Skip to main content

Privacy Policy

Last updated: September 14, 2026

Who we are

Candela Memorial ("Candela," "we") operates candela.memorial from the United States. This policy covers the family product, funeral-home accounts, memorial pages, and Apple Wallet / Google Wallet cards.

1. Information we collect

Account. Email, display name, password or magic-link tokens, and (if you use it) Sign in with Apple. Funeral-home accounts may also include business name, address, phone, and logo.

Memorial content. The name of the person the memorial is for, their dates, photos, obituary text, prayers, guestbook notes, candle lightings, relationship labels (for example "grandchild"), service date, time, and place, and places that mattered to them.

Wallet cards. When someone adds a card, we store enough to create and update the card: the name of the person it is for, their photo, service details, and a device registration token from Apple or Google so the card can change when a wake time changes. We do not read live GPS from the browser. Place relevance on the lock screen is handled by Apple Wallet and Google Wallet on the phone.

Payments. If you buy a plan or contribute to a memorial, Stripe processes the card. We receive the amount, last four digits / brand when Stripe sends them, email, and a payment id. We do not store full card numbers.

Analytics and session replay. We use PostHog on every public and signed-in page. That includes page views, clicks, feature events, exception reports, heatmaps, and session recordings. Recordings mask typed input and block photos, video, and canvas. Page text on a public memorial is already public and can appear in a recording. We identify a signed-in account in PostHog by user id and email. We do not run a consent banner. We do not currently load Google Analytics.

Technical. IP address, browser, device, and request logs as a normal part of hosting, rate limits, and security.

2. How we use it

  • To run accounts, memorials, and Wallet cards
  • To show a memorial to the people you share it with, and a public memorial to anyone with the link
  • To send mail that is part of the product: magic links, password resets, invites, receipt mail from Stripe, and (if a funeral home enrolls aftercare) signed notes from that home
  • To date or describe photos when you use those tools, which can send an image to our photo-analysis service
  • To see how the product is used, fix bugs, and keep the site up
  • To take payment and prevent fraud

3. What we do not do

  • We do not sell personal information or memorial content.
  • We do not use memorial photos in ads or marketing campaigns.
  • We do not run third-party advertising cookies or ad networks.
  • We do not train our own models on your memorials. Photo dating and writing tools may send content to a model provider for that request only. Their terms apply to that call.

4. Who else sees data (processors)

We hire companies to run the product. They see what they need to do that job. They are not given your memorials to use as their own product.

  • PostHog: analytics and session replay
  • Stripe: payments
  • Resend: transactional email
  • Cloudflare R2: photo and file storage
  • Railway (or successor host): application hosting
  • Sentry: error reports, when enabled
  • Apple and Google: Wallet card delivery and updates.
  • Photo-analysis and writing providers (including Phototology and, when configured, OpenAI, Anthropic, or Google Cloud) when you use those features

A funeral home you work with can see the memorials they create or that a family attaches to their account.

5. Memorial visibility

A published memorial with a public link can be opened by anyone who has that link. Do not put a secret in a public obituary. Draft and private memorials stay with the people you authorize. Search engines may index a public page.

6. Cookies and similar storage

Essential cookies keep you signed in (httpOnly session). PostHog sets its own first-party identifiers so a visit can be one person across pages, and so a recording can be one session. That is tracking. It is not an ad cookie. There is no cookie banner. Turning on "block third-party cookies" in the browser does not turn PostHog off, because it runs on our domain through /ingest.

7. Security

Traffic is encrypted in transit (HTTPS). Photos live in access-controlled object storage. Auth tokens are httpOnly cookies. Wallet signing keys stay on the server. No setup is perfect. If we learn of a breach that affects you, we will email the address on the account.

8. Retention

Memorials stay up while the account is open. Paid plans have no scheduled expiration; that is not a promise the company exists forever. Close the account and ask, and we export then delete memorial data within 30 days, except records we must keep for taxes, disputes, or security. Analytics and recordings follow PostHog's project retention. Stripe keeps payment records under its own rules.

9. Your rights

You can ask us to access, correct, export, or delete personal information we hold. Email [email protected]. If you are in California you can also ask what we collected and whether we sold or shared it. We do not sell it. Session replay is "sharing" with PostHog as a service provider, not a sale.

10. Children

The Service is not directed at children under 13. A memorial may be about a child; the account that creates it should belong to a parent or guardian.

11. Changes

If we change how we use memorial content or analytics in a way that is worse for you, we will email the address on the account. Small corrections land on this page with a new date.

12. Contact

Privacy: [email protected]. Support: [email protected].

← Home
Privacy Policy | Candela