Privacy Policy
What we collect, why we hold it, who can see it, and what you can do about it — written for a platform where much of the data is about someone other than the person who entered it.
Last updated
1. Who we are and what this covers
World Ancestry is a collaborative genealogy platform operated by Valleon Technologies. This policy explains what personal data we collect through our website and applications, why we hold it, who can see it, and what you can do about it.
Genealogy is unusual among online services in one important way: much of the data on this platform is about people other than the person who entered it, including people who are deceased and people who have not yet joined. We have written this policy to be explicit about that rather than to gloss over it.
For the purposes of the UK GDPR and EU GDPR, Valleon Technologies is the data controller for account data and for the operation of the platform. Where you build a family record, you are the source of that content and we process it on the terms set out here.
2. What we collect
Account data
Your name, email address, phone number (if you provide one), password (stored only as a salted hash — we never hold the password itself), authentication tokens, and the record of whether your email or phone has been verified.
Profile and family data
The information you enter about yourself and about relatives: names and alternate names, dates and places of birth and death, gender at birth, marital status, life status, biography, occupations, education, traditional and professional titles, languages, hobbies, citizenships, social profile links, and the relationships connecting people to one another.
Special category data
Some fields the platform offers are, in data protection law, special category personal data requiring a higher standard of care: ethnicity, race, religion, blood group and genotype. These fields exist because they are genuinely part of family and medical history for many of our users, but they are always optional. We ask for your explicit consent before you enter any of them, and the fields are not shown to you until you give it. You can withdraw that consent at any time from your privacy settings, which deletes the data straight away.
Recording these fields about a living relative is different: they, not you, are the person the data is about, and only they can truly consent to it. We ask you to confirm that they asked you to record it, and we keep a record of that confirmation — but please think carefully before entering anything a relative has not asked you to. Blood group and genotype are also kept in their own Health privacy section, which starts Private and stays Private unless you deliberately change it, so making a profile public never publishes them.
Media
Photographs, video, audio recordings and documents you upload, together with any caption, title or description, and the technical metadata of the file. Media is stored with our media hosting provider rather than on our own servers.
Messages and notifications
The content of messages you send to other members through the platform, and the record of notifications generated for you. Messages are not end-to-end encrypted: they travel over an encrypted connection and are stored on encrypted infrastructure, but we are technically able to read them, and we will do so only where we must for safety, abuse or legal reasons. Treat a message here as private from other members, not as private from us.
Verification and dispute records
Evidence you attach to support a relationship or a profile, the disputes you raise or that are raised against records you contributed, and the outcome recorded by a reviewer.
Technical and usage data
IP address, device and browser information, pages viewed, profile view counts, and security logs including sign-in attempts and administrative actions taken on your account.
3. Why we hold it, and our lawful basis
- To provide the service — creating your account, building and displaying family trees, matching relatives, delivering messages. Lawful basis: performance of our contract with you.
- To keep the platform safe and accurate — verification, dispute handling, moderation, fraud and abuse prevention, security logging. Lawful basis: our legitimate interests in running a trustworthy platform, balanced against your rights.
- To record special category data (ethnicity, race, religion, blood group, genotype). Lawful basis: your explicit consent, which we ask for before you enter any of these fields and which you may withdraw at any time from your privacy settings. Withdrawing deletes this data immediately rather than at the end of any grace period.
- To send service email — verification codes, password resets, relationship requests, notifications you have opted into. Lawful basis: performance of our contract, and consent for anything optional.
- To meet legal obligations — responding to lawful requests, keeping records we are required to keep. Lawful basis: legal obligation.
4. Who can see what
Visibility is set per section of a profile, not once for the whole thing. A profile can be public while its contact details are restricted to confirmed family, and its medical fields visible to nobody but you.
- Public — visible to anyone, including people who are not signed in, and potentially indexed by search engines.
- Connections — visible to members you are connected to on the platform.
- Family — visible to people with a confirmed relationship to the person.
- Private — visible only to the profile owner and, where applicable, its creator.
Living people are treated more cautiously than the deceased. Profiles of people recorded as living are restricted by default, and details of living people are withheld from anonymous visitors regardless of the tree they appear in.
