Legal
Privacy Policy
Version 3.3 | Last updated: October 2, 2026
Quick Summary
- We collect: Account info, voice recordings, images, family data
- AI processing: Transcription, memory generation, psychological insights
- Your data is NOT used to train AI models
- You control: Local-only or cloud storage, analytics opt-out
- You can: Access, export, correct, delete, or suspend your data anytime
- Age requirement: 13 years or older
- Website waitlist: joining stores your email and a few technical signals (Section 1.9)
Creatiwi AI ("we", "our", or "us") operates the Arloom mobile application ("Arloom" or "the App") and the website at arloom.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App, and when you use our website, including the pre-launch early-access waitlist described in Section 1.9 that is open to visitors who have no Arloom account.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Display name (optional)
- Profile photo (optional)
- Authentication tokens from your chosen sign-in method (Google, Apple, or email)
1.2 Voice & Audio Data
Arloom allows you to record voice conversations and stories. We collect:
- Audio recordings you create within the App
- Duration and timestamps of recordings
- Language preferences for transcription
- Speaker identification data (which family members are speaking)
1.3 Images & Documents
You may upload photos, documents, and other media files. We collect:
- Image files and their metadata
- Document scans (letters, certificates, etc.)
- Text extracted from images via optical character recognition (OCR)
1.4 Family Information
To build your family tree, we collect:
- Names and relationships of family members ("Nearlings")
- Birth and death years (optional)
- Biographical information you provide
- Photos of family members
- Pet information (if you choose to include them)
1.5 AI-Generated Content
Our AI systems create content based on your recordings and data:
- Transcriptions of your voice recordings
- Memory narratives and story summaries
- Memory card images and visualizations
- Extracted facts, dates, places, and people mentioned
1.6 Psychological Insights (ACEO Analysis)
Our ACEO (Arbo Conversation Extraction Ontology) system may analyze your content to identify:
- Values: Core beliefs and principles expressed in stories (e.g., family loyalty, education, resilience)
- Dispositions: Personality traits and behavioral tendencies mentioned
- Patterns: Recurring themes, traditions, and family dynamics
- Life events: Significant milestones, challenges, and experiences
- Relationships: Family roles and interpersonal dynamics
This analysis is used solely to enrich your family story experience and provide personalized insights. You can withdraw your consent to ACEO analysis in Settings at any time. Withdrawing it does not delete insights already created; deleting your account does. A version that also deletes, in most cases, the insights drawn from a recording when you delete that recording has not been released to the live service yet; until it is, deleting a recording leaves its insights in place.
1.7 Usage & Analytics Data
With your consent, we collect:
- App usage patterns and feature interactions
- Device type and operating system version
- Crash reports and error logs
- Performance metrics
You can opt out of analytics collection in the App's Settings under "Data & Privacy."
1.8 Payment Information
For subscriptions, payment processing is handled by:
- Apple App Store (for iOS users)
- Google Play (for Android users)
We do not directly collect or store your payment card details. We only receive confirmation of purchase and subscription status.
1.9 Waitlist & Early Access Signup (Website Visitors)
Until Arloom is generally available, our website offers an early-access waitlist. You do not need an Arloom account to join it, and joining does not create one. Apart from the ordinary server-side request logs any website generates, a waitlist signup is the only personal data we collect from visitors who are not App users. We run no analytics or tracking scripts on the website, and the site's own code sets no cookies.
When you submit the signup form, we record:
- Your email address: the only thing we ask you for, and the only part of the entry that identifies you directly
- The page you signed up from: which page of our site the form was on, and which language version you were reading (English or Polish), so we can follow up in the right language
- A salted one-way hash of your IP address: stored instead of the address itself, and used only to limit how many signups can come from one source within an hour
- Your browser's user-agent string: the browser and operating system your browser reports, shortened, kept for the same abuse-prevention purpose
The last two are technical signals your browser sends with every web request. We keep them so the form cannot be used to flood our systems with fake signups. They are not used to build a profile of you and are not combined with anything else.
Purpose: to run the pre-launch waitlist. That means holding your place, emailing you when early access opens or when there is news about the launch, and keeping the form from being abused.
