Kerabat

Privacy policy

Last updated 24 September 2026. In force from the same day.

Kerabat is a private family planner: one family keeps its spending, receipts, children's classes and payment dates in one place, and sees them in its own Google Calendar.

This policy says what the app stores, where it stores it, who can see it, and how you take it with you or have it deleted. It describes this app as it actually works — not a kind of app in general.

1. Who we are

Kerabat is run by Yahor Karabelnikau, a private person, in Poland.

Write to privacy@kerabat.app with any question about this policy or about your data; the answer comes from the same address. For the purposes of the GDPR the data controller is Yahor Karabelnikau.

2. What Kerabat stores

2.1 How you sign in

There are two ways in, and you choose. With Google: from your Google profile the app takes and stores your email address, your display name and the account identifier Google gives it — and nothing else. With a code sent to your email: you type an address, the app emails an eight-digit code to it, and that address becomes your account; nothing about you comes with it, so the app asks you for a name separately. Either way, your email address is how the rest of your family recognises you, and how the family calendar is shared with you. What signing in by a code leaves on the server while it is happening is in §2.3.

2.2 What your family writes into the app

2.3 Technical records

2.4 What Kerabat does not collect

There is no analytics, no advertising and no third-party tracker of any kind in the app: no Google Analytics, no advertising SDK, no session recorder, no measurement library. We build no profile of you and do not follow you across other sites.

3. What is kept in your browser

Some of what the app remembers never leaves your device. It is kept in the browser on that device alone:

Clearing your browser data removes all of it. None of it is used to recognise you anywhere else.

4. Google Calendar

Kerabat asks for access to your Google Calendar. Here is exactly what it does with it.

4.1 What the app writes

4.2 What the app reads

4.3 Sharing the family calendar

The family calendar belongs to the Google account that created it. Its owner opens it to another member of the family by hand, from that person’s card in the app, using the email address that person is in the family under. What is granted is the right to write to that calendar, so that a lesson moved in Google moves for everybody.

The app closes again what it opened itself. Only a calendar’s owner may change who it is open to, and the app acts for them: it remembers each grant it made, offers to close it, and closes it by itself, on the owner’s next visit, for anyone who has left the family. Access that was opened before the app learned to keep track of its own grants it cannot close — it says so plainly and leads the owner to the place in Google where that one is taken away (§6).

4.4 Where the Google token lives

The app’s access to your calendar is a short-lived access token from Google, good for about an hour. It is kept in your browser on your device only. Kerabat has no refresh token, and our servers never hold any credential to your Google account: when the token runs out, your calendar is out of the app’s reach until you press the button again.

You can withdraw the app’s access to your Google account at any time at myaccount.google.com/permissions. Events Kerabat has already written into your calendar stay there, and you can delete them, or the whole calendar, in Google Calendar.

4.5 Limited Use

Kerabat’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain words: what comes from your Google Calendar is used to show you your day in Kerabat and to keep your family’s calendar up to date, and for nothing else. It is not sold, not passed on, not used for advertising and not used to train any model.

5. Receipt photographs and automatic reading

When you photograph a receipt, the picture is uploaded to our storage and sent to Google Vertex AI (Google’s Gemini models) to read the total, the date, the shop and the lines.

5.1 How long a receipt photograph is kept

Receipt photographs are deleted automatically 24 months after they are uploaded. That is a lifecycle rule on the storage bucket, not somebody remembering to do it.

The expense stays, and so does everything that was read off the photograph. Only the picture goes. The amount, the date, the shop, the categories — and every line of the receipt, each purchase by name and price — stay in your family’s history for as long as the family does. The app shows such an expense as usual, just without a picture.

You can also delete a receipt photograph yourself at any time, from the receipt’s screen in the app.

6. Who can see your data

Only the members of your family. This is held up by the database’s own security rules and not merely by which screens the app draws: a request from someone who is not a member of the family at that moment is refused by the server.

