Privacy Policy

How we handle your data.

Genealogy research deals with sensitive personal information about living and deceased people. This policy explains what we collect, how we use it, who we share it with, and the rights you have.

Last updated
August 14, 2026
Effective date
June 8, 2026

Section 1

Who we are

KleioBase is operated by Itamar Denkberg (“we,” “us,” or “our”), a sole proprietor based in Israel.

KleioBase is a genealogy platform that helps users digitize, organize, and explore historical family records using artificial intelligence.

Contact for privacy matters

Email: [email protected]
Website: https://kleiobase.com

EU representative (GDPR Article 27)

To be appointed. Details will be added here once an EU representative service is designated.

UK representative (UK GDPR Article 27)

To be appointed. Details will be added here once a UK representative service is designated.

Section 2

Scope of this policy

This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use KleioBase, including our website at kleiobase.com and all related services (collectively, the “Service”).

This policy applies to users worldwide and includes jurisdiction-specific sections for the European Economic Area (EEA), the United Kingdom, California (USA), Australia, Canada, Israel, and New Zealand.

Section 3

What personal data we collect

3.1 Data you provide directly

Data typeExamplesWhen collected
Account informationEmail address, display name, password (hashed), and/or OAuth profile data from Google and/or GitHub sign-in - an account can have more than one of these connected at the same timeAccount creation
Profile informationName, profile preferencesProfile setup
Uploaded documentsPhotographs, scanned records, historical documents containing names, dates, places, and family relationshipsWhen you upload records for AI processing
Imported family tree filesGEDCOM (.ged) or GEDZIP (.gdz) files you import, containing names, dates, places, and family relationships for yourself and your relatives. GEDZIP archives may also bundle media files (photos, document scans, PDFs), which we store in private file storage tied to your account for later useWhen you import a GEDCOM or GEDZIP file
Profile picturesPhotographs you upload or crop from a linked record to represent a person profile. May depict living relatives. Stored in private file storage tied to your account.When you set or replace a person profile picture
Research Companion file attachmentsImages (JPEG, PNG, WebP) or PDFs you attach directly to a Research Companion conversation to ask about - separately from your knowledge base and separately from the record-upload pipeline. Up to 10 MB per file, 5 per message, 20 pages per PDF. Picking, pasting, or dropping a file is a local-only step; nothing is uploaded until you press Send. Once sent, the file is stored in private file storage tied to your account for the life of the conversation and deleted when the conversation is deleted. Attaching a file does not use an upload credit; it counts against your Research Companion usage instead.When you send a message with a file attached (via the paperclip button, paste, or drag-and-drop)
User-generated contentNotes, tags, corrections to AI-extracted data, family tree entries, and an optional living/deceased status marker (with a qualifying date) you can set on a person profileWhen you use the platform
Payment informationTransaction history, subscription status. All payment data is collected and processed entirely by Freemius as Merchant of Record. We never receive or store credit card numbers, full billing addresses, or payment method details. When a purchase completes, Freemius does pass us the billing country and postal code alongside the transaction. We do not store them; if you have consented to marketing cookies, they are used once to help match the purchase to your advertising click (see Section 7.1, Meta).When you subscribe or purchase credits
CommunicationsEmails, support requestsWhen you contact us

3.2 Data we collect automatically

Data typeExamplesPurpose
Device and browser dataIP address, browser type and version, operating system, device type, screen resolution, browser fingerprintService operation, security, and analytics
Usage dataPages visited, features used, click patterns, session durationProduct improvement and analytics
Cookies and similar technologiesAuthentication tokens, analytics identifiers, marketing pixelsSee Section 10 (Cookies).
Acquisition-source attributionWhich marketing channel brought you to sign up (for example, a search engine, a social network, or an advertisement), the campaign details from that visit, and the referring and landing page (the referring page's own query string is removed before we store it). Captured either in memory for that browser tab, or in the analytics-consent-gated cookie described in Section 10, and copied once to your account when you sign up.Measuring which marketing channels are effective
Service notificationsIn-app notifications we generate as you use the Service - record-processing results, profile-match alerts, research insights, and system messages. Each holds a short title, body, an optional in-app link, and read state, linked to your account.Keeping you informed of activity in your account

3.3 Data generated through AI processing

When you upload documents for processing, our AI system extracts structured data including:

  • Names of individuals mentioned in the document
  • Dates (birth, death, marriage, immigration, and similar)
  • Places and locations (which may be geocoded to coordinates via Mapbox)
  • Family relationships
  • Other factual details present in the record

Important: Uploaded documents, particularly historical records, frequently contain personal data of third parties (people other than you). This may include living individuals. See Section 6 for how we handle third-party data in genealogy records.

Section 4

How we use your data

We process your personal data for the following purposes and on the following legal bases:

