Privacy Policy
Effective 4 July 2026 · Last updated 4 July 2026
Family Treeexists to help families preserve their story on terms the family controls. That promise only means something if we are clear and honest about the personal data we hold, why we hold it, where it lives, and what you can do about it. This policy explains exactly that. It is written to align with India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”); we aim to hold ourselves to a comparable standard for users elsewhere.
In this policy, “we”, “us”, and “the Service” refer to Family Tree, operated by [legal entity — pending CA/tax-advisor confirmation, see PRD §4]. “You” means the person who holds an account with us.
1. The data we collect
Data you give us to create and run your account
- Your name and email address, so we can identify your account and contact you.
- Your password, which we never store in readable form — it is kept only as a one-way cryptographic hash.
- An optional profile photo, if you choose to add one.
Data you add about your family
The heart of the Service is the family information you build: people (names, other names they were known by, approximate or exact birth and death dates, whether a person has passed away, places, and free-text notes), the relationships between them, and the photos, written stories, and audio recordings you attach.
Much of this is, by its nature, personal data about other people — living relatives, and people who have passed away. Some of it may be sensitive. When you add information about another person, you are responsible for having a proper basis to do so (see our Terms of Service). If someone who is the subject of a record wants it corrected or removed, see “People who are not members” below.
Data from a sign-in provider
If you choose to sign in with Google, we receive your basic profile information (name, email address, and profile picture) from Google to create or connect your account. We do not receive your Google password.
Data we collect automatically
- A session cookie that keeps you signed in. It is strictly necessary for the Service to work and is not used for advertising.
- Basic technical and diagnostic data — such as device and browser information and error reports — which we use to keep the Service secure and working, and to fix problems.
Payment data
When paid plans launch, payments will be handled by our payment gateway, Razorpay. We do not see or store your full card or bank details; we keep only the record of your plan and payment status needed to run your subscription.
2. Why we use your data
We use personal data only to:
- provide, maintain, and improve the Service;
- create and secure your account, and let the people you invite see what you have chosen to share with them;
- send you account and service messages (such as email verification, password resets, and invitations you trigger);
- keep the Service safe — preventing abuse, fraud, and unauthorised access;
- process payments and manage subscriptions, once paid plans exist;
- meet legal and regulatory obligations.
We rely on your consent, and on the other lawful bases permitted under the DPDP Act, to process this data. We do not sell your personal data, and we do not use your family’s data to show you advertising.
3. Who we share data with
Within your family. The whole point of the Service is sharing within a tree. Information is visible to the other members of a tree according to the role each person has and the privacy settings that apply — for example, members with a viewer role see year-only birth dates for living people, rather than exact dates.
Service providers who run the Service for us. We use a small set of trusted providers, and share only what each needs to do its job:
- Neon — hosts our database (your account and family data).
- Cloudflare R2 — stores the photos, audio, and documents you upload, as private files served only through short-lived, signed links.
- Vercel — hosts and serves the application.
- Resend — delivers our transactional emails (verification, password reset, invitations).
- Google — only if you choose Google sign-in.
- Sentry — collects error diagnostics so we can fix faults.
- Razorpay — processes payments, once paid plans launch.
Legal reasons. We may disclose data if the law requires it, or to protect the rights, safety, and security of our users and the Service.
4. Where your data is stored
We are honest about this because it matters: today the Service runs on infrastructure located in Singapore and other locations in the Asia-Pacific region, not within India. This is a deliberate, cost-driven choice for our early stage, and we intend to revisit data residency as the Service grows. By using the Service you understand that your data is processed in these locations. Wherever it is stored, it is protected as described in this policy.
5. How long we keep your data
We keep your personal data for as long as you have an account, and for as long as needed to provide the Service. If you delete your account, we act as described below. We may retain limited information for longer where the law requires it (for example, records relating to payments).
6. Your rights
Under the DPDP Act you have real, exercisable rights over your personal data. You can:
- Access a summary of the personal data we process about you;
- Correct or complete inaccurate or incomplete data — you can edit most of your data directly in the Service;
- Erase your personal data by deleting your account (see the next section);
- Withdraw consent at any time (this does not affect processing already carried out);
- Nominate another person to exercise your rights on your behalf if you die or become incapacitated;
- Raise a grievanceand have it addressed (see “Contact and grievances”).
To exercise a right that you cannot action yourself in the app, contact us using the details at the end of this policy.
7. Deleting your account and data
Real deletion is a core promise of this Service, not an afterthought. When you delete your account:
- Your personal data is purged — your email, sign-in credentials, and profile photo are permanently removed, and your account can never be signed into again.
- Your family’s shared memories are not destroyed. Content you contributed to a shared tree — such as a recorded story or an uploaded photo that other members rely on — is kept, but re-attributed to an anonymised “Former Member” rather than to you.
“We delete your data” and “we don’t destroy your family’s shared history” are both promises, and the Service is built to keep both.
8. People who are not members
A family tree naturally contains information about people who do not have an account — living relatives and people who have passed away. If you are the subject of a record in someone else’s tree and you want it corrected or removed, you can contact us using the details below and we will address your request. This channel exists specifically for people who cannot simply log in and edit their own information.
9. Children’s data
Family trees include children. You must be an adult to hold an account, and when you add information about a child you confirm you have the authority to do so, including any parental consent required by law. We do not knowingly build behavioural profiles of children, track them, or show them advertising. If you believe a child’s data is on the Service without proper authority, contact us and we will act.
10. How we protect your data
- Data is encrypted in transit and at rest.
- Passwords are stored only as one-way hashes, never in plain text.
- Trees are private by default — nothing is public, and there is no cross-tree discovery of your family without your explicit opt-in (a feature that does not yet exist).
- Uploaded photos and recordings are private files, served only through short-lived signed links rather than public URLs.
No online service can promise perfect security, but protecting your family’s data is central to why this Service exists, and we treat it that way.
11. Changes to this policy
We may update this policy as the Service grows. When we make a material change, we will update the “Last updated” date above and, where appropriate, let you know in the app or by email.
12. Contact and grievances
If you have a question, a request about your data, or a complaint, you can reach our Grievance Officer, [Grievance Officer name], at [contact email — e.g. privacy@your-domain]. We take grievances seriously and will respond within the timeframes required by applicable law.