Kinwhistle

Privacy policy

Kinwhistle is an iPhone app for a family's shared memory archive. Anyone in the family tells what they remember, out loud or in writing, and the app keeps it for the family. This page says what the app collects, where it goes, how long it is kept, and how to take it out or remove it.

Draft of 10 October 2026, not yet published. It describes version 1.0 of the app and this website. The facts only the owner can supply are marked To be completed.

Who is responsible

Kinwhistle is run by To be completed: [CONTROLLER], the name and postal address of the person or organisation responsible for this data (the controller).

Questions about this policy or about your data, and requests to see, correct or erase it, go to support@kinwhistle.com. We answer within one month.

The short version

What the app collects

What you tell

Voice recordings, memories you write, photographs you add or photograph with the app, and what your family adds around them: names of people and places, dates kept as precisely as they were told (such as “the 1950s”), relationships between people, places on a map, facts on a person's card, and questions to one another. With your permission (see AI), also what the app makes from them: the text of a recording, the people, places and dates named in a memory, follow-up questions, a story composed from a card's memories, and coloured versions of photographs.

The original recording and its first transcript are kept even when the memory is edited, because the person who told it may not be there to ask again. They are deleted from our server only when an account is deleted, or on request (see Deleting your account).

Who you are in the app

The app creates a random identifier and a secret for your phone and keeps them in the iPhone's Keychain. You choose a display name, which the other members of your family see. You join a family through an invitation from someone already in it.

Notifications

To tell you when a family member has asked you a question, answered yours, or thanked you for a memory you told, the app registers your phone with Apple's notification service and sends our server the phone's notification token. A notification can include the display name of the member who asked, or of up to two members who thanked you; it never contains the question or a memory. A heart on a photograph sends no notification. Notifications arrive quietly unless you change that in the iPhone's settings.

What our server keeps, and what it can read

The family's server runs on Cloudflare: a small program that answers the app, a database and storage for media.

Sealed on your phone before it is sent, so that the server stores it without being able to read it: the words of every memory and its first transcript, the names of cards (a photograph's, a person's, a place's or an event's), the facts and the story on a card, the questions family members ask, and every photograph, coloured photograph and voice recording. A card's name is sealed so that the same name always seals the same way, which tells the server whether two cards have the same name and nothing else about it. The one exception is a request for AI from a phone that allows it, which passes through the server unsealed on its way to the AI and is not kept there (see AI).

Readable to the server, because keeping the family's phones in step needs it: the members' display names; the name written on an invitation, until the invitation is used; dates and how precise they are; which people are related and how; which memory names which card; the map coordinates of places, and who placed them; how long each recording is; who told or added what, and when; who gave a heart to which photograph and who thanked the teller of which memory, and when; the phones' notification tokens; when each member's phone last synced; how much of the month's transcription and colouring the family has used; and which member pays for the family's subscription and when it ends.

When you create or join a family, your IP address is used to limit how often that can be tried; our code does not store it. Cloudflare handles each request to our server, including your IP address, to deliver it, under its own policy (linked below). The server's own log keeps only the messages and errors our program writes, for up to seven days, and they describe what happened by its kind, a count or a status, never by what was told.

AI, only with your permission

Some of what Kinwhistle does uses AI: writing a recording down as text, finding the people, places and dates in a memory, suggesting follow-up questions, composing a card's story from its memories, and colouring a photograph. The first time your phone would send something for one of these, which is usually just after you have told your first memory, the app asks on a screen of its own: “May this phone send tellings to an AI?” Nothing is sent until you answer Allow, and telling a memory never waits for the question.

If you allow it

What is sent goes through our server to OpenRouter, a service that passes each request on to a provider of the AI model. The models chosen today are Google's Gemini models, with OpenAI's GPT-4o mini as a fallback for organising a memory. OpenRouter chooses which provider runs the model, so GPT-4o mini can be run by OpenAI or by Microsoft Azure (see Data handled outside the EEA). Depending on the feature, a request can carry your recording; the words you wrote, or the text of your recording; the photograph the memory is about; names, places, dates and open questions from the archive; and, for a card's story or a colouring, what other members of the family have told about the same card, with, for a story, who told each memory.

Every request asks OpenRouter to use only providers that, in OpenRouter's words, do not collect user data, so none of them may train AI on it. It does not ask for zero data retention, so OpenRouter and the model's provider may still keep a request for a while under their own policies. Our server keeps no copy of what was sent or of the answer: it counts only the seconds transcribed and the photographs coloured, for the family's monthly allowance. The answers are saved in the archive, sealed like everything else, and a coloured photograph is kept only if somebody in the family accepts it.

If you choose “Not now”

Nothing goes from your phone to an AI. Your recording and the words you write are still saved and reach your family as they are. Recordings are not written down as text, and your phone does not look for names, suggest questions, compose stories or colour photographs.

Changing your answer

You can change the answer at any time in Settings → AI. Turning it off stops what your phone sends from then on; it does not undo what has already been sent or made. If you allow it later, your recordings that have no text yet are written down then; memories you wrote yourself stay as you wrote them.

