Privacy Policy
The short version. We do not sell your information. We do not show advertising. We run no analytics or tracking of any kind — there is no Google Analytics, no advertising pixel, and no cross-site tracking in this product. Most of the information in AncestorOS is information you record about other people, and Section 4 explains what that means for you and for them.
1. Who We Are
AncestorOS is operated by Commoner Apps LLC, a United States limited liability company. Commoner Apps LLC is the business responsible for the information described here.
Privacy questions and requests: privacy@ancestoros.com.
2. Scope of This Policy
This policy covers the AncestorOS website and application. It does not cover third-party sites we link to, or records repositories you visit from within the product.
Geographic scope. AncestorOS is operated from the United States and is intended for users in the United States and Canada. We do not target the Service to individuals in the European Economic Area, the United Kingdom, or Switzerland. We have not appointed a representative under Article 27 of the UK or EU GDPR, and we do not offer a data processing agreement or standard contractual clauses. If you are subject to those regimes and require that framework, AncestorOS is not a suitable product for you. We would rather tell you that plainly than claim a compliance posture we do not operate.
3. Information We Collect
3.1 Information you give us about yourself
When you create an account: your first and last name, email address, and password. Passwords are handled by Google Firebase Authentication and are stored as salted hashes; we never see your password.
During setup and in settings, if you choose to provide them: display name, professional title, business name, specialty, website, hourly rate, preferred currency, and a research goal. Your browser's time zone is captured automatically to display dates correctly.
If you subscribe: billing records including your Stripe customer and subscription identifiers, plan, billing interval, subscription status, and current period end. We never receive or store your card number. Card details are collected by Stripe on Stripe's own pages.
If you configure your own outgoing mail server (Professional plan): the host, port, from-address and password you supply. That password is stored unencrypted in your account record so it can be used to send on your behalf. Only you can read your own account record. We recommend using a provider-issued app password rather than your primary mail password, and revoking it if you stop using the feature.
If you contact us through the website form: your name, email address, category, subject, and message.
3.2 Information you create in the product
Everything you record: people and their names, dates, places, occupations, biographies and notes; relationships; memories and stories; photographs and their captions, tags and dates; scanned documents and any text extracted from them; timeline events; research logs, citations, evidence records, obituaries, newspaper clippings, burial and cemetery records; research tasks and queues; DNA test and match records; and a change history of edits you make to person records.
On the Professional plan, additionally: your clients' names, email addresses, phone numbers, postal addresses and notes; projects; invoices and their amounts and terms; time entries; expenses and receipts; and appointments.
3.3 Information collected automatically
Because we run no analytics, this is a short list. Our hosting provider records ordinary web server logs, which include IP addresses, and our application error log may record an email address or account identifier when an error occurs. Rate-limiting records a one-way hash of the IP address of contact-form submissions. We do not build profiles, and we do not track you across sites.
3.4 What we do not collect
We do not ask for your date of birth, government identifiers, or financial account numbers. We do not collect precise device location from your browser: the product contains code to request it, but the site's own security headers disable that capability, so any coordinates in your account are ones you typed yourself.
4. Information About Other People
This is the most important section in this policy, and the one most privacy policies for genealogy products skip.
Most of the information in AncestorOS is not about you. It is information you record about relatives, ancestors, DNA matches, research subjects and, on the Professional plan, your own clients. Many of those people are living. They are not our users, they have no account, and in most cases they have not been asked.
Our role. For that information we act as a custodian on your behalf. You decide what to record, whether it is accurate, whether you are entitled to hold it, and whether to publish it. We do not independently verify any of it and we do not contact the people it describes.
Your responsibility. Section 8 of the Terms of Service sets out what you promise us when you record information about another person. In short: that you may lawfully hold it, and that you will exercise judgement before publishing anything about a living person.
Their rights. A living person described in someone's tree can contact us at privacy@ancestoros.com. What we can and cannot do for them is set out in Section 13 and in the Living Persons and Third-Party Information Policy.
5. Sensitive Information
Genealogy records touch categories of information that are treated as sensitive under various laws. Here is precisely what exists in AncestorOS.
DNA and genetic information. AncestorOS does not accept raw DNA files. There is no upload for genotype, SNP, or sequence data, and none is stored. What you can record is match information you copy from a testing service: the match's name or handle, the testing company, a kit number, centimorgans shared, segment count, and a predicted relationship. That is still genetic-relationship information about an identifiable person, and several state statutes treat it as sensitive, so we handle it as sensitive. We do not sell it, share it, or use it for any purpose other than displaying it to you. There is no ethnicity or admixture feature in the product.