PurposeData usedLegal basis (GDPR)
Providing the Service (account management, document storage, AI processing, family tree features)Account info, uploaded documents, AI-extracted dataPerformance of contract (Art. 6(1)(b))
AI transcription and data extractionUploaded documentsPerformance of contract (Art. 6(1)(b)). You upload documents specifically for AI processing.
Geocoding locations mentioned in recordsPlace names extracted by AILegitimate interest (Art. 6(1)(f)). Enhancing the usefulness of extracted data.
Analytics (PostHog) - full, identifiableUsage data, device info, IP address, account identifierConsent (Art. 6(1)(a)), via cookie consent banner
Analytics (PostHog) - cookieless, anonymizedPage views and aggregate usage, with no cookies or browser storage; IP and user-agent are consumed into a daily-rotating, server-side hash that is then deleted, so no individual is identifiedLegitimate interest (Art. 6(1)(f)). Measuring overall product usage without tracking or identifying visitors. Applied when you have not consented to analytics; no information is stored on your device.
Marketing analytics and advertising (Meta Pixel and Conversions API)Page views and conversion events (sign-up, pricing page view, checkout start, subscription, purchase, and your first confirmed record), together with the matching details Meta uses to attribute them: your email address, your account identifier, your first and last name, the Meta browser cookies, your IP address and browser user-agent, and, for a purchase, the billing country and postal code. Your first and last name, email address, country and postal code are hashed before they are sent. Your account identifier, the Meta cookie values, your IP address and your browser user-agent are sent in the clear.Consent (Art. 6(1)(a)), via cookie consent banner
Transactional emails (account verification, password reset, sign-in method changes, billing notifications)Email addressPerformance of contract (Art. 6(1)(b))
Product update emails and newsletters (opt-in only)Email addressConsent (Art. 6(1)(a)). You must explicitly opt in at sign-up or via Settings > Account > Email preferences. You can withdraw consent at any time using the same settings toggle or the unsubscribe link in any marketing email.
“On This Day” weekly digest email (family anniversaries and historical context drawn from your own account data)Email address, dates and family relationships already in your accountLegitimate interest (Art. 6(1)(f)), on by default (weekly) as a feature-related update about your own tree, separate from the opt-in newsletter above. Change the frequency or turn it off any time in Settings > Account & Preferences, or use the one-click unsubscribe link in any digest email.
Matching historical context to your family timeline and the “On This Day” dashboard widgetDates and places already in your account; religion, nationality, or caste when recorded on a person's profile, or derived from a parent or spouse when it is not directly recordedLegitimate interest (Art. 6(1)(f)), the same basis as providing the knowledge-base service.
Waitlist managementEmail addressConsent (Art. 6(1)(a))
Payment processingBilling details (held by Freemius)Performance of contract (Art. 6(1)(b))
Measuring which marketing channel brought you to sign upUTM campaign parameters, ad click identifiers, referring page (query string removed), landing pageLegitimate interest (Art. 6(1)(f)) for the server-side record on your account, made once at signup. The cookie that lets this survive a reload or a later visit (Section 10) is separately gated on your analytics consent (Art. 6(1)(a)).
Security and abuse preventionIP address, usage patternsLegitimate interest (Art. 6(1)(f)). Protecting the Service and its users.
Legal complianceVarious, as requiredLegal obligation (Art. 6(1)(c))

4.1 Legitimate interest assessments

Where we rely on legitimate interest as a legal basis, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting us at [email protected].

Section 5

AI processing and automated decision-making

5.1 How AI processing works

When you upload a document, it is sent to Google’s Gemini API for text extraction and analysis. The AI identifies and structures information such as names, dates, places, and relationships contained in the document.

The Research Companion also uses the Google Gemini API to answer questions about your knowledge base and assist with research. With your explicit confirmation, the Research Companion can modify your knowledge base on your behalf - for example, creating or updating person profiles, linking records to profiles, adding family relationships, merging duplicate profiles, or resolving and dismissing research findings. The AI reads current data before proposing any change, and every modification requires your explicit approval before it is applied.

You can also attach your own image or PDF files directly to a Research Companion conversation, separately from your knowledge base, to ask about a document you have not uploaded through the normal record-processing flow. The file is sent to Google’s Gemini API as soon as you send the message you attached it to, and again later if the assistant needs to look at it again, and is stored in private file storage for the life of the conversation, deleted when the conversation is deleted. Attaching a file this way does not use an upload credit; it counts against your Research Companion usage budget instead.

At your request, the Research Companion can also generate a written biography for a person in your knowledge base. To do this, the existing data you have already saved for that person (linked records, facts, family relationships, and timeline) is sent to Google’s Gemini API, which returns a prose life story. No new category of data is collected; the biography is derived from data you already provided. You can view the result in the app and download it as a PDF.

When it helps answer your question, the Research Companion can also search the public web and read public web pages. In production, web searches are sent primarily to the Brave Search API (operated by Brave Software, Inc.), which receives the search query text. Once our monthly Brave request budget is nearly exhausted, or if Brave returns an error, searches overflow to a self-hosted search service we operate on our own infrastructure, which queries public search engines on your behalf. When the assistant opens a public web page to read it, our server fetches that page; the third-party website sees our server's request (our IP address and a KleioBaseBot/1.0 identifier), not your identity. We do not send your account details, uploaded documents, or other personal data to these third-party websites beyond the search query and the page address the assistant chooses to open.

On the Archivist and Professional plans, our AI also runs a periodic background analysis (batched once daily) that looks for possible relationships between people named across the records you have already uploaded - for example, suggesting that two of your separate family branches may connect. This uses the Google Gemini API and operates only on the genealogical data you have already provided; it does not collect any new category of data and does not share your data with any new third party. Any suggested connection is presented for your review and is never applied to your knowledge base automatically.

On the Researcher plan and above, our AI also helps detect when your own notes record one fact - such as an occupation - under several different wordings on the same person (for example, two translations of the same job title). To do this, we ask the Google Gemini API a narrow, deliberately context-freequestion: given two recorded values and the kind of fact they are, do they mean the same underlying thing? We send only those two short values and the fact type - never a person’s name, a profile identifier, or any other information about your tree. The answer is stored in a dictionary shared across all KleioBase accounts, keyed only on the two values and the fact type, so the dictionary itself never contains your name, your profile data, or any way to identify you. We manually review each proposed pair before it is treated as confirmed, and a candidate pair that has not yet been reviewed is temporarily linked to the account that triggered it so we can see where a proposal came from during review; that link is removed once the pair is confirmed or rejected. Nothing is merged or changed on your profile automatically - you always choose which recorded wording to keep, and the others are kept as alternates rather than deleted. This feature is available on the Researcher plan and above; on the free Explorer plan, the underlying detection is available up to a lifetime total of 20 AI lookups, and upgrading removes that limit immediately.

We also offer an in-app customer support chat provided by Chativox, which uses an AI assistant to answer your product and account questions. When you open the support chat we share your account identifier, name, email address, and plan tier so the assistant can identify you, along with the messages you send. Chativox generates replies using Google’s Gemini AI and retains support conversations for up to 12 months, with deletion available on request. The support chat is separate from the Research Companion and does not have access to your uploaded documents or knowledge base. You control when to start a conversation and what you share in it.