Legal basis: your consent, under GDPR Article 6(1)(a). You give it by choosing to submit the form with your email address, and there is no other way onto the list. You can withdraw it at any time by asking us to remove your entry, which we then delete in full.
Retention: we keep your waitlist entry until early access opens or until you ask us to remove it, whichever comes first. To be precise about what that means in practice: there is currently no scheduled job that deletes waitlist entries automatically, so an entry goes when the waitlist has served its purpose or when you ask us to remove it. The separate rate-limiting record that counts signups per hashed IP address holds no email address and is marked to expire two hours after its counting window opens.
How to have your entry removed: email privacy@creatiwi.ai from the address you signed up with, or name that address in your message, and we will delete the entry. We look entries up by the address itself, so we do need to know which one to remove. Write to the same inbox to ask what we hold about you, or to have it corrected.
Who else is involved: the website and its signup endpoint are served by Cloudflare, which therefore handles your submission in transit (see Section 4.1). The entry itself is stored in Google Cloud Firestore in the EU (europe-west1). Waitlist addresses are not passed to any advertising network or third-party marketing platform, and joining the waitlist does not subscribe you to anything other than email from us about Arloom's launch.
2. How We Use Your Information
We use your information to:
- Provide the Service: Enable recording, storage, and family tree features
- AI Processing: Transcribe recordings, generate memories, and extract insights
- Personalization: Customize your experience based on your family data
- Synchronization: Sync data across your devices (if cloud storage is enabled)
- Communication: Send service updates and respond to support requests
- Improvement: Analyze usage patterns to improve the App (with consent)
- Security: Detect and prevent fraud or unauthorized access
3. AI & Automated Processing
3.1 Transcription Services
Your voice recordings are processed by Google's Gemini AI models to:
- Convert speech to text
- Identify different speakers in conversations
- Detect the language being spoken
3.2 Memory Generation
AI analyzes your transcripts and family data to:
- Create narrative summaries of family stories
- Extract key facts, dates, and locations
- Generate visual memory cards
- Suggest connections between stories and family members
3.3 Psychological Analysis (ACEO)
Our ACEO system uses AI to identify deeper themes in your family stories:
- Values and beliefs expressed by family members
- Behavioral patterns and family traditions
- Emotional themes and relationship dynamics
- Life lessons and wisdom passed down through generations
This processing is designed to help you understand and preserve your family's psychological heritage.
3.4 Image Recognition (OCR)
When you upload images of documents, letters, or photos with text, AI extracts readable text to make it searchable and usable in your family stories.
3.5 No AI Training
4. Data Sharing & Third Parties
4.1 Sub-Processor List
We engage the following sub-processors to provide our services. Each operates under a Data Processing Agreement (DPA):
| Processor | Purpose | Data Location | DPA/Transfer Mechanism |
|---|---|---|---|
| Google Cloud Platform (Firebase) | Authentication, Firestore database, Cloud Storage, Functions | EU (europe-west1) | Google DPA, SCCs |
| Google Vertex AI (Gemini) | AI processing: transcription, memory generation, ACEO analysis | EU (europe-west1) | Google DPA, SCCs |
| Firebase Analytics & Crashlytics | Usage analytics (with consent), crash reporting | EU/US | Google DPA, SCCs |
| Cloudflare, Inc. | Hosting and delivery of the arloom.app website (CDN and edge compute), including the waitlist signup endpoint | Global edge network (served from the location nearest the visitor) | Cloudflare DPA, SCCs, EU-US DPF |
| FamilySearch | Genealogy integration (optional) | United States | FamilySearch Privacy Notice, SCCs |
| Apple Inc. | App distribution (App Store), iOS payments | United States | Apple DPA |
| Google Play | App distribution, Android payments | United States | Google DPA |
You can request an up-to-date list of all sub-processors by contacting privacy@creatiwi.ai.
Cloudflare sits in front of everything on our website, so its role is worth spelling out. As our content delivery network it terminates the encrypted connection between your browser and arloom.app. The traffic passing through it, including your IP address and the contents of a waitlist submission on its way to us, is therefore processed on Cloudflare's infrastructure. That is inherent to using a CDN, and it is the same kind of infrastructure-level access Google Cloud has over the data we store there. Cloudflare acts as our processor under its Data Processing Addendum and does not use the traffic for its own purposes. The App does not route through Cloudflare.