Racial or ethnic origin. The document transcription screen includes a "race" field, because historical records such as census returns and death certificates frequently record it. This field may be filled in automatically from a document you submit to the transcription feature, as well as typed by you. If you do not want that recorded, clear the field before saving.
Religious information. There is no religion field. However, importing a GEDCOM file records sacrament events such as baptism, christening, confirmation and burial where the file contains them, and burial records include cemetery names. These can indicate religious affiliation.
Health information. There is no medical, cause-of-death, diagnosis, or health field anywhere in the product. Free-text notes could of course contain anything you type. AncestorOS is not designed for health information and is not a HIPAA-covered service.
Children. Family trees routinely include living children, with birth dates and birthplaces. See Section 14.
Location. Burial records and research logs can store latitude and longitude that you enter.
Photographs. You can tag a person in a photo by drawing a box and choosing them from a list. This is manual tagging only. There is no facial recognition in AncestorOS. We do not compute, store, or derive faceprints, templates, or biometric identifiers of any kind.
Not present. There are no fields for sexual orientation, political opinions, trade union membership, disability, or criminal history.
6. How We Use Information
- To provide the Service: storing your records and displaying them back to you.
- To authenticate you and keep your account secure.
- To process subscription payments and send billing-related messages.
- To respond to support and privacy requests.
- To send transactional messages such as email verification, password reset, and a welcome message.
- To operate features you actively invoke, such as document transcription or generating a share link.
- To detect and prevent abuse, fraud, and security incidents, including rate limiting.
- To comply with law and to establish, exercise, or defend legal claims.
We do not use your family history content to improve or develop the product beyond providing it to you, and we do not use it to train machine-learning models.
7. What We Do Not Do
These statements describe the product as built, and we intend to keep them true. If any of them ever ceases to be true, we will say so in this policy before the change takes effect.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California and other state privacy laws.
- We run no analytics. There is no Google Analytics, no Firebase Analytics, no product-analytics tool of any kind. A Google measurement identifier appears in our configuration file but the analytics library is never loaded, so it collects nothing.
- We display no advertising and embed no advertising or social media tracking pixels.
- We set no cookies of our own. See Section 16 and the Cookie Policy.
- We do not share your family history with other users unless you publish a share link yourself.
- We do not use your content to train AI models, and our AI provider is engaged on terms that do not permit it either.
8. Service Providers
We use the following third parties to run the Service. Each receives only what it needs.
| Provider | What it receives | Why |
|---|---|---|
| Google (Firebase) | Your account credentials and all content you store: the family tree, photographs, documents, and Professional-plan records | Authentication, database, file storage |
| Stripe, Inc. | Your email address, an account identifier, plan and interval. Card details go directly to Stripe and never reach us | Subscription payments |
| Anthropic, PBC | Only when you use an AI feature: the document image you submit, or a short summary line of a person's name, dates and places. See Section 9 | Document transcription and research assistance |
| Twilio SendGrid | The recipient address and full contents of emails we send | Transactional email |
| Hostinger | Web server traffic and application error logs | Hosting the application layer |
| OpenStreetMap Foundation | Place names you have recorded, sent as geocoding queries, plus your IP address, when you open the map | Converting place names to map positions, and map tiles |
| Google Fonts and gstatic | Your IP address and browser details on page load | Typefaces and application libraries |
| unpkg and Quill CDN | Your IP address on the map, cemetery, and memory pages | Delivering mapping and text-editor libraries |
| PayPal, Venmo, Block (Cash App) | Only an invoice amount and reference, and only if a Professional user publishes such a payment link and a recipient clicks it | Payment links the user chooses to offer |
| Your own mail provider | Recipients and message contents, if you configure your own outgoing mail server | Sending mail as you |
We may also disclose information: to comply with a law, subpoena, or lawful request; to enforce our Terms; to protect the rights, safety, or property of any person; and to a successor entity in a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different policy.
9. AI Processing
Three optional features use Anthropic's API: document transcription, research suggestions, and historical background.
Transcription sends the document image you upload, which may be a census page, death certificate, or military record containing personal details about several people. Research suggestions and historical background send only a short derived line: a person's name, birth and death years and places, and occupation.
