Oncebook

Privacy policy

Last updated: 7 October 2026

This policy explains which personal data we process in the Oncebook iPhone app and its web pages (the shared family page, the password reset page and these legal pages), why and for how long, who can access it, and what your rights are. It is based on the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information (Infotv.).

In short:

  • We only store what the service needs to work.
  • No ads, no tracking, no analytics, no third-party cookies.
  • We do not sell your data and do not use it to train artificial intelligence.
  • In the app you can download all your data and delete your account at any time. Deletion is immediate and permanent, photos and videos included.

1. Who is responsible for your data?

The controller is:

Name
Szentiványi András Szilveszter e.v.
Registered address
2800 Tatabánya, Előd vezér utca 18.
Sole trader registration no.
56933738
Tax number
58441406-1-31
Email
[email protected]

We are not required to appoint a data protection officer. For data protection questions, contact us at the email address above.

2. Who does this policy cover?

3. Which data do we process?

Account data

Name, email address, your password (only as an irreversible hash; we cannot see your password), when you registered, when you accepted the terms of use and this policy and which version, and which family you belong to, in which role (owner or member) and since when.

Family data

The family name, and the children's names, birth dates and (if you upload one) profile pictures.

Uploaded content

Photos, videos and texts: the title, description and date of each memory, which children it belongs to, and which family member added it. For files we also store technical data (file name, type, size, width, height, video length) and the smaller preview images the app makes from photos.

The original photo and video files may contain metadata written by the phone (for example when it was taken, the device model and, if location was turned on, where). We do not read or use this, but it is stored as part of the original file.

Uploaded content often shows children and other people. The person uploading is responsible for having the right to upload it: a parent (legal guardian) may upload pictures of themselves and their child; if someone else appears (for example a relative, a friend, another person's child), their consent or another legal basis is needed. We do not analyse the content of pictures and do not use face recognition.

Please do not record health data or other special categories of data (for example a diagnosis). If you do, we store it only at your explicit request, to provide the service (GDPR Art. 9(2)(a)), and you can delete it at any time.

Sharing data

If the family owner turns sharing on: the random identifier of the shared page (part of the link), the share password as a hash (we cannot see the password), and whether sharing is on.

Invites

The invite code, the family it is for, who created it, when it expires, and who used it and when.

Subscription data

The subscription status (trial, active, expired), when the trial and the subscription end, and the identifiers Apple assigns to the purchase. We never receive or store card or other payment details: Apple handles payment entirely.

Technical logs and security data

For every request our servers log the IP address, the time, the requested address, the browser or app type (user agent) and any error messages. To block too many attempts (for example password guessing) we briefly count requests per IP address. For each device you are signed in on we store an access token (its name, for example "ios", and when it was last used).

Contact

If you write to us: your email address, name and the content of the conversation.

4. Why do we process data, and on what legal basis?

PurposeDataLegal basis
Providing the service: account, storing and showing the family timeline, shared family account, invites, shared pageAccount, family, uploaded, sharing and invite dataPerformance of a contract (GDPR Art. 6(1)(b))
Password reset and service emailsName, email addressPerformance of a contract (Art. 6(1)(b))
Managing the subscription and trialSubscription dataPerformance of a contract (Art. 6(1)(b))
Security, preventing abuse and attacks, debugging, rate limitingTechnical logs, IP address, tokensLegitimate interest (Art. 6(1)(f)): protecting the service and users' data. In our assessment this small amount of briefly kept data does not disproportionately affect your interests; you can object (see section 9).
Accounting obligations, where we issue or keep invoices or accounting recordsData on the recordLegal obligation (Art. 6(1)(c)), Hungarian Accounting Act C of 2000 (Sztv.) section 169
Answering your messagesContact dataPerformance of a contract or legitimate interest (Art. 6(1)(b) and (f))
Establishing, exercising or defending legal claimsData needed for the matterLegitimate interest (Art. 6(1)(f))

We do not make automated decisions or create profiles.

5. Who can access your data?

Your family members

Every member of a family (the owner and invited members) can see and edit the family's children, memories, photos and videos, and can see the other members' names and email addresses. When someone joins a family with an invite, the content they add belongs to that family, and the family owner controls it.

Visitors of the shared page

Anyone the family owner gives the link and password to can see the children's names, ages and profile pictures, and the memories with their photos and videos. Visitors can save or photograph what they see; we cannot prevent this.

Our processors

These providers process data on our behalf, under our instructions and a contract (GDPR Art. 28):

Independent controllers

We do not sell your data, do not give it to advertisers, and do not use it to train artificial intelligence.

6. Transfers outside the European Economic Area

Cloudflare, Inc. is a US company. Transfers to the United States rely on the EU-US Data Privacy Framework, under which Cloudflare is certified, supplemented by the European Commission's Standard Contractual Clauses (SCCs). Transfers related to Apple are covered by Apple's own terms and safeguards.

7. How long do we keep data?

If your subscription ends, your data stays: you can still view, download and delete it.

8. How do we protect data?

If a personal data breach happens, we handle it as the law requires, report it to the Hungarian authority (NAIH) within 72 hours where required, and notify you if it is likely to result in a high risk to you.

9. Your rights

You can exercise your rights in the app, or by emailing [email protected]. We answer within one month at the latest; in justified cases (for example complex requests) this can be extended by two further months, and we will tell you within the first month. This is free of charge. We may verify your identity, for example by asking you to confirm from the email address of your account.

10. Where can you complain?

If you feel we have violated your rights, please write to us first so we can put it right. You can also complain to the supervisory authority:

Authority
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address
1055 Budapest, Falk Miksa utca 9-11.
Postal address
1363 Budapest, Pf. 9.
Phone
+36 1 391 1400
Email
[email protected]
Website
www.naih.hu

You can also go to court (GDPR Art. 79, Infotv. section 23). In Hungary such cases are heard by the regional courts (törvényszék); you can also bring the case before the court of your place of residence. Court contact details: birosag.hu. If you live in another EU country, you can also complain to the data protection authority there.

11. Cookies

The app does not use cookies. The token that keeps you signed in is stored on your device.

On the web pages (the shared family page and the password reset page) we only use cookies that are strictly necessary: a session cookie (oncebook-session) that remembers that you entered the password, and a security cookie (XSRF-TOKEN) that protects forms against forged requests. These do not require consent (Hungarian Act C of 2003 on electronic communications, section 155(4), implementing the ePrivacy Directive). We use no analytics, advertising or tracking cookies, and fonts are served from our own server, so no third party learns about your visit.

12. Children

The service is for adults aged 18 or over. Children are not users but data subjects: their parents record memories about them. Parents (legal guardians) exercise the rights on the child's behalf. If someone (for example a child who has since come of age, or a relative who appears in a photo) asks for content about them to be removed, they can write to us: we will look into the request and, where needed, act together with the family owner.

13. Changes to this policy

If this policy changes materially, we will tell you in advance in the app or by email. The current version is always on this page; earlier versions are available on request. Version: 2026-10-07.