1. Who is responsible?
Kireli is offered by Anchor Labs. Anchor Labs is the legal operator of the Kireli service.
Anchor Labs is the controller for account, platform, security, billing and other operational processing needed to provide Kireli.
Users decide which personal content they place or share in Spaces. Kireli processes that content technically to host and make the service available. Legal roles may differ depending on context; this notice does not claim that Anchor Labs is in every conceivable situation the sole controller for all data in a Space.
- Anchor Labs
- Van Wesembekestraat 113
- 3132 XW Vlaardingen
- Netherlands
- KvK: 92264514
- VAT ID: NL004946495B59
- Email: support@kireli.eu
- Phone: 085-0607073
No separate data protection officer (DPO) has been appointed. You can address privacy questions to support@kireli.eu.
2. Who does this notice cover?
This notice applies to visitors of https://kireli.eu, account users, invitees who receive an invitation, and persons whose data are placed in a Space by a user.
Shared content in a Space may contain personal data of others. Whoever uploads or shares content remains responsible for lawful and careful handling of that content.
3. Which personal data does Kireli process?
Depending on how you use Kireli, we may process among others the following categories:
- Account data: email address, display name, preferred language, time zone, account status
- Security data: password hash, session data, email verification and reset status
- Confirmation timestamps: independent 16+ age (where applicable), terms, privacy information
- Account participation mode (independent or family participation via parent/guardian)
- Space and membership data: roles, status, invitations (including invitation type)
- Parent/guardian authorisations for participation under 16 in a Space (without date of birth on that path)
- Optional birthday on the account profile (month/day; optional year). The year stays account-private. Sharing into Spaces is explicit and month/day only, without age. Not used for 16+ access
- Content: memories, messages, reactions, albums, media metadata and files you upload
- Special moments in a Space (user-entered meaningful dates, optionally linked to a member, memory or event)
- Space games: participation, year guesses, timeline orders, rounded map-point guesses (not device location) and scores inside a Space. No public leaderboards or matchmaking
- Location data you deliberately share in Trip Mapping (device location, map selection, or optionally from a photo)
- Notifications addressed to you
- Subscription and billing references via Stripe
- Print orders: product configuration, delivery details, order status and temporary print assets
- Safety reports and related context
- Audit and security events (without unnecessary secrets)
- Formal privacy requests (type, status, deadlines, limited explanation)
We do not process separate marketing profiles and do not use advertising tracking systems on the current Kireli website.
4. Where does personal data come from?
- Directly from you (registration, profile, content, print checkout, privacy requests)
- From other Space members (shared content, invitations, reactions)
- From payment and billing processes via Stripe
- From print fulfilment status updates via our print partner
- Technically generated by the service (sessions, logs, rate limits, order status)
5. Why do we process this data?
- To provide and maintain the Kireli service
- To secure accounts and prevent abuse
- To enable Spaces, invitations and shared memories
- Optional Space games among active members of one Space, using memories and trip places those members can already see
- Private Trip Mapping: showing stops and locations to authorised members of the chosen Space
- To send transactional emails
- To handle subscriptions and print orders
- To comply with legal administrative obligations
- To handle privacy rights
- To improve the service insofar as that happens without tracking analytics
6. Lawful basis per processing purpose
Below we explain how we legally ground processing. Agreeing to the terms or reading privacy information at registration is not general GDPR consent for all processing. For core delivery of Kireli we primarily rely on the contract and, where appropriate, legitimate interest or legal obligation.
- Account registration and core delivery of the Kireli service: Performance of the contract. Needed to provide your account and Spaces under the terms.
- Authentication, sessions, password recovery and account security: Legitimate interest. Interest: securing accounts and preventing abuse. Also partly necessary for contract performance.
- Hosting of Spaces, memories, media and shared content: Performance of the contract. Core of the digital service.
- Invitations to email addresses: Performance of the contract. Needed to share Spaces as the service works. The inviting user is responsible for a correct email address.
