Privacy Policy
Last updated: 4 September 2026. This is how our private family archive handles family data. It is not a public SaaS privacy notice. Creating a login means you have read and accepted this policy and the Terms of Service.
1. What this archive is
A private genealogy and family-records site for invited Seignemartin relatives — including people who no longer carry the name. Content sits behind family login. Search engines should not index the archive (robots: noindex). There is no public tree.
2. Data we store
- Account details: username or email, display name, role, password hash, and when you accepted these legal pages
- Person records: names, dates, places, notes, relationships, verification status
- Claims, comments, feedback, invites, and change history
- Media files and optional transcripts in private object storage (Firebase Storage / GCS) or local
data/uploadsduring migration - Optional Google (or later Apple) identifiers if you use that sign-in
Archive storage is Google Cloud Firestore (project seignemartin-chronicle) with private media in Cloud Storage. Media is not served from a public CDN — downloads go through signed-in API routes. Domain DNS for seignemartin.com stays at GoDaddy; the app runs on Firebase App Hosting.
3. Living-person defaults
Living relatives are identity-hidden by default from ordinary members. Without an opt-in, other members typically see a placeholder photo, optional location, and that children exist — not real names or identifying photos. Deceased relatives are generally visible to signed-in family for names and media contribution.
4. Who can see what
- Owner (me) — full visibility for stewardship, verification, invites, import/export, and moderation
- Moderator — can verify and edit, review claims, import/export, and see living identity as needed for moderation
- Member — sees deceased records and living identity only when shared; may invite others (not as moderator); may add media to deceased people
Search is built so hidden living names do not leak into another member’s results.
5. Sign-in
Primary login is email or username and a password. Google sign-in is optional when I have enabled it, and only for an invited family email. Apple may be added the same way later. Facebook is not supported and will not be added. If you use Forgot password, we email a one-time reset link to the address on your family account (when mail is configured). We do not say whether a login exists.
6. Public sources
When a person is added, the archive may query public sources (for example Wikidata, Wikipedia, Wikimedia Commons, and open-web search for pages that name this person) for candidate photos, links, and facts. Those suggestions stay pending until a family member accepts or rejects them. People-finder or address scrapers are not offered. Rejected items need a written reason and are audited. Accepted media is copied into the private library.
7. Sharing outside the family
Do not export or forward living-person details outside the invited family without a clear family need and respect for privacy defaults. Owner and moderator GEDCOM and media export is for family backup and research continuity, not public publication.
8. Retention and control
I may remove accounts, revoke access, revert imports, and delete or correct records. If you want your login closed or a living record hidden, contact me. Origin remains the code source of truth.
9. Contact
Privacy questions for this private archive come to Justin (owner). See also the Terms of Service.