Our StoriesHow It WorksOur RootsMy Family

Legal

Privacy Policy

Last updated: 22 May 2026

At Ancestorii, your privacy is fundamental to our mission. We exist to help you preserve life stories, memories, and personal moments — and we treat that responsibility with the highest level of care.

This Privacy Policy explains how Ancestorii Ltd ("Ancestorii", "we", "us", or "our") collects, uses, stores, shares, and protects your personal information when you use the Ancestorii platform, website at ancestorii.com, and all related services including the Our Stories public feed, My Family private library, My Heirlooms physical products, and AI-assisted writing tools (collectively, the "Service").

Ancestorii Ltd is the data controller for the purposes of UK GDPR and the Data Protection Act 2018. Our contact address for all data-related enquiries is support@ancestorii.com.

1.Information We Collect

We collect only the information necessary to operate, maintain, and improve the Service. The categories of data we collect are as follows:

Account information: your full name, email address, and authentication credentials. If you sign up using Google, we receive your name, email address, and profile photo from Google. You may also optionally provide a phone number, date of birth, biography, location, and a profile photograph.

Family information: the name of your family space, the names and roles of family members you invite, and family membership details. When you create profiles for loved ones, you may provide their names, dates of birth, dates of passing, biographical details, relationship descriptions, and photographs.

Content you upload: photographs, videos, audio recordings (including voice notes), written memories, captions, timeline events, album descriptions, and any other media or text you choose to store on the platform. This may include associated metadata such as file names, file sizes, and image dimensions. Content may be stored in your private family library (My Family) or published to the public feed (Our Stories).

Public feed interaction data: when you interact with the Our Stories public feed, we collect data relating to stories you publish, likes you give, comments you write, and shares you make. We also collect data relating to reports you submit about other users' content.

Content review data: every story submitted to the Our Stories public feed is reviewed before publication. We collect data relating to the review process including the review outcome, the reason for any rejection, and any community standards violations recorded against your account under our three-strike policy.

Order and shipping information: when you purchase a physical product through My Heirlooms (Memory Book, Canvas Print, or Acrylic Print), we collect your shipping name, address, email, and phone number as provided during checkout.

Payment information: payment transactions are processed securely by Stripe. Ancestorii does not receive, store, or have access to your full payment card details. We receive a confirmation of payment status, transaction ID, and billing currency from Stripe.

AI interaction data: if you use the optional Story Assistance feature, the names, dates, and contextual details you provide as prompts are sent to a third-party AI language model to generate writing suggestions. We log the type of assistance requested, token usage, and response time for service-quality purposes. We do not use your content to train AI models.

Technical and usage data: browser type, device type, operating system, IP address, pages visited, feature interactions, and session duration. This data is collected automatically and used in aggregate to improve the Service.

Email validation data: at the point of registration, your email address may be checked against a third-party email verification service to confirm deliverability and reduce fraud. This check returns a validation result only — no personal content is shared.

2.How We Use Your Information

We use the information we collect for the following purposes:

To create, authenticate, and manage your account and family space. To store, organise, display, and protect your uploaded memories and content within your private family library. To display stories, likes, comments, and shares on the Our Stories public feed where you have chosen to publish content. To review content submitted to the Our Stories public feed against our community standards before publication. To enforce our community standards and three-strike policy, including issuing warnings, suspensions, and bans from the public feed. To process reports submitted by users about content on the public feed. To process physical product orders through My Heirlooms, generate print-ready files, and coordinate fulfilment and delivery. To provide AI-assisted writing suggestions when you opt to use the Story Assistance feature. To send transactional communications including welcome emails, onboarding guidance, order confirmations, family invitation notifications, community standards notifications, strike warnings, and account security alerts. To validate email addresses at registration to ensure deliverability of essential communications. To provide customer support and respond to enquiries. To maintain the security, integrity, and performance of the platform. To detect and prevent fraud, abuse, and violations of our Terms. To improve the Service based on anonymised and aggregated usage insights.

3.Legal Basis for Processing (UK GDPR)

We process your personal data under the following legal bases as defined by the UK General Data Protection Regulation:

Performance of a contract: processing necessary to provide the Service you have signed up for, including account management, content storage, public feed functionality, order fulfilment, and delivery of physical products.

Consent: where you have given explicit consent, such as opting in to the AI Story Assistance feature or providing optional profile information. You may withdraw consent at any time through your account settings or by contacting us.

Legitimate interests: processing necessary for our legitimate business interests, including platform security, fraud prevention, content moderation and review of the public feed, enforcement of community standards, service improvement, and sending non-marketing service communications. We balance these interests against your rights and freedoms.

Legal obligation: processing required to comply with applicable laws, regulations, or legal processes.

4.Our Stories — Public Feed Data

When you publish a story to Our Stories, the following data becomes publicly visible to all Ancestorii users: the story title, story content, any photos or media attached to the story, your display name, and your profile photograph.

Likes, comments, and shares. When you like, comment on, or share a story on Our Stories, your display name and profile photograph are visible alongside that interaction. Comments you write are publicly visible. You may delete your own comments at any time.

Content review. Every story submitted to Our Stories is reviewed before it appears on the public feed. This review process may involve automated systems and manual review. The purpose of the review is to ensure compliance with our community standards, which prohibit religious content, political content, hate speech, harassment, spam, self-promotion, and any content that is not a genuine family memory. The outcome of each review (approved or rejected) and the reason for any rejection are recorded against your account.

Three-strike policy data. If a published story violates our community standards, a strike is recorded against your account. We store the number of strikes, the date and reason for each strike, and the status of any suspension or ban. This data is used solely to enforce our community standards and is not shared publicly. Strike data is retained for the lifetime of your account.