Key facts about our AI processing:

  • We use the Google Gemini API on a paid tier. Under Google’s paid API terms, your data is not used to train or improve Google’s AI models.
  • Google retains prompts and contextual information for 55 days solely for abuse monitoring and policy enforcement purposes. This data is not used for model training or fine-tuning.
  • All AI-extracted results are placed in a “review” state by default. You must manually confirm or correct the extracted information before it is treated as verified. The AI does not make final decisions. Human review is always required.
  • Knowledge-base modifications proposed by the Research Companion also require your explicit confirmation before they are applied. No change is made to your data automatically.
  • AI extraction may contain errors. We make no guarantee of the accuracy of AI-generated genealogical conclusions. You are responsible for verifying all extracted data.

5.2 Automated decision-making (GDPR Article 22)

KleioBase’s AI processing assists you in extracting information from documents and in managing your knowledge base. It does not make decisions that produce legal effects or similarly significantly affect you. The AI is a tool that presents suggestions and proposed changes for your review. It does not determine legal rights, financial outcomes, or access to services.

You always have the ability to review, correct, or reject any AI-extracted data or AI-proposed knowledge-base modification.

5.3 AI transparency (EU AI Act)

KleioBase deploys AI systems for document analysis, data extraction, and research assistance (including knowledge-base modifications initiated by the Research Companion with your confirmation). We are transparent about the use of AI throughout the platform: our use of AI is disclosed in this Privacy Policy and in our Terms of Service, which you accept when you create an account, and AI-processed results are clearly labeled in the product and placed in a “review” state for your confirmation.

Section 6

Third-party data in genealogy records

Genealogy records inherently contain personal data about individuals other than the user who uploads them. Historical records may reference living individuals (for example, a birth certificate from 40 years ago names a person who is likely still alive).

Our approach:

  • Deceased individuals are generally not data subjects under the GDPR (Recital 27). However, some jurisdictions may offer limited post-mortem privacy protections.
  • Living individuals named in records you upload are data subjects with privacy rights. By uploading records containing third-party personal data, you represent that you have a lawful basis for doing so (such as a legitimate interest in family history research) and accept responsibility for ensuring that the upload does not violate any applicable privacy laws.
  • We process third-party data contained in your uploads under legitimate interest (Art. 6(1)(f) GDPR), specifically the recognized interest in historical and genealogical research. We have conducted a balancing test weighing the genealogical research purpose against the privacy interests of individuals named in records.
  • Special-category data. Genealogy records can reveal special categories of personal data within the meaning of Art. 9 GDPR, in particular racial or ethnic origin and religious belief. Where they do, our primary condition is Art. 9(2)(j) GDPR - processing necessary for archiving in the public interest or for historical research - applied with the safeguards required by Art. 89(1). Those safeguards include data minimization (we extract only what the record itself contains), strict per-user access isolation so records are not shared across accounts by default, mandatory human review before extracted data is treated as verified, and the right of any identified individual to seek access, correction, or erasure. Where a record was manifestly made public by the individual concerned (for example, a published or publicly archived record), we may additionally rely on Art. 9(2)(e). The large majority of individuals in historical records are deceased and fall outside the GDPR (Recital 27).
  • Historical context matching. Some entries in our admin-curated library of historical events are further scoped to a specific religion, nationality, or caste (for example, the Holocaust is shown only for an ancestor recorded as Jewish or Romani). Where we do this, we compare that event against the religion, nationality, or caste already recorded on a person's profile in your tree. If a person has none of their own recorded, we derive one from their nearest recorded ancestor or, failing that, a spouse, so that relevant historical context can still be shown; a person's own recorded value always takes priority over one derived this way. You can switch that derivation off at any time with the Infer historical context from relatives setting in your account preferences, in which case we match historical events only against what each person has recorded of their own. This is an additional use of special-category data you or a record you uploaded has already provided under Section 4 above - we do not ask you or any user for a person's religion, nationality, or caste, and we never infer it from a name, a place, or any source outside your own tree.
  • If an individual identified in a record contacts us directly to exercise their privacy rights (access, erasure, objection), what we do depends on our role. Where we act as a customer’s processor (see below), we do not answer the request substantively: we forward it to that customer without undue delay, tell the requester that we have done so and that the customer is the controller responsible for answering, and assist the customer in responding. Where KleioBase is the controller, we handle the request ourselves in accordance with applicable law.

If you use KleioBase professionally

Where you use KleioBase in the course of a business - for example, a professional genealogist researching on behalf of a client - you are the controller of the records you upload and KleioBase acts as your processor for that content, on the terms of our Data Processing Agreement. That agreement is in force automatically for every customer within its scope, from its effective date, with no signature and no request needed.

The legitimate-interest basis described above applies where KleioBase is the controller. That is the position for personal and family history research: researching your own family history for yourself falls within the household exemption in Article 2(2)(c) GDPR, so there is no controller-to-processor relationship to govern, the Data Processing Agreement does not apply, and this Privacy Policy governs our handling of your data instead.

Section 7

Who we share your data with

We do not sell your personal data. We share data only with the following categories of recipients, and only to the extent necessary for the stated purposes.

