AncestralFire Privacy Policy
Last updated: June 2026
AncestralFire is a subscription product built by Event Horizon Partners. You pay us to research your family history, and that means our interests run exactly parallel to yours: we want you to keep subscribing because we made your family history feel real, not because we've trapped your data or monetized your attention.
Three things this policy guarantees: no ads, no data sale, no AI training on your data. Export anytime. Delete anytime.
Table of Contents
- The short version
- Who we are
- What we collect
- How we use it
- Who we share it with — sub-processors
- Where your data lives
- How long we keep it
- Your rights
- Cookies and tracking
- Children
- California-specific rights (CCPA + SB 243)
- EU and international rights (GDPR + global)
- How we secure your data
- AI-specific disclosures
- Changes to this policy
- How to contact us
1. The short version
- We collect your email address, your family tree data, your conversations with the AI companion, and usage analytics — that's it.
- We never sell your data to anyone. Ever.
- We never use your data to train AI models. Not ours (we don't have one), not Anthropic's, not OpenAI's, not Google's.
- We never run ads. AncestralFire is subscription-funded.
- You can download everything we hold about you at any time from Settings.
- You can permanently delete your account and all your data at any time from Settings. We give you 30 days to change your mind; after that, it's gone.
- Your family tree data is yours. We never share it with other subscribers.
- Questions go to: roger@ancestral-fire.com. We aim to respond within 5 business days.
2. Who we are
AncestralFire is a product of Event Horizon Partners, a US-based company. We operate the service at app.ancestral-fire.com.
For the purpose of this policy, "AncestralFire," "we," "us," and "our" all refer to Event Horizon Partners and the AncestralFire product.
Contact: roger@ancestral-fire.com
3. What we collect
We collect the minimum necessary to deliver the service.
| What |
Details |
Shared with |
| Account |
Email (required), display name (optional), WorkOS user ID, plan status |
WorkOS (auth); Stripe (billing) |
| Family tree |
Ancestor names, dates, places, relationships, GEDCOM files, record hints. Per-subscriber — no other subscriber sees your tree. FamilySearch data read-only when you connect (opt-in). |
AncestralFire only |
| Conversations |
Full chat turns (you + AI), tool calls the AI made on your behalf, sources cited. Only you can access these. |
AI inference providers during active requests only (see §14) |
| AI memories |
Facts the AI recorded about your research preferences. Every memory is visible and deletable at /activity. |
AncestralFire only |
| Discoveries |
Genealogy insights you or the AI save. Public sharing via link is opt-in and off by default. |
AncestralFire; public if you share |
| Activity log |
Every significant action AncestralFire takes on your behalf. Visible to you at /activity. |
AncestralFire; WorkOS Audit Logs |
| Usage analytics |
Anonymous page views and feature events. No conversation content, no tree data. |
PostHog |
| Billing |
Stripe customer ID and subscription ID only. Card numbers never touch our systems. |
Stripe |
| Error traces |
Stack traces when something breaks. PII is scrubbed before leaving our systems. |
Sentry |
| Edge logs |
IP addresses, request paths, timestamps. Deleted after 7 days (Cloudflare Workers Logs default). |
AncestralFire; Cloudflare |
What we do not collect: raw DNA files; your current location; device fingerprints; advertising identifiers. If you mention DNA results in conversation, that text lives in your conversation history as text — no genetic file is stored.
4. How we use it
We use your data to run the service you subscribed for. In concrete terms:
- Powering the AI companion. Your conversation turns, memories, and tree data are assembled into context and sent to an AI inference provider (Anthropic or OpenRouter) to generate a response. Without this, the companion can't work.
- Remembering your research context. Memories persist across sessions so the companion knows your research focus without you repeating yourself every time.
- Billing. Your email and Stripe IDs are used to manage your subscription and send billing receipts.
- Email. Transactional messages (welcome email, billing receipts, material service updates) go to your email via Resend. If you've consented to product updates, we send those too. You can unsubscribe from non-transactional emails at any time.
- Product improvement. Anonymous PostHog analytics tell us which features people use and which ones aren't landing — so we can make the product better.
- Security and reliability. Sentry error traces help us find and fix bugs. Cloudflare edge logs help us detect abuse.
- Legal compliance. We retain billing records for legally required periods.
We do not use your data for advertising, cross-subscriber profiling, or AI model training.
