Historicaly (“we,” “us,” “our”) provides genealogical research services through historicaly.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data. We’ve tried to write this in plain English. Where legal terminology is unavoidable, we’ve added context.

If you have questions about this policy or your data, email privacy@historicaly.com.


1. What we collect

Account information. When you create an account, we collect your name, email address, and a password (stored only in hashed form — we cannot see your password). If you sign in with a third-party provider (such as Google), we receive the email address and profile information that provider shares with us.

Project information. When you submit a research project, we collect the information you provide about the person or family you’re researching. This typically includes names, approximate dates, places, family relationships, and any context you share to guide the research. You may also upload documents such as certificates, photographs, prior research reports, or family trees. Everything you upload is stored privately in your account.

Research outputs. We generate and store the research deliverables we produce for you — record images we locate, transcriptions, translations, written narratives, family charts, and maps. These are stored in your account for as long as your account is active.

Payment information. When you purchase a project, payment is processed by Stripe, Inc. We do not receive or store your full credit card number. We retain a transaction record (amount, date, last four digits of the card, and Stripe’s transaction ID) for accounting, tax, and refund purposes.

Technical information. Our hosting provider logs standard web server data when you visit the Service — IP address, browser user-agent, request timestamps, and pages visited. This information is used for security, debugging, and aggregate usage analysis. We do not use third-party analytics or advertising trackers.


2. What we do with it

We use your information to:

What we do not do:


3. Who else sees your information

We use a small number of service providers to operate the Service. Each has access to only the data necessary for their specific function, and each is contractually required to protect it:

These providers process data on our behalf under written agreements and do not use your personal information for their own purposes. We do not sell, rent, or trade your personal information to any third party.

We may disclose information if we believe in good faith that disclosure is required to comply with a valid legal process, protect the rights or safety of users, or enforce our Terms of Service. When legally permitted, we will notify you of such requests.


4. How long we keep your data

We keep your account information and research outputs for as long as your account is active. You can delete individual uploaded documents from your dashboard at any time, and delete your entire account from account settings.

When you delete your account:

Certain records must be retained longer for legal or accounting reasons — for example, transaction records for tax purposes. We retain these only as required by law and only in limited form (typically: user ID, amount, date, no personal family content).


5. A note about what you share with us

Please do not include personal identifying information for yourself or living relatives in your project submissions. Information such as Social Security numbers, current addresses, driver’s license numbers, bank account numbers, or government ID numbers is not needed for genealogical research and should not be uploaded.

Our research focuses on historical records — typically ancestors who are no longer living. We do not need personal identifying information for any living person to perform our work.

If we discover that you have uploaded sensitive personal information that is not needed for research, we may ask you to remove it or, if the information poses a clear risk, remove it ourselves and notify you.


6. Your rights

You have the following rights regarding your personal information:

California residents (CCPA): You have the right to know what personal information we have collected about you, the right to delete it, the right to correct inaccurate information, and the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. We do not sell or share personal information for advertising, but the right to opt out is available to you regardless. We will not discriminate against you for exercising these rights.

EU/UK residents (GDPR): Your rights include the above, plus the right to lodge a complaint with a data protection authority. Our legal basis for processing your data is either (a) performance of the contract you entered into when you purchased a project, (b) your consent (for optional features you opt into), or (c) our legitimate interests in operating and improving the Service, balanced against your rights.

To exercise any right, email privacy@historicaly.com. We will respond within 30 days.


7. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete it.

Users aged 13–17 may use the Service with parental or guardian consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact privacy@historicaly.com.


8. Security

We protect your data with industry-standard security practices: passwords are hashed (bcrypt), data is encrypted in transit (TLS), our database and storage are hosted on Supabase with access controls and audit logging, and administrative access to production systems is restricted and logged.

No system is perfectly secure. If we become aware of a data breach affecting your information, we will notify you within 72 hours of confirming the breach, as required by applicable law.


9. International transfers

The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States. Our service providers (Supabase, Anthropic, Vercel, Stripe) may process data in their respective jurisdictions. For EU/UK residents, we rely on Standard Contractual Clauses and other approved transfer mechanisms.


10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address on your account) and post a notice on the Service at least 30 days before the changes take effect. Non-material changes (clarifications, typo fixes) may be made without notice, with the “Last updated” date reflecting the change.


11. Contact

For any questions about this Privacy Policy, your data, or to exercise your rights:

Email: privacy@historicaly.com Mailing address: [COMPANY ADDRESS — to be added after LLC formation]

Historicaly LLC Wyoming, USA