7.1 Service providers (data processors)

ProviderPurposeData sharedLocationTransfer safeguard
SupabaseDatabase hosting, authentication, file storageAll user data, uploaded documents, AI-extracted dataUSAStandard Contractual Clauses (SCCs) and DPA
Google (Gemini API)AI document transcription and data extraction; Research Companion conversations, including files you attach directly to a conversationUploaded documents and processing context; images/PDFs attached to a Research Companion conversationUSAEU-US Data Privacy Framework (certified)
Brave Search (Brave Software, Inc.)Primary web-search provider for the AI Research Companion in production. Our self-hosted search service is used for overflow once the monthly Brave request budget is nearly exhausted, and as a fallback if Brave errors.Search query text derived from your Research Companion request. No account details or uploaded documents are sent.USAData Processing Addendum incorporating EU Standard Contractual Clauses
FreemiusPayment processing (Merchant of Record)Email address, subscription status. Freemius independently collects and controls all payment details. We never receive or store card numbers, full billing addresses, or payment method details. Freemius does pass us the billing country and postal code with a completed purchase, which we do not store (see Section 3.1).USADPA. Freemius acts as independent controller for payment processing.
MapboxGeocoding of locations extracted from recordsPlace names and addressesUSAEU-US Data Privacy Framework (certified)
PostHogProduct analytics and AI performance monitoringUsage data, device info, anonymized identifiers, and AI request metadata (model, token counts, latency, cost). Prompts and AI responses are never sent.USAEU-US Data Privacy Framework (certified) and SCCs; consent-based
ResendTransactional and marketing email delivery; receives inbound mail to role addresses (privacy@, contact@, support@, abuse@, security@, legal@, marketing@) and forwards it to our application via webhookEmail addresses, email content (outbound and inbound), and the acquisition channel that brought you to sign up (for example, "organic_search" or "meta_ads"), stored as a contact property so we can segment and measure marketing performance. Only the derived channel label is shared, never the underlying UTM parameters, click identifiers, or referrer.USAEU-US Data Privacy Framework (certified) and SCCs
Meta (Facebook Pixel and Conversions API)Marketing analytics and advertisingPage views and conversion events (sign-up, pricing page view, checkout start, subscription, purchase, and your first confirmed record), plus the details Meta uses to match an event to an advertising click: your email address, your account identifier, your first and last name, the Meta browser cookies (_fbp and _fbc), your IP address and browser user-agent, and, for a purchase, the billing country and postal code, the amount and currency, and the transaction reference. Your first and last name, email address, country and postal code are hashed before transmission. Your account identifier, the _fbp and _fbc cookie values, your IP address and your browser user-agent are sent in the clear, because Meta matches them in that form. We do not send your phone number, street address, uploaded documents, or any genealogy data. Nothing is sent unless you have consented to marketing cookies.USAEU-US Data Privacy Framework (certified); consent-based
RailwayApplication hosting and deploymentIP address, request data (server logs)USADPA and SCCs
SentryError monitoring, performance tracking, and masked session replay (only after you consent to analytics)Error reports, which may include IP address, browser info, and application state at the time of an error; and, only if you consent to analytics, masked session replays (a reconstruction of page interactions - clicks, navigation, and DOM changes - with all text and form inputs masked) recorded for a sample of sessions and on errors, buffered in your browser's sessionStorageUSAEU-US Data Privacy Framework (certified) and SCCs
incident.ioIncident management and on-call alerting; receives error and uptime alerts forwarded from Sentry so we can coordinate our response to outages and significant errorsError and incident metadata forwarded from Sentry (error type, affected endpoint, and timestamps), which may include an IP address or user identifier embedded in an error’s contextUnited Kingdom (provider); data stored in the EU/EEA (Google Cloud European regions)Data Processing Addendum; EU/UK adequacy decision (for EU/EEA-origin data) plus EU Standard Contractual Clauses and the UK Addendum for the provider's onward US sub-processors
LinearProduct issue tracking and triage of feedback you submit through the in-app feedback formYour email address and the feedback content you submit (description, steps to reproduce, and any screenshot you attach)USADPA and SCCs
ChativoxAI-powered in-app customer support chat; replies are generated using Google's Gemini AI. You control when to start a conversation, and conversations are retained by Chativox for up to 12 months (deletion available on request).Your account identifier, name, email address, and plan tier (sent to identify you in the chat), plus the messages and any details you choose to share in the support conversationIsrael (Chativox); United States (Google Gemini, for AI replies)Israel holds EU and UK adequacy decisions; Google is EU-US Data Privacy Framework certified
Cloudflare (Turnstile + Email Routing + media hosting)Bot protection on forms; inbound email routing (forwards mail sent to our role addresses - e.g. privacy@, support@, contact@ - to our email provider); and hosting of static site media, such as the onboarding walkthrough video, on Cloudflare R2Browser interaction data and IP address for bot challenges (processed transiently); and, for email routing, the sender address and message content of mail you send to our role addresses. Static media hosting shares no personal data - the files served are fixed marketing assets, not customer content.GlobalEU-US Data Privacy Framework (certified)
Google, GitHub (OAuth)Single sign-on authenticationProfile data you authorize during sign-in (email, name, avatar)USAEU-US Data Privacy Framework (Google); DPA (GitHub/Microsoft)

7.2 Sharing and collaboration features

Certain paid plans offer sharing and collaboration features that allow you to invite other users to access your knowledge base. Where these features are available on your plan:

  • Read-only collaborators you invite can view but not edit your shared knowledge base.
  • Edit-access collaborators you invite can view and modify the shared knowledge base.
  • Revoking an invitation immediately removes access.
  • We do not share your data with other users unless you explicitly enable sharing.

Availability of these features depends on your subscription plan. See our pricing page for current details.

7.3 Public profile sharing

You can choose to publish a public, read-only web link to a single person profile’s AI-generated biography. This is entirely owner-initiated: no link exists unless you create one, and you can revoke any link at any time, which immediately removes public access.

What a shared link exposes.A shared page shows only a curated public subset of the profile: the person’s name, lifespan dateline, birth and death places, the AI-generated biography text (including its historical-context callouts and external historical references), and a read-only event timeline.

What is never exposed.Shared pages do not include source record images or scans, transcriptions, extracted structured data, or any other person’s profile.

  • Living-person safeguard. If a profile could be a living person (no evidence of death and a birth within the last 100 years, or an unknown birth year), you must explicitly confirm that the person is deceased or that you have consent to share before a link can be created. We store this acknowledgment.
  • Optional password protection. You can require a password to view a shared page. We store the password only as a salted scrypt hash, never in plain text.
  • Expiry controls. A link can be set never to expire, or to expire after 7, 30, or 90 days.
  • Not search-indexed. Shared pages carry a KleioBase attribution and are marked noindex so they are not added to search-engine results.