4.2 Google Cloud Services Detail
Specific Google Cloud services we use:
| Service | Purpose | Data Processed |
|---|---|---|
| Firebase Authentication | User sign-in | Email, auth tokens |
| Cloud Firestore | Data storage | Family data, metadata |
| Cloud Storage | File storage | Recordings, images |
| Vertex AI (Gemini) | AI processing | Audio, text, images |
| Firebase Analytics | Usage analytics | Anonymous usage data |
| Firebase Crashlytics | Crash reporting | Error logs |
4.3 FamilySearch Integration
If you choose to connect your FamilySearch account:
- We access your FamilySearch family tree data via OAuth
- We may sync memories and stories to your FamilySearch account
- FamilySearch's own privacy policy applies to data stored there
- You can disconnect FamilySearch at any time in Settings
4.4 Payment Processors
- Apple: Handles iOS subscription payments
- Google Play: Handles Android subscription payments
We do not have access to your payment card details.
4.5 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
5. Data Storage & Security
5.1 Storage Options
You control where your data is stored:
- Local Only: All data remains on your device. Nothing is uploaded to cloud servers. You are responsible for backups.
- Cloud Storage: Data is encrypted and stored on Google Firebase servers. Syncs across your devices.
- Hybrid: Metadata in cloud, media files stored locally.
5.2 Encryption Standards
- In Transit: All data transmitted using TLS 1.3 encryption
- At Rest: Cloud data encrypted using AES-256
- Authentication: Secure token-based authentication via Firebase Auth
5.3 Data Retention Schedule
Different types of data are retained for different periods:
| Data Type | Retention Period | Notes |
|---|---|---|
| User account data | Until account deletion | Core profile, settings, preferences |
| Recordings & memories | Until you delete them or your account | Kept until you delete them. The inactive-account policy in Section 5.4 would also delete them, but it is not enforced yet. Deleting a nearling deletes its memories, with their card images, animated cards and narrations, and its animated photos and arc videos. Memories of that nearling you shared disappear from your relatives' accounts, though the copies of the card image, animated card and narration made for them stay in their storage. Your recordings and your chats about that nearling stay, because they are your own and can be about several people |
| AI processing tasks | 7-30 days | Temporary task records automatically cleaned up |
| Analytics data | 14 months | Anonymized usage metrics (with consent) |
| Crash reports | 90 days | Diagnostic data for bug fixes |
| Email communications | 2 years | Support and privacy request records |
| Waitlist entries (website signup) | Until early access opens, or until you ask us to remove your entry | No automatic expiry; removal on request (see Section 1.9) |
| Waitlist rate-limiting records | Intended lifetime of two hours from the counting window opening; not yet enforced by an automatic deletion job, so a record can persist longer until that job ships | Hashed IP address and a signup count only; holds no email address |
| Inactive accounts (free tier) | Not enforced yet: nothing is archived or deleted for inactivity today | The policy we plan to apply (archive after 1 year, content deletion after 2 years, the account kept) is described in "Inactive Account Policy" below |
| Account deletion record | Expires one day after the account is deleted. Automatic removal is not yet switched on for the live service | Holds your account ID, the times the deletion ran and a random ID for that run, and nothing else. It stops a device that is still signed in from recreating the account while its session runs out |
| One-time purchase records (Google Play) | Kept after the account is deleted, with no automatic expiry | Order ID, product, purchase token, purchase and consumption state, the credits granted, and when the purchase was verified and consumed. On account deletion your account ID is replaced with a placeholder and the time of that change is noted; a refund adds a refund marker. The record stays so the same purchase cannot be redeemed twice. Subscription purchase records are deleted with the account; a refund notice that arrives later for that subscription is kept like a notification that matches no account (next row) |
| Google Play notifications that match no account | Expire 90 days after they arrive. Automatic removal is not yet switched on for the live service | A one-way fingerprint (SHA-256) of the purchase token and the token's first 20 characters, product ID, notification type and time received, kept for manual review; for a refund notice, also its order ID and the product and refund type. They hold no account ID. Deleting an account does not cancel a Google Play subscription, so later notices about that subscription land here. Notices stored by earlier versions of the service hold the whole purchase token and do not expire |
