Privacy Policy
Last updated: 29 August 2026
Culturily (“Culturily,” “we,” “us,” or “our”) is operated by Jake Geise, an individual based in California, United States. This Privacy Policy explains what we collect when you use the Culturily app and website (including our waitlist), where it is stored, who can see it, how long we keep it, and what happens when you delete your account. If you have any questions, contact us at support@culturily.com.
Culturily records people’s voices. That makes this policy longer and blunter than most, and in places it describes things we have not built rather than things we have. Where we keep something forever, or where a deletion leaves something behind, this page says so in those words.
Who is responsible for your data
Jake Geise is responsible for the data described here, contact support@culturily.com. Because Culturily is currently operated by an individual rather than a company, “we” throughout this policy refers to Jake Geise trading as Culturily.
Who can use Culturily
Culturily is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If you believe someone under 16 has provided us personal data, contact support@culturily.com and we will delete it. We chose 16 because it is the highest age of digital consent used by any EU member state, so a single limit applies everywhere rather than one that changes by country.
Recording your voice
Culturily asks you one question a day about where you come from, and lets you answer it out loud. If you press the microphone button, your browser records your answer as an audio file and uploads it to us when the answer saves. Typing your answer is always available, and on browsers without speech support the microphone button is never shown at all. If you refuse the microphone permission, or the recording fails for any reason, your written answer still saves — the recording never blocks the answer.
Where the recording goes. The audio file is uploaded to a private storage bucket held at Supabase, our database and hosting provider. We store it in whatever audio format your device produced — m4a, webm, ogg, mp3 or wav — and we do not convert, trim, normalise, denoise or otherwise alter it. A single recording can carry up to 4 MB of audio. The bucket is private: no browser holds a credential that can read or write it, and the internal path of your audio file is never sent to any browser, including yours.
How long we keep it: indefinitely. We want to be blunt, because this is the part people assume works differently. There is no expiry, no retention window and no automatic deletion for voice recordings anywhere in our system. A recording stays until you delete your account. And if you re-record an answer, the earlier recording is not deleted either — superseded recordings are kept on purpose, so a single answer may have several recordings of you behind it. We are not going to name a retention period we have not built.
Transcripts of what you said
While the microphone is open, your browser’s own built-in speech recognition runs alongside the recording and turns what you say into text. That text appears in the answer box as you speak, and we store it as a transcript on your answer (up to 20,000 characters). We keep it verbatim: we do not tidy it, summarise it, or correct it.
We do not send your audio to any transcription company. There is no speech-to-text vendor anywhere in our system. The recognition is done by the browser itself, which is why it costs us nothing and why there is no third-party transcription account involved.
The honest limit to that. Whether your browser performs speech recognition on your own device, or sends your audio to the browser maker’s servers to do it, is a decision made by your browser — not by us. It differs between browsers and versions, we cannot detect which is happening, and we cannot control it. If that matters to you, type your answer instead of speaking it.
Your transcript is stored as text, it is shown to anyone you have given listening access to, and it is included when you download your data.
Who can hear your recordings
A recording can be played by you, and by a listener you invited who has accepted the invitation. Nobody else. A listener sees and hears the same card you do: the recording, the transcript, and your written answer.
There is no permanent link to any recording. Each time a recording is played, our server checks — on that exact request — that there is a live, accepted invitation binding that listener to you, and only then creates a playback link that expires after 60 seconds. Our own server holds the credential that can read the storage bucket, because it has to be the one to mint those links.
You can take access away. Revoking a listener works, and because permission is re-checked on every single play, it takes effect on their next attempt to play anything. An invitation that is never accepted expires by itself after 14 days. If a listener deletes their own Culturily account, their access ends with it.
People who do not have a Culturily account
Culturily holds information about people who never signed up. There are three kinds, and we would rather set them out than leave them to be discovered.
- People you invite to listen. The moment you send an invitation, we store the email address you typed — before that person has replied, accepted, or done anything at all. The invitation email itself is the only place we tell them we hold it: it explains that the link works only from that address, that it expires in 14 days, that you can remove their access at any time, and it offers them a way out — if they would rather we did not keep their address, they can reply to that email and we will delete it. There is nothing else in Culturily that asks their permission before that email arrives. If you invite someone, you are the reason we hold their address.