Retention of share links. We store share links in a profile_share_links record (link token, optional expiry, optional password hash, the deceased acknowledgment, the living-person consent confirmation and the date it was given, a revocation timestamp, and a view count). Active links are retained until you revoke or delete them. Once a link is revoked or has expired, the underlying record is permanently purged 30 days after revocation or expiry by a scheduled job. The consent confirmation and its date are part of that same record and are purged with it.

Sharing a profile of a living person.Where a person is marked as living in your knowledge base, we ask you to confirm that you hold their consent, or their guardian’s if they are a minor, before a public link can be created, and we require the link to be password-protected. We record that confirmation and the date you gave it as evidence of the lawful basis you asserted. If a person is marked as living after a link was shared, the shared page stops loading unless that confirmation was recorded.

7.4 On This Day share cards

From the dashboard’s On This Day widget, you can share a single anniversary highlight as an image card. This is entirely user-initiated: nothing is shared unless you click the share button on that specific highlight.

What a share card exposes.Only the subject’s first name, the type of event (born or died), how many years ago it happened, and their relationship to you (for example “Great-Aunt”).

What is never exposed.A share card never includes a person or profile identifier, source records, your full tree, or any other person’s data.

How the link works. The link is a signed token that is not stored in our database, so there is nothing to revoke or that expires on a timer. It stops reflecting current data if the underlying fact in your account changes.

7.5 Legal requirements

We may disclose personal data if required by law, legal process, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of KleioBase, its users, or the public.

Section 8

International data transfers

KleioBase is operated from Israel. Your data may be transferred to and processed in countries outside your country of residence, including the United States and Israel.

8.1 Transfer safeguards

We use the following mechanisms to ensure adequate protection for international transfers:

Israel: Israel has an adequacy decision from the European Commission (and a separate UK adequacy decision), meaning transfers of personal data from the EU/EEA and UK to Israel are permitted without additional safeguards.

United Kingdom: The United Kingdom has an adequacy decision from the European Commission, so transfers of personal data from the EU/EEA to the UK (for example, to incident.io, our UK-based incident-management provider) are permitted without additional safeguards.

United States: For each US-based service provider, we rely on one or more of the following:

  • EU-US Data Privacy Framework (DPF): Google, Mapbox, PostHog, Resend, Sentry, and Cloudflare are certified under the EU-US DPF, providing an adequate level of protection for transatlantic transfers. Meta is certified under the EU-US DPF for its onward transfers and acts as an independent (and, for the initial collection, joint) controller of advertising-measurement data rather than as our processor.
  • Standard Contractual Clauses (SCCs): For providers not certified under the DPF (Supabase, Freemius, Railway, Linear, and Brave Search), we rely on the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914, controller-to-processor module), supplemented by additional technical and organizational measures (encryption in transit and at rest, data minimization, and per-user access isolation). We have assessed these transfers in an internal Transfer Impact Assessment and concluded they provide an adequate level of protection. Brave Search relies on a Data Processing Addendum incorporating these Standard Contractual Clauses, and only minimal search query text is shared with that search provider.
  • Data Processing Agreements (DPAs): Each service provider is bound by a DPA that includes commitments on data security, confidentiality, and breach notification. Most DPAs are incorporated automatically into the provider’s terms or accepted electronically; the remainder are executed by signature.

8.2 United Kingdom transfers

For personal data of UK users transferred to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) for providers that have separately certified to the UK Extension (Google, Mapbox, Cloudflare, PostHog, Resend, and Sentry). UK certification is a separate step from EU-US certification, so for other US providers we rely on the UK International Data Transfer Addendum to the SCCs, supported by a transfer risk assessment. Transfers from the UK to Israel are permitted under the UK’s adequacy decision for Israel without additional safeguards.

8.3 Australian users: cross-border disclosure (APP 8)

If you are located in Australia, your personal information will be disclosed to overseas recipients in the United States (all providers listed above) and Israel (KleioBase’s place of operation). As our reasonable steps under APP 8.1, we bind each overseas recipient by an enforceable Data Processing Agreement requiring it to handle your personal information in a way consistent with the Australian Privacy Principles. We do not ask you to consent to a waiver of APP 8 protections.

Under section 16C of the Privacy Act, we remain accountable for the handling of your personal information by these overseas recipients as if we had handled it ourselves. If an overseas recipient mishandles your information, you retain your rights and remedies under the Privacy Act against us.

8.4 Canadian users: international transfers

If you are located in Canada, your personal information is transferred to and processed in the United States and Israel. Under PIPEDA, this transfer to our service providers for processing is a “use” of your information for the purposes you originally agreed to, not a separate disclosure requiring fresh consent. We remain accountable for your information and bind each processor by contract to a comparable level of protection.

Foreign access: while your information is stored or processed outside Canada, it may be accessible to the courts, law enforcement, and national security authorities of those jurisdictions under their laws.

Meaningful consent: so that your consent is meaningful, we highlight throughout this policy (1) what personal information we collect, (2) the parties we share it with, including the service providers listed in Section 7, (3) the purposes for which we use it, and (4) the residual risks involved, including the foreign-access risk described above.

8.5 Quebec residents (Law 25)

If you are a resident of Quebec, Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25) applies to our handling of your personal information, regardless of where KleioBase is located.

  • Person in charge of privacy. Our designated privacy officer is Itamar Denkberg, reachable at [email protected].
  • Transfers outside Quebec. Before transferring your personal information outside Quebec (to our US and Israel-based infrastructure and service providers), we conduct a privacy impact assessment of the transfer, confirm the information will receive adequate protection, and bind the recipient by contract.
  • Sensitive information. Genealogy records can constitute sensitive personal information. We collect and process it only with your consent, which you provide when you upload documents for processing, and use it solely to provide the Service.
  • Your rights. You have the rights of access, rectification, and, where applicable, de-indexing and data portability. To exercise them, or to complain, contact our privacy officer above. You may also lodge a complaint with the Commission d’accès à l’information du Québec (CAI).

