A file you import is never stored by Kunbaa: it is read where you chose it and discarded when the import finishes. We keep a short record of an import's progress, so an interrupted import can continue where it stopped, and the report of what was written; the people you confirmed are part of your family tree from then on and follow the family-content rules above.

Photos and videos sent in chat have their own clock, and it depends on your family's plan. On the free plan we keep a file sent in a chat for 12 months from the time it was sent. We then mark it as expired, which immediately stops it being served — the message stays and a placeholder takes the file's place — and at least 14 days later we delete the stored file and its thumbnail from our storage. Before the 12 months are up, a member who administers or edits the family can save the file into the family archive, after which it is kept like any other archive content. While a family is on a paid plan, files sent in its chats are kept in the family archive instead of expiring, and a file kept while the family was on a paid, settled subscription is never put back on an expiry clock afterwards.

Three limits on that, so it is clear what expiry can and cannot reach. It applies only to files sent in chat: a photo posted to the family wall, attached to an event or set on a person's profile is archive content and has no expiry clock at all. It is forward-only: only files sent after we switched this on can ever expire, and anything stored before that date is treated as archive content. And the copy your own phone downloaded to show you the photo lives in your device's cache, which your phone can clear whenever it needs the space — it is outside our systems, it is not a backup, and we cannot restore from it. If we ever change this in a way that shortens what is kept, we will tell you at least 30 days beforehand, as our Terms set out.

Location data has its own, shorter clock — in fact two of them. The recent positions behind the map and the arrival and departure log for saved places are kept for 7 days and then deleted automatically. The latest position you shared is not on that clock: we hold it while sharing is on — for a timed share, until shortly after it ends, as described below — so it has no fixed lifetime and no retention period to wait out. Turning sharing off clears all three at once, and so does deleting your account.

Live location shared for a set time has a limit of its own. When a timed share in Family Safety ends, your latest position is hidden from everyone else at that moment and deleted within about an hour, even if your phone is switched off. Live location shared into a chat keeps no last position: once the share ends, the chat shows only that it has ended, and the stored position is deleted within about an hour of the end — straight away if you stop the share yourself. Deleting your account deletes all of it.

You can delete certain content through the product where controls are available. Deleting content or your account may not immediately remove every copy from backups, logs, legal or billing records, or shared family spaces where another member retains a lawful copy. Account deletion instructions are available on the Kunbaa account deletion page, and you can contact us for help with any access, correction, or removal request.

15. Children and minors

Kunbaa is a family platform, and family spaces often include information about children — but Kunbaa accounts are for adults aged 18 and over. The Service is not directed to children, and we do not offer child or teen accounts. Anyone under 18 takes part only as information an adult family member records about them, never as an account holder.

We do not knowingly create accounts for, or knowingly collect personal information directly from, anyone under 18. This is consistent with the U.S. Children's Online Privacy Protection Act (COPPA), the children's-data provisions of the GDPR and UK GDPR, and comparable laws: because there are no child accounts, we do not seek verifiable parental consent for a child to use Kunbaa. Where an adult family member adds information about a child to a family tree, memory, photo, or event, we process that information on the family's behalf, and the adult who added it is responsible for having the authority to share it.

If you believe someone under 18 has created an account, or that a child's information has been added without the required authority, contact us at privacy@kunbaa.com and we will take appropriate steps to review and, where required, delete it. Please avoid uploading highly sensitive information about any relative — including children, elders, and people without an account — unless it is necessary for your family use case and you are comfortable with the relatives who can access it.

16. Your privacy rights

Depending on where you live, you have some or all of the following rights over your personal information. We will respond to valid requests in accordance with applicable law and may need to verify your identity first.

Access and portability

Ask for a copy of the personal information we hold about you, and request an export in a portable format where that right applies.

Rectification

Correct information that is inaccurate or incomplete. Many details can be updated directly in your profile and account settings.

Erasure

Request deletion of your account and associated personal information, subject to legal, billing, backup, and shared-family-space limits described below.

Restriction and objection

Ask us to restrict or object to certain processing, including processing based on our legitimate interests, and to opt out of non-essential analytics and advertising.

Withdraw consent

Where we rely on consent (for example optional cookies, marketing, or certain device permissions), you can withdraw it at any time without affecting prior lawful processing.

Non-discrimination

We will not deny you service, charge a different price, or provide a lesser experience for exercising your privacy rights.

You can manage many preferences directly in Kunbaa, including notification settings, profile details, family sharing, optional cookies, device permissions, who can see each post you share, and — on the Connected apps page on kunbaa.com or in the Kunbaa app — any AI apps you have connected, which you can revoke at any time. App-store and platform settings may also give you controls over tracking, notifications, and device access. A plan bought on kunbaa.com is managed there, under Settings → Plans; a plan bought in an app store is managed — and cancelled — in that store's own subscription settings, and deleting your Kunbaa account does not cancel it. To make a request, email privacy@kunbaa.com. You will not be discriminated against for exercising your rights.

17. Region-specific disclosures

EEA and UK (GDPR). Our legal bases are described in Section 7. You have the right to lodge a complaint with your local data-protection authority, such as your national supervisory authority in the EEA or the UK Information Commissioner's Office. Where a representative or Data Protection Officer is required, their contact details will be published here before or at launch in the relevant region.

California (CCPA/CPRA). In the prior 12 months we may have collected the categories of personal information described in Section 3 for the business purposes described in Section 6. We do not "sell" personal information and do not "share" it for cross-context behavioural advertising as those terms are defined under the CPRA. California residents have the right to know, access, correct, delete, and limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. You may submit a request as described in Section 16, and you may use an authorized agent.

Australia (Privacy Act and Australian Privacy Principles). We handle personal information in accordance with the Australian Privacy Principles. You may ask us to access or correct your personal information, and you may complain to us at privacy@kunbaa.com. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

18. Third-party links and services

Kunbaa may contain links to third-party websites, apps, or services that we do not control, including content shared by other members, the app stores, and any AI app you choose to connect to your account (Section 9). This policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their privacy notices before providing them with your information.

19. Changes to this policy

We may update this policy as Kunbaa changes, as laws or platform requirements change, or as we add new features. We will update the effective date above and, where required, provide additional notice such as an in-app message or email. Your continued use of Kunbaa after an update takes effect means you accept the revised policy.

20. Contact us

Kunbaa is operated by Vritul Pty Ltd (Australia). For privacy questions, requests, or complaints, contact our privacy team at privacy@kunbaa.com. We will acknowledge and respond to your request within the time required by applicable law.