Skip to content
Family-Tree
English

Privacy policy

Effective from [to be filled in]

Who is responsible for the data

The data is stored by, and is the responsibility of, the operator: [to be filled in].

Jurisdiction: [to be filled in].

Contact for questions about your data: [to be filled in].

What we store about your account

Your name, interface language and time zone. Also the identifier of the external Google or Telegram account you sign in with.

We request your profile from Google and Telegram and keep only your name from it. We do not request your e-mail or phone number, and we do not store your profile photo or a password.

What is stored in trees

Whatever you and the other members of a tree enter: people, dates and places of events, relationships, notes, sources, photos and documents.

A change log is stored as well: who edited what.

Technical data

We use session cookies and cookies that protect against forged requests. There are no advertising or third-party trackers.

Server logs contain no names, record contents or tokens, only numbers (ids).

Error reports go to Sentry without the IP address, the request body and query string, cookies and database values.

Where the data is stored

The database and the application run on our own server (VPS).

Photos and documents are kept in private Cloudflare R2 storage: a file opens only through a link that is valid for 15 minutes.

Error reports are received by Sentry.io.

Google and Telegram take part only in signing in.

What we use the data for

Only to make the service work: to store your tree and show it to the people you have invited.

We do not sell data and we do not show advertising.

Who can see a tree

A tree is visible to its members, according to their roles: owner, editor, viewer. Through a public link, only what the owner has opened is visible.

Protection of living people: a person with no death date who was born less than 100 years ago, or who has no dates at all, is considered living. A viewer, or anyone using a public link, sees only the name and place in the tree of a living person. Dates, places, photos, notes and sources are hidden.

This protection is on by default. Only the owner of the tree can turn it off.

A service administrator may open a tree read-only — and then sees all of it, including data hidden by the protection of living people — to handle a complaint, a breach of the terms or your own support request. Every such opening is recorded in a log: who, when and which tree. The log is kept for one year.

How long we keep the data

  • An active tree: as long as it has an owner.
  • A deleted tree: 30 days, then completely, together with its files.
  • A deleted account: 30 days, then completely, together with the trees you own.
  • The change log: 24 months.
  • Revoked invitations and links: 90 days.
  • Server logs: 14 days.
  • Backups: 30 days.

Backups

Data cannot be removed from backups before the backup is replaced. Whatever you delete disappears from backups within 30 days.

Your rights

  • Get your data: export the tree to GEDCOM, always free of charge.
  • Correct your data: in the interface.
  • Delete your account: in your profile; the data is removed completely after 30 days.
  • Move your data: GEDCOM 5.5.1, an open format.
  • Object to processing: write to [to be filled in] and we will review your request by hand within 30 days.

If you found yourself in someone else’s tree

Write to [to be filled in]. There is no form and you do not need to register.

We will ask you to confirm that the entry is about you, and we will inform the owner of the tree.

If you are alive and the request is justified, your data in the tree is hidden and anonymised. Your place in the tree stays as a nameless node, so that other people’s relationships are not broken.

The decision and its grounds are recorded. The deadline is 30 days.

Changes to this policy

We publish changes on this page and update the date at the top.