Last updated: July 2026
The following information gives you an overview of what happens to your personal data when you use our website and web app. Personal data means all data by which you can be personally identified or are identifiable.
This Privacy Policy applies to the use of our website, the web app, user accounts and the family, family tree, contact, media, invitation and communication features provided in them.
The controller responsible for data processing on this website and in the web app is:
Dr. Martin Anduschus
Wartenburgstraße 1B
10963 Berlin, Germany
Email: stammbaum at anduschus.com
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
3.1 Terms: "Personal data" means any information relating to an identified or identifiable natural person, for example name, email address, telephone number, address, IP address, user identifier, profile information or content relating to living persons.
3.2 Purposes and legal bases: We process personal data in particular for the following purposes:
Depending on the context, the legal bases are in particular:
3.3 Recipients and processors: We use service providers that may process personal data on our behalf, for example for hosting, database operation, email delivery, authentication, storage, error analysis or support. Where required, these service providers are engaged as processors under Art. 28 GDPR.
We only disclose personal data if this is necessary to provide the service, if consent has been given, if there is a legal obligation or if another legal basis permits it.
Service providers currently used include in particular:
Where contact details are voluntarily shared within an extended family in the web app, active members of the same extended family are also recipients of those shared details.
3.4 Transfers to third countries: If we use service providers outside the European Economic Area or service providers with possible access from third countries, personal data will only be transferred if the requirements of Art. 44 et seq. GDPR are met, for example through an adequacy decision, standard contractual clauses or explicit consent where required.
3.5 Storage period and deletion: We store personal data only for as long as is necessary for the respective purposes or as long as statutory retention obligations apply. Afterwards, the data is deleted or anonymized unless there is another legal basis for continued storage.
Where specific retention periods are stated in this Privacy Policy, those periods take precedence. If no specific period is stated, the storage period depends on the processing purpose, the duration of the user account, visibility and sharing settings, legal obligations and legitimate security and documentation interests.
Each time the website or web app is accessed, technical data is processed by our server or hosting provider. This may include:
The purposes of processing are the technical provision of the website and web app, stability, error analysis, detection of misuse and attacks, and IT security.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional operation of the website and web app.
The storage period is usually 7 to 30 days unless a security incident, error analysis or legal obligation requires longer retention.
5.1 Technically necessary storage: We use technically necessary cookies, local storage or similar technologies that are required for the operation of the website and web app. These include, for example, storage for:
The legal basis is Art. 6(1)(b) GDPR where this storage is necessary to provide the user account or requested features, and Art. 6(1)(f) GDPR based on our legitimate interest in secure and usable operation.
Where Section 25 TDDDG applies, access to technically necessary information is based on Section 25(2) TDDDG.
5.2 Non-essential cookies, analytics and tracking: For reduced web analytics on public pages, we use PostHog without PostHog cookies and without persistent browser storage. PostHog SDK storage is limited to memory. Further information is provided in section 12.
If we use non-essential cookies, marketing tracking or comparable technologies in the future, this will be done only with your prior consent where required. The legal basis will then be Art. 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG.
If you contact us, for example by email, contact form or support function, we process the data you provide. This may include:
The purpose of processing is to handle your request, communicate with you and document the handling of the request.
The legal basis is Art. 6(1)(b) GDPR where the communication is related to a user account or requested service, and Art. 6(1)(f) GDPR based on our legitimate interest in handling requests.
The data is generally stored until final handling of the request and then for up to 6 months, unless statutory retention obligations or legitimate interests require longer storage.
7.1 Registration and user account: When creating and using a user account, we typically process:
The purposes are account creation and management, authentication, security, provision of features and management of access rights.
The legal basis is Art. 6(1)(b) GDPR for providing the user account and Art. 6(1)(f) GDPR for IT security, misuse prevention and technical traceability.
7.2 Invitations and roles: If you invite family members or other persons, or if you are invited yourself, we process the data required for this. This may include:
The purposes are sending and managing invitations, assigning users to a family or extended family, managing rights and enabling secure use of the web app.
The legal basis is Art. 6(1)(b) GDPR where the feature is necessary for use of the service, and Art. 6(1)(f) GDPR based on our legitimate interest in secure and collaborative use.
7.3 Account deletion: You can generally have your user account deleted through the intended function or through the support contact.
We delete or anonymize account data unless legal obligations or overriding legitimate interests prevent this. Such legitimate interests may include evidence of misuse, security logs, records of consents and withdrawals, or technical integrity requirements within shared family content.
7.4 Contact details and voluntary sharing within the extended family: Contact details can be stored in the user account. These may include in particular:
These contact details are initially used for management in your own account. The login email address remains separate unless it is expressly also stored or shared as a contact detail.
You can voluntarily decide whether individual or all contact details become visible within your extended family. If you activate the "Share with family" option, the selected contact details become visible to active members of the same extended family, for example in the contact list or family-tree profile.
Sharing is voluntary. You can also use your account without sharing contact details within the extended family. If you do not give consent or withdraw consent, this has no disadvantages for normal use of your account.
The purposes of processing are:
The legal basis for displaying shared contact details within the extended family is your consent under Art. 6(1)(a) GDPR.
The legal basis for storing technical records of granted consents, changes and withdrawals is Art. 6(1)(f) GDPR. Our legitimate interest lies in being able to prove consents and withdrawals, handle data subject rights, prevent misuse and ensure the security and integrity of the application.