These features never send DNA records, client or invoicing data, email addresses, or your account identifier. We do not log AI prompts or responses. Requests are made server-side so that our credential is never exposed to your browser.
These features are optional and the product is fully usable without them. If you would rather no document ever leave our infrastructure, do not use the transcription feature.
10. Sharing and Public Links
Share links. You can generate a link that lets anyone holding it view a read-only snapshot of your tree without signing in. Understand what that means:
- The link contains a long random token. It is not guessable, but anyone you give it to can pass it on, and it may be saved, forwarded, or indexed if you post it publicly.
- The snapshot contains, for each included person: name, birth date and place, death date, gender, occupation, whether they are marked living, and their photograph. It does not contain memories, documents, notes, biographies, relationships, DNA records, or Professional-plan data.
- It also shows your display name as the owner of the tree.
- Living people are excluded while the "hide living people" setting is on, which is the default. If you turn it off, living relatives are published with the fields listed above.
- A snapshot is a copy taken at a moment in time. Editing or deleting someone in your tree does not change an existing snapshot until you refresh it.
- Links do not expire on their own. Revoke a link from the Sharing page when you no longer want it to work.
- Photographs are an exception you should understand. Image files are served from a long, unguessable storage URL. Once such a URL has been included in a published snapshot, anyone who obtained it can continue to reach that image directly even after you revoke the link. To be certain an image is no longer reachable, delete the photograph itself.
Invitations. You can email an invitation to a family member. The invitation contains your display name and a link, and no tree data. Shared editing is not yet available: an accepted invitation does not currently give anyone access to your tree.
Invoices. On the Professional plan, an invoice you mark as sent can be opened by anyone who has its link, so that a client can view it without an account. Such an invoice shows the invoice number, amounts, dates, your terms and notes, and any payment instructions you configured, which may include bank or payment-handle details you entered. Your client list itself is never publicly readable. Do not put anything in invoice notes that you would not want a recipient to forward.
11. Retention and Deletion
While your account is open, we keep your content until you delete it. There is no automatic expiry.
Deleting individual records removes them. Note that the edit history feature retains previous values of person fields you have changed, so a corrected entry may persist in that history until the person record itself is deleted.
Closing your account (Settings → Delete Account) cancels any active subscription, then deletes your family history and Professional records, your uploaded files, and your published tree snapshot, and finally your login. This is permanent and we cannot restore it. Export anything you want to keep first.
What survives account deletion, stated plainly:
- Messages you sent us through the website contact form, which we keep as business correspondence.
- Records held by Stripe, including payment history and invoices, under Stripe's own retention obligations. We cancel the subscription; we cannot erase Stripe's financial records.
- Server and error logs, which may contain an email address or account identifier, for a limited period.
- Copies in routine backups until they age out.
- Any image whose storage URL was previously published, as explained in Section 10.
- Anything a third party downloaded, exported, or copied while it was shared with them. We cannot reach into someone else's copy.
- Information we are required to retain by law or to resolve a dispute.
12. Your Choices and Rights
Wherever you live, you may:
- Access and correct your information directly in the product at any time.
- Export your people and relationships as a GEDCOM file from the Export page. Please note this format covers your tree; it does not include memories, photographs, documents, DNA records, or Professional-plan data. If you need a copy of something not covered, email us and we will help.
- Delete individual records, or your entire account, from Settings.
- Cancel your subscription from Billing at any time.
- Ask us questions about what we hold and why, at privacy@ancestoros.com.
We aim to respond to requests within 30 days. We may need to verify your identity, usually by confirming control of the account email address. We will not charge you for a reasonable request or treat you differently for making one.
Email preferences. We send only transactional messages: email verification, password reset, billing notices, and a welcome message. We do not operate a marketing list. If we ever introduce one it will be opt-in, and every message will carry an unsubscribe link.
13. If You Are Not a User
If you have found that information about you is held in someone's AncestorOS tree, contact privacy@ancestoros.com.
We will be straightforward about what we can do. We can identify and disable a published share link, remove specific content where it is unlawful or presents a risk of harm, and pass your request to the account holder. What we generally will not do is silently alter or delete the private research files of an account holder at the request of a third party, because we cannot adjudicate competing family claims about who is entitled to record what, and because doing so would itself require us to examine private records.
The full process, including what information to include and how we handle disputes, is in the Living Persons and Third-Party Information Policy.