- Transactional email (verification, reset, invitations, order/billing, rights confirmation): Performance of the contract. No marketing newsletter in the current product architecture.
- Subscriptions, payments and Stripe Tax/invoicing: Performance of the contract. Stripe processes payment data as payment service provider.
- Retention of relevant financial data: Legal obligation. Insofar as accounting or tax rules require this.
- Print orders, production and shipping via PrintAPI: Performance of the contract. Including delivery details and print files needed for fulfilment.
- Safety/reporting, rate limiting, audit and security logs: Legitimate interest. Interest: safety, integrity of the service and investigation of abuse.
- Handling formal privacy requests (access, restriction, objection): Legal obligation. GDPR rights and accountability. Additionally contract where it concerns service delivery.
- Age confirmation (16+) at independent registration: Legitimate interest. Interest: appropriate access to the service for independent accounts. No DOB. Guardian-mediated minors use a separate family route without a 16+ claim.
- Parent/guardian authorisation for family participation under 16 in a Space: Consent / authorisation (product route). Explicit attestation by the Space owner. No claim that this makes every conceivable processing lawful. No DOB or identity documents.
- Optional birthday on the account profile: Performance of the contract for storage on the account. Sharing only the day (month/day) in Spaces: consent via an in-product switch. No age without a year. If that day is visible in a Space, Kireli may send an in-app notice and optional Web Push on the day (no birth year, no age, no email). You can turn off Moments notifications in notification preferences.
- Special moments in a Space: Performance of the contract. User-entered content that belongs to the Space, visible to active members.
- Space games: Performance of the contract. Play, answers and scores stay inside one Space among active members.
7. Spaces and shared memories
Kireli is built around private Spaces. Content you share is visible to members (or a narrower visibility group) according to the settings in the Space. Anchor Labs hosts that content to provide the service, but does not take ownership of your family photos or stories.
Other members can continue to see their own content for as long as that Space exists, even if you later close your account. Account closure therefore does not automatically erase all shared content everywhere. Special moments belong to the Space, not exclusively to the creator, and are removed when the Space is deleted.
8. Invitations and data about others
If you invite someone, we process the email address you provide to send the invitation. Use only addresses for which you have a good reason to invite someone. Invitees receive a transactional email with context about the Space and the inviter.
9. Media and uploads
Media are stored privately via object storage. Uploads use temporary, secured upload URLs. We do not display or share a public media library outside the Space context. Object storage keys and signing secrets do not belong in customer exports.
Kireli does not use your photos to train AI models, not for advertising profiles, and not for facial or biometric identification. For platform safety we may use technical safety controls to detect prohibited or illegal content. At present no automated media classification is active. Print fulfilment to an external production partner happens only for content you consciously include in a print order, and only when the order has passed the required safety and operational checks.
Stored/READY photos are technically stripped of metadata such as EXIF, GPS, IPTC and XMP. If you explicitly choose in Trip Mapping to use location from a photo, we may read that location before sanitisation to create a separate PrivateLocation/stop. Declining does not prevent a normal photo upload. Kireli does not restore GPS into the stored photo.
READY videos are copied privately into object storage without metadata stripping. Video containers may still contain device or location metadata. Kireli does not strip that in this phase. Videos are not sent to YouTube, Vimeo or an external transcoder.
In Albums, Space members may store a shared heart on a photo they can see (a count is visible to authorised Album viewers; we do not publish a list of who liked it) and a private personal favourite that is visible only to that member. These records are not used for marketing, ranking people, or AI. Feed post reactions remain separate from Album photo hearts.
Members may link a feed post to Albums they can already see in that Space, using a name search (SmartTags). We store the link (which post, which Album, who linked it). This does not copy photos or use extra storage. Album names from another Space, or from a private Album you cannot see, are not suggested.