- People you talk about. Your recordings, transcripts and written answers are about your family — that is the entire point of the product. You can also save other people’s birthdays, anniversaries and arrival days, and answers about your heritage. There is no consent step anywhere in Culturily for the people this information is about. They are not asked and not notified, and they have no account here to object with. Please record and write only what you have the standing to share. These entries are deleted when you delete your account.
- Waitlist signups and cancellation requests. Joining the waitlist stores your email address and, if you gave them, a name and heritage note. Using our cancellation and withdrawal form stores the name, email address, message and contract reference you enter, whether or not you have an account.
Other data we collect
- Account and identity: you can create an account in three ways, and which data reaches us depends on which you use. With email and password, we receive your email address; the password is stored only as a hash, which we cannot reverse. With Google, Google provides your email address and Google account identifier. With Sign in with Apple (iOS app only), Apple provides your email address and, only on first sign-in if you allow it, your name — used once to suggest a username, never stored on your profile; if you use Apple’s “Hide My Email,” we only ever receive Apple’s relay address. We also generate an internal username and collect your date of birth to enforce the 16+ age requirement.
- Your profile and reading preferences: which culture’s edition you follow, and profile fields such as country and a short bio where you fill them in.
- Things you save and write: the pieces you keep, your private notes on them, dates you add to your personal calendar and the name days you save, plus which days you have read, your reactions, and any fact reports or feedback you submit. Your private notes are never published and never used to generate content.
- Answers made before you signed up: you can answer a question without an account, in which case the answer is tied to an identifier stored on that device rather than to a person. If you later create an account you can claim those answers onto it.
- Technical and analytics data: product analytics (PostHog) and in-browser error monitoring (Sentry) collect usage events and error data — neither runs in your browser until you accept analytics in our consent banner. Where you have an account and have accepted, PostHog is given your account identifier, so those events are linked to you rather than anonymous. Separately, we keep first-party records of basic in-app events on our own database to run and debug the service, and we monitor errors that happen on our servers — see “Error monitoring” below. When you report a fact, and on requests we rate-limit, we log the associated IP address for security and abuse prevention. If you enable push notifications, our push provider (OneSignal) is given a device identifier and your account identifier to deliver them.
- Membership and billing: if paid membership opens, your membership status and a customer identifier from our payment processor. We never see or store your card details.
- Storage on your device: Culturily uses your browser or device local storage (not cookies) to remember your session, your theme, your analytics choice, and the identifier used for answers made before signing up. This data stays on your device.
Information about your background
An earlier version of this policy said Culturily deliberately held nothing about your ethnic or national origin. That is no longer a fair description of the product, and we are correcting it rather than leaving it standing. Culturily now asks you a question a day about where you come from and your family, and stores your answer — in your own words, and often in your own voice. It also stores heritage answers you give and the cultures you choose to follow.
What remains true is narrower, and we will hold ourselves to it: we do not infer your background. We do not guess it from your surname, your location, or anything else. We hold what you chose to tell us, and nothing we worked out about you behind your back. Choosing to read a culture’s edition is a content preference, not a declaration of ancestry, and a reader with no connection to a culture is as welcome as anyone.
But a recording of you talking about your grandmother is information about your background, it is stored indefinitely, and anyone you have given listening access to can hear it. We would rather say that plainly than repeat a reassuring line that the product has outgrown.
Who we share data with
We do not sell your personal data. This is the full list of outside services any of your data reaches, and what reaches each one:
- Supabase — database, accounts and file storage. Everything lives here: your account and password hash, every table described on this page, and the private bucket holding your voice recordings.
- Netlify — website and server-function hosting. Every request you make passes through Netlify, including your IP address, and appears in its access logs.
- Google — Sign in with Google, if you choose it. Google receives your sign-in request and provides us your email address and Google account identifier.
- Apple — Sign in with Apple and app distribution (iOS app only). If an in-app purchase is ever offered, we send Apple’s servers the transaction identifier to verify it.
