Skip to main content

Privacy Policy

Last updated: October 7, 2026 — Version 3.2

1. Who we are

Familink is a family gazette platform operated from Israel. We provide a service allowing families to send a monthly printed gazette made up of photos and messages contributed by their members.

2. Data collected

  • Account: email, first name, last name, password (hashed), preferred language, phone (optional), date of birth (optional), profile photo (optional). If you use "Continue with Google": your Google ID, name, email and Google profile photo.
  • Family: family name, gazette title, members and their roles, print recipients (see section 3).
  • Content: photos sent (from the app, the website or by email), captions, contributions to the family pot.
  • Payment: handled by Nedarim Plus. We never store card numbers; we only keep a technical payment reference, the last 4 digits and the expiry date of the card, as well as the billing history and receipts. Data sent to us by Nedarim Plus during a payment is filtered: only the fields needed to track the payment and for billing are kept.
  • Technical: IP address, user agent, push notification token (mobile app), app version, the source link of your first visit (UTM parameters) saved with your account when you sign up.
  • Support: contact requests and feedback you send us, including any screenshot.
  • Error logs: automatic crash capture via Sentry (PII removed: email, tokens, Authorization/Cookie headers).
  • Mobile app analytics: 7 journey events (app opened, sign-up, first photo, payment) with a pseudonymized user ID (SHA-256 hash), hosted by PostHog Cloud EU (European Union). No email, name or family identifier is sent. You can turn these statistics off at any time in the app (Profile → Personal data).
  • Website analytics (Google Analytics, explicit opt-in via the cookie banner): page views and anonymized audience statistics. Only fires after your consent; you can decline it without any impact on your use of the site.

3. Data about other people

The service involves data about people who do not have a Familink account themselves. The family member who enters it confirms they are entitled to do so and undertakes to inform them.

  • Gazette recipient (for example a grandparent): first name, last name, postal address, phone and notes (optional), entered by the family. The recipient does not use the website: they only receive the printed gazette.
  • Children: first name, last name, date of birth, photo and notes (optional), entered by a parent who confirms they hold parental authority and consent to this processing.
  • Email contributors: when someone sends photos to the family's email address, we process their email address, name, the subject and an excerpt of the message, and the attached photos. If the sender is not yet authorized, this information is kept pending a decision by the family administrator.
  • Invited people: email address of the person invited to join a family.

4. Legal bases

  • Performance of the contract: account creation, composing, printing and sending the gazette, payment, receiving photos by email.
  • Legal obligation: retention of billing data.
  • Legitimate interest: service security and abuse prevention (blocking unauthorized senders), error logs, technical support, pseudonymized usage statistics of the mobile app (can be turned off).
  • Consent: website audience measurement cookies (Google Analytics), sign-in with Google.

5. Sub-processors

We use the following sub-processors to provide the service. No data is transferred to third parties for advertising purposes.

  • Railway (USA — standard contractual clauses): API and database hosting.
  • Vercel (USA — standard contractual clauses; runs in the Frankfurt region): website hosting.
  • Cloudflare R2 (USA — standard contractual clauses): storage of photos and gazettes.
  • Scaleway (France — European Union): sending transactional emails.
  • Resend (USA — standard contractual clauses): receiving emails sent to the family's address, and backup email sending.
  • Nedarim Plus (Israel — adequacy decision): payment processing.
  • Google Places API (Google — standard contractual clauses): postal address autocomplete. Only the text of the address being typed is sent, from our servers, without any account identifier.
  • Google Sign-In (Google Ireland Ltd. — standard contractual clauses): only if you choose "Continue with Google". We then receive your name, email and Google profile photo, nothing else (no access to your emails, contacts or files).
  • Google Photos (Picker API) (Google Ireland Ltd. — standard contractual clauses): only if you choose "Choose from Google Photos" to add photos. You select the photos in Google's interface; we receive those only, never access to your library. The access token stays in your browser for the duration of the import and is not kept.
  • Google Analytics (Google Ireland Ltd. — standard contractual clauses): website audience statistics, only if you accepted the cookie banner.
  • PostHog Cloud EU (European Union): pseudonymized usage statistics of the mobile app.
  • Sentry (USA — standard contractual clauses): error and crash capture (PII removed).
  • Anthropic (USA — standard contractual clauses): AI models used by our automated support agent to analyze reports and incidents. This agent has read-only access to the database (passwords, security tokens and payment references excluded); only the information needed for diagnosis is sent to Anthropic.
  • Hetzner (Germany — European Union): hosting of the support agent's server.
  • Expo (USA — standard contractual clauses), Apple Push Notification Service and Firebase Cloud Messaging (USA — standard contractual clauses): issuing and delivering the mobile app's push notifications. Push tokens contain neither email nor name.
  • Local Israeli printer: printing and shipping of the paper gazettes (only the recipient's name + postal address, no other data).

6. Retention periods

  • Account and content: as long as the account is active.
  • Deleted account: deactivated immediately, then profile data irreversibly anonymized after 30 days (can be restored through support during that period).
  • Closed family: if you were its only administrator, its photos, gazettes, recipients, children and contributors are deleted immediately, including from our storage, and its subscription is cancelled. A closed family cannot be restored.
  • Unprocessed requests from unknown senders (and their photos): 90 days.
  • Received email logs and contact requests: 12 months.
  • Feedback: anonymized after 12 months.
  • Gazette access links: deleted 30 days after they expire.
  • Technical events (webhooks): from 90 days up to 12 months maximum, depending on their type.
  • Audit log of sensitive actions: 24 months.
  • Billing data: 7 years (Israeli legal requirement), detached from your personal data.

7. Your rights (GDPR)

  • Access and portability (art. 15 + 20): from your mobile profile, "Export my data" section → complete JSON of your account.
  • Erasure (art. 17): from your mobile profile, “Delete my account”. Your account is deactivated immediately. If you were the only administrator of a family, that family is closed immediately: its photos, gazettes, recipients, children and contributors are deleted, including from our storage, and its subscription is cancelled. Your profile data is irreversibly anonymized after 30 days; during that period, you can ask support to restore your account (a closed family cannot be restored). Billing data is kept for 7 years, detached from your personal data.
  • Rectification (art. 16): edit your profile in the application.
  • Objection / restriction (art. 21 + 18): contact support@familink.co.il. A person whose data was entered by a family (recipient, child, contributor) can exercise the same rights at this address.

8. Security

  • Mandatory TLS 1.3 encryption (HTTPS everywhere, strict iOS ATS).
  • Passwords stored with bcrypt cost 12. Auth tokens in HttpOnly cookies on the web side, in Keychain/Keystore on the mobile side (never in localStorage or insecure AsyncStorage).
  • Minimal audit log for sensitive actions (account deletion, admin action).
  • Rate limiting and brute-force protection on authentication (5 attempts = 30 min lock).

9. Contact

For any question about your personal data: dpo@familink.co.il.

You have the right to lodge a complaint with the competent supervisory authority (CNIL in France, Privacy Protection Authority in Israel).

Privacy Policy — Familink