Skip to content

Privacy Policy

Last updated: 11 August 2026

This policy explains how Kandelo ("the Service") collects, uses, and protects personal data. It applies to the Kandelo mobile application and the website at kandelo.gregadamski.com.

Kandelo is a genealogy and cemetery-records application. It lets you record gravesites, upload photographs of memorials, transcribe inscriptions, build family trees, and share individual gravesite pages with other people.

1. Data controller

The controller of your personal data is Greg Adamski, operating the Kandelo service as an individual.

Contact for all privacy matters, including exercising your rights: gregadamski@gmail.com

2. What data we collect

2.1 Account data

When you create an account we process:

  • your email address
  • your display name
  • your profile photograph, if you provide one
  • the authentication identifier issued by Google Firebase Authentication
  • if you sign in with Google or Facebook, the basic profile information that provider returns to us (name, email address, and profile picture)

2.2 Genealogical and cemetery content you create

The core purpose of the Service is to store records you enter. This may include:

  • names, including maiden names and alternative names
  • dates and places of birth, death, burial, marriage, and other life events
  • family relationships between individuals
  • postal addresses and telephone numbers attached to records
  • free-text notes, sources, and citations
  • GEDCOM files you import

Data about other people. Records you create will frequently concern people other than yourself, including people who are still alive. Where that happens you act as the controller of that data and you are responsible for having a lawful basis to process it. We process it on your behalf as described in this policy. Do not upload data about living people unless you are entitled to.

2.3 Photographs, media, and audio

  • Photographs of graves, memorials, and documents that you upload or capture with your device camera
  • Images you select from your device photo library
  • Audio recordings you make in order to transcribe a headstone inscription

Photographs may contain embedded metadata (EXIF), including the coordinates at which the photograph was taken.

2.4 Location data

With your permission, the mobile application accesses your device's precise location so it can record where a gravesite is, show nearby graves, and navigate you to a grave. Location is processed only while you are using the relevant features. You can withdraw this permission at any time in your device settings; the rest of the Service continues to work without it.

2.5 "Favors" between users

The Service lets one user ask another to visit a grave on their behalf. When you take part we process the request, the messages, any photograph submitted as proof, and any accompanying note. These are visible to the other party to the request.

2.6 Technical and security data

  • an audit log of significant actions taken in your account, retained for security and accountability
  • server logs, including IP address, request time, and user agent
  • a record of files stored against your account, used to enforce storage limits

We do not use advertising identifiers or advertising analytics. When the public website's performance measurement is enabled, it sends only standard Core Web Vitals measurements (such as page loading and interaction timing), a coarse page category, and a quality rating. It does not send the page URL, grave or cemetery identifiers, share-link credentials, account identifiers, cookies, IP addresses, or browser identifiers in the measurement payload. Kandelo honours the browser's Global Privacy Control and Do Not Track signals for this measurement. The measurements are used only to find performance problems and are retained with server logs for up to 12 months.

3. Why we process your data, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and running your accountPerformance of a contract, Art. 6(1)(b)
Storing and displaying the genealogical records you enterPerformance of a contract, Art. 6(1)(b)
Hosting photographs and media you uploadPerformance of a contract, Art. 6(1)(b)
Transcribing audio you recordPerformance of a contract, Art. 6(1)(b)
Using your location to locate and record gravesYour consent, Art. 6(1)(a), given via the device permission prompt
Making a gravesite page public when you create a share linkYour consent, Art. 6(1)(a)
Measuring aggregate public-site performance without identifiersLegitimate interests in diagnosing and improving service performance, Art. 6(1)(f); browser GPC and DNT signals are honoured
Security, abuse prevention, and audit loggingLegitimate interests, Art. 6(1)(f)
Responding to your support and rights requestsLegal obligation, Art. 6(1)(c), and legitimate interests

4. Public sharing

You can generate a revocable public link to a gravesite page. Anyone holding that link can view a deliberately limited projection without logging in, but the page is marked not to be indexed by search engines. It contains only people explicitly recorded and reviewed as deceased and official grave photographs whose publication rights and owner authority have been recorded. Living people, people with unknown death status, visitor photographs, uploader identity, notes, recordings, comments, exact biographical dates, and family relationships are excluded.

Creating or revoking a link is entirely your choice. A grave is searchable only after a separate, explicit search-publication consent flow becomes available and you opt into it; existing records are never made searchable automatically. You can stop sharing at any time from within the application, but we cannot recall copies that other people have already made. Search engines may also retain a previously indexed page temporarily after publication is withdrawn.

5. Who we share data with

We do not sell personal data. We share it only with the service providers below, who process it on our instructions:

  • Google (Firebase Authentication, Firebase Storage, Google Maps) — authentication, file storage, and mapping.
  • Amazon Web Services (S3) — storage of photographs and media files.
  • Microsoft Azure OpenAI Service — transcription of audio recordings you make, and text analysis of records where you request it. Audio and text are transmitted to this service in order to return a result.
  • Meta (Facebook Login) — only if you choose to sign in with Facebook.
  • Expo — delivery of application updates to the mobile app.

We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise, or defend legal claims.

6. International transfers

Some of the providers listed above process data outside the European Economic Area, including in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. You may request further detail on these safeguards by writing to the contact address above.

7. How long we keep data

  • Account data — for as long as your account exists.
  • Records, photographs, and media you create — until you delete them, or until your account is deleted.
  • Audit logs and server logs — up to 12 months, for security purposes.
  • Correspondence with us — up to 3 years, or longer where needed to defend a legal claim.

When your account is deleted, your account data and the content you created are removed from live systems. Backup copies are overwritten in the normal backup rotation.

8. Your rights

Under the GDPR and the Polish Personal Data Protection Act of 10 May 2018, you have the right to:

  • access your data and obtain a copy of it
  • rectify data that is inaccurate or incomplete
  • erase your data ("right to be forgotten")
  • restrict processing in certain circumstances
  • data portability — receive your data in a machine-readable format
  • object to processing based on our legitimate interests
  • withdraw consent at any time, where processing is based on consent; this does not affect the lawfulness of processing carried out beforehand

To exercise any of these rights, or to request deletion of your account, write to gregadamski@gmail.com. We will respond within one month.

You also have the right to lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl

If you are in another EU or EEA country, you may complain to your own national supervisory authority instead.

9. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means. The transcription and text-analysis features suggest content for you to review; they never decide anything about you.

10. Security

Data is transmitted over encrypted connections and stored with the providers listed in section 5, using their access controls. Access to production data is limited to the controller. No system is completely secure; if a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.

11. Children

The Service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us with personal data, write to the address above and we will delete it.

12. Changes to this policy

We may update this policy. The date at the top shows when it last changed. Where a change materially affects how we use your data, we will notify you in the application or by email before it takes effect.

13. Contact

Greg Adamski gregadamski@gmail.com