Section 9

Data retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

Data categoryRetention period
Active account dataRetained while your account is active
Uploaded documents and AI-extracted dataRetained while your account is active; permanently deleted from the live Service immediately upon account deletion (see the note on backups below)
Person profile picturesRetained until you remove or replace the picture, delete the profile, or delete your account. Deleted immediately on account deletion.
Research Companion file attachmentsA file you attach is not uploaded or stored until you press Send. Once sent, it is retained for the life of the conversation you attached it to; deleted immediately when that conversation is deleted, and deleted on account deletion. In the rare case a send fails after the file finished uploading, it is deleted immediately as part of that failure; if that immediate cleanup itself cannot complete, a periodic cleanup collects it the next time you use this feature, rather than on a fixed schedule.
Imported GEDCOM / GEDZIP files (.ged / .gdz)The uploaded file is retained only while an import is in progress. It is deleted as soon as the import is confirmed or cancelled, and any import left unconfirmed is automatically deleted within one hour. The family-tree data extracted from a confirmed import is kept for the life of your account (as profiles and records). Media files bundled inside a GEDZIP archive are saved to private storage tied to your account and kept for the life of your account, until you delete them or erase your account.
Generated exports (GEDCOM / GEDZIP, research reports, data exports)Files we generate on request and deliver by emailed download link are stored in private storage and automatically deleted 7 days after generation (and removed immediately on account deletion).
Trashed records and profilesPermanently deleted 30 days after you move them to trash
In-app notificationsRetained while your account is active; permanently deleted immediately upon account deletion
Analytics data (PostHog)Retained according to PostHog's default retention settings; anonymized or deleted when no longer needed
Marketing data (Meta Pixel)Subject to Meta's data retention policies; we cease sharing data when you withdraw consent
Advertising attribution details held on your accountWith marketing consent, we keep a small snapshot on your account row (the Meta browser cookie values, and the IP address and browser user-agent of the session in which the snapshot was taken, with the time it was taken) so a later purchase confirmation sent from our server can be matched correctly. It is overwritten by the next snapshot and deleted immediately on account deletion.
Acquisition-source attributionWe keep a record of which marketing channel brought you to sign up on your account row. It is written once, at signup, and is not replaced by a later visit, so it always reflects your original first touch. Deleted immediately on account deletion, and included in your data export like any other account field.
Transactional email recordsRetained for up to 2 years for operational and legal purposes
Marketing email subscription state (product update opt-in)Retained while your account is active. Withdrawing consent (via the Settings toggle or per-email unsubscribe link) removes you from the marketing audience immediately. Deleted on account deletion.
Payment recordsRetained as required by tax and accounting laws (typically 7 years)
Server logs (Railway)Retained for up to 30 days
AI processing logs (Google)Google retains for 55 days for abuse monitoring, then deletes
Waitlist entriesRetained until you convert to an account or remove yourself via the one-click unsubscribe link in any waitlist email

When you delete your account via the self-service flow (Settings - Account), deletion is processed immediately and covers: all data in our database (records, profiles, families, conversations, and your account row), your uploaded files in our file storage, your contact record in Resend (email delivery), your analytics profile in PostHog, and your active Freemius subscription (if any). A durable audit log entry is retained without personally identifiable information for fraud-prevention and legal-compliance purposes. Payment records held by Freemius as Merchant of Record are subject to their own retention obligations (typically 7 years for tax purposes).

Backups. Deleting data removes it from the live Service immediately, but a copy may remain in routine encrypted infrastructure backups until those backups expire on their normal rotation. Our database provider currently retains daily backups on a rolling 7-day window, after which they are overwritten. Backups are encrypted at rest, are not accessible from the running Service, and are used only for disaster recovery. If a backup is ever restored, we re-apply any deletion that the restore reversed. The same position is set out in the deletion and return section of our Data Processing Agreement.

Data sharing with Meta via the Meta Pixel is governed by the CCPA opt-out described in Section 11.3. Account deletion removes the identifiers we share with Meta going forward; historical attribution data already processed by Meta is subject to Meta's own retention policies.

Mail you send to our role addresses (privacy@, contact@, support@, abuse@, security@, legal@, marketing@) is stored in our own systems and retained until manually deleted. Quarantined spam is automatically deleted after 30 days. You may request deletion of your message at any time by writing to [email protected].

Section 10

Cookies and tracking technologies

We use cookies and similar technologies on our website. We categorize them as follows.

Essential cookies (always active)

  • Supabase authentication session cookies (managed by @supabase/ssr)
  • kb-low-contrast - accessibility preference (stores your display contrast setting)
  • kb-theme - interface preference (stores your light or dark theme choice)
  • kb-date-format - interface preference (stores how dates are displayed: day, month, or year first)
  • kb-cookie-consent - records your analytics and marketing cookie choices, the detected region, any Global Privacy Control signal, the timestamp, and whether you have answered the banner yet. It is written as soon as you arrive, before you choose, so that the settings that apply to your region by default (see below) are applied consistently by both your browser and our servers. Answering the banner overwrites it with your actual choice

Local storage (browser storage, not cookies)

  • Essential functional preferences.We store small interface and draft-state values in your browser’s local storage (under the kb- prefix) so the app remembers things like your view and sidebar settings, in-progress upload tabs, export options, and recent searches. These are not used for tracking, are not shared with anyone, and require no consent.
  • PostHog analytics identifiers. Only after you consent to analytics, PostHog uses browser localStorage (not cookies) to maintain a session identifier for product analytics that can be linked to your account.
  • PDF pages, while you pick them.When you drop a PDF into the upload workspace, we hold it temporarily in your browser’s IndexedDB storage (not on our servers) so you can open the page picker and choose which pages to bring in. It stays there until you close that page picker tab, which removes it immediately, or until you clear your browser’s storage. If a picker tab is ever lost without being closed (a browser crash, for example), the next time you open the upload workspace clears any PDF left without a tab. Like the preferences above, this is first-party, is not used for tracking, is never shared with anyone, and requires no consent. Only the individual pages you choose to add are ever uploaded to us.