The answer belongs to your phone. Another family member's phone that has allowed AI can send what you told when it composes a card's story or colours a photograph, and names and questions from the archive go with its own memories.

An archive kept on one phone only (Keep the memories on this phone only) sends nothing to an AI or to our server, and is never asked.

Purchases

A Kinwhistle subscription can be bought in the app. Apple handles the payment, the billing and your Apple Account details under its own terms and privacy policy, and we never see your card details.

The app uses RevenueCat to manage subscriptions. RevenueCat receives your phone's random identifier, never your name, and from Apple the details of your purchases, such as the product, the price, the date and any renewal, cancellation or refund. Our server asks RevenueCat whether a subscription is active, so that one member's purchase opens the paid features for the whole family, and it stores which member pays and when the subscription ends. The app does not show the other members who pays.

Other services the app uses

Where these companies can handle data outside the EEA, and what protects it there, is under Data handled outside the EEA.

Data handled outside the EEA

Several of the companies above are in the United States, and they can handle data outside the European Economic Area (the EU, Iceland, Liechtenstein and Norway, together called the EEA). Two safeguards appear below. The EU–U.S. Data Privacy Framework is a scheme under which the European Commission has found that personal data sent to U.S. companies certified under it is adequately protected. The EU Standard Contractual Clauses are contract terms, adopted by the European Commission, that oblige a company receiving data to protect it.

Cloudflare. Our server, database and file storage are provided by Cloudflare, Inc., a company in the United States. It handles that data on our behalf and may handle it outside the EEA. Cloudflare, Inc. is certified under the EU–U.S. Data Privacy Framework. Our data processing addendum with Cloudflare also includes the EU Standard Contractual Clauses. They apply if that certification lapses, and to transfers to other countries outside the EEA.

OpenRouter. From a phone that allows AI, the recordings, texts and photographs sent for AI processing go to OpenRouter, Inc., a company in the United States. It handles them on our behalf and passes each request to a provider of an AI model. Transfers to OpenRouter are covered by the EU Standard Contractual Clauses (the controller-to-processor module) in OpenRouter's data processing agreement. That agreement also requires OpenRouter to bind the model providers it uses, as its sub-processors, to written data protection terms no less protective than those in our agreement with OpenRouter. We instruct OpenRouter to use only providers that, according to OpenRouter, do not collect user data.

The AI models. OpenRouter may pass a request to Google's Gemini models. It lists Google Cloud as a sub-processor located in the United States, and Google LLC and its wholly-owned U.S. subsidiaries are certified under the EU–U.S. Data Privacy Framework. If the Gemini model fails twice in a row while organising a memory, our server asks OpenRouter for OpenAI's GPT-4o mini model instead, which OpenRouter serves either from OpenAI or from Microsoft Azure. OpenRouter lists both as sub-processors located in the United States. Microsoft Corporation is certified under the EU–U.S. Data Privacy Framework. OpenAI is not, and that transfer relies on OpenRouter's obligations under the Standard Contractual Clauses and its data processing agreement.

RevenueCat. Subscriptions are managed by RevenueCat, Inc., a company in the United States that handles the details described under Purchases on our behalf. Transfers to RevenueCat are covered by the EU Standard Contractual Clauses (the controller-to-processor module) in RevenueCat's data processing addendum.

Apple. Notifications, iCloud Keychain, Apple Maps and App Store purchases are provided by Apple. Apple's privacy policy says that the personal data of people in the EEA is controlled by Apple Distribution International Limited in Ireland, and that Apple's international transfers of that data are governed by Standard Contractual Clauses. Apple handles App Store purchase data under its own privacy policy. Apple lists iCloud Keychain among the data it encrypts end to end, without holding the keys.

What stays on your phone

Your phone keeps the whole archive: its text in one file in the app's own storage, and the family's photographs and recordings, which it downloads over Wi-Fi. Your settings, such as the text size, the language and your answer about AI, are kept on the phone only. The identifier, the secret and the family key are in the Keychain. On the phone the archive is not sealed with the family key: it is in the app's own storage, which iOS encrypts when the phone has a passcode.

The app uses the microphone when you record and the camera when you photograph a paper photograph, and it receives from your photo library only the photographs you pick. It never asks for your location.

The family key, invitations and security

Each family has one key, made on the phone of the person who created the archive: 256 bits, used with AES-GCM. It is what seals the archive, and every member's phone holds it. Our server never receives it.

An invitation carries the key, which is how a new member's phone can open the archive. Whoever has an unused invitation can join the family and read what it has told, so send it, or show its QR code, only to the person it is for. An invitation admits one person and expires after seven days, and the messaging app you send it with sees what you send. A used or expired invitation lets nobody in, but the key in it would still open the family's sealed content if that content ever leaked from our server, so treat an invitation like a password.

If the family key is lost from every phone and is not kept in any iCloud Keychain, nobody can open the archive on our server, not even us. Keep your own copy with Settings → Export the archive.