Recipients of shared contact details are active members of the same extended family. Contact details that are not shared remain visible only in your account, to the extent they are stored there.
You can withdraw your consent at any time with effect for the future by deactivating sharing of the relevant contact details again. From the time of withdrawal, these details will no longer be displayed as current family contact data. The lawfulness of processing before withdrawal remains unaffected.
We generally store current contact details for as long as your user account exists or until you change or delete the details. Shared contact details are displayed within the extended family only for as long as the relevant sharing setting is active.
Changes, sharing decisions and withdrawals may be stored in a technical change history. This history is retained only for as long as it is required for documentation, security, access, rectification or deletion purposes. Afterwards, it is deleted or anonymized unless statutory retention obligations or overriding legitimate interests prevent this.
To document consent, the following may be stored in particular:
8.1 Which data may be affected? Depending on use, we process data that you or authorized co-users add or edit. This may include:
8.2 Special aspects for living persons: Where content relates to living persons, it is personal data within the meaning of the GDPR. Please ensure that you have an appropriate legal basis for adding, editing or sharing such data, in particular consent from the affected person where required.
We recommend recording data about living persons only with restraint and adding only information that is necessary for the respective purpose. Particularly sensitive information, full birth dates, private addresses, telephone numbers or health information should only be added if this is necessary and legally permissible.
8.3 Special categories of personal data: Genealogical content, media, stories or notes may in individual cases contain special categories of personal data, for example information about health, religion, political opinions or ethnic origin.
Please add such content only if you are authorized to do so and the affected person has expressly consented where required, or another legal basis exists.
8.4 Data of deceased persons: Data of deceased persons is generally not within the scope of the GDPR. Nevertheless, we handle this information respectfully and according to the principle of data minimization. National special rules, personality rights of relatives or other legal requirements may need to be observed in individual cases.
8.5 Visibility and sharing: In the current configuration, content is not shared publicly. Content is restricted to invited or authorized members within the relevant family or extended family.
Visibility and access may differ depending on role, family assignment and feature. If public sharing or external publication becomes possible in the future, this will be made transparent in this Privacy Policy and, where required, implemented only with consent.
8.6 Legal bases: Depending on the specific use, the legal bases are:
8.7 Uploads and metadata: Uploads, especially photos and documents, may contain metadata, for example EXIF data, location data, device data or timestamps. Please remove sensitive metadata before uploading if you do not want to share it.
If you publish comments, reactions, guestbook entries or similar content, we process the data you provide. This may include:
The purposes are providing the respective community feature, displaying the post to authorized users, moderation and misuse prevention.
The legal basis is Art. 6(1)(b) GDPR for providing the feature and Art. 6(1)(f) GDPR for moderation, misuse prevention and IT security.
The storage period depends on the duration of publication, your deletion options, moderation decisions and legitimate security or documentation interests.
We may use your email address to send you necessary messages related to your user account or use of the web app. These include, for example:
The legal basis is Art. 6(1)(b) GDPR where the communication is necessary to provide the user account or features, and Art. 6(1)(f) GDPR for security and misuse prevention notices.
Where optional notifications or newsletters are offered, they are sent only on the basis of your consent under Art. 6(1)(a) GDPR or another permissible legal basis. You can withdraw consent at any time with effect for the future.
If you subscribe to a newsletter, we process your email address and, where applicable, other voluntarily provided information for sending the newsletter.
The legal basis is Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future, for example via an unsubscribe link in the newsletter or by sending a message to stammbaum at anduschus.com.
If no newsletter is currently offered, this processing does not take place.
We use PostHog EU for reduced web analytics on public pages. The web analytics $pageview event is captured with limited properties such as page group, language, referrer domain and, where applicable, UTM parameters; sensitive path parts such as invitation tokens are grouped before sending.
Autocapture, session replay, heatmaps, surveys, feature flags, performance and exception capture, person profiles and persistent browser storage are disabled. Browser storage is limited to memory; no PostHog cookies are set. On private routes, pageviews and automatic interactions are not captured.
In addition, the web app captures only selected, manually triggered conversion events: successful logins, created or sent invitations, the start and completion of an invitation registration, and creation of a new family space. These events contain only broad technical categories and status values; names, email addresses, contact values, family or person IDs, invitation tokens and free text are not sent to PostHog.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in understanding the use of public pages, improving the public website, checking technical quality and measuring the described data-minimized conversions. Do-Not-Track settings are respected.
If broader analytics or marketing tools are used in the future, we will update this Privacy Policy accordingly and obtain your consent in advance where required. In particular, providers, purposes, data categories, legal bases, storage periods and withdrawal options will be described.
We take appropriate technical and organizational measures to protect personal data. These may include in particular:
Despite these measures, complete security cannot be guaranteed for data transmissions over the internet.
Subject to the statutory requirements, you have the following rights:
If you withdraw consent, the lawfulness of processing before withdrawal remains unaffected.
To exercise your rights, it is sufficient to send a message to stammbaum at anduschus.com.
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.
The right to lodge a complaint exists in particular with the supervisory authority of your usual place of residence, your workplace or the place of the alleged infringement.
This Privacy Policy is currently valid and was last updated in July 2026.
Due to the further development of our website and web app, new features or changed legal or regulatory requirements, it may become necessary to amend this Privacy Policy.
The current version can be accessed on our website at any time.