Last updated September 4, 2026
Privacy Policy
The Family Press helps families create a shared photo magazine that can be printed and mailed to someone they love. Itempass BV operates The Family Press and is the data controller responsible for the processing described in this policy. This policy explains how Itempass BV, doing business as The Family Press (“we,” “us,” or “our”), handles information through our iPhone and iPad app, website, and related services.
Information we collect
We collect information that is needed to provide and operate the service:
- Account and profile information: your name, email address, account identifier, profile photo, authentication details, magazine memberships, and notification preferences.
- Family and magazine content: photos, captions, descriptions, dates, image descriptions, contributor information, invitations, and other content you or your family members add to a magazine. A post keeps the contributor name and profile picture that were in use when it was created, so the issue stays historically consistent after later profile changes or departure from the magazine.
- Pending invitation names:a magazine owner may enter another person's name to label an invitation that has not been claimed yet. This label is not an identity check and does not create an account or grant magazine access. Please enter a name only when you have permission to use it for this purpose.
- Recipient and delivery information:a recipient's name and mailing address, along with the magazine and issue information needed to prepare and deliver it. Please only provide another person's information when you have permission to do so.
- Website magazine setup information:when you create a magazine on our website, we collect your name and email address, the recipient names you enter, your print-plan choice, the recipient's mailing address, and any pending invitation names. Supabase provides the signed-in account and stores the magazine setup. Stripe hosts payment entry and returns the subscription status we need to continue setup.
- Subscription and transaction information:the plan you select, trial and renewal dates, consent records, subscription status, purchase history, invoice status, and identifiers used to coordinate billing with Stripe. Payment-card details and billing information are entered on Stripe's hosted pages. Stripe may make limited payment-method information, such as card brand and last four digits, available to us for subscription support, but we do not receive or store complete card numbers or security codes.
- Reports and moderation information: when a member reports a post, we collect the selected reason, any optional details they provide, the reported post and account relationships, and the timestamps and status needed to review the report.
- Automatic safety-check information:each new or edited caption and photo, the result of its safety check, and the related post and author information. If the author asks us to review a decision, we also keep the request, the reviewer's decision, and any internal note.
- Notification information: if you enable deadline, shipping, or activity notifications, the app registers a notification token from Apple with our private service and links it to your account so we can deliver the notifications you selected. We keep limited delivery state so a reminder is sent once and at the right time, and we use magazine dates, membership and invitation status, and contribution progress to decide whether a reminder is still relevant. None of this is used for advertising, analytics, profiling, or tracking across apps or websites.
- Diagnostics: limited technical events such as app version and build, operating-system version, a coarse device class, timestamps, severity, and stable error categories and codes. Diagnostic events reported by the app use random event and app-session identifiers and do not contain names, email addresses, account IDs, photos, captions, payment details, persistent device identifiers, or precise location. Our server-side logs may also contain limited technical error and request details associated with an operation. We do not deliberately log request bodies, recipient details, postal addresses, or payment details.
- Website and network information: our hosting and network providers process information normally sent with a request, such as IP address, browser or device type, requested page, and request time, to deliver and protect the website and service. For signed-in requests, these short-lived logs can associate that request information with the account and session so we can diagnose failures and investigate abuse.
- Website analytics: we collect information such as the page visited, referring site, browser and device type, approximate time spent, interactions such as clicks and scrolling, and whether an App Store link was selected. We may use session replays to understand how visitors use the website. During magazine setup, PostHog receives only fixed steps and outcomes. We do not include names, email addresses, mailing addresses, account, magazine, or Checkout identifiers, invitation credentials, payment details, or error text in those events. Session replay is turned off before magazine setup.
- App analytics and selectively masked session replay: the iOS app sends anonymous screen views and magazine-setup funnel steps to help us understand where people spend time and where setup is left. PostHog also processes a visual replay of app sessions. Ordinary interface text and bundled app artwork may appear in a replay. Text entered into forms, names, email addresses, mailing addresses, captions, and family photos are masked on the device before replay data is sent. The app does not attach account identifiers, magazine identifiers, family content, mailing addresses, payment information, or error text to analytics events.
- Website ad measurement: on measured website pages, we record visits, App Store clicks, and fixed Family Press Web Funnel milestones such as viewing the funnel, requesting a sign-in code, opening Checkout, and completing a purchase. For Checkout and purchase events, Meta also receives the currency and value. Meta receives the event, time, page path without query parameters, IP address, browser and device information, Meta browser identifiers such as
_fbpand_fbc, and a random or one-way event identifier used to prevent duplicate reporting. We do not send Meta your name, email address, recipient relationship, mailing address, Family Press account, magazine, Checkout, Stripe, or invitation identifiers, photos, captions, or other magazine information.