- Cloudflare — the anti-bot check on our login, registration and settings pages (Cloudflare Turnstile). Your browser interacts with Cloudflare so it can tell a person from a script. It loads before any consent choice, because it is a security control rather than analytics.
- Resend — sending our email. Recipient addresses and names reach Resend: waitlist confirmations, welcome and reminder email, and the invitation email you send to a listener, which carries that person’s address.
- PostHog — product analytics, in the United States, and only after you accept analytics. Session recording is switched off and no advertising cookies are set. If you have an account, your account identifier is sent with these events.
- Sentry — error monitoring. It is configured not to attach your IP address, headers or cookies to a report.
- OneSignal — push notifications, if you enable them. OneSignal holds your device’s push token and your Culturily account identifier.
- Stripe — payment processing for web membership, if and when it opens. On checkout Stripe receives your email address and your account identifier, and returns a customer identifier that we store.
- Google Fonts — fonts on two email-related pages only: the page that confirms a waitlist signup and the page that unsubscribes you. Loading a font from Google reveals your IP address to Google, as any web request does. No other page on Culturily loads them.
- Anthropic — the AI provider used to prepare editorial content. It receives source text and facts drawn from published historical sources. No part of your account, your answers, your recordings or your transcripts is sent to it — see “AI-generated content” below.
- Formspree — an endpoint for this form service is still defined in our configuration, but nothing in the product calls it. As far as we can establish, no data of yours reaches it. We list it because it is configured, not because it is used.
Some of these providers process data in the United States. Deleting your Culturily account does not instruct any of them to delete their own copies — see “Deleting your account” below.
No paid subscription is available yet. Once one is, web-based membership payments will be handled through Stripe, which acts as the merchant of record and seller for that purchase — processing your payment, billing, and applicable VAT or sales tax. Your payment relationship and receipt for the sale itself will be with Stripe, not directly with Jake Geise. (If an in-app purchase is ever offered in an iOS app, it would be billed by Apple, the merchant of record for that purchase instead.) Stripe acting as merchant of record for the sale does not change who is responsible for Culturily’s own refund and withdrawal commitments — see Terms of Service — which remains Jake Geise.
AI-generated content
Some content in the Service — including the writing in each day’s edition — is generated with the assistance of artificial intelligence from published historical sources, then checked against those sources, but may still contain errors.
Your own material is not sent to an AI provider. The only thing our system sends to one is source text and facts drawn from it. Your recordings, your transcripts, your answers, your notes and your saved dates are not part of that, and answers you write are barred by rule from ever entering the content corpus.
Error monitoring
We monitor errors in two places, and they are treated differently on purpose.
In your browser, the Sentry error monitor does not load at all until you accept analytics in our consent banner. If you decline, or never answer, no error data leaves your browser. It is configured not to attach your identity to a report.
On our servers, we monitor errors thrown by our own code — the message, where in our code it happened, and which function was running. This is not gated on your consent, and we want to be straightforward about why: server errors frequently happen on requests that have no signed-in user at all, and consent choices are stored in your browser rather than sent to us, so there is often no consent to check. These reports carry no name, email, or account identifier. You can object to this at support@culturily.com.
How long we keep things
- Voice recordings — indefinitely. No expiry exists. Superseded recordings are kept too. See “Recording your voice” above.
- Transcripts and answers — indefinitely, for as long as your account exists.
- Account data — for as long as your account is active.
- Records of notifications we sent you — a 90-day clean-up for these has been written, but nothing in the running system calls it. In practice they are not being cleaned up.
- Analytics events on our own database — no clean-up exists for these.
- Rate-limiting records keyed to your IP address — short-lived, and cleared as later requests come through.
- Waitlist entries — kept until you ask us to erase them or you unsubscribe. Joining the waitlist does not create an account, so deleting an account does not remove a waitlist entry; email support@culturily.com to have it erased.