9b. Guest uploads via DropZone
A Space manager can create a temporary DropZone link or QR code so someone without a Kireli account can contribute photos or videos to one chosen album. That link is not membership, sign-in, or access to the Space, members, feed, albums or existing media. The guest only sees the contribution page.
Uploads use the same private object storage as other media and count toward the Space owner's storage quota. Photos are stripped of EXIF/GPS. Videos are copied privately without metadata stripping. Contributions stay quarantined until an authorised manager approves or rejects them. Rejected or unreviewed contributions are cleaned up within a bounded period. Approved media then belong to the album/Space under ordinary rules. There is no public gallery and no guest profile.
9c. Space games
Active members of a Space can play optional games that reuse memories and trip places already visible to those members. Guess the year, Kireli Quiz and Timeline use structured Space facts. Where were we? shows a photo from a Trip Stop. Questions are generated from existing authorised Space data only. Kireli does not use AI, image recognition or external recommendation services for this.
We store participation, submitted answers and scores as Space activity. Other members of that game can see the scoreboard. There is no public matchmaking, no global ranking, no gambling and no game currency. A game never shows a private or selected memory that is not already visible to every current player. Guests without Space membership cannot play.
In Where were we? you tap a point on the same-origin Kireli map. That is game input, not your current device location: Kireli does not request browser geolocation for this game. We store your rounded guessed coordinates, the distance to the actual Trip Stop, and the score. Actual trip coordinates remain existing Space-private location data; they are not added to your account export merely because you played. Other players in that round can see each other's guesses after the round closes, as ordinary game results. There is no reverse geocoding, no external map or geocoding service that receives game coordinates, and no new processor. Kireli does not keep a browsable archive of historic guess maps.
9a. Trip Mapping and location data
Trip Mapping is a private Space feature. Kireli processes location data only when you add it deliberately: with your current device location (after browser/device permission and an action in Kireli), by choosing a point on the map, or by optionally using location from a photo. Purposes include adding stops to a private trip, showing that trip to authorised members of the chosen Space, and keeping the trip as part of the private Kireli experience.
A location you deliberately share in a Space is visible to authorised ACTIVE members of that Space, including exact coordinates when you share them deliberately. It is not made publicly searchable merely by using Trip Mapping. Unauthenticated users, members of another Space, and platform admins without Space membership do not receive that location. Coordinates are not placed in audit logs, lock-screen notifications or public URLs.
Map display uses a Kireli-hosted copy of OpenStreetMap-derived global geography (PMTiles), stored as Kireli infrastructure on Backblaze B2 in a dedicated bucket separate from private trip photos. Your browser talks only to Kireli for that basemap. It does not send trip titles, Space IDs, user IDs, photos or coordinates to OpenStreetMap, Protomaps, Backblaze or a public tile server. OpenStreetMap and Protomaps are not processors of your private trip data; MapLibre and PMTiles are software libraries, not processors. Visible map credit includes OpenStreetMap contributors (ODbL) and Protomaps as the produced-work/basemap source.
Trip Mapping is not background tracking, not an emergency or safety service, and not real-time positioning. Stops appear when someone adds them deliberately. Authorised members of the Space can open an ongoing trip and see the latest deliberately shared place; Kireli does not follow location in the background. Locations follow the Space/trip lifecycle: removing a stop unlinks the location and deletes a PrivateLocation only if nothing else still uses it.
A Trip Stop may include a long-form story and private photos or videos. That is Space content, not public, and is not sent with basemap requests. Story text is not placed in audit metadata or lock-screen notifications. Only the stop’s author receives that story in an account export.
10. Account, security and sessions
For sign-in we use a first-party session cookie. Sessions are stored in our database and can be revoked by you. Passwords are stored hashed. Rate limiting helps against abuse.
11. Email communications
We send transactional email via Mailjet, for example for email verification, password reset, invitations, important Space events, warnings when a temporary Space is scheduled to be archived or deleted, billing updates, print status and confirmation of privacy requests. There is no separate marketing consent because Kireli has no marketing newsletter flow in the current architecture.