How we collect information
We receive information:
- directly from you when you create an account, edit a profile, add content, report a post, or ask us to review an automatic safety decision;
- from family members who invite you or add information to a shared magazine;
- from Apple when you choose Sign in with Apple, subject to your Apple privacy choices;
- from Apple and your device when you allow deadline, shipping, or activity notifications;
- from Stripe when you begin or manage a subscription;
- automatically when the app reports a limited diagnostic event;
- automatically when the app reports anonymous analytics or masked replay data;
- automatically when someone visits a website page; and
- from your browser and website request when you visit a measured landing page.
How we use information
We use information to:
- create and secure accounts and authenticate users;
- save and resume signed-in magazine setup on the website;
- let invited family members collaborate on shared magazines and let an owner keep track of invitations that have not been claimed;
- prepare, print, mail, and manage magazine issues;
- send the deadline reminders, shipping updates, and activity reminders you enable. Activity reminders may relate to invitations, a first contribution, or issue progress, and a reminder about a pending invitation may include the name the owner entered for it;
- manage trials, subscriptions, billing, and payment recovery;
- provide support and respond to privacy requests;
- understand app and website use and interest in downloading the app;
- automatically check new and edited captions and photos before they are shared with family members or included in a printed issue;
- review reports and automatic decisions challenged by an author, enforce our content standards, and protect member safety;
- diagnose failures, protect the service, and improve reliability;
- measure visits, App Store clicks, web-funnel milestones, purchases, and the performance of our ads; and
- comply with legal obligations and enforce our agreements.
We do not sell personal information. We do not use Family Press account information or family content for targeted advertising. PostHog provides website analytics, anonymous iOS screen and setup-funnel analytics, and selectively masked iOS session replay. PostHog may use cookies or browser storage for website analytics. Meta receives the limited website activity described above so we can measure our ads. We do not use this information to personalize the Family Press service.
Magazine setup uses same-tab browser storage for the minimum draft needed to return from Stripe, including the chosen relationship, recipient names, your first name, print-plan context, timezone, and an account identifier used to detect an account change. It does not store your email code, mailing address, invitation credentials, or Stripe URL there. A secure, HttpOnly cookie keeps an opaque Checkout identifier for up to seven days so the server can recheck payment and resume setup. Draft and resume data are cleared when setup finishes and at other recovery boundaries.
Automatic safety checks and reviews
Before a new or edited post is shared with family members or included in a printed issue, we send its caption and photos to OpenAI for automated safety moderation. OpenAI processes this content as our service provider.
Content denied by the automatic check remains private. The author can edit or delete it, or ask us to review the decision. Authorized team members may access the relevant content and safety-check information to investigate the decision and complete a requested review.
We do not use family photos, captions, or safety-check results for advertising, tracking, or training artificial-intelligence models.
When information is shared
We share information only as needed for the purposes described above:
- With your magazine members.People who belong to the same magazine can see shared magazine content and the profile information needed to collaborate. A pending invitation name is visible only to the magazine's current owner, who can also correct or remove it; it is not shown to other members, and the invitation link the owner shares does not contain it. Each invitation has personal credentials for its intended recipient, and there is no reusable general magazine invitation.
- With service providers.Supabase provides authentication, database, private file storage, and server functions. Apple receives the notification token and notification content needed to deliver deadline, shipping, and activity reminders; a reminder about a pending invitation can include the name the owner entered for it, which may appear on the owner's lock screen. Stripe receives the subscription, billing information, and payment information needed to provide hosted checkout, calculate applicable tax, prevent fraud, and manage the subscription. Supabase stores recipient names and mailing addresses for magazine setup and fulfillment. OpenAI processes new and edited captions and photos for automated safety moderation. PostHog processes website and app analytics and selectively masked iOS session replay. Our hosting, network, and diagnostics providers support service operations and privacy-minimized diagnostics. On measured website pages, Meta receives the limited website events and technical information described above. When an issue is fulfilled, print and mailing providers receive the magazine content and recipient details needed to produce and deliver it.
- For legal and safety reasons. We may disclose information when required by law or when reasonably necessary to protect people, rights, and the security or integrity of the service.
- In a business transaction. Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy and applicable law.
We require providers to use information only to perform services for us and to protect it consistently with this policy and applicable law. We do not give service providers permission to use family photos or captions for their own advertising or to train their own artificial-intelligence models.
Legal bases for processing
Where applicable law requires a legal basis, we process information:
- to perform our contract with you and provide the service you request;
- for our legitimate interests in securing, supporting, and improving the reliability of the service and, where permitted, understanding app and website use and measuring advertising performance, balanced against your rights;
- with your consent, when we specifically ask for it; and
- to comply with legal obligations and establish or defend legal claims.
