Privacy Policy

Last updated September 06, 2026

1. Overview

FamilyBranch is a collaborative family-tree service for building, sharing, and exporting family trees with relatives you invite. This Privacy Policy explains what we collect, how we use it, and the choices you have.

Family trees can include information about living people, children, and relatives who are not users of FamilyBranch. Please add and share that information thoughtfully.

2. Information we collect

We collect account information such as your name, email address, encrypted password, preferred language, time zone, authentication settings, and support communications.

We collect family-tree content you and invited relatives provide, including names, relationships, dates, places, biographies, living or deceased status, photos, profile claims, invitations, roles, share-link settings, export requests, and generated export files.

When you subscribe, Stripe processes payment details for us. We receive subscription status, billing identifiers, receipts, and limited payment metadata, but we do not store full card numbers.

We also collect basic technical information such as IP address, browser and device details, log entries, cookies, session data, and feature usage needed to secure, operate, and improve the service.

3. How we use information

  • Provide, secure, maintain, and improve FamilyBranch.
  • Render family trees, photos, invitations, claims, public share pages, and JPEG or PDF exports.
  • Manage accounts, permissions, subscriptions, billing notices, support requests, and service emails.
  • Detect, investigate, and prevent abuse, fraud, security incidents, and violations of our terms.
  • Comply with legal, tax, accounting, and regulatory obligations.

4. Family data, living people, and minors

You control the family information you add. If you add information about another living person, including a minor, you are responsible for having an appropriate basis to do so and for respecting that person's privacy and family expectations.

Do not add sensitive information such as health, financial, legal, or identity-document details unless you have consent and a clear family purpose. FamilyBranch is not intended for storing records that require special legal or medical protections.

5. Collaboration, invitations, public links, and exports

Family trees are private to the account by default. Account admins can invite relatives and assign roles. Invited relatives may see tree information that existed before they joined and information added later.

Admins can create public share links. Anyone with a valid share link can view the shared tree until the link is revoked. Revoking a link stops future access through that URL, but it cannot remove copies, screenshots, downloads, or exports already made.

Exports may include photos and living-person data. Signed export links are temporary, but downloaded JPEG and PDF files are outside FamilyBranch's control.

6. How we share information

We do not sell personal information. We share information only as needed to operate the service, at your direction, or when legally required.

  • Service providers, including application hosting, Amazon S3 file storage, Resend email delivery, Stripe payment processing, and security, analytics, or error-monitoring tools we configure.
  • Other users in your account according to their role, invited relatives you or an admin add, and people who receive a public share link or exported file.
  • Authorities, courts, or other parties when required by law or when necessary to protect rights, safety, security, or the integrity of the service.
  • Successors in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to this policy or comparable protections.

7. Security

We use technical and organizational safeguards such as encrypted transport, authenticated sessions, role-based access, revocable share tokens, limited export tokens, access logging, and managed service providers. No internet service can be guaranteed to be perfectly secure.

8. Retention and deletion

We keep account, tree, photo, invitation, share-link, export, billing, and log information for as long as needed to provide the service, meet legal obligations, resolve disputes, enforce agreements, and maintain backups.

You can edit or delete family-tree content in the app, revoke public share links, cancel subscriptions, and request account or data deletion by contacting info@brightitsolutions.biz. Deleted data may remain for a limited time in backups, logs, billing records, security records, or files already exported or shared by users.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, object to, or restrict certain processing of your personal information. Contact info@brightitsolutions.biz to make a request.

You can manage account details, language preferences, photos, tree content, invitations, public links, and subscription cancellation from the product where those controls are available.

10. Cookies, email, and children's privacy

We use cookies and similar technologies for sign-in, security, preferences, and billing flows. Browser settings may let you block cookies, but some features may stop working.

We send transactional emails such as invitations, account notices, billing notices, export notifications, and security messages. You cannot opt out of messages needed to provide or secure the service.

FamilyBranch is not directed to children under 13. A parent, guardian, or authorized family member should manage any information about children in a family tree. Contact info@brightitsolutions.biz if you believe a child created an account or provided personal information without appropriate consent.

11. Changes and contact

We may update this Privacy Policy as the service changes. If the change is material, we may ask signed-in users to accept the updated policy before continuing.

Questions or requests can be sent to info@brightitsolutions.biz. The service is operated for Bright IT Solutions, obrt, vl. Yevheniia Lysenko (OIB 35307545070) at familybranch.live.

12. Controller and European privacy rights

The data controller is Bright IT Solutions, obrt, vl. Yevheniia Lysenko (OIB 35307545070), Rizzijeva ulica 28, 52100 Pula, Croatia. Contact: info@brightitsolutions.biz.

We process account and subscription data to perform our contract with you, billing records to meet legal obligations, and security and operational data for our legitimate interests in running a reliable service. Information about relatives may come from other family members. Our interest in enabling private family collaboration must be balanced against those relatives' rights; contact us to object or request removal, even if you do not have an account. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.

You may request access, correction, erasure, restriction, portability where applicable, or object to processing. We normally respond within one month; if a lawful extension is needed, we explain it within that month. You may complain to Croatia's supervisory authority, AZOP (https://azop.hr), or your local supervisory authority. We do not make solely automated decisions producing legal or similarly significant effects about you.

13. Providers, transfers, and retention

Our hosting uses DigitalOcean through Hatchbox, files use Amazon S3, service emails use Resend, and payments use Stripe. External font and JavaScript providers receive connection information when your browser requests their resources. Providers may process data outside the European Economic Area; where required, transfers must be covered by an adequacy decision or appropriate safeguards such as standard contractual clauses. Contact us for information about applicable safeguards.

Retention depends on whether your account or shared tree remains in use, a deletion request, outstanding disputes, security needs, and mandatory accounting retention. Removing your user account does not necessarily remove information relatives independently contributed to their shared tree. You can request review of that information separately. Copies in backups are removed through the backup rotation cycle; contact us for the applicable retention period.

Temporary tokens used to render exports are different from photo and download URLs. A copied signed file URL may remain usable while its file exists, even after a tree share link is revoked. Contact us to request removal of a file.