Legal · Version 0.1 · September 27, 2026
Privacy Policy
This policy explains what information The Unbroken Table Limited collects, why, and the choices and rights you have. We are the agency (under the NZ Privacy Act 2020) and controller (under the GDPR) responsible for your information.
- Company: The Unbroken Table Limited, NZBN 9429053895943, [registered office address to be confirmed]
- Privacy officer: [privacy officer to be named], privacy@theunbrokentable.com
- EU and UK representatives: to be appointed before we offer the service in the EU and UK.
What we collect
- Account details: your name, email address, sign-in method and, when paid plans arrive, billing details (card details are handled by our payment provider; we never store card numbers).
- What you keep: photographs of originals, recipes, stories, memories, and later voice recordings.
- Information about other people in that content: the grandmother whose recipe it is, the uncle in the photograph, the children at the table.
- Device and usage information: what is needed to keep you signed in, keep the service secure, and fix problems.
Recipes and stories can reveal sensitive things, such as religion, ethnic background or health. We treat all content as private by default and never use it for advertising.
Why we use it
| Purpose | Legal basis (GDPR) |
|---|---|
| Running The Unbroken Table: storing and showing what you keep to the people you share it with | Contract |
| Reading handwriting with AI (you can switch this off for each Table) | Contract |
| Keeping the service secure and preventing abuse | Legitimate interests |
| Billing and tax records | Legal obligation |
| Product improvement, using aggregated measurement (see early access below for what applies during beta) | Legitimate interests |
| Occasional emails about the product, only if you agree | Consent |
During early access (beta and development)
While The Unbroken Table is in early access, we are still building it, and we need to see how it is really used so we can fix problems. On our beta and development sites (for example dev.theunbrokentable.com), we therefore collect more than we will once the service is launched:
- Usage and performance analytics: pages visited, how long they take to load, the device and browser type, and the country you visit from.
- Error reports: technical details when something goes wrong in your browser.
- Session recordings: a recording of how the pages you use appear and respond, including what is shown on screen, such as the text of recipes and memories. Passwords and payment details are never recorded.
This information is collected by Ghostwire Analytics, our own analytics service, which we operate ourselves. It is not sent to Google or any other outside analytics or advertising company, it is never sold, and it is never used to train AI models. Only the people building The Unbroken Table can see it, and only to understand and fix problems. Recordings and analytics from early access are kept for up to [retention period to be confirmed] and then deleted.
If you would prefer not to be recorded, please don't use the beta or development sites with family content you'd rather keep out of recordings, and contact us to have any recordings of your sessions deleted. Session recording will be switched off, or limited to screens without family content, before we launch.
Reading handwriting with AI
When a Table has AI reading switched on, images of originals are sent to our AI provider (Anthropic) to produce a readable draft. The provider processes them only to return that draft; they are not used to train AI models, and we use the shortest retention the provider offers. The readable version is always labelled as an AI draft until a person has reviewed it. A Keeper can switch AI reading off, and originals are then read by people only.
Who can see it
- People at your Table, according to each item's visibility. Items are private or shared with the Table; nothing is public unless someone deliberately makes it so.
- Our subprocessors, who help us run the service under contract. See the subprocessor list.
- Authorities, only where the law requires it.
We never sell information and we have no advertising trackers.
People in the content who don't have an account
Families keep information about people who never signed up. If that includes you, or someone you represent, you can ask us to show you what we hold, correct it, or remove it, using our contact page. You do not need an account. We balance your rights with the family's legitimate interest in preserving its history, and we will explain our decision.
People who have died
Privacy laws often do not cover people who have died, but families care deeply about them. We handle requests from relatives about a person who has died respectfully and consistently; see our succession and family disputes policy.
Where it is stored
Information is stored with our hosting and storage providers in the regions listed on the subprocessor list. When information leaves New Zealand or the EU, we use contractual safeguards that give it comparable protection.
How long we keep it
- Your account and content: while your account and Tables exist.
- Deleted items: recoverable for 30 days, then permanently deleted.
- Closed accounts: deleted after a 30-day grace period, with an export link emailed to you.
- Backups: kept for 35 days, so deleted information has left all backups within that time.
- Security and audit records: up to 7 years, with personal details kept to a minimum.
Your rights
You can ask to access, correct, delete, restrict or object to our use of your information, and to receive a copy to take elsewhere. Many of these you can do yourself: export and delete are in your account settings. Otherwise use our contact page. We reply within 20 working days.
If you are unhappy with our response, you can complain to the Office of the Privacy Commissioner in New Zealand, or the data protection authority where you live.
Children
Accounts are for people aged 16 and over. Photographs of children at the family table are common; they are private to the Table, never publicly indexed, and we do not use facial recognition. See our children's policy.
Security
Information is encrypted in transit and at rest, access is limited to the people who need it, and originals are stored so they cannot be overwritten. If a breach is likely to cause serious harm, we will tell you and the regulators promptly.
Changes
We will tell you about material changes before they take effect.