Retention and deletion
We keep account information and live family magazine content while needed to provide the service. Other information is kept for limited periods:
- a pending invitation name remains until the invitation is claimed, the magazine owner removes it, or the magazine is deleted. After an invitation is claimed we keep a protected record that its credentials were used, for the life of the magazine, so the same credentials cannot grant access again;
- app and server diagnostics are automatically deleted after 30 days;
- PostHog analytics events are retained for up to 84 months, and PostHog session replays are retained for 30 days. Session replay is not collected during website magazine setup;
- a notification registration is removed when you turn all three remote-notification choices off, sign out, delete your account, or Apple reports the token invalid, and after 90 days without the app refreshing it. Notification delivery records and expired in-app reminder snoozes are deleted after 30 days;
- our providers' request, function, and security logs are kept for a short period, currently around seven days;
- Meta retains website measurement events according to its privacy policy;
- post reports are automatically removed after 180 days; an account suspension resulting from a report may remain while the suspension is active;
- safety-check evidence is kept for up to 30 days after a decision, or while a review request is open and for up to 30 days after it closes. Approved magazine content itself remains available as described elsewhere in this policy;
- working copies of information from an incomplete checkout are removed seven days after the attempt is closed;
- Stripe may retain transaction, invoice, tax, dispute, or refund records for the period required by financial and legal obligations; and
- backups and security logs are removed on their normal schedules unless they must be preserved to investigate abuse, fraud, or a legal claim.
You can delete individual posts you created while an issue is still open. You can delete your account in the app from Settings by choosing Delete account, reviewing the impact, confirming a new owner for each shared magazine you own, and verifying your identity. You do not need to contact support before starting deletion.
Changing your profile name or picture does not rewrite existing posts. Their contributor snapshots remain with those posts, including after you leave or are removed from a magazine, and are removed when the post or your account is deleted.
Account deletion removes your authentication account, profile, preferences, memberships, onboarding data, authored posts and photos, and other account-linked application data. Your authored content is removed from the live service even when it was shared in another member's magazine or belonged to an older issue. A magazine you own alone is deleted. A shared magazine is transferred to the existing member you select, while content authored by its other members remains.
We also cancel the Stripe subscriptions for magazines you pay for and remove their saved payment methods. We do not transfer your payment details or subscriptions to a new magazine owner. A transferred magazine may continue through an already-paid end date, after which the new owner can subscribe with their own payment method. For Sign in with Apple accounts, we attempt to revoke the Apple authorization; if Apple cannot complete that step, the app gives instructions for removing access in Apple Settings and continues deleting the Family Press account. Deletion may take up to 24 hours and continues after you close the app.
A photo or page already downloaded by another person, included in a previously generated file, or physically printed or mailed cannot be recalled. This practical limit does not cause us to keep the live server copy. Deleting an account stops unstarted fulfillment for a magazine owned by that account alone, but cannot recall a copy already printed or shipped. Account deletion is not itself a refund request; contact privacy@thefamilypress.com about any refund right that may apply.
Your choices and rights
You can update your profile and notification preferences in the app, delete eligible posts while their issue is open, and manage pending invitations from Magazine membersif you own a magazine. Turning notifications off in the app, withdrawing iOS notification permission in Settings, signing out, or deleting your account all remove the app's notification registration. Depending on where you live, you may also have the right to access, correct, export, delete, restrict, or object to the processing of your personal information, or withdraw consent where processing is based on consent.
To exercise a privacy right, email privacy@thefamilypress.com. We may need to verify your identity before completing a request. This email path remains available for access, correction, export, and other privacy requests; account deletion is available directly in the app. You may also have the right to complain to your local data protection authority.
Do Not Track and Global Privacy Control
If your browser sends a Global Privacy Control signal, website ad measurement stays off. Because Do Not Track does not provide a standard signal, the website does not respond to it.
Children's privacy
An account holder who pays for a magazine must be an adult, and invited family members must be at least 13 to have their own account. We do not knowingly collect personal information from children under 13, and we will delete an account we learn belongs to one. Adults may add family photos or other information that relates to children of any age, and are responsible for having permission to do so. If you believe a child's information was provided improperly, contact us so we can review and remove it where appropriate.
Security
We use technical and organizational safeguards designed to protect information, including encrypted network connections, private file storage, access controls, and short-lived links for viewing private photos. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
International processing
We and our providers may process information in countries other than the country where you live. Where required, we use contractual and other safeguards intended to protect information when it is transferred internationally.
Changes to this policy
We may update this policy as the service or legal requirements change. We will post the updated policy here, revise the date above, and provide additional notice when required.
Contact us
For privacy questions or requests, email privacy@thefamilypress.com.
Itempass BV
Enterprise and VAT number: BE 1022.799.375
Sluisstraat 24 bus 302
3000 Leuven, Belgium