5. Who we share it with — sub-processors
We share data only with the sub-processors below, each receiving only what's necessary for their specific function. All are bound by data processing agreements (DPAs) or contractual terms that require them to protect your data.
| Sub-processor |
Country |
Purpose |
Data received |
Privacy policy |
| Cloudflare |
US / global |
Workers compute; Durable Object storage; D1 database; R2 object storage; AI Gateway; Workers AI (voice); CDN; Secrets Store |
All data in transit and at rest — Cloudflare is our primary data processor |
cloudflare.com/privacypolicy |
| WorkOS |
US (EU infra available) |
Authentication, sessions, audit logs |
Email, user ID, session tokens |
workos.com/legal/privacy |
| Stripe |
US |
Payment processing and billing |
Email, Stripe customer/subscription IDs |
stripe.com/privacy |
| OpenRouter |
US |
LLM provider routing (primary AI path via CF AI Gateway) |
Conversation turns (see §14) |
openrouter.ai/privacy |
| Anthropic |
US |
AI inference when Claude models are used |
Conversation turns (see §14) |
anthropic.com/legal/privacy |
| Resend |
US |
Transactional email delivery |
Email address, message content |
resend.com/legal/privacy-policy |
| Cloudflare Workers AI |
US / global |
Speech-to-text and text-to-speech for voice features |
Audio (STT) or text (TTS) during active request only |
Covered by Cloudflare DPA |
| Sentry |
US |
Error monitoring and debugging |
Error traces (PII scrubbed) |
sentry.io/privacy |
| PostHog |
US (EU data residency option) |
Product analytics |
Anonymous usage events |
posthog.com/privacy |
| ElevenLabs |
US |
Voice synthesis (paying subscribers, opt-in voice features) |
Text passed for TTS synthesis; no persistent storage |
elevenlabs.io/privacy |
| FamilySearch |
US (nonprofit) |
Tree data (read-only, when connected) |
Read access to your connected FS tree |
familysearch.org/privacy |
No one else. We don't share your data with data brokers, advertising networks, or any third party not on this list. We don't sell your data. We don't share it with other AncestralFire subscribers.
6. Where your data lives
AncestralFire runs entirely on Cloudflare's global edge network (~330+ points of presence as of 2026). There is no single-region server, no VPS, and no traditional data center hosting location. All data layers are globally distributed and auto-replicating.
Per-subscriber Durable Object SQLite. Every subscriber gets a dedicated, isolated Cloudflare Durable Object (DO) — a private SQLite database that belongs exclusively to your account. Your conversations, family tree, memories, discoveries, activity log, and notes all live here. No other subscriber's DO shares this storage or these tables. Durable Objects have regional affinity (requests are routed to the DO instance closest to you), but the data is not pinned to a single country.
Cloudflare D1 (admin database). Your account record — email, plan status, billing IDs — is stored in Cloudflare D1 (af-prod-v3), a globally replicated SQL database. Five administrative tables only. Personal content (conversations, tree, memories) lives in your DO, not D1.
Cloudflare R2 (object storage). GEDCOM file uploads, voice recordings, attachments, and your data-export ZIP archives are stored in Cloudflare R2. R2 is globally distributed with automatic replication. No single regional location.
Cloudflare Vectorize. A vector embedding index (af-ancestors) powers semantic search over ancestor names and places. This index contains embeddings derived from your family tree data.
Sub-processor locations.
Your email is processed by WorkOS (US/EU), Resend (US), and Stripe (US). Conversation turns are sent to AI inference providers (US) during active requests only.
GDPR transfers — EEA, UK, and international.
Cloudflare provides Standard Contractual Clauses (SCCs) under GDPR Article 46 through its Data Processing Addendum, covering EEA → US data transfers. WorkOS, Stripe, and PostHog also have DPAs and SCCs in place. DPAs with Anthropic, OpenRouter, ElevenLabs, Sentry, and Resend are being confirmed before EEA commercial launch.
Note to Roger / counsel: Confirm SCCs and DPAs with Anthropic, OpenRouter, ElevenLabs, Sentry, and Resend before publishing for EEA subscribers. Also confirm Cloudflare DO regional affinity treatment under GDPR Art. 46 (DO instances are not pinned to a single EEA region by default). Vectorize erasure (ancestor embeddings are not currently deleted by the subscriber deletion flow) — this gap should be addressed before EEA launch.