Session replay (requires your consent to analytics)

Only after you consent to analytics, our error-monitoring provider (Sentry) records masked session replays for a small sample of sessions and for sessions where an error occurs. A session replay is a reconstruction of how a page behaved - clicks, navigation, and page changes - so we can diagnose bugs. All text and form inputs are masked(their contents are not captured), and the replay is buffered in your browser’s session storage. If you do not consent to analytics, or before you make a choice, no session replay is recorded. Withdrawing analytics consent stops any further recording immediately.

Cookieless, anonymized analytics (no consent required)

If you reject analytics, or before you make a choice, we still measure overall product usage (such as page views and aggregate traffic) in a cookieless, anonymized mode. In this mode PostHog stores nothing on your device - no cookies, no local or session storage. Visitor identity is derived by PostHog on its servers as a privacy-preserving hash of your IP address and browser user-agent combined with a secret salt that rotates daily and is then deleted, so the result cannot be traced back to you and is not used to identify or track you across days. Because nothing is stored on your device and the data is anonymized, this does not require your consent; we rely on our legitimate interest in understanding whether the product is being used (see Section 4). If you consent to analytics, we switch to full, identifiable analytics as described above.

Analytics cookies (requires your consent)

  • kb_attr - remembers which channel brought you to the site (for example, a search engine, a social network, or an advertisement) so we can measure our marketing. It stores the campaign parameters and referring page from your first visit, and lasts up to 90 days. We write it only once you have consented to analytics cookies, and it is never written before then. If you sign up, the value is copied once to your account so we can report which channel brought us your signup; it is not overwritten on later visits, so it always reflects your original first visit.

Marketing cookies (requires your consent)

  • Meta Pixel: sets cookies to measure advertising effectiveness and deliver relevant advertisements. The two it uses are _fbp (a browser identifier) and _fbc (a record of the advertising click that brought you here). Both last up to 90 days.
  • _fbc, written by us: if you arrive from a Meta advertisement (your link carries an fbclid parameter) and the Meta Pixel has not written this cookie itself, our own code writes it, using the same format and the same 90-day lifetime, so the click can still be attributed. We do this only once you have consented to marketing cookies, and we never overwrite a value the Pixel has already set.
  • Account-side copy: while you are signed in with marketing consent given, we copy these cookie values, along with your IP address and browser user-agent, to your account so our server can send the matching sign-up, checkout, subscription and purchase confirmations to Meta. This account-side copy is deleted along with the rest of your account data if you delete your account.

Bot protection

  • Cloudflare Turnstile: may set cookies transiently during bot verification challenges on forms.

You can manage your tracking preferences at any time through our consent banner or by visiting your tracking settings. Rejecting non-essential tracking does not affect your ability to use KleioBase.

For more information about how to control cookies and local storage in your browser, visit your browser’s help documentation.

Section 11

Your privacy rights

11.1 Rights for all users

Regardless of where you are located, you can:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your data (including GEDCOM export of family tree data)
  • Withdraw consent for optional processing (analytics, marketing)
  • Object to processing based on legitimate interest

Many of these rights are available as self-service actions inside the platform, without needing to contact us:

  • Download my data - a full ZIP export of all personal data we hold (account, records, people, families, matches, Research Companion history, and original file uploads) is available at Settings - Import / Export. We email you a download link when the archive is ready. The link expires after 7 days and can be regenerated.
  • Delete account - permanently erases your account and all associated data. Available at Settings - Account. The flow requires you to type your account email, click a single-use confirmation link sent to that address, and then re-authenticate (re-enter your password, or re-sign-in with your identity provider). See Section 9 for what deletion covers.
  • Clear KB data - deletes all knowledge-base content (records, profiles, families, matches, Research Companion conversations) while keeping your account active. Available at Settings - Account. Like account deletion, it requires confirming via a single-use link emailed to you and then re-authenticating.

For any right not covered by a self-service flow, contact us at [email protected].

11.2 EEA and UK residents (GDPR / UK GDPR)

If you are in the European Economic Area or the United Kingdom, you have the following additional rights under the GDPR (or UK GDPR):

  • Right of access (Art. 15): obtain a copy of all personal data we process about you.
  • Right to rectification (Art. 16): correct inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): request deletion of your personal data (“right to be forgotten”).
  • Right to restriction of processing (Art. 18): request that we limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format. We support GEDCOM export for genealogy data and JSON export for other data.
  • Right to object (Art. 21): object to processing based on legitimate interest, including profiling.
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint: you may file a complaint with your local supervisory authority. A list of EEA data protection authorities is available at edpb.europa.eu. For UK residents, contact the Information Commissioner’s Office (ICO) at ico.org.uk.

11.3 California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.

Categories of personal information collected

Using CCPA-defined categories, we collect the following:

CCPA categoryExamplesSourceBusiness purposeRetention
A. IdentifiersEmail address, display name, IP address, device identifiersDirectly from you; automatically collectedAccount management, service delivery, analyticsDuration of account
B. Personal information categories (Cal. Civ. Code § 1798.80(e))Name, email addressDirectly from youAccount managementDuration of account
C. Protected classification characteristicsRacial or ethnic origin, nationality, or ancestry as may be revealed by genealogy records you uploadGenerated from your uploads via AI processingCore service functionality (genealogy research)Duration of account
D. Commercial informationSubscription type, purchase history, PAYG credit balanceDirectly from you; from FreemiusBilling, service deliveryDuration of account + 7 years (tax records)
F. Internet or similar network activityBrowsing history on our site, interactions with the Service, including where you came from before arriving (campaign parameters, referring page, landing page)Automatically collectedAnalytics, product improvementPer analytics retention settings
G. Geolocation dataIP-derived approximate locationAutomatically collectedAnalytics, content deliveryPer analytics retention settings
H. Sensory dataPhotographs and scanned images of historical documents you uploadDirectly from youAI processing and document storageDuration of account
K. InferencesAI-extracted genealogical relationships, family connectionsGenerated from your uploads via AI processingCore service functionalityDuration of account

Sale and sharing of personal information

We do not sell your personal information as defined by the CCPA.

