Anthavi
Privacy policy
Last updated: 8 May 2026
What we collect
When you create an account or accept an invitation we collect your email address and the name you provide. When you contribute to a memorial we collect the photos, videos, audio, written memories, and any captions or metadata you upload. When a funeral home creates a case we collect details about the loved one (name, dates, place of service) supplied by the arranger.
How we store it and who processes it
Account data lives in a managed PostgreSQL database operated by Supabase, and uploaded media lives in Amazon S3 — both in the United States. To produce a memorial we rely on a small set of reputable service providers, each handling only the data needed for its function:
- Amazon Web Services — Stores every uploaded photo, video, voice recording, and written memory, plus the finished videos. Face matching, so the same person can be recognized across a story's photos and videos. This derives face-geometry data from photos and videos. Renders the finished video and queues rendering jobs.
- Vercel — Runs the application; sees request traffic, IP addresses, and application logs.
- Google Cloud — Drafts suggested captions and descriptions from uploaded media. Google does not use this data to train its models, and processing stays within the United States.
- Supabase — Accounts, sign-in sessions, and all structured data about stories and memories.
- Stripe — Billing identity and payment details.
- Resend — Sends invitations, sign-in links, and notifications — names, email addresses, and story context.
- Inngest — Coordinates processing work; sees record identifiers and job metadata, not media.
- Upstash — Short-lived sign-in session state and rate-limiting counters.
- OpenStreetMap Foundation — Converts location coordinates embedded in a photo into a readable place name (and typed place names into map locations).
- Modal — An inactive earlier rendering path, still deployed. No routine customer data flows here.
The full register — broken out by service, with what each one processes — is published at /legal/subprocessors and updated whenever a provider changes.
How we use it
Your data is used solely to produce the memorial story you or your funeral home is gathering — assembling videos, building memorial pages, and notifying invited family members. We do not sell or rent your data, and we do not share it with advertising or analytics partners. Aggregated, non-identifying usage metrics may be used to improve the product.
Retention
Memorial storiesare retained for the lifetime of the account that created them, unless you ask us to delete them sooner. You can request deletion at any time (see “Your choices” below). Audit logs (sign-in events, invitation redemptions) are kept only as long as needed for security review, then deleted.
Your choices
You can request a copy of your data, correct it, or delete it by emailing privacy@anthavi.com. We acknowledge requests promptly and complete them within the time required by applicable data-protection law — normally within 30 days.
Sign-in providers
If you sign in with Google, Apple, or Facebook, those providers share your email and basic profile (name, avatar) with us. We do not receive your password, your contacts, or your wider account data. You can revoke our access at any time from the provider’s account settings.
Contact
For privacy questions, deletion requests, or any concerns, contact privacy@anthavi.com.