| Usage, reservation, connection and queued email records | Until you delete your account. Storage reservations also expire 7 days after they are made; automatic removal is not yet switched on for the live service, and reservations made by earlier versions of the service do not expire | Records of AI usage (your account ID, your plan, the AI model, amounts processed and the item it was for), storage reservations that record your account ID, connection locks named after the IDs of two connected accounts, and queued copies of emails about your account (your address and the message). Deleting your account deletes them. The emails are found by the account ID they carry and, for older ones, by your account's verified sign-in address; older ones of an account whose address was never verified are not found. Clear Data deletes the connection locks along with your family connections and keeps the rest with your account |
| Server logs | The logging service's retention period | Can contain your account ID and short excerpts of a transcript. Deleting your account does not remove them |
| Backup copies | 30 days after deletion | Encrypted disaster recovery backups |
Not live yet: the service runs in released versions, and the version this section describes has not been released to the live service. Until it is, the live service differs in these ways. Deleting a nearling removes the nearling and its recording links, but not its photo or its memories. Deleting your account writes no account deletion record, does not remove the usage, reservation, connection and queued email records listed above, and is not followed by the cleanup described in the next paragraph. Google Play notifications that match no account keep the whole purchase token, with no expiry. The data export leaves out some of what Section 7.4 lists. We will update this note when that version is live.
After you delete your account: another device that is still signed in can save new items under the account for up to about an hour, and processing that was already running can finish. A follow-up cleanup deletes those items too, usually within about two hours of the deletion. Copies kept only on your device, such as content stored Local Only, the offline chat history and the App's cached copies of your cloud data, stay there until you uninstall the App or clear its data. If a deletion stops partway, what was already deleted stays deleted and the account remains; delete it again to finish. If the App says it could not confirm the deletion and your account is still there, wait about an hour and a half before deleting it again.
5.4 Inactive Account Policy
Not enforced yet. The policy below is written down, but the job that would apply it does not act on any account today. Nothing is archived or deleted because an account is inactive, and none of the warning emails below are sent. We will update this page before that changes.
Once enforced, it applies to free-tier accounts with no sign-in, following industry-standard retention (1 year archive, 2 years content deletion):
- 330 days (~11 months): First warning email sent (35 days before archive)
- 355 days: Second warning email (10 days before archive)
- 365 days (1 year): Storage files moved to archive storage class (data preserved but slower access)
- 700 days: First deletion warning email (30 days before deletion)
- 720 days: Second deletion warning (10 days before deletion)
- 725 days: Final deletion warning (5 days before deletion)
- 730 days (2 years): Your recordings and stored files, memories, nearlings, transcripts, AI insights, chats, settings, consent records, subscription history, family connections and invitations, memories others shared with you, suggested nearlings, the search index built from your content, queued photo animations, AI task records, AI usage records, storage reservations, connection locks, rate-limit counters, a linked FamilySearch connection and your remaining allowance, including credits you bought, would be permanently deleted. Memories you shared with relatives would disappear from their accounts; the copies of the card image, animated card and narration made for them would stay in their storage until they clear their data or delete their own account
What the 730-day deletion would keep: it does not delete the account. Your sign-in and the account record with your email address remain, so you can still sign in. It also keeps your promo code redemptions, your purchase records and the queued emails addressed to you. Deleting your account in the App's Settings removes these too, except the records described in Section 5.3 as kept after deletion.
Warning emails: the emails in the timeline above are not delivered today. No email service is connected to send them yet.
Paid subscribers: Active subscriptions are exempt from the inactive account policy. Data is retained as long as your subscription is active. Buying one-time credits does not exempt a free account. A suspended account (Section 7.5) is also exempt while it stays suspended.
Restore archived data: nothing is archived today, and the App has no restore option. If your files are ever archived, email privacy@creatiwi.ai and we will restore them.