We may “share” personal information (as defined by the CCPA/CPRA) with Meta for cross-context behavioral advertising purposes when you have consented to marketing cookies. The categories shared are A. Identifiers (email address, account identifier, IP address, and the Meta browser cookies), B. Personal information categories (first and last name), D. Commercial information (that you started a checkout or subscribed, and the amount, currency and transaction reference of a purchase), F. Internet or similar network activity (page views, your browser user-agent, and the fact that you confirmed your first record), and G. Geolocation data (the billing country and postal code of a purchase). We do not share uploaded documents or any genealogy data with Meta. You can opt out of this sharing at any time by:

  • Adjusting your cookie preferences to reject marketing cookies
  • Using the “Do Not Sell or Share My Personal Information” link in our website footer
  • Enabling the Global Privacy Control (GPC) signal in your browser. We honor GPC signals as a valid opt-out request.

Sensitive personal information

Genealogical data may be considered sensitive personal information under the CPRA, particularly where it reveals racial or ethnic origin. We use sensitive personal information only as necessary to provide the Service (document processing and genealogy research) and do not use it for purposes beyond what is permitted under the CCPA/CPRA.

Your CCPA/CPRA rights

  • Right to know: request disclosure of (a) the categories of personal information we have collected about you, (b) the categories of sources, (c) the business or commercial purpose for collecting, and (d) the specific pieces of personal information we have collected about you (CCPA § 1798.110).
  • Right to delete: request deletion of your personal information.
  • Right to correct: request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: opt out of the sharing of your personal information for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information: direct us to limit the use of your sensitive personal information to what is necessary for the Service.
  • Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights.

We do not use or disclose sensitive personal information for purposes other than those permitted under CCPA § 1798.121.

Authorized agents

You may designate an authorized agent to make requests on your behalf. We may require the agent to provide proof of your written authorization and verify your identity directly.

Financial incentive programs

We do not offer any financial incentive programs tied to the collection of personal information.

11.4 Australian residents

Under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), you have the right to:

  • Access your personal information (APP 12)
  • Request correction of inaccurate, out-of-date, incomplete, or misleading personal information (APP 13)
  • Complain about a breach of the APPs. We will respond to your complaint within 30 days.
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you are not satisfied with our response.

Sensitive information: genealogy records may contain information that reveals racial or ethnic origin, which is “sensitive information” under the Australian Privacy Act. We collect such information only with your consent (which you provide by uploading the document) and use it solely for the purpose of providing the genealogy service.

11.5 Canadian residents (PIPEDA)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access your personal information held by us
  • Challenge the accuracy and completeness of your personal information and have it amended as appropriate
  • Withdraw consent for the collection, use, or disclosure of your personal information (subject to legal or contractual restrictions)
  • Complain to us about our personal information handling practices
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca if you are not satisfied with our response.

11.6 New Zealand residents

Under the New Zealand Privacy Act 2020 and the Information Privacy Principles (IPPs), you have the right to:

  • Access your personal information (IPP 6)
  • Request correction of your personal information (IPP 7)
  • Lodge a complaint with the Office of the Privacy Commissioner at privacy.org.nz.

11.7 Israeli residents

Under Israel’s Protection of Privacy Law 5741-1981 (as amended, including Amendment 13 effective August 2025), you have the right to:

  • Access personal data held about you in our databases
  • Request correction or deletion of inaccurate data
  • Object to the use of your data for direct marketing purposes
  • Sue for privacy violations without the need to prove actual harm (under Amendment 13)
  • Lodge a complaint with the Privacy Protection Authority (PPA) at gov.il/privacy-protection-authority.

We have designated a Privacy Protection Officer, reachable at [email protected], who is responsible for our compliance with the Protection of Privacy Law and for handling your requests.

Section 12

How to exercise your rights

To exercise any of the rights described above, please contact us at:

Email: [email protected]

We will respond to your request within:

  • 30 days for GDPR / UK GDPR requests (extendable by two further months for complex requests)
  • 45 days for CCPA/CPRA requests (extendable by an additional 45 days with notice)
  • 30 days for Australian Privacy Act requests
  • 30 days for PIPEDA requests (extendable to 60 days with notice)
  • 20 working days for New Zealand Privacy Act requests
  • 30 days for Israeli Protection of Privacy Law requests

We may need to verify your identity before processing your request. We will not charge a fee for processing reasonable requests, except where requests are manifestly unfounded or excessive.

Section 13

Children's privacy

KleioBase is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe that we have collected personal information from a child under 16, please contact us at [email protected], and we will take steps to delete that information.

Note regarding genealogy data: uploaded historical records may contain information about individuals who were minors at the time the record was created. This data is processed solely for genealogical research purposes and does not involve the direct collection of data from children.

Section 14

Data security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Authentication via secure, industry-standard methods (Supabase Auth)
  • Access controls limiting who can access personal data
  • Regular review of security practices
  • Incident response procedures (see Section 15)

No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee its absolute security.

Section 15

Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Art. 33 and UK GDPR)
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
  • Notify the OAIC and affected individuals as soon as practicable under Australia’s Notifiable Data Breaches scheme
  • Comply with breach notification requirements under CCPA, PIPEDA, the NZ Privacy Act 2020, and Israel’s Privacy Protection Law as applicable

Section 16

Changes to this privacy policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the “Last updated” date at the top of this policy
  • Notify you by email or through a prominent notice on our website
  • Where required by law, obtain your consent to material changes

We encourage you to review this policy periodically.

Section 17

Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: [email protected]
Website: https://kleiobase.com/privacy

For EEA residents: a GDPR Article 27 EU Representative is being appointed. Until then, please direct any EEA data-protection enquiries to us using the contact details above and we will respond.

For UK residents: a UK GDPR Article 27 UK Representative is being appointed. Until then, please direct any UK data-protection enquiries to us using the contact details above and we will respond.

This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Australian Privacy Act 1988, the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the New Zealand Privacy Act 2020, and Israel’s Protection of Privacy Law 5741-1981 (as amended).

We use cookies and similar technologies. Essential cookies keep the site working. We only load analytics (PostHog) and marketing (Meta Pixel) with your consent. See our Privacy Policy.