12. Billing and Stripe
Subscriptions and payments run via Stripe Checkout and the Stripe customer portal. Stripe processes payment data. Kireli stores subscription status and Stripe reference identifiers needed to link your subscription, not your full card number. If you stack unused Space entitlements onto one owned Space, we store that allocation (which Space, how many extra units). If you buy Space XL or Event XL, we also store which Space the add-on applies to, the tier, status and validity window. Stripe Price identifiers are billing configuration, not Space capacity records.
Invoices and VAT specification are generated by Stripe. Stripe Tax may calculate tax based on billing details.
13. Print Studio, PrintAPI and fulfilment
Print is optional. Kireli does not send your private media to a printer merely because they are in Kireli. Only media and content you consciously include in a print product may be processed for production and shipping. For that we process product configuration, order data, delivery address and the print files needed to make the chosen product. Fulfilment is via an external production partner (PrintAPI / Galeri.nl B.V.). Processing is limited to fulfilment and related operational purposes. Kireli does not use print content for advertising or AI training.
Print orders may undergo a content safety review. During Controlled Print Beta that review may be manual per order. There is no claim that automated media classification is active. Once physical production has started, deletion or withdrawal may be limited where that is operationally unavoidable. Temporary print assets and shipping data follow Print Studio privacy and retention logic.
More details about orders are in the print terms.
14. Safety and reporting
Kireli provides safety and reporting functionality within Spaces. Reports and related context may be processed to assess abuse or unsafe situations. Reports do not contain copies of images or permanent public media URLs.
Kireli does not routinely or randomly inspect private Space content. There is no quarterly manual review of private photos and no consent checkbox that would allow staff to browse private content periodically. Private content may be reviewed when necessary for a concrete safety report, a serious abuse or safety signal, or a legal obligation. That access is limited to what the case needs and is logged.
Lawful basis for this processing is legitimate interest in protecting people and the integrity of the service, and where applicable a legal obligation. Consent is not the default basis. Reporter identity is not shown to the reported person or ordinary Space members. Internal investigation notes are not included in the self-service account export.
14a. Private conversations (end-to-end encryption)
Kireli offers 1-to-1 private conversations between users who share at least one active Space. Message text, emoji, photos and voice messages are encrypted on the sender’s device (HPKE, RFC 9180). Kireli servers store ciphertext and routing metadata. Kireli cannot normally read these conversations. There is no silent administrator key.
Kireli still processes metadata: conversation id, sender, recipient devices, timestamps, delivery/read state and ciphertext size. Push and email notifications do not include message content. Conversation search happens on the device only.
If you report a private message, your client decrypts the selected messages and you deliberately send them to Trust & Safety. That is not a backdoor into the whole conversation. Lost device keys without a recovery code can make older history unreadable; a password reset does not unlock these messages.
15. Audit and security logs
We keep security and account events, for example login, session changes, privacy requests and account closure. In customer exports we show only a safe projection of your own actions, without raw security metadata such as IP hashes.
17. Who do we share data with?
We share personal data only where needed for:
- technical delivery of the service (hosting, database, storage, email)
- payments and invoicing (Stripe)
- print production and shipping (PrintAPI)
- members of a Space, insofar as you or the Space settings share content
- legal obligations or protection of rights, safety and integrity
18. Processors and categories of recipients
A customer-friendly overview of important external services is on the Processors page. The formal internal processor register is used for governance and is not a public page.
19. International transfers
Some service providers (for example payment, storage or email providers) may process personal data outside the European Economic Area or provide support from third countries. We do not claim that all data always remain exclusively in the EU. Where transfer takes place, we use the safeguards legally required for that, as set out in the contracts and documentation of those providers (for example a data processing agreement and, where applicable, standard contractual clauses or an adequacy mechanism).