7. How long we keep it
| Data type |
How long |
Why |
| Account and profile |
Until deletion + 30-day grace, then permanent purge |
Contract performance |
| Family tree (individuals, families, files) |
Until deletion + 30-day grace, then permanent purge |
Contract performance |
| Conversation history and turns |
Until deletion + 30-day grace, then permanent purge |
Contract performance |
| AI memories |
Until you delete them, or account deletion + 30-day grace |
Contract performance |
| Discoveries |
Until you delete them, or account deletion + 30-day grace |
Contract performance |
| Activity log |
Until account deletion + 30-day grace |
Legitimate interests (audit/trust) |
| GEDCOM raw file uploads (R2) |
90 days from upload |
Data minimisation — file is parsed on upload; raw copy not needed afterward |
| Billing records (Stripe) |
7 years |
Legal obligation (financial record-keeping) |
| Edge request logs (Cloudflare Workers Logs) |
7 days rolling |
Security / legitimate interests |
| Error traces (Sentry) |
90 days |
Reliability / legitimate interests |
| Usage analytics (PostHog) |
12 months rolling |
Product improvement / legitimate interests |
| Workers Analytics Engine telemetry |
90 days |
Aggregate telemetry / legitimate interests |
| Outbound email events (Resend) |
12 months |
Marketing consent compliance |
When we delete your data, we: wipe your Durable Object SQLite database, delete your R2 files, remove your D1 account record, write tombstones to any shared content you created (so shared content no longer exposes your personal information to recipients), and instruct sub-processors to delete their copies per their data processing agreements.
8. Your rights
These are live features, not future promises.
Access / data portability (GDPR Art. 15 + 20; CCPA §1798.100).
Download a complete copy of everything we hold about you — account profile, family tree, conversations, memories, discoveries, and activity log — as a machine-readable ZIP archive. The export walks your entire Durable Object SQLite database, your D1 account record, your R2 files, and your CF Agent Memory summary (where available).
→ Settings → Your data → "Download my data", or GET /api/me/export
Deletion / right to be forgotten (GDPR Art. 17; CCPA §1798.105).
Permanently delete your account and all associated data. Your account is deactivated immediately. All data is purged after a 30-day grace period (in case you change your mind). After 30 days, it's gone and cannot be recovered. Billing records may be retained for legally required periods (typically 7 years for financial records).
The deletion process executes deleteSubscriber(): wipes your Durable Object SQLite, deletes R2 objects under your subscriber prefix, removes your D1 account record, writes tombstones to shared content in recipient Durable Objects so the content is replaced with an anonymised placeholder rather than remaining attributed to you.
→ Settings → Your data → "Delete my account", or POST /api/me/delete
To cancel a pending deletion during the grace period: email roger@ancestral-fire.com.
Correction (GDPR Art. 16).
Update your name and preferences directly in the app. For anything else: email roger@ancestral-fire.com and we'll correct it within 10 business days.
Restriction (GDPR Art. 18).
You may request that we restrict processing of your data while a dispute is being resolved. Email roger@ancestral-fire.com.
Object to legitimate-interest processing (GDPR Art. 21).
You may object to processing of your data based on legitimate interests (analytics, error monitoring, edge security logging). Email roger@ancestral-fire.com.
Visibility — the /activity log.
Every action AncestralFire has taken on your behalf is recorded and visible to you at /activity. Memories written, discoveries saved, files uploaded, sign-ins, data exports. You don't have to ask us — it's already there.
Opt out of analytics.
Contact roger@ancestral-fire.com and we'll exclude your account from PostHog event capture. This doesn't affect anything else.
Opt out of marketing email.
Every marketing email has an unsubscribe link. You can also email roger@ancestral-fire.com. Transactional messages (billing receipts, service notices) can't be opted out of while your account is active.
Non-discrimination.
Exercising any of these rights will not affect your access to AncestralFire or the price you pay.
To submit a formal data subject request: email roger@ancestral-fire.com with "Data Request" in the subject line. We'll verify your identity and respond within 30 days (GDPR) or 45 days (CCPA).
9. Cookies and tracking
We use two cookies. That's it.
| Cookie |
Purpose |
Duration |
Can you decline? |
WorkOS session cookie (wos-session) |
Keeps you signed in. AES-GCM encrypted; never tracks you across other sites. |
Session or 30 days |
No — required for the app to work |
| PostHog analytics cookie |
Recognises returning visitors for anonymous usage metrics. No personal content is sent. |
1 year |
Yes — contact us and we'll exclude your account |
We do not use advertising cookies, third-party tracking pixels, or fingerprinting.
10. Children
AncestralFire is not directed at children under 16. We do not knowingly collect personal information from anyone under 16 (GDPR Art. 8 sets 16 as the EU default; US COPPA applies at under-13).
If you believe a child under 16 has created an account, email roger@ancestral-fire.com immediately. We will investigate and, if confirmed, delete all associated data.
11. California-specific rights (CCPA + SB 243)
If you live in California, the California Consumer Privacy Act (CCPA) and related regulations give you additional rights.