14. Children
Account holders. AncestorOS is not directed to children under 13 and we do not knowingly allow anyone under 13 to register. Account holders must be 18 or older to subscribe; a person aged 13 to 17 may use an account only under the supervision of a parent or guardian who holds it. If you believe a child under 13 has registered, contact privacy@ancestoros.com and we will close the account and delete the data.
Children recorded in trees. This is a different matter, and we want to be clear about it. Family trees commonly contain living children, including their names and birth dates, entered by an adult relative. We do not collect that information from the child and have no relationship with them. If you record information about a child who is not your own, consider whether the parent or guardian would agree, and use the "hide living people" setting before publishing anything. A parent or guardian may contact us under Section 13.
15. Security
What we actually do:
- All traffic is encrypted in transit with HTTPS, enforced by redirect and by a strict transport security policy.
- Data at rest in Google Firebase is encrypted by Google as a platform default.
- Access rules are enforced server-side, so every record is readable only by the account that owns it, regardless of what a browser asks for.
- A content security policy, clickjacking and content-type protections, and a restrictive permissions policy are applied to every page.
- Rate limits apply to sensitive operations such as AI requests, email sending, invitations, and the contact form.
- Every request to our own endpoints verifies your login token server-side.
- Card details never reach our systems.
- The edit history log cannot be altered.
What we do not do, stated so you can make an informed decision:
- We do not offer multi-factor authentication.
- We do not apply application-level or field-level encryption beyond the platform default; your outgoing-mail password in particular is stored unencrypted.
- We hold no SOC 2, ISO 27001, or comparable certification, and have not commissioned an independent penetration test.
- We do not operate intrusion detection or a web application firewall.
- Data cached on your own device is not encrypted by us. See Section 16.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law, without undue delay. Report a suspected vulnerability to security@ancestoros.com.
16. Storage on Your Device
AncestorOS sets no cookies of its own. It does keep data in your browser's local storage, and it keeps an offline copy of your records in the browser's database so the application works when your connection drops. That offline copy can include your whole family tree and, on the Professional plan, client and invoice records. It is not encrypted by us and it stays on the device until the browser's data is cleared. On a shared or public computer, sign out and clear site data when you are finished.
The Cookie Policy lists every key we store and what it holds.
17. Location of Data
Commoner Apps LLC operates from the United States, and our hosting and service providers are principally located there. Your information is processed in the United States. Some providers, such as the mapping and font services described in Section 8, are reached from wherever you are and may process a request in another country.
If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws differ from those of your own country. As stated in Section 2, we do not offer the transfer safeguards required by European or United Kingdom data protection law.
18. United States State Privacy Rights
Several states give residents specific rights. Regardless of whether a given law applies to us, we extend the following to every user: the right to know what we hold, to obtain a copy, to correct it, to delete it, and to be free from discrimination for exercising those rights. Exercise them as described in Section 12, or by emailing privacy@ancestoros.com.
California. For the purposes of the CCPA as amended by the CPRA, the categories of personal information we have collected in the last 12 months are: identifiers (name, email address, account identifier); commercial information (subscription and payment records); internet activity limited to server logs; approximate location only where a user has typed coordinates; and, within user-created content, sensitive personal information as described in Section 5. The business purposes for collection are those in Section 6, and the categories of recipients are in Section 8.
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months, and we do not do so now. We therefore do not offer a "Do Not Sell or Share My Personal Information" link, because there is nothing to opt out of. We do not use or disclose sensitive personal information for any purpose other than providing the Service, so no limitation right arises. You may designate an authorised agent to make a request; we will ask for proof of authorisation.
Genetic privacy. Several states regulate genetic and DNA-related information specifically. We do not accept raw genetic data, we do not sell or share DNA match information, we do not disclose it to insurers, employers, or law enforcement except where legally compelled, and we delete it when you delete the record or your account.
Nevada. We do not sell covered information as defined by Nevada law.
19. Changes
We may update this policy. When we do, we will change the "Last updated" date. If a change materially reduces your privacy protections or expands how we use your information, we will give notice at least 14 days beforehand by email, where we have a working address for you, and by prominent notice in the product. Continuing to use the Service after the effective date means you accept the updated policy.
20. Contact
Commoner Apps LLC
United States
Privacy and data requests: privacy@ancestoros.com
General support: support@ancestoros.com
Security reports: security@ancestoros.com
Legal notices: legal@ancestoros.com