KinWeave is a family-tree service. This policy explains what we collect, how we use it, access limitations, and the choices you have.
Your family data belongs to you. We do not sell it. Access controls are intended to limit viewing to owners and invited guests.
We only process the data we need to run the service you asked for: showing your tree, answering your history questions, and billing you if you upgrade.
You can print a chart or directory and use your browser to save it as PDF. Whole-tree GEDCOM export and self-service account deletion are not available; contact us for data access or deletion requests.
Earlier releases included legacy family records in public frontend files. On October 7, 2026, we removed 57 older deployments, blocked anonymous reads of legacy edit records, made uploaded-photo storage private, and revoked the publicly exposed invitation. We cannot recall copies already downloaded.
KinWeave (“we”, “us”) is the operator of kinweave.net and the data controller for the information described here.
Questions about privacy? Write to [email protected].
Account data: your email address and authentication credentials managed by Supabase. We cannot view your plaintext password.
Family data you create or import: names, dates, places, relationships, occupations, notes, supported GEDCOM/JSON imports, and uploaded photographs.
AI historian questions: the questions you type, recent conversation messages, and a compact representation of the active tree, including names, relationships, dates, places, occupations and selected notes.
Billing data (only if you subscribe): handled entirely by Stripe. We store a subscription reference and status — never your card number.
Minimal technical data: standard server logs and the browser storage described under “Cookies” below. We do not run third-party advertising or cross-site tracking.
To provide the service: build and display your tree, run search, retain existing photos and supported edit revisions, and prepare printable charts and directories.
To power the AI historian: when you ask a question, we send recent conversation messages and a compact representation of the whole active tree to Anthropic. Short record identifiers do not anonymize names or family details. Avoid using the assistant for information you do not want sent to this provider.
Anthropic states that commercial API inputs and outputs are not used for model training by default, subject to its policy and any explicit data-sharing choices. Provider retention is governed by its applicable terms; we do not promise zero retention. Policy: https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training.
To handle billing and support, secure the service, and comply with the law.
Supabase — authentication, database-backed trees, edit revisions and uploaded-photo storage.
Cloudflare — hosting, legacy tree/media delivery, content delivery and network security for kinweave.net.
Stripe — payment processing for subscriptions.
Anthropic — the AI model that answers your history questions.
These providers process data needed for the service. We do not sell your data or share it with advertisers or data brokers. Data may also be disclosed when required by law or necessary to address a security incident.
Database-backed trees and edit records use ownership policies. The legacy tree and its bundled photos require server authorization. Uploaded photographs are stored in a private bucket and displayed through signed links that expire after five minutes.
Invitation links provide read-only access to a tree. Anyone who obtains a valid link can view the shared content. Redeeming an invitation creates a guest session lasting up to 24 hours, capped by the invitation expiry. Owners can revoke their invitations and stop new reads by issued guest sessions. Revocation cannot remove copies a recipient already saved.
KinWeave does not offer a public tree directory. That does not establish that every historical deployment or previously shared copy is inaccessible or absent from search indexes.
Data is transmitted over encrypted connections (HTTPS/TLS) and stored on Supabase and Cloudflare infrastructure, which may process data in the United States and the European Union.
We use ownership checks, invitation validation and row-level policies. Revocation prevents new invitation access. Photo links issued before revocation can remain usable until their five-minute expiry; saved copies cannot be recalled. Signing out clears local access state, but an access token may remain valid until it expires.
Access & export: print supported charts/directories or save them as PDF. GEDCOM re-export is not available. Request a copy of your stored data at [email protected].
Correction: owners can edit supported person and family fields. Supported edit revisions can be inspected, and revisions with a restorable before-state can be reverted. Deleted records cannot be restored through revision history.
Deletion: supported person/family controls remove records from the active tree view; prior values may remain in revisions or legacy source records. Whole-tree and account deletion are not self-service controls. Send a deletion request to [email protected]; we will review stored records, photos, revisions and retention obligations.
Depending on where you live (for example under GDPR or CCPA) you may have additional rights to access, portability, correction, restriction or erasure. Exercise them by writing to [email protected].
We use your browser’s local and session storage for essential things: keeping you signed in, remembering your language and light/dark theme, storing your AI chat history on your device, and holding a temporary guest session credential.
An essential HttpOnly cookie holds temporary authorization for legacy media. The application clears it on logout or guest exit; clearing browser storage also removes local preferences and chat history.
We do not use advertising cookies or third-party trackers.
A family tree naturally contains information about other people, living and deceased. You are responsible for having a reasonable basis to record information about living relatives, and for honoring any request from a living relative to correct or remove their details.
KinWeave is not directed to children, and accounts are intended for adults.
Data may remain in active records, edit revisions, technical logs and provider backups. Removing a record from the displayed tree does not erase every retained copy. For deletion or retention questions, write to [email protected]; we do not promise an unverified automatic deletion or backup schedule.
If we make material changes we will update this page and the date below. Continued use after an update means you accept the revised policy.