Your CCPA rights: know · delete · correct · opt out of sale/sharing (we don't sell or share) · limit use of sensitive personal information · non-discrimination.
To exercise any: email roger@ancestral-fire.com or use in-app controls at /settings. We respond within 45 days.
SB 243 — AI companion disclosure.
California SB 243 requires operators of AI companion chatbots to clearly identify the AI as artificially generated, not human. AncestralFire complies:
- The AI companion is identified as an AI throughout the experience — in the onboarding flow, in the interface, and in the product copy. A reasonable person interacting with AncestralFire will not be misled into thinking they are talking with a human.
- AncestralFire is a genealogy research assistant, not a social or romantic companion chatbot. We note this because SB 243 was primarily aimed at romantic companion chatbots; it applies to AncestralFire by its broad definition and we comply with it in spirit and in letter.
CCPA categories of personal information we collect:
| CCPA category |
Examples we collect |
| Identifiers |
Email, name (optional), WorkOS user ID |
| Personal information (Cal. Civ. Code §1798.140) |
Family tree data (ancestor names, dates, places) |
| Internet/network activity |
Conversation history, activity log, PostHog events |
| Financial information |
Stripe customer ID and subscription ID (card numbers never touch our systems) |
| Geolocation (indirect, historical) |
Ancestor places in your tree — not your current location |
12. EU and international rights (GDPR + global)
AncestralFire is designed to serve subscribers internationally. GDPR sets the floor for our data practices globally — not just for EEA subscribers. We comply with GDPR Art. 5 (data minimisation, purpose limitation, accuracy, storage limitation, integrity, accountability), Art. 6 (lawful bases), and the transparency obligations of Art. 13 and 14.
If you are in the EEA, United Kingdom, or Switzerland:
GDPR gives you additional rights and we process your data on a lawful basis:
Lawful bases (GDPR Art. 6):
- Contract performance (Art. 6(1)(b)) — running the service: account, family tree, conversations, memories, discoveries, activity log.
- Legal obligation (Art. 6(1)(c)) — billing records retention (7 years).
- Legitimate interests (Art. 6(1)(f)) — security, reliability, product improvement analytics (assessed proportionate to privacy impact).
- Consent (Art. 6(1)(a)) — marketing email.
Your GDPR rights:
| Right |
Article |
How to exercise |
| Access |
Art. 15 |
Settings → Download my data, or email us |
| Portability |
Art. 20 |
Same as Access — ZIP export is machine-readable JSON |
| Erasure |
Art. 17 |
Settings → Delete my account, or email us |
| Rectification |
Art. 16 |
In-app settings, or email us |
| Restriction |
Art. 18 |
Email roger@ancestral-fire.com |
| Object |
Art. 21 |
Email roger@ancestral-fire.com |
| Withdraw consent |
Art. 6(1)(a) |
Unsubscribe link in email, or contact us |
| Lodge complaint |
Art. 77 |
Your local supervisory authority |
Automated decision-making (GDPR Art. 22).
AncestralFire does not make automated decisions with legal or similarly significant effects. The AI companion generates genealogy research responses — it does not evaluate creditworthiness, employment eligibility, or anything else that would trigger Art. 22 obligations.
EU contact: roger@ancestral-fire.com. Formal GDPR requests receive a response within 30 days.
If you are in Canada (PIPEDA / Quebec Law 25):
Your data is handled in accordance with PIPEDA and, for Quebec residents, Quebec Law 25. You have the right to access, correct, and request deletion of your personal information. Contact roger@ancestral-fire.com.
If you are in Australia (Privacy Act 1988):
We handle your data in accordance with the Australian Privacy Principles. You have the right to access and correct your personal information. Contact roger@ancestral-fire.com.
GDPR data flow — transparency (Art. 13 / 14):
We collect data directly from you (Art. 13) via account creation, use of the service, and file uploads. We do not obtain personal data from third parties without your knowledge, except for FamilySearch data which you explicitly authorise when connecting your account (Art. 14 notice: source is FamilySearch; data type is your connected FS tree; purpose is genealogy research within AncestralFire).
13. How we secure your data
- Global edge, no exposed server. AncestralFire runs on Cloudflare Workers. There is no VPS or server to compromise. Cloudflare's WAF and DDoS protection operate at the network edge before any request reaches our code.
- Per-subscriber isolation. Every subscriber's data lives in a dedicated, isolated Durable Object SQLite database. Cross-subscriber data access is architecturally impossible — a subscriber's DO can only be addressed by requests authenticated to that subscriber.