6. International Data Transfers
Your data may be transferred to and processed in countries outside your residence, including:
- United States: Google Cloud data centers
- European Union: Firebase regional servers (when applicable)
- Cloudflare's global edge network: website requests, including waitlist submissions, are handled at the Cloudflare location nearest you, which may be outside your country
For transfers from the EU/EEA, we rely on:
- Standard Contractual Clauses (SCCs) with Google
- Cloudflare's Data Processing Addendum, which incorporates the SCCs and relies on the EU-US Data Privacy Framework for transfers to the United States
- Google's compliance with EU-US Data Privacy Framework
7. Your Privacy Rights
7.1 Rights for All Users
Regardless of your location, you can:
- Access: Request a copy of your personal data
- Correct: Update inaccurate information in the App
- Delete: Use "Clear Data" (your content) or "Delete Account" (the account and its data) in the Danger Zone of Settings, or contact us
- Export: Download your data in a portable format
- Opt-out: Disable analytics and crash reporting in Settings
These controls live in the Arloom app and cover the data held under your account. If you do not have an account, for example because you only joined the website waitlist, email privacy@creatiwi.ai and we will handle the request by hand, as described in Section 1.9.
7.2 GDPR Rights (EU/EEA Residents)
Under the General Data Protection Regulation, you also have the right to:
- Restriction: Request we limit processing of your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time without affecting prior processing
- Lodge Complaint: File a complaint with your local data protection authority
Data Controller: Creatiwi – Krzysztof Głuszczyk (NIP 9542715800) — full details in Section 12, Data Controller.
Contact: privacy@creatiwi.ai
7.3 CCPA Rights (California Residents)
Under the California Consumer Privacy Act, you have the right to:
- Know: Request disclosure of personal information collected, used, and shared
- Delete: Request deletion of your personal information
- Opt-Out of Sale: We do not sell personal information
- Non-Discrimination: We will not discriminate against you for exercising your rights
Categories of Personal Information Collected:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Email, name, account ID | Yes |
| Biometric Information | Voice recordings | Yes |
| Internet Activity | App usage, interactions, waitlist signup signals (Section 1.9) | Yes (with consent) |
| Geolocation | Precise location | No |
| Audio/Visual | Recordings, photos | Yes |
| Inferences | Psychological insights | Yes (ACEO) |
Do Not Sell My Personal Information: We do not sell your personal information to third parties as defined under the CCPA.
To exercise your CCPA rights, contact us at privacy@creatiwi.ai or use the in-app privacy settings.
7.4 How to Exercise Your Rights (DSAR Procedure)
You can exercise your privacy rights through multiple methods:
The in-app routes below require an Arloom account. If you only joined the website waitlist, use the email route in Section 1.9.
In-App Data Export (Recommended)
The fastest way to access your data:
- Open the Arloom app and go to Settings
- Navigate to "Data & Privacy" section
- Tap "Export My Data"
- Wait for export to complete (you'll see progress in the app)
- Download your data package directly from the app
The export includes everything that deleting your account removes: your account record, nearlings, memories, recordings, transcripts, ACEO insights, chats, consents, usage and reservation records, queued emails, your purchase records, and signed download links for your media files; a file whose link could not be made is listed by name instead. Two things are left out, and the file lists them: the sign-in tokens of a linked FamilySearch account, which work like a password for that account, and Google Play purchase tokens. Export files are available for 7 days.
Rate limit: You can request one export per 24 hours.
Email Request
Alternatively, email privacy@creatiwi.ai with:
- Your account email address
- Type of request (access, correction, deletion, etc.)