The data is held with Google Firebase / Google Cloud, which is our main processor. The second is Resend, the mail service the sign-in code and the letters about deleting an account go through. It is given only the recipient’s address and the text of the letter itself — nothing of the spending, the receipts or the classes. Resend keeps that on servers in the United States; the transfer rests on its certification under the EU-US Data Privacy Framework, and the Article 28 data processing agreement has been in force since our account was opened. There are no other processors.

7. Where your data is kept

WhatServiceWhere
Family data — spending, classes, bills, settingsCloud Firestoreeur3 — a multi-region in the EU (Belgium and the Netherlands)
Receipt photographsCloud Storageeurope-west1 (Belgium)
Server code — reading receipts, reminders, deletionCloud Functionseurope-west1 (Belgium)
Reading receiptsVertex AIthe global endpoint — the reading may happen outside the EU (§5)
Sign-in, push notificationsFirebase Authentication, Firebase Cloud MessagingGoogle’s own infrastructure

8. Why we are allowed to hold this data

the exact GDPR bases for the country of registration, if the owner takes legal advice on them

9. Taking your data with you

Write to privacy@kerabat.app and we will send you your records in a machine-readable form — within one month at the latest.

10. Deleting your data

10.1 Deleting your account

The button is in the app: Settings → Your account → «Delete my account». If you are in no family at the moment, the same button is on the welcome screen. Pressing it erases nothing on the spot: your account is deleted after thirty days, exactly as a family is — the same number of days on purpose, so that calling it off never gives you back less than it took — and for all of those days the app works as usual and carries one line on every screen — «Your account will be deleted 22 October» — with a tap that brings it back.

The warning is in the app: for all thirty days every screen carries one line — the day the account will be deleted — and next to it the tap that calls the deletion off. We also send two letters to the address of the account: the moment you ask, and three days before that day. A letter is an addition to that line, not a replacement for it: delivery depends on mail services we do not control, we do not promise it, and a letter may be delayed or land in your spam folder. Nothing in either letter deletes or restores anything — the way back is always the app.

What happens on that day depends on who else is in your family.

What is erased. Your profile — your settings, your notification choices, the language you picked, the tokens of the phones you allowed notifications on — and the account itself in Firebase Authentication: your email address, your name and the identifier the account was given. Nothing is left to sign in with; signing in afterwards with the same address makes a new, empty person.

What stays with your family, and we would rather say it than promise otherwise. The spending and payments you recorded belong to the family, not to you, and they are not deleted with your account — a family goes on reading its own history. So the family’s member list keeps one thing about you: your name stays, and your email address is erased along with the account. The name is what stands under everything you recorded, and taking it away would leave a year of a family’s money saying “somebody paid for this”. The address never stood under anything, so there is no reason to keep it.

What deleting your account cannot remove. The app cannot delete the events it has written into your Google Calendar, because our servers hold no credential to your Google account and never will. Kerabat says so at the moment you ask, in the same words as above: delete that calendar, or those events, in Google Calendar yourself — nothing on our side can do it for you afterwards.

11. Your rights

If you are in the EU, the EEA or the UK you have the right to see your data, to correct it, to have it erased, to restrict or object to its processing, and to take it with you (§9). One of those you do not have to ask us for: erasure is the button (§10.1) — it is in the app and does not wait on us. For anything else, taking your data with you included, write to privacy@kerabat.app and we answer within one month.

You may also complain to a supervisory authority — in Poland that is the President of the Personal Data Protection Office (UODO).

12. Children

Kerabat is used by adults. A parent records their own children’s classes and payments, so a family’s records may hold a child’s name and their schedule. Children have no account of their own and do not sign in. An account can be opened from the age of 13; younger than that, the app is not for you.

13. Selling and sharing

We do not sell your data. We do not share it with advertisers, data brokers or resellers of information. We do not use it for advertising, for credit scoring, or to train models. Nobody but Google, as the provider of the infrastructure the app runs on, has access to it.

14. Changes to this policy

If we change this policy in a way that changes how your data is used, we will say so in the app before the change takes effect, and change the date at the top.

Contact: privacy@kerabat.app