Who we are
Onole Kae is a digital heritage and memory archive operated by TsaQwaQwa/YaQwaQwa. It enables people to preserve and share family memories, community history, stories, places, photographs, memorials, lineage information, and related cultural records.
Privacy enquiries and personal-information requests can be sent to support@tsaqwaqwa.co.za.
Information we process
Account and profile information
This can include an authentication identifier, email address, optional phone number, username, display name, profile photograph, account status, preferences, and dates associated with the account.
Archive content
Content chosen by users can include places, family names, stories, memories, photographs, optional audio, albums, comments, memorials, tributes, lineage and relationship records, invitations, requests, responses, and other contributions. Content may identify or describe people other than the account holder.
Usage and activity information
The service can process viewing history, read states, view sessions, timestamps, selected archive-place identifiers, app-generated session identifiers, platform, app version, build number, update version, and coarse time buckets. This supports account-scoped history, abuse prevention, reliability, and product improvement.
Optional product analytics
Optional first-party product analytics are off by default and are enabled only after a signed-in user chooses to turn them on. Events use an allowlist of event names and limited operational fields. They do not intentionally include names, email addresses, story text, photographs, search terms, exact photo locations, arbitrary form values, or advertising identifiers. Turning analytics off removes analytics events linked to the account.
Crash and reliability diagnostics
When diagnostics are enabled for a release, Onole Kae may process scrubbed error fingerprints, exception categories, stack traces, route names, platform, release channel, app version, build number, runtime version, and update identifier. The app is configured to limit or remove story content, photographs, form values, screenshots, session replay, and unnecessary identifying information from diagnostic reports.
Google Drive backup information
Google Drive backup is optional. After a user connects Google Drive, Onole Kae processes the basic Google account details needed to show the connected account and accesses only the Drive files created by Onole Kae under the permissions granted by the user.
Support and privacy requests
When a person contacts support, we process the information supplied in the message, such as an email address, account identifier, description of the issue, and any supporting material they choose to provide.
How we use information
Information is processed to:
- authenticate users and maintain account security;
- create, store, retrieve, display, and share archive content;
- apply audience, visibility, membership, invitation, and stewardship rules;
- provide optional Google Drive backup and restore;
- remember user preferences and account-scoped activity;
- detect abuse, investigate failures, protect the service, and provide support;
- measure and improve the product where the user has enabled optional analytics;
- comply with lawful obligations and resolve disputes.
Onole Kae does not sell personal information and does not use personal information for third-party behavioural advertising.
Public and restricted content
Public archive content can be viewed by visitors. Link-accessible content can be viewed by people who have the relevant link. Restricted content is made available only according to the audience and access controls selected for that record.
Users should review the selected visibility before publishing. Removing an account does not undo copies that another person lawfully made outside Onole Kae before deletion.
Service providers and international processing
Onole Kae uses service providers to operate the service, including:
- Supabase for authentication, database, storage, and server functions;
- Expo and EAS for app build, update, and distribution infrastructure;
- Google Drive only when a user connects it for optional backup and restore;
- Sentry and Datadog when diagnostics are enabled for the relevant release;
- Vercel for website hosting and privacy-conscious website traffic analytics;
- Resend for transactional account-deletion confirmation email.
These providers process information on our behalf or at the user's direction. Their infrastructure may process information outside South Africa. We use providers and technical controls intended to provide appropriate protection for the information involved.
Browser storage and website analytics
This website does not use advertising cookies or third-party behavioural marketing trackers. The account-deletion page temporarily keeps the entered email address in the current browser tab's session storage so that the verification step can continue. The verified Supabase authentication session remains in memory only and is not restored after the page is refreshed, closed, or reopened. The stored email is cleared after successful deletion or when the user cancels the deletion flow.
Vercel may process limited website request and page-view information, such as IP-derived region, browser or user-agent information, referrer, request time, and requested path, for delivery, security, reliability, and aggregate website analytics. The site does not use this information for personalised advertising.
Retention and deletion
Account information and archive content are retained while needed to provide the service or until the relevant account or record is deleted. First-party product analytics and account-linked app error reports are retained for up to 180 days unless deleted sooner. Third-party diagnostic retention follows the configured provider account settings and is limited to what is reasonably needed for reliability and security.
A user can permanently delete their account in the mobile app or through the web deletion flow. Account deletion removes the authentication account, profile, account-owned archive content, uploads, comments, relationship contributions, membership and invitation records, account-linked activity, diagnostics, and the other associated Onole Kae records covered by the deletion process. After deletion, Onole Kae sends a transactional confirmation to the verified account email address.
If another person lawfully owns a record, that person's record is not deleted only because the deleting user contributed to it; the deleting user's account-linked contribution and attribution are removed where applicable. Information may be retained only where reasonably necessary for a lawful obligation, security, fraud prevention, dispute resolution, or the establishment or defence of legal claims. Any retained information remains restricted to that purpose.
During deletion, the verified email address can be held temporarily in a service-role-only cleanup job so that server-side media removal, authentication deletion, and confirmation-email delivery can be retried after a temporary failure. That job is removed after completion and is automatically discarded after no more than seven days if delivery cannot be completed.
Onole Kae attempts to remove its connected Google Drive backup during in-app deletion. The web flow cannot access a Google token stored on the user's mobile device, so a user completing deletion on the web should manually remove any Onole Kae backup from Google Drive.
Security
Information is transmitted over encrypted HTTPS connections. Authentication and connected-service tokens are stored using platform-protected storage where supported. Access controls, database policies, server-side verification, limited diagnostics, and destructive-action confirmations are used to reduce unauthorised access or deletion.
No internet service can guarantee absolute security. Report a suspected security or privacy issue to support@tsaqwaqwa.co.za.
Your rights and choices
Subject to applicable law, including South Africa's Protection of Personal Information Act, a person may ask whether we hold personal information about them, request access, request correction or deletion, object to certain processing, withdraw consent where processing depends on consent, and lodge a complaint with the Information Regulator.
Profile details and analytics choices can be changed inside the app. Account deletion is available in the app and on the external deletion page. Other requests can be sent to support@tsaqwaqwa.co.za. We may ask for reasonable verification before disclosing, changing, or deleting information.
Information about the South African Information Regulator and prescribed POPIA request forms is available from the Regulator's POPIA page.
Information about children and other people
Onole Kae lets users preserve family and community history, which may include information about other people. A user who submits a name, story, photograph, audio recording, lineage record, or other personal information must have the right and appropriate authority or consent to do so. Extra care should be taken for children and vulnerable people.
Changes to this policy
This policy may be updated when the service, providers, legal requirements, or data practices change. The date at the top identifies the current published version. Material changes will be communicated through an appropriate in-app or service notice where required.
Contact
Privacy, access, correction, deletion, objection, and support requests can be sent to support@tsaqwaqwa.co.za.