- Encryption in transit. All traffic uses HTTPS (TLS 1.2+). Cloudflare handles TLS termination at the edge.
- Encryption at rest. Cloudflare D1, R2, and Durable Object storage are encrypted at rest by Cloudflare.
- Authentication. Sessions are managed by WorkOS AuthKit with
HttpOnly, Secure, and SameSite=Lax cookies. Server-side session invalidation on sign-out.
- Secrets management. All credentials and API keys are stored in Cloudflare Secrets Store (account-level vault) and Doppler (CI/human access). No secrets are committed to the codebase.
- Access control. All AI inference requests are routed through Cloudflare AI Gateway, which provides request logging, rate limiting, and audit trails.
No system is 100% secure. If we discover a breach that affects your personal data, we will notify you and any required regulators within the timeframes required by law (72 hours for GDPR; promptly for CCPA).
14. AI-specific disclosures
AncestralFire is an AI product
AncestralFire is powered by large language models (LLMs). The AI companion you interact with is not a human. This is disclosed throughout the product experience, in compliance with California SB 243 and the EU AI Act's transparency requirements.
We do not train AI models on your data
When you chat with AncestralFire, your conversation turns are sent to an AI inference provider (Anthropic, or alternative models via OpenRouter) via Cloudflare AI Gateway. These requests are made under our commercial API agreements with each provider.
Under those agreements:
- Anthropic does not train its foundation models on API customer data. See Anthropic's privacy policy.
- OpenRouter routes requests to model providers and does not store conversation content beyond what's needed to complete the request.
We pay these providers for inference compute. They are data processors acting on our instructions. They are not independent data controllers of your conversation data.
We do not build or fine-tune our own AI models. We have no model training pipeline. There is no path by which your data enters a training dataset.
What the AI agent does with your data
The AI companion may, in the course of a conversation:
- Write a memory about something you mentioned (visible and deletable at
/activity).
- Save a discovery if you or the AI finds something worth saving (visible and deletable at
/activity).
- Call external tools (Wikipedia, Wikidata, FamilySearch, Exa web search, YouTube) to research your ancestors. These tools receive search queries derived from your conversation — they don't receive your full conversation history.
Every action the agent takes on your behalf is logged to your activity feed. Nothing happens behind the scenes.
No advertising profiling
AncestralFire does not engage in profiling for advertising purposes (GDPR Art. 5(1)(b) — purpose limitation). PostHog analytics are used solely for product improvement.
15. Changes to this policy
We'll post any changes to this policy at ancestral-fire.com/privacy. For material changes, we'll email you at least 30 days before the change takes effect, so you have time to decide whether to continue using the service.
"Material changes" means: changes to what we collect, changes to how we use it, new sub-processors, or changes to your rights. Version history will be available on the page.
Continued use of AncestralFire after the effective date constitutes acceptance of the revised policy.
16. How to contact us
For privacy questions, data access requests, deletion requests, corrections, or complaints:
Roger Parkinson
roger@ancestral-fire.com
AncestralFire (a product of Event Horizon Partners)
We aim to respond within 5 business days.
For formal GDPR data subject requests, we will respond within 30 days as required by law.
For formal CCPA data subject requests, we will respond within 45 days as required by law.
If you are located in the EEA and are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu. If you're in the UK, contact the Information Commissioner's Office.
If you are located in Canada and wish to escalate, contact the Office of the Privacy Commissioner of Canada.
If you are located in Australia and wish to escalate, contact the Office of the Australian Information Commissioner.
AncestralFire turns the open record of humanity into the story of who came before you. We take privacy seriously because the data you share with us — your family's history — is not just personal. It's sacred. Our job is to be trustworthy with it.
DRAFT — not legal advice. Review with counsel before publishing at ancestral-fire.com/privacy.
Key open items for legal review: (1) confirm SCCs and DPAs with Anthropic, OpenRouter, ElevenLabs, Sentry, and Resend before serving EEA subscribers commercially; (2) confirm Cloudflare DO regional affinity treatment under GDPR Art. 46 (DOs are not region-pinned by default — Cloudflare DPA SCCs may be sufficient, but counsel should verify); (3) Vectorize index erasure is not currently in deleteSubscriber() — add before EEA launch or document as a known gap; (4) CF Agent Memory is private beta — confirm Cloudflare DPA covers beta bindings before using for EEA subscriber data at scale; (5) cookie consent banner threshold for EEA visitors to ancestral-fire.com marketing site; (6) PIPEDA / Quebec Law 25 compliance review for Canada-specific language; (7) confirm SB 243 "companion chatbot" classification for AF genealogy assistant.