told.

Privacy Policy

Last updated: 22 September 2026·Effective date: 25 August 2026

1. Who we are

Told is a family memoir and oral history service operated by RAF B.V., a private limited company incorporated in the Netherlands (KvK number 92038565), with its registered address at Singel 126, 1015 AE, Amsterdam.

In this policy, “Told,” “we,” “us,” and “our” refer to RAF B.V. operating the Told service at gettold.app. “You” refers to the person using Told to record and preserve family interviews.

If you have questions about this policy or want to exercise your rights, contact us at hello@gettold.app.

2. Who controls what data

Told operates on a two-tier data controller model. This matters because Told is used to record other people (typically family members), and the law treats your account data and the interview content you create as separate categories.

Told (RAF B.V.) is the data controller for:

  • Your account information (name, email address, password)
  • Your payment and billing information
  • Your usage of the Told service (logs, analytics, audit records)
  • Your preferences and settings
  • Communications between you and us

You are the data controller for:

  • The audio recordings you create
  • The transcripts and stories generated from those recordings
  • The photos you upload
  • The personal information of interviewees and other people mentioned in your interviews
  • The books and documents you generate
  • The contact details of any family circle you invite, and the updates and answers you choose to share with them

For interview content, Told acts as a data processor on your behalf. We process this content only to provide the service to you: storing it, transcribing it, generating chapters, producing books, and so on. We do not use it for any other purpose.

This means that when you record someone, you are responsible for having their permission to record them and to process their personal information using Told. Our Terms of Service explain this in more detail.

3. What data we collect and why

Account and service data (Told as controller)

DataPurposeLegal basis
Email addressAccount creation, login, transactional emailsContract
NamePersonalisation of the serviceContract
Password (hashed)Account securityContract
Payment informationProcessing book ordersContract
Shipping addressDelivering printed booksContract
IP address, device infoSecurity, fraud preventionLegitimate interest
Usage logs and audit recordsService operation, security, GDPR complianceLegitimate interest, legal obligation
Consent recordsDemonstrating compliance with GDPRLegal obligation
Cookie preferencesRespecting your cookie choicesConsent

Interview content (you as controller, Told as processor)

DataPurposeLegal basis
Audio recordingsCreating transcripts and books for youYour instructions as controller
TranscriptsGenerating organised chapters and storiesYour instructions as controller
PhotosIncluding in your books and on profilesYour instructions as controller
Names, biographies, life events of intervieweesBuilding the family tree and book contentYour instructions as controller
Story content (places, dates, relationships, events)AI-assisted organisation and enrichment of storiesYour instructions as controller

Family circle data (you as controller, Told as processor)

If you use the family circle to share written updates about your conversations, Told also processes:

DataPurposeLegal basis
Names and email addresses of circle members you inviteSending the updates and answers you approveYour instructions as controller
Questions circle members submitBringing them to your next conversation and answering themYour instructions as controller
A circle member's choice to hear about the finished bookSending them book updates they asked forTheir consent

4. How we use AI

Told uses AI services to make interviews easier and to organise what you record. Specifically:

  • AssemblyAI turns your audio into text. Your audio is sent to their servers in Dublin (EU), transcribed, and deleted the moment we have saved the transcript. Nothing of yours stays with them.
  • Claude, Anthropic’s AI model, generates follow-up questions during conversations, detects significant story moments, extracts people and places, organises content into chapters, edits prose, adds light historical context, and, if you use the family circle, drafts the updates, answer excerpts and reminders you send to it. These drafts are only ever shown to you; nothing is sent to your circle until you approve the exact text. Claude runs for us on Amazon Web Services servers inside the EU. Every request is marked zero data retention: your words are not stored after the answer comes back, and are never used to train AI models. Anthropic itself does not receive your data.

For every AI request we record which provider answered it and in which region, so we can show that it stayed in the EU.

You can disable AI features in your privacy settings. Some features of Told depend on AI processing, so disabling it will reduce what the service can do.

5. Where your data is stored

Your data is stored on Supabase servers in Frankfurt, Germany (EU). Backups are also held within the EU.

Your AI processing happens inside the EU. A few other sub-processors (payments, printing, email) are based outside the EU; there we rely on the European Commission’s Standard Contractual Clauses (SCCs).

6. Who we share data with (sub-processors)

We work with the following service providers to operate Told. Each is bound by a data processing agreement with us.