- Any additional context
Other Privacy Controls
- Clear Data: "Clear Data", in the Danger Zone of Settings, deletes your content immediately and keeps the account
- Delete Account: "Delete Account", in the Danger Zone of Settings, deletes your account and its data immediately; Terms of Service Section 14.1 and Section 5.3 above list what is kept afterwards
- Suspend Account: "Suspend Account", in the Danger Zone of Settings, pauses processing (see Section 7.5)
- Opt-out of Analytics: Settings → Data & Privacy → Toggle off "Share Analytics"
Response Times:
- In-app export: Immediate (typically completes within minutes)
- Email requests: Within 30 days (or 45 days for complex CCPA requests)
- Deletion requests: Processed within 30 days
7.5 Account Suspension (Right to Restriction)
Under GDPR Article 18, you have the right to restrict processing of your personal data. Arloom provides a self-service account suspension feature:
How to Suspend Your Account
- Open Settings and scroll to the Danger Zone
- Tap "Suspend Account"
- Confirm your choice
What Happens When Suspended
- AI Processing Disabled: All AI features (transcription, memory generation, ACEO analysis) are blocked
- Data Preserved: Your data remains stored but is not processed
- Read-Only Access: You can view your existing data but cannot create new content
- No Deletion: Unlike account deletion, your data is preserved for when you return
How to Reactivate
- Open Settings and scroll to the Danger Zone
- Tap "Reactivate Account"
- Your account is immediately restored with full functionality
You can suspend and reactivate your account as many times as needed.
8. Biometric Data Notice
Voice recordings may contain unique voiceprints that could identify individuals. We want you to understand how we handle this sensitive data:
- Collection: We collect voice recordings only when you actively record within the App
- Purpose: Recordings are used for transcription, speaker identification, and memory generation
- Storage: Voice files are encrypted and stored according to your storage preference (local or cloud)
- Retention: Voice recordings are retained until you delete them or your account
- No Biometric Template Creation: We do not create persistent biometric templates or voiceprints for identification purposes
- No Third-Party Sharing: Voice recordings are not shared with third parties except for AI processing (transcription)
Illinois Residents (BIPA): By using the recording features, you consent to the collection and processing of your voice recordings as described above. You may withdraw consent by discontinuing use of recording features and deleting existing recordings.
9. Children's Privacy
Arloom is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13.
- If you are under 13, please do not use this App or provide any information
- If you believe we have collected information from a child under 13, please contact us immediately at privacy@creatiwi.ai
- We will promptly delete any such information
Note: Family stories and recordings may mention children. This is expected use of the App for preserving family history. We recommend not recording children directly without parental awareness.
10. Data Breach Notification
We take data security seriously and have established procedures to detect, respond to, and notify you of data breaches in compliance with GDPR Articles 33 and 34.
10.1 Our Commitment
- Detection: We monitor our systems for security incidents using automated threat detection
- DPA Notification: In case of a personal data breach likely to result in risk to your rights, we will notify the relevant Data Protection Authority within 72 hours
- User Notification: If a breach is likely to result in high risk to your rights and freedoms, we will notify affected users without undue delay
10.2 What We'll Tell You
In the event of a high-risk breach affecting your data, our notification will include:
- Nature of the breach and approximate timing
- Categories of data affected (e.g., recordings, family data, ACEO insights)
- Likely consequences of the breach
- Measures we've taken to address the breach
- Recommendations for protective measures you can take
- Contact information for our Data Protection Officer
10.3 How We'll Notify You
- Email: To the email address registered with your account
- In-App: Prominent notification when you next open the app
- Website: Public notice on our website if the breach affects many users
10.4 Our Data Protection Officer
For breach-related inquiries or to report a suspected security incident:
Email: dpo@creatiwi.ai
Privacy Team: privacy@creatiwi.ai
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last updated" date at the top
- For significant changes, we will notify you via in-app notification or email
- Continued use of the App after changes constitutes acceptance
We encourage you to review this policy periodically.
12. Contact Us
For privacy-related questions, concerns, or to exercise your rights:
- Email: privacy@creatiwi.ai
- General Support: support@creatiwi.ai
- Legal Inquiries: legal@creatiwi.ai
Data Controller / contracting entity:
Creatiwi – Krzysztof Głuszczyk
Sole proprietorship (jednoosobowa działalność gospodarcza), registered in CEIDG, Poland
NIP: 9542715800 · REGON: 389220645
Contact: privacy@creatiwi.ai
A correspondence address will be published here once a registered business address is in place. Until then, all data-protection and legal correspondence should go to the addresses above, which are monitored.
We aim to respond to all privacy inquiries within 30 days.