You can also share an individual profile through a time-limited link. Those links expire, and you can revoke one at any time from the profile it belongs to.
5. Recording data about other people
You may add a relative who does not have an account. That creates a profile they can later claim as their own. When they claim it, they gain control of it — including the ability to correct it, restrict its visibility, or ask for it to be removed.
Before you add detail about a living relative, please consider whether they would want it recorded. Contact details, medical fields, religion and ethnicity about a living person who has not asked you to record them are the categories that most often cause harm, and we would rather you left them blank.
If a profile about you exists and you did not create it, you can claim it, or you can write to us at privacy@worldancestry.net and we will act on it.
6. Data about deceased people
Data protection law in most countries does not apply to the deceased, and a genealogy platform could not function if it did. We still apply judgement: recently deceased people are treated with more care than distant ancestors, and we will remove or restrict a record at the reasonable request of a close relative, particularly where a cause of death, medical detail or a photograph of the deceased is involved.
8. International transfers
World Ancestry is used across many countries and our infrastructure providers operate globally, so your data may be processed outside the country you live in. Where data leaves the UK or European Economic Area, we rely on an adequacy decision where one exists, and on Standard Contractual Clauses with the receiving provider where one does not.
9. How long we keep it
- Account data — for as long as your account is open. When you ask us to delete your account we deactivate it immediately and erase it 30 days later, apart from anything we must retain by law. We keep your details during those 30 days for one reason: so that reactivating brings your profile back as you left it. If we erased on the first click, the reactivation window would only be about your login, not your data. Nothing is visible to anyone else in the meantime.
- Family records you contributed — these usually outlive the account that created them, because other relatives depend on them. When you close your account, your authorship is anonymised: the records remain, but they are no longer attributed to you. Your own profile is anonymised rather than deleted outright, for the same reason — the relationships that connect other people's records to it have to survive.
- Messages — kept for as long as the conversation exists. When you close your account your messages stay, but they stop being linked to you and show as sent by an anonymised member. We do not blank them, because the conversation belongs to the person you were talking to as much as it does to you.
- Media you uploaded — deleted from us and from our media provider when your account is erased.
- Audit records — the log of administrative actions taken on accounts and records is kept for 12 months, then deleted automatically. Sign-in and other security events are written to our infrastructure logs, which our hosting providers rotate on their own schedules.
- Backups — deleted data persists in encrypted backups for up to 35 days before those backups rotate out.
10. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — get a copy of the personal data we hold about you. You can download it yourself, immediately, from Settings → Your Data.
- Rectification — correct data that is wrong. Most of this you can do yourself from your profile.
- Erasure — ask us to delete your data, subject to the retention rules above.
- Portability — receive your data in a structured, machine-readable format. The download in Settings → Your Data is JSON, covering your account, your own profile, your relationships, and the consents and document versions you have agreed to.
- Restriction and objection — ask us to stop a particular kind of processing, including anything we do on the basis of legitimate interests.
- Withdraw consent — for anything we do on the basis of consent, including special category fields.
- Complain — to your data protection authority. In the UK that is the Information Commissioner's Office.
To exercise any of these, use the tools in your settings or write to privacy@worldancestry.net. We respond within 30 days.
11. Security
Traffic is encrypted in transit with TLS. Passwords are stored as salted hashes. Authentication uses short-lived tokens. Access to production data by our staff is limited to those who need it and is logged. Administrative actions on accounts and records are written to an audit trail.
No system is perfectly secure. If a breach occurs that is likely to affect your rights, we will notify you and the relevant regulator within the timescales the law requires.
12. Children
You must be at least 13 to hold a World Ancestry account. We ask for your date of birth when you sign up and we do not create accounts below that age. Children frequently appear within family trees, as they must — but a child's profile is restricted by default, and we will act promptly on a parent or guardian's request to remove or restrict one.
14. Changes to this policy
When we change this policy we update the date at the top of the page. For changes that materially affect your rights or how we use your data, we will notify you by email or in the application before the change takes effect.
Questions about this policy, or want to exercise a right? Email privacy@worldancestry.net or use the contact form.
