Privacy policy
What Geneacta records, why, for how long, and what you can demand of us. Written to be read, not to be signed unread.
Last revised: 2026-08-01
Who processes your data
Geneacta, operated by Tony Renard (Belgium). Any question about your data: contact@geneacta.com.
The applicable regulation is the GDPR (EU regulation 2016/679).
What you entrust to us
Your account: e-mail address, password (never stored in clear — only a hash is), optional username, optional photograph.
Your tree: the people, dates, places, records, images and notes you enter or import. This data may concern third parties, including living people — see below.
Your public contributions: forum posts, wiki pages, guides, transcribed records, open puzzles, reviews.
Nothing else. Geneacta buys no data, sells none, and does no advertising profiling.
The living people in your tree
This is the most delicate point of any genealogy site, and it is handled by DESIGN rather than by a setting.
A person whose death is not known NEVER enters the public index that other members can search — not in your tree, not in anyone's. This is not a filter applied to the search — a filter gets forgotten in a condition — it is data that is never written.
A tree hosted on Geneacta is findable by other members — but ONLY people who can be taken as deceased appear in it: those with a known death, those born more than 150 years ago, and those with a child born more than 100 years ago. A living contemporary never enters the public index.
You may withdraw a whole tree from the search at any time; its projected rows are then erased. In return you no longer search other members' trees: the index is shared, and one does not draw from it without contributing.
You remain responsible for third-party data you enter. If a living person asks you to remove their data, do so, or write to us.
Why we process this data
Performance of the service you ask for (GDPR article 6.1.b): keeping your tree, authenticating you, sending you the indispensable e-mails.
Legitimate interest (6.1.f): site security, abuse prevention, aggregate audience measurement.
Consent (6.1.a): for AI-written stories, which you trigger explicitly and case by case.
Who else sees this data
Hosting: Vercel (application) and Supabase (database and files), both configured on servers located in the European Union.
E-mail: Resend, for address verification and notifications.
Payment: Stripe. No banking data passes through Geneacta or is stored by it — the payment page is hosted by Stripe.
AI stories: Anthropic, and ONLY the facts of the people you tick, at the moment you start the writing. The dossier sent is kept alongside the text produced, so that everything can be checked.
Audience measurement: Umami. It counts page views, with no cookie and no lasting identifier — so it cannot recognise you from one visit to the next. Like any script loaded from another domain, it does see your IP address for the duration of the request; Umami turns it at once into a daily hash and does not keep it.
No other recipient. No ad network, no data broker, no social media button that follows you.
For how long
Your account and your tree: as long as the account exists.
Sessions: thirty days, then automatic expiry.
A suspended account is kept without access: its contributions remain attributed and the sanction remains reversible. It is not deleted, and that is deliberate.
On a deletion request, your account and trees are erased within thirty days. Your public contributions may remain, detached from your identity, so as not to punch holes in discussions others have replied to.
Your rights
Access, rectification, erasure, restriction, objection, portability.
Portability is immediate and requires no procedure: the export button gives you your whole tree back in the open .genea format, and in GEDCOM. Whatever those formats cannot write is reported to you rather than lost in silence.
For the other rights, write to contact@geneacta.com. Answer within one month.
You may also complain to the Data Protection Authority (Belgium) or to the authority of your country of residence.
Security
Encrypted connections (HTTPS), passwords stored as salted hashes, sessions with random tokens.
The files you upload — records, photographs — live in private buckets, served through signed links of limited duration, never through a guessable public URL.
The database is reachable only by the application. No public interface opens onto it.