ProviderWhat they doWhere they processPrivacy policy
SupabaseDatabase, file storage, authenticationEU (Frankfurt)supabase.com/privacy
AssemblyAIAudio transcriptionEU (Dublin)assemblyai.com/legal/privacy-policy
Amazon Web ServicesRuns Claude for our AI featuresEUaws.amazon.com/privacy
VercelApplication hosting and AI GatewayEU (with SCCs)vercel.com/legal/privacy-policy
StripePayment processingEU/US (with SCCs)stripe.com/privacy
LuluPrint-on-demand book fulfilmentUS (with SCCs)lulu.com/legal/privacy-policy
ResendTransactional email deliveryEU/US (with SCCs)resend.com/legal/privacy-policy

We do not sell your data, and we do not share it with anyone else for marketing or advertising purposes.

When you order a printed book, we share your name and shipping address with Lulu so they can fulfil the order. Stripe receives your payment details directly through their secure checkout; we do not store full card numbers.

Sharing with your family circle. If you use the family circle, then at your instruction Told emails the updates and answers you have reviewed and approved to the circle members you have nominated (delivered by Resend). You approve the exact text of every message before it is sent — nothing is sent automatically. A single line offering a copy of the finished book is included only for circle members who have opted in to hearing about it, and every email carries an unsubscribe link.

7. How long we keep your data

DataRetention
Account dataUntil you delete your account
Interview content (audio, transcripts, photos, books)Until you delete it or delete your account
Audio and transcript at AssemblyAIDeleted as soon as we have saved the transcript, and always within one hour
AI requests (Claude)Not stored after the answer is returned; never used for training
Payment records7 years (Dutch tax law requirement)
Gift invitation detailsRemoved when the associated account is deleted; pending invitations are cancelled. Minimal purchase and redemption records remain for accounting and to preserve unused gift value and prevent reuse of spent gifts. Unused gifts do not expire. Earlier emails and payment-provider records are handled separately.
Anonymised order recordsKept after account deletion for accounting purposes
Audit logs12 months; IP addresses anonymised after 30 days
Marketing email consent withdrawalPermanent record of withdrawal
Family circle members, their questions, and shared updatesUntil you remove them or delete your account

When you delete your account, we delete your data within 30 days, except records we are legally required to keep (such as tax records, which are anonymised).

8. Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: ask us to correct inaccurate data.
  • Right to erasure (“right to be forgotten”): ask us to delete your data.
  • Right to data portability: receive your data in a portable format.
  • Right to restrict processing: ask us to limit how we process your data.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw any consent you have given, at any time.

You can exercise most of these rights directly in Settings > Privacy in the Told app, including downloading your data and deleting your account. For anything else, email hello@gettold.app and we will respond within one month.

A note on interviewee rights: if you are an interviewee (someone whose recording is in Told because a family member recorded you), the person who recorded you is the controller of that content. Contact them first. If you cannot reach them or need our help, email hello@gettold.app and we will assist within our role as processor. If a family member shares written summaries of your stories with a circle of people, you can ask them to stop at any time.

A note for family circle members: if you receive emails from Told because someone added you to a family circle, you can stop them at any time using the unsubscribe link in any email. The person who added you is the controller of what is shared with you; to see or delete the details Told holds about you, contact them, or email hello@gettold.app and we will help within our role as processor.

9. Cookies

We use a small number of cookies. See our Cookie Policy for details. You can manage your preferences at any time through the cookie banner or in Settings > Privacy.

10. Security

We take reasonable technical and organisational measures to protect your data, including:

  • Encryption in transit (HTTPS) and at rest
  • Row-level security on our database, so users can only access their own data
  • Authenticated access to all account features
  • Regular security updates to our infrastructure
  • Audit logging of significant actions

No system is completely secure. If we become aware of a data breach affecting your personal data, we will notify you and the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours, as required by GDPR.

11. Children

Told is not intended for use by children under 16. We do not knowingly collect data from children. If you are recording an interview with a minor, you confirm that you have permission from their parent or guardian.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you by email and through the app. The “last updated” date at the top of this page always reflects the current version.

13. Complaints

If you believe we have not handled your data correctly, you can complain to the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
Postbus 93374
2509 AJ Den Haag
autoriteitpersoonsgegevens.nl

We hope you will contact us first so we can try to resolve any concern directly.

14. Contact

For all privacy-related questions or requests:

RAF B.V. (Told)
Singel 126, 1015 AE, Amsterdam
KvK: 92038565
Email: hello@gettold.app