Historicaly (“we,” “us,” “our”) provides genealogical research services through historicaly.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the rights you have over your data. We’ve tried to write this in plain English. Where legal terminology is unavoidable, we’ve added context.
If you have questions about this policy or your data, email privacy@historicaly.com.
1. What we collect
Account information. When you create an account, we collect your name, email address, and a password (stored only in hashed form — we cannot see your password). If you sign in with a third-party provider (such as Google), we receive the email address and profile information that provider shares with us.
Project information. When you submit a research project, we collect the information you provide about the person or family you’re researching. This typically includes names, approximate dates, places, family relationships, and any context you share to guide the research. You may also upload documents such as certificates, photographs, prior research reports, or family trees. Everything you upload is stored privately in your account.
Research outputs. We generate and store the research deliverables we produce for you — record images we locate, transcriptions, translations, written narratives, family charts, and maps. These are stored in your account for as long as your account is active.
Payment information. When you purchase a project, payment is processed by Stripe, Inc. We do not receive or store your full credit card number. We retain a transaction record (amount, date, last four digits of the card, and Stripe’s transaction ID) for accounting, tax, and refund purposes.
Technical information. Our hosting provider logs standard web server data when you visit the Service — IP address, browser user-agent, request timestamps, and pages visited. This information is used for security, debugging, and aggregate usage analysis. We do not use third-party analytics or advertising trackers.
2. What we do with it
We use your information to:
- Operate the Service — authenticate your account, process your projects, and deliver research reports to you
- Conduct genealogical research on your behalf using the information you provide
- Send you transactional messages about your projects (order confirmations, research completion notifications, billing notices, and responses to support requests you initiate)
- Process payments through Stripe
- Detect and prevent fraud, abuse, and violations of our Terms of Service
- Improve the Service by analyzing aggregated, de-identified usage patterns
What we do not do:
- We do not sell your personal information to third parties
- We do not share your project data with other users
- We do not use your personal family information for advertising
- We do not publish research results or family information without your explicit consent
- We do not send marketing emails unless you opt in
3. Who else sees your information
We use a small number of service providers to operate the Service. Each has access to only the data necessary for their specific function, and each is contractually required to protect it:
- Supabase, Inc. — database, authentication, and file storage
- Anthropic, PBC — AI models used in the research pipeline (project inputs may be processed through Anthropic’s API as part of delivering your research)
- Vercel Inc. — web hosting and deployment infrastructure
- Stripe, Inc. — payment processing
These providers process data on our behalf under written agreements and do not use your personal information for their own purposes. We do not sell, rent, or trade your personal information to any third party.
We may disclose information if we believe in good faith that disclosure is required to comply with a valid legal process, protect the rights or safety of users, or enforce our Terms of Service. When legally permitted, we will notify you of such requests.
4. How long we keep your data
We keep your account information and research outputs for as long as your account is active. You can delete individual uploaded documents from your dashboard at any time, and delete your entire account from account settings.
When you delete your account:
- Your account record, project data, uploaded documents, and research outputs are deleted from the production database immediately
- Backups that may contain your data are purged within 30 days as part of our standard backup rotation
Certain records must be retained longer for legal or accounting reasons — for example, transaction records for tax purposes. We retain these only as required by law and only in limited form (typically: user ID, amount, date, no personal family content).
5. A note about what you share with us
Please do not include personal identifying information for yourself or living relatives in your project submissions. Information such as Social Security numbers, current addresses, driver’s license numbers, bank account numbers, or government ID numbers is not needed for genealogical research and should not be uploaded.
Our research focuses on historical records — typically ancestors who are no longer living. We do not need personal identifying information for any living person to perform our work.
If we discover that you have uploaded sensitive personal information that is not needed for research, we may ask you to remove it or, if the information poses a clear risk, remove it ourselves and notify you.
6. Your rights
You have the following rights regarding your personal information:
- Access. You can view and download your project data and research outputs from your account dashboard at any time.
- Correction. You can update account information directly from settings. Contact us for corrections to research outputs.
- Deletion. You can delete uploaded documents from your dashboard and delete your entire account from settings. For deletion requests that can’t be self-served, email privacy@historicaly.com.
- Portability. You can download your research outputs as PDF files from your dashboard. Raw project data can be exported on request.
- Objection and restriction. You can object to or restrict certain uses of your data by contacting us.
California residents (CCPA): You have the right to know what personal information we have collected about you, the right to delete it, the right to correct inaccurate information, and the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. We do not sell or share personal information for advertising, but the right to opt out is available to you regardless. We will not discriminate against you for exercising these rights.
EU/UK residents (GDPR): Your rights include the above, plus the right to lodge a complaint with a data protection authority. Our legal basis for processing your data is either (a) performance of the contract you entered into when you purchased a project, (b) your consent (for optional features you opt into), or (c) our legitimate interests in operating and improving the Service, balanced against your rights.
To exercise any right, email privacy@historicaly.com. We will respond within 30 days.
7. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete it.
Users aged 13–17 may use the Service with parental or guardian consent. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact privacy@historicaly.com.
8. Security
We protect your data with industry-standard security practices: passwords are hashed (bcrypt), data is encrypted in transit (TLS), our database and storage are hosted on Supabase with access controls and audit logging, and administrative access to production systems is restricted and logged.
No system is perfectly secure. If we become aware of a data breach affecting your information, we will notify you within 72 hours of confirming the breach, as required by applicable law.
9. International transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States. Our service providers (Supabase, Anthropic, Vercel, Stripe) may process data in their respective jurisdictions. For EU/UK residents, we rely on Standard Contractual Clauses and other approved transfer mechanisms.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address on your account) and post a notice on the Service at least 30 days before the changes take effect. Non-material changes (clarifications, typo fixes) may be made without notice, with the “Last updated” date reflecting the change.
11. Contact
For any questions about this Privacy Policy, your data, or to exercise your rights:
Email: privacy@historicaly.com Mailing address: [COMPANY ADDRESS — to be added after LLC formation]
Historicaly LLC Wyoming, USA