No system is completely secure. The app talks to our server over encrypted connections, and the server keeps only a hash of each phone's secret, so its database alone lets nobody sign in as you. If our server's data leaked, the sealed content would stay unreadable without the family key, but what the server can read, listed above, would be readable.

If there is a data breach, we report it to the Office of the Data Protection Ombudsman within 72 hours, unless it is unlikely to put anyone at risk. If the risk to you is high, we say so on this website and on Kinwhistle's App Store page, because the app does not know your email address.

Deleting your account

While your phone is in a family, Settings → Delete my account and data deletes your account. It happens at once and cannot be undone, and there is no waiting period, so export the archive first if you want a copy of your own.

It deletes from our server, and from every phone in the family when it next syncs:

What stays with the family: the memories you told into someone else's phone; the memories saved on your phone with someone else chosen as the teller, or with the teller's name not shown, even if you told them yourself; other members' memories, including those about you; and the people, places and relationships the family has confirmed. If you are the family's last member, the deletion takes the family's whole archive off our server.

The deletion also asks RevenueCat to delete your customer record there, unless that record is shared with another member who restored the same purchases, so that their purchases are not lost. Apple keeps your purchase history in your Apple Account under its own terms, and we cannot delete it. Deleting your account does not cancel a subscription. Cancel it first in the iPhone's Settings, or Apple goes on billing for it.

Photographs and recordings already downloaded to family members' phones can stay in their storage. A story composed from your memories keeps its words until it is composed again. We cannot reach exports made before the deletion.

Delete your account before you leave the family or clear the phone. After that the app no longer offers it, and you can ask for it by writing to support@kinwhistle.com.

How long things are kept

The archive is kept for as long as the family uses it; nothing in it expires. When a teller deletes a memory, it disappears from every phone in the family, and its teller can restore it for 30 days, unless its card went with it. A deleted photograph, person or place cannot be restored.

Whatever is deleted one at a time disappears from view, but its sealed record stays on our server marked as deleted, with its photograph or recording. The app has no button that erases everything from the server at once. Deleting an account erases for good the deleted memories and photographs it covers (see Deleting your account), and the last member's deletion takes the whole archive. For any other erasure, write to support@kinwhistle.com.

Photographs and recordings deleted with an account are removed from storage at once. The database can be restored to an earlier moment from up to 30 days back, so deleted data can be recoverable for that long. We use a restore only to repair a fault.

We also back up the database by hand and keep the three newest copies. A backup holds the same as the database: the sealed content and what the server can read. Deleted data disappears from the backups once three newer copies have been made, and at the latest after To be completed: a set time.

A report of inappropriate content arrives by email at the support address, with the identifiers of the family and of the memory or photograph, and whatever the person reporting writes and attaches, such as a screenshot that shows the content. We keep a report and its attachments for 90 days after it has been handled, and then delete them. Of a request to erase, we keep only a record of when and what was erased, for To be completed: how long, so that we can show the request was carried out.

What OpenRouter, the model's provider, RevenueCat and Apple keep is kept under their own policies, linked above. The server's own log is kept for up to seven days.

Why we may use it

The law asks for a reason, called a legal basis, for each use of personal data. These are ours.

Sensitive matters

Memories can tell of health, beliefs or other sensitive matters. Our server stores what is told sealed, and cannot read it. Such matters reach an AI only with explicit consent, given by answering Allow on the phone that sends them, and on the way they pass through our server unsealed, without being kept there (see AI). A report shows us whatever the person reporting writes and attaches.

Automated decisions

No decision that affects you in a legal or similarly significant way is made by a machine alone. The AI writes recordings down as text, finds names and suggests questions, but the people and places it hears stay proposals until someone in the family confirms them, and a person always decides on a report.

Your choices and your rights

Children

A child can tell a memory without a phone, an invitation or a display name of their own. They speak into a family member's phone, and after the telling the person holding it chooses who told it, or adds the child by name. The name is kept as a card in the family's archive, sealed on the phone like every other card's name. Record a child only with the agreement of their parent or guardian.

What a child tells is kept and sealed like any other telling, and the same rules decide whether it reaches an AI (see AI): the answer of the phone it was told into covers it, so ask the child's parent or guardian for permission both to record and to use AI. If you are under 13, your parent or guardian decides for you whether your phone may send memories to an AI. Only the family member on whose phone it was told can edit or delete it.

A memory with a child chosen as its teller does not go when the phone's owner deletes their account. A parent or guardian can ask for what a child told to be erased by writing to support@kinwhistle.com, and we answer within one month.

What Kinwhistle does not do

It shows no advertising, contains no analytics or crash-reporting services, does not track you across other apps or websites, and does not sell what you tell. It never asks where you are: a place you name is looked up by its name.

This website

The site at kinwhistle.com sets no cookies, runs no analytics and loads nothing from another company. Its pages, pictures and scripts all come from the site itself. Cloudflare hosts it, and handles each request, including your IP address, to deliver the page, under its own policy (linked above).