Backups. A copy of the whole database is taken once a night onto a machine controlled by Jake Geise. The most recent 14 nightly copies are kept and older ones are deleted — but separately from those, an archive of 22 older copies is kept permanently and is never deleted. Backups are whole-database snapshots: they cannot be edited to remove one person, and nothing re-applies your deletion to them. This means data from before your deletion continues to exist in that frozen archive with no end date. We use backups only to restore the service, and we do not query them to look anyone up. We state this plainly rather than leaving it implied, because “deleted” should mean what a reader thinks it means.
Deleting your account — what goes, and what stays
You can delete your account from the app. Here is what that actually does.
It deletes:
- Every voice recording of you, including superseded ones — the audio files themselves are removed from storage, not merely unlinked.
- Your answers, their earlier revisions, and your claims on answers made before you signed up.
- Your reactions and the records of notifications sent to you.
- Invitations you sent, including the email addresses of the people you invited.
- Your account itself, and everything attached to it: your profile, reading progress, streaks, friendships, private notes, family dates, heritage answers, saved name days and daily results.
If we cannot read or delete your recordings for any reason, the whole deletion stops before anything is removed and your account is left intact so it can be retried. We would rather fail visibly than delete your account and leave your voice behind.
It leaves behind:
- Cancellation and withdrawal requests, with your name, email address and message still attached. Only the link to your account is removed. This is the least comfortable item on this page and we are not going to bury it.
- Analytics events, records of consent given at checkout, fact reports you filed, and question flags — all kept, with the link to your account removed.
- Your waitlist entry, if you have one — untouched. Email us to remove it.
- Answers you made before creating an account and never claimed, and their recordings. Nothing connects them to your account, so deleting your account cannot find them. An automatic clean-up for these has been written but is not switched on, so at present they remain.
- Short-lived rate-limiting records keyed to an IP address.
- Copies held by other companies. Deleting your Culturily account does not send a deletion instruction to Stripe, OneSignal, PostHog, Resend, Sentry or Apple. What they hold is governed by their own retention, not by this action.
- Backups, as described above — including the permanent archive.
If you want any of the items in that second list removed, email support@culturily.com and we will do it by hand.
Downloading your data
If you have an account, you can download your vault. You get every answer and every earlier revision of it, the transcripts, the written text, and the actual audio files in the formats they were recorded in, packaged into a single zip file that is assembled in your browser. If any file fails to download it is named in the archive rather than silently dropped.
What the download does not include. It covers your vault only. It does not include your profile, your private notes, your saved family dates, your heritage answers, your reactions or your analytics events. There is no export for answers made before you had an account. If you want any of that, email support@culturily.com and we will put it together for you.
What you can ask us to do
Whatever your country entitles you to, this is what we will do when you ask, and you can ask by emailing support@culturily.com:
- Send you a copy of what we hold about you, including the parts the in-app download leaves out.
- Correct anything that is wrong.
- Delete your account, or delete specific things without deleting the account.
- Remove a waitlist entry, a cancellation request, or another record that account deletion leaves behind.
- Stop sending you email, or stop a use of your data you object to.
- Withdraw your analytics consent.
We answer these ourselves, by email, and we will not treat you any worse for asking. If you invited someone and they would rather we did not hold their address, they can reply to the invitation email or write to us directly, and we will delete it.
Cookies & tracking
Culturily uses no advertising cookies, sets no cross-site trackers, and does not profile you for advertisers. Product analytics and in-browser error monitoring only run after you accept them in our consent banner. Server-side error monitoring, our own first-party service records, and the anti-bot check are not part of that banner — the anti-bot check runs first because it is a security control.
Security
We would rather point at specific things than make a general promise. Your voice recordings sit in a private storage area that no browser can read directly; every playback link is created by our server for one recording at a time and expires after 60 seconds; the internal path of a recording is never sent to a browser; permission to play is re-checked on every request rather than cached. If you sign in with a password, it is stored only as a hash we cannot reverse. Traffic to the site is encrypted in transit.
No system is perfectly secure, and we are not claiming more than the paragraph above. If we become aware of a breach affecting your data, we will tell you.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the app or by email. The “Last updated” date at the top shows the latest version.
Contact
Questions, requests, or complaints: support@culturily.com. Jake Geise, California, United States.