← Back
Privacy Policy
Last updated August 5, 2026
This describes what information Heritage American collects, how it's used, and who it's
shared with. We built this platform to hold irreplaceable family history — we take that
seriously.
1. What we collect
- Account info — email, a hashed password (never stored in plain text),
and your display name.
- Family tree data — people, relationships, life events, and dates/places
you or other family members add.
- Uploaded media — photos, videos, and documents (including sensitive
categories like gravestone photos, marriage certificates, land records, and court documents).
- Recorded stories — video/audio recordings and their transcriptions.
- Usage data — likes, comments, notification preferences, and sharing
settings you configure.
2. How your data is processed
Some processing happens entirely on our own server, with nothing sent to a third party:
- Story video/audio transcription (runs locally, via an open-source speech-to-text model —
your recordings are not sent to an external transcription service).
- Malware scanning of uploaded documents (runs locally before a file is ever stored).
Some processing uses third-party services, only for the specific purpose described:
- Anthropic (Claude) — generates personalized story-prompt questions, and
reads scanned documents to transcribe their text (OCR).
- xAI — assists in scoring how relevant an external historical record match
is, to help sort your review queue.
- Wikidata (public, free database) — checked for name/birth-year matches to
surface notable figures who may share your lineage. Only a name and birth year are sent —
information already present in your family tree.
- National Archives (NARA) — searched for historical records (military,
land, census) matching people in your tree, using name and date information already in your
tree.
- Resend — sends transactional emails (invites, password resets) on our
behalf. Not yet active for this beta; see note below.
- Stripe — processes payments for both merch store orders and voluntary
donations. Printful fulfills merch orders specifically. Your shipping address
and order details are shared with these providers only when you place an order or make a
donation.
- FamilySearch — not yet active (pending FamilySearch's approval of our
application for API access). Once approved, this platform will be able to search FamilySearch
for records matching people in your tree, and — only after a family member explicitly reviews
and approves each specific item — contribute new persons, relationships, facts, source
citations, or photos to FamilySearch's shared Family Tree. Nothing is ever sent to FamilySearch
automatically; every contribution requires an explicit human approval first.
We do not sell your data to advertisers, and we do not use your family's content to train
third-party AI models.
3. Who can see your data
Information you add is visible to other members of your family archive, according to the
sharing-depth setting you choose (limiting how many degrees of relation can see content you
upload about living people) and your role in the family (owner/admin/editor/viewer). Deceased-
person content and the family tree map itself are not gated by sharing depth. Full detail is in
the app's sharing settings.
4. Security
- All traffic to the site is encrypted (HTTPS).
- Passwords are hashed (PBKDF2-SHA256 with a random salt per account) — we never store or
can retrieve your actual password.
- The server is protected by a firewall restricting access to only what the site needs.
- Uploaded documents are scanned for malware before being stored.
- Both core databases are backed up nightly to separate, off-server storage.
5. Data retention and deletion
You can delete your own account at any time from your account settings. Deleting your account
removes your login credentials and personal profile information (your email, password, and
display name are permanently scrubbed and cannot be recovered).
What account deletion does NOT do: content you contributed to a family
archive — stories, photos, documents, comments, and tree edits — stays in that family's archive
for other members after your account is deleted, the same way it would if you'd invited a
relative to a shared photo album and later moved away. This is a deliberate choice: your family's
shared history shouldn't disappear because one contributor's account is deleted. If you want
specific content removed from a family archive (not just your login), contact the platform
administrator or the family's owner/admin directly and we'll handle it manually.
Honest note, since this platform is early in its beta: a self-service data
export tool (downloading a copy of everything you've contributed) is planned but not yet built.
If you'd like a copy of your data in the meantime, contact the platform administrator directly.
6. Children's information
Accounts are only created by adults (18+). A family archive may include photos, stories, or
tree information about minors, added by a parent or adult relative — this platform does not
knowingly collect information directly from anyone under 13.
7. Changes to this policy
If this policy changes, we'll update the date at the top of this page. Significant changes
will be communicated to members directly.
8. Contact
Questions about your data? Reach out through the family member who invited you, or to the
platform administrator directly.