Privacy Policy

1. Data Controller

Aaron Pollvogt
famband (Einzelunternehmen)
Hildastraße 18
77654 Offenburg
E-Mail: [email protected]

2. Overview of Data Processing

We process personal data only to the extent necessary to provide our platform "famband". famband is a web-based platform for creating and managing family trees with AI-powered image generation and an optional print service.

3. Legal Basis

We process your data based on the following legal grounds:

  • Art. 6(1)(a) GDPR — Consent (e.g. when using OAuth login providers)
  • Art. 6(1)(b) GDPR — Performance of contract (providing the service, payment processing, AI image generation)
  • Art. 6(1)(c) GDPR — Legal obligation (e.g. tax record retention requirements)
  • Art. 6(1)(f) GDPR — Legitimate interest (e.g. security, fraud prevention, service improvement)

4. Data We Collect

4.1 Account Data

During registration and account management, we collect:

  • Email address (as login identifier)
  • Name (optional, provided by OAuth provider if applicable)
  • Password hash (for email registration; passwords are never stored in plain text)

4.2 Family Tree Data

When creating and editing family trees, you may enter the following data:

  • First name, last name, birth name, nickname of family members
  • Birth and death dates, birth and death places
  • Gender, occupation, biography
  • Photos (profile pictures of family members)
  • Family relationships (parent-child, marriage/partner relationships including wedding date and place)

4.3 Payment Data

Payment data (credit card numbers, bank details) is processed exclusively by our payment provider Stripe and is never stored on our servers. We only store a Stripe customer ID for assignment purposes.

4.4 Usage Data

We record usage data (e.g. selected features, generation jobs, timestamps) for billing, service delivery, and improvement. We do not use any tracking or analytics tools (such as Google Analytics).

Feedback data

When you use the in-app feedback form (avatar menu), we store the following information so we can fix bugs and derive product roadmap cards (Art. 6(1)(f) GDPR — legitimate interest in product improvement):

  • Area, tags and 1–5 star rating
  • Your free-text comment (up to 2,000 characters) — please do not include sensitive data such as IBAN, credit card numbers or passwords. Before any forwarding to our AI provider, the comment is automatically scrubbed of phone numbers, emails, IBANs, credit card numbers and URLs.
  • A snapshot of your email address at the time of submission — needed so admins can follow up. On account deletion this snapshot is anonymised and the comment text is replaced with a placeholder; the anonymous metadata (area, tags, rating) is retained for analytics.

5. AI Image Generation — Data Transfer to Third Parties

When you use the AI image generation feature, your uploaded photos and the associated prompt are transmitted to external AI service providers:

  • xAI Corp. (Grok Image) — San Francisco, CA, USA

The transfer is based on Art. 6(1)(b) GDPR (performance of contract) and Art. 49(1)(b) GDPR (third-country transfer). The providers process the images solely for generating the requested result.

Please note: By using the AI image generation, you consent to the temporary transfer of your photos to these third-party providers. The providers may have their own privacy policies, which we recommend you read.

6. Social Login (OAuth)

You can register and log in using the following third-party accounts:

  • Google (Google Ireland Ltd.)
  • Apple (Apple Inc.)
  • Facebook (Meta Platforms Ireland Ltd.)

We receive your name, email address, and possibly your profile picture from the respective provider. We do not access any other data from your social media account. Using Social Login is voluntary — you can alternatively register with email and password.

7. Payment Processing (Stripe)

For payments and usage-based billing, we use Stripe as our payment provider:

Stripe, Inc.
510 Townsend Street, San Francisco, CA 94103, USA
https://stripe.com/de/privacy

Stripe processes your payment data under its own responsibility according to their privacy policy. We receive confirmations, your customer ID, and metadata about usage and billing periods. We do not store full card or bank details.

8. Email Delivery

For sending transactional emails (verification, password reset, payment confirmations), we use the service Resend. Your email address and email content are transmitted to Resend. These are exclusively system-relevant emails — we do not send marketing emails or newsletters.

Resend, Inc.
https://resend.com/legal/privacy-policy

9. Hosting & Infrastructure

Our platform is hosted with the following providers:

  • DigitalOcean, LLC (web hosting, CDN) — New York, NY, USA Datenschutz
  • MongoDB Atlas (database) — MongoDB, Inc., New York, NY, USA Datenschutz

Both providers are covered by the EU-US Data Privacy Framework. Standard log data (IP address, timestamp, browser type) may be collected by these providers in their own logs.

10. Cookies

We use only technically necessary cookies:

  • Session cookie — authentication and session management (NextAuth.js)
  • Language cookie — storing the selected language (i18next)
  • Theme cookie — storing the selected display mode (light/dark)

No tracking cookies, advertising cookies, or third-party analytics cookies are used. Therefore, no cookie consent banner is required.

11. Data Transfer to Third Countries

Some of our service providers are based in the USA (xAI, Stripe, DigitalOcean, MongoDB, Resend). The transfer is based on the EU-US Data Privacy Framework (adequacy decision of the EU Commission of July 10, 2023), Standard Contractual Clauses (SCC), or your explicit consent pursuant to Art. 49(1)(a) GDPR.

12. Data Retention

We store your personal data only as long as necessary for providing our services or as required by legal retention obligations. Account data is completely and irrevocably deleted upon account deletion. Submitted product feedback is retained in anonymised form (without comment text and without email snapshot) after account deletion so that published roadmap cards remain valid. Payment-related data is retained in accordance with tax law retention periods (up to 10 years).

13. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) — What data we have stored about you
  • Right to rectification (Art. 16 GDPR) — Correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) — Deletion of your data (via account deletion in settings or by email)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR) — Export of your data in a common format
  • Right to object (Art. 21 GDPR) — Objection to processing based on legitimate interests
  • Right to withdraw consent (Art. 7(3) GDPR) — At any time with effect for the future

To exercise your rights, please contact [email protected].

14. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

15. Changes to This Privacy Policy

We reserve the right to update this privacy policy to reflect changes in legal requirements or service modifications. The current version is always available on this page.

Last updated: 11.04.2026