Last updated 24 September 2026. In force from the same day.
Kerabat is a private family planner: one family keeps its spending, receipts, children's classes and payment dates in one place, and sees them in its own Google Calendar.
This policy says what the app stores, where it stores it, who can see it, and how you take it with you or have it deleted. It describes this app as it actually works — not a kind of app in general.
Kerabat is run by Yahor Karabelnikau, a private person, in Poland.
Write to privacy@kerabat.app with any question about this policy or about your data; the answer comes from the same address. For the purposes of the GDPR the data controller is Yahor Karabelnikau.
There are two ways in, and you choose. With Google: from your Google profile the app takes and stores your email address, your display name and the account identifier Google gives it — and nothing else. With a code sent to your email: you type an address, the app emails an eight-digit code to it, and that address becomes your account; nothing about you comes with it, so the app asks you for a name separately. Either way, your email address is how the rest of your family recognises you, and how the family calendar is shared with you. What signing in by a code leaves on the server while it is happening is in §2.3.
There is no analytics, no advertising and no third-party tracker of any kind in the app: no Google Analytics, no advertising SDK, no session recorder, no measurement library. We build no profile of you and do not follow you across other sites.
Some of what the app remembers never leaves your device. It is kept in the browser on that device alone:
Clearing your browser data removes all of it. None of it is used to recognise you anywhere else.
Kerabat asks for access to your Google Calendar. Here is exactly what it does with it.
The family calendar belongs to the Google account that created it. Its owner opens it to another member of the family by hand, from that person’s card in the app, using the email address that person is in the family under. What is granted is the right to write to that calendar, so that a lesson moved in Google moves for everybody.
The app closes again what it opened itself. Only a calendar’s owner may change who it is open to, and the app acts for them: it remembers each grant it made, offers to close it, and closes it by itself, on the owner’s next visit, for anyone who has left the family. Access that was opened before the app learned to keep track of its own grants it cannot close — it says so plainly and leads the owner to the place in Google where that one is taken away (§6).
The app’s access to your calendar is a short-lived access token from Google, good for about an hour. It is kept in your browser on your device only. Kerabat has no refresh token, and our servers never hold any credential to your Google account: when the token runs out, your calendar is out of the app’s reach until you press the button again.
You can withdraw the app’s access to your Google account at any time at myaccount.google.com/permissions. Events Kerabat has already written into your calendar stay there, and you can delete them, or the whole calendar, in Google Calendar.
Kerabat’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain words: what comes from your Google Calendar is used to show you your day in Kerabat and to keep your family’s calendar up to date, and for nothing else. It is not sold, not passed on, not used for advertising and not used to train any model.
When you photograph a receipt, the picture is uploaded to our storage and sent to Google Vertex AI (Google’s Gemini models) to read the total, the date, the shop and the lines.
Receipt photographs are deleted automatically 24 months after they are uploaded. That is a lifecycle rule on the storage bucket, not somebody remembering to do it.
The expense stays, and so does everything that was read off the photograph. Only the picture goes. The amount, the date, the shop, the categories — and every line of the receipt, each purchase by name and price — stay in your family’s history for as long as the family does. The app shows such an expense as usual, just without a picture.
You can also delete a receipt photograph yourself at any time, from the receipt’s screen in the app.
Only the members of your family. This is held up by the database’s own security rules and not merely by which screens the app draws: a request from someone who is not a member of the family at that moment is refused by the server.
The data is held with Google Firebase / Google Cloud, which is our main processor. The second is Resend, the mail service the sign-in code and the letters about deleting an account go through. It is given only the recipient’s address and the text of the letter itself — nothing of the spending, the receipts or the classes. Resend keeps that on servers in the United States; the transfer rests on its certification under the EU-US Data Privacy Framework, and the Article 28 data processing agreement has been in force since our account was opened. There are no other processors.
| What | Service | Where |
|---|---|---|
| Family data — spending, classes, bills, settings | Cloud Firestore | eur3 — a multi-region in the EU (Belgium and the Netherlands) |
| Receipt photographs | Cloud Storage | europe-west1 (Belgium) |
| Server code — reading receipts, reminders, deletion | Cloud Functions | europe-west1 (Belgium) |
| Reading receipts | Vertex AI | the global endpoint — the reading may happen outside the EU (§5) |
| Sign-in, push notifications | Firebase Authentication, Firebase Cloud Messaging | Google’s own infrastructure |
the exact GDPR bases for the country of registration, if the owner takes legal advice on them
Write to privacy@kerabat.app and we will send you your records in a machine-readable form — within one month at the latest.
The button is in the app: Settings → Your account → «Delete my account». If you are in no family at the moment, the same button is on the welcome screen. Pressing it erases nothing on the spot: your account is deleted after thirty days, exactly as a family is — the same number of days on purpose, so that calling it off never gives you back less than it took — and for all of those days the app works as usual and carries one line on every screen — «Your account will be deleted 22 October» — with a tap that brings it back.
The warning is in the app: for all thirty days every screen carries one line — the day the account will be deleted — and next to it the tap that calls the deletion off. We also send two letters to the address of the account: the moment you ask, and three days before that day. A letter is an addition to that line, not a replacement for it: delivery depends on mail services we do not control, we do not promise it, and a letter may be delayed or land in your spam folder. Nothing in either letter deletes or restores anything — the way back is always the app.
What happens on that day depends on who else is in your family.
What is erased. Your profile — your settings, your notification choices, the language you picked, the tokens of the phones you allowed notifications on — and the account itself in Firebase Authentication: your email address, your name and the identifier the account was given. Nothing is left to sign in with; signing in afterwards with the same address makes a new, empty person.
What stays with your family, and we would rather say it than promise otherwise. The spending and payments you recorded belong to the family, not to you, and they are not deleted with your account — a family goes on reading its own history. So the family’s member list keeps one thing about you: your name stays, and your email address is erased along with the account. The name is what stands under everything you recorded, and taking it away would leave a year of a family’s money saying “somebody paid for this”. The address never stood under anything, so there is no reason to keep it.
What deleting your account cannot remove. The app cannot delete the events it has written into your Google Calendar, because our servers hold no credential to your Google account and never will. Kerabat says so at the moment you ask, in the same words as above: delete that calendar, or those events, in Google Calendar yourself — nothing on our side can do it for you afterwards.
If you are in the EU, the EEA or the UK you have the right to see your data, to correct it, to have it erased, to restrict or object to its processing, and to take it with you (§9). One of those you do not have to ask us for: erasure is the button (§10.1) — it is in the app and does not wait on us. For anything else, taking your data with you included, write to privacy@kerabat.app and we answer within one month.
You may also complain to a supervisory authority — in Poland that is the President of the Personal Data Protection Office (UODO).
Kerabat is used by adults. A parent records their own children’s classes and payments, so a family’s records may hold a child’s name and their schedule. Children have no account of their own and do not sign in. An account can be opened from the age of 13; younger than that, the app is not for you.
We do not sell your data. We do not share it with advertisers, data brokers or resellers of information. We do not use it for advertising, for credit scoring, or to train models. Nobody but Google, as the provider of the infrastructure the app runs on, has access to it.
If we change this policy in a way that changes how your data is used, we will say so in the app before the change takes effect, and change the date at the top.
Contact: privacy@kerabat.app