20. Retention periods and criteria
We do not invent fixed periods for all data categories. In practice:
- account and service data for as long as your account is active and the contract runs
- after account closure, direct account data (such as email address and display name) in the live environment may be anonymised when there are no longer blockers; that does not necessarily happen immediately on closure
- shared memories and messages in other people's Spaces may remain; identifiable account data are removed or replaced there where possible
- data needed for security, abuse prevention or disputes, for as long as necessary
- financial and administrative data for as long as needed for business administration
- print orders and temporary print assets according to the existing Print Studio lifecycle
- Trip Mapping stops and related PrivateLocations for as long as the Space/trip exists, unless you remove a stop and the location is no longer used elsewhere
- DropZone configuration for as long as the Space exists; pending guest contributions for a bounded period after expiry or rejection; approved media according to Space/album rules
- Space games: abandoned waiting games after 7 days and stale in-progress games after 24 hours are cancelled; finished games remain with the Space until the Space is deleted
- formal privacy requests for as long as accountability reasonably requires
Technical retention periods (such as sessions and one-time tokens) are enforced. Not every log or report category already has a fixed period. Backups and copies at providers do not disappear automatically at the moment of account closure.
21. Backups
Technical backups may contain data longer than the live environment. We do not promise that data disappear immediately and individually from all backups at the moment of account closure.
22. Rights of data subjects
Insofar as the GDPR applies, you may among other things request:
- access
- rectification
- erasure
- restriction of processing
- portability where applicable
- objection to processing based on legitimate interest
Submitting a request does not automatically mean the request has already been granted. We confirm receipt and handle it within the statutory periods, unless we let you know that more time is needed.
23. Privacy and data in Kireli
After signing in you will find under Account the Privacy and data section. There you can among other things start a machine-readable download, view confirmation timestamps, and submit formal requests for additional access, restriction or objection. Account closure is also explained there, including existing blockers such as open privacy requests, active print orders or ownership of shared Spaces.
24. Complaint to the Autoriteit Persoonsgegevens
If you disagree with how we handle personal data, you may lodge a complaint with the Autoriteit Persoonsgegevens. Information: autoriteitpersoonsgegevens.nl. If you live in Belgium, you may also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / GBA). Information: gegevensbeschermingsautoriteit.be. We appreciate it if you first give us a chance to help via support@kireli.eu.
25. Minors and family participation
Independent registration is intended for users aged 16 or older. Anyone who creates an account themselves without a family invitation confirms that age at registration. This is Kireli product policy, not a statement that the GDPR automatically requires every online service to start at age 16.
Younger family members (for example 11 or 14 years old) may participate in a private Space via a supported parent/guardian invitation. Only the Space owner can start such a family invitation and must explicitly declare that the invitee is under 16, that the inviter is a parent, legal guardian or otherwise authorised, that participation in that Space is allowed, and that the relevant privacy information has been read. An ordinary invitation from an arbitrary member does not count as parent/guardian consent.
Kireli does not store a date of birth for this path and does not ask for identity documents. Consent or authorisation via this path does not automatically make every possible processing lawful; it is the product route for family participation with extra care. Parents and guardians remain jointly responsible for what they share about minors. Family Spaces may contain photos, videos or stories about minors when users add those themselves.
Separately, you may later add an optional birthday on your account profile. That data is not used to check whether you are 16+. The year stays on your account by default. Only if you turn sharing on yourself may the day (month and day, without year or age) appear in Spaces for members.
26. Automated decision-making and profiling
Kireli does not use public feed algorithms and no advertising profiling. There is no automated decision-making with legal effects in the sense of exclusively automated scoring of persons.
27. Changes to this notice
We may adapt this notice if the service or legislation changes. The date and version at the top of this page show the current publication. For material changes we inform where that reasonably fits the impact.
At registration we store a timestamp that you have read the privacy information. That is not a full historical link to every later document version.
28. Contact
- Anchor Labs
- Van Wesembekestraat 113, 3132 XW Vlaardingen, Netherlands
- Email: support@kireli.eu
- Phone: 085-0607073