Privacy notice
What we hold, and why
Draft — to be reviewed by a solicitor before the service is sold. Last updated 13 September 2026.
Who we are
tokeepsafe provides private family archives. For the purposes of UK data-protection law, the family that keeps an archive decides what goes into it; we process it on their behalf and hold it safely. Contact: hello@tokeepsafe.com.
What we hold
For members: the email address and name of the Google account used to sign in, the name and relation the family gives you, and what you add — photographs, video, recordings, written memories, names of people in pictures, and family connections. For guests using an event link: the name you type and what you add. Nothing else about guests.
We also record which pages members visit within their own archive, so keepers can see whether the family is using it. Guests are never recorded.
Why we hold it
To run the archive the family asked for. There is no other purpose. We do not advertise, profile, sell, share or train anything on what you give us.
Where it is kept
In the European Union (Ireland), with daily backups. Web pages are served through a content network so they load quickly; photographs themselves are served from the EU through links that expire within an hour.
Who can see it
Only members of the family named by a keeper, and — for one event at a time, while its link is open — the guests they invite. Access by us is limited to what is needed to support you.
Children
Family archives naturally contain photographs of children. They are added by the family, and only the family and its invited guests can see them. Guests should only add photographs they are comfortable the family keeping.
Your rights
Any keeper can export the complete archive, or delete it entirely, at any time, without asking us. Any member can ask a keeper to remove something about them; if that fails, ask us. A guest can ask the family, or us, to remove anything they added.
How long
For as long as the family keeps the archive. An archive whose subscription lapses becomes read-only; it is not deleted for non-payment. Deletion happens only when a keeper chooses it.