Reports. When you report a story or comment, we collect the content of the report and your identity for the purpose of investigating the report. Your identity as the reporter is not disclosed to the person whose content was reported.

Removal. You may remove a story from Our Stories at any time. Upon removal, the story content, associated likes, comments, and shares are removed from the public feed. Removal from Our Stories does not affect content stored in your private family library.

No algorithms. Our Stories does not use engagement-based algorithms, behavioural profiling, or personalised content ranking. Stories are displayed in chronological order. We do not track or profile your reading behaviour on the public feed for the purpose of content recommendation.

5.My Family — Private Library Data

Content stored within My Family is treated as private data. This includes timelines, albums, stories, voice recordings, family member profiles, and all associated media.

Privacy guarantee. Content within My Family is never displayed on the Our Stories public feed unless you explicitly choose to publish it. Private content is never included in search results, surfaced in recommendations, shared with other users outside your family space, or used for any purpose other than providing the Service to you and your invited family members.

Family member access. All content within a family space is visible to every invited member of that space. This includes content uploaded by any family member. By inviting someone to your family space, you acknowledge that they will have access to all content within it.

No moderation of private content. Ancestorii does not monitor, review, or moderate content within private family spaces unless a violation of our Terms is reported by a member of that family space.

Community standards enforcement does not affect private data. Strikes, suspensions, and bans under our three-strike policy apply exclusively to the Our Stories public feed. A user's private family library, including all timelines, albums, stories, voice recordings, and the ability to order physical products, is never affected by public feed enforcement actions.

6.My Heirlooms — Physical Product Data

When you order a physical product through My Heirlooms (Memory Book, Canvas Print, or Acrylic Print), the following data is processed:

Content data: a print-ready file is generated from the photos, stories, and layouts you have selected from your private family library. This file is shared with our third-party print-fulfilment partner solely for the purpose of producing your order. The fulfilment partner does not retain your content beyond what is necessary to complete production and delivery.

Shipping data: your shipping name, address, email, and phone number are shared with our fulfilment partner for delivery purposes only.

Payment data: physical product payments are processed by Stripe. Ancestorii does not store your full card details. We receive a payment confirmation, transaction ID, and billing currency.

PDF and image rendering: print-ready files for Memory Books are generated using a cloud-based browser rendering service. Your content is temporarily processed to produce the output file and is not stored by the rendering service beyond the duration of the rendering request.

Order records: order details including the product type, order date, delivery address, and transaction reference are retained for up to six years in accordance with UK tax and accounting requirements.

7.Family Collaboration & Shared Data

When you create or join a family space, all content within that space is visible to every member. This means photographs, voice notes, timelines, albums, and other memories uploaded by any family member are accessible to all members of the same family.

Family invitations are sent via email and include a unique, time-limited token. The recipient's email address is used solely to deliver the invitation. If the recipient does not accept the invitation within seven days, the token expires and no account is created on their behalf.

If you leave or are removed from a family space, your access to that family's shared content is revoked immediately. Content you uploaded to the shared space may be removed in accordance with our deletion policies.

8.Data Sharing & Third-Party Services

Ancestorii does not sell, rent, or trade your personal data to any third party.

We share limited data with trusted third-party service providers strictly as necessary to operate the Service. Each provider processes data only for the specific purpose described and is subject to contractual obligations to protect your information:

Authentication & database: we use Supabase to manage user authentication, database storage, and file storage. Your account data, content, and uploaded media are stored on Supabase's infrastructure.

Payment processing: payments for subscriptions and physical products are handled by Stripe. Stripe receives your payment details directly — Ancestorii does not have access to your full card information.

Email delivery: transactional emails (welcome messages, order confirmations, family invitations, onboarding guidance, community standards notifications, strike warnings, and activity notifications) are sent via Resend from support@ancestorii.com. Resend receives your email address and name for the purpose of delivering these communications.

Email validation: at registration, your email address may be checked by Kickbox to confirm it is deliverable and to suggest corrections for typos. Only the email address is shared — no other personal data.

Print fulfilment: when you order a physical product through My Heirlooms, your shipping name, address, email, phone number, and a print-ready file containing your content are shared with our print-fulfilment partner solely for the purpose of producing and delivering your order. Your content is not retained by the fulfilment partner beyond what is necessary to complete the order.

PDF and image rendering: print-ready files for Memory Books are generated using a cloud-based browser rendering service. Your content is temporarily processed to produce the output file and is not stored by the rendering service.

Content review: stories submitted to the Our Stories public feed may be reviewed using automated systems including third-party AI services. The content of the story is processed solely for the purpose of determining compliance with our community standards. Content processed for review is not retained by third-party review services beyond the duration of the review request and is not used to train AI models.

AI processing: if you use Story Assistance, the contextual details you provide (names, dates, descriptions) are sent to a third-party AI language model provider to generate writing suggestions. These inputs are not used to train AI models. The AI provider processes data in accordance with its own data-handling policies and does not retain your inputs beyond the duration of the request.

Hosting: the Ancestorii website and application are hosted on Vercel. Vercel may process technical data such as IP addresses and request headers as part of serving the platform.

We may also disclose personal data if required to do so by law, in response to a valid legal request, or to protect the rights, safety, or property of Ancestorii, our users, or the public.

9.Data Storage & Security

Your data is stored using secure, industry-standard cloud infrastructure with encryption in transit and at rest. We apply technical and organisational measures to protect against unauthorised access, alteration, disclosure, or destruction of your personal data.

These measures include row-level security policies on our database ensuring users can only access data belonging to their own family space, secure authentication with support for third-party OAuth providers, HTTPS encryption across all connections, separation of public feed data and private family data at the database level, and restricted access to production systems.

Content within My Family is stored with row-level security policies that prevent any user outside the family space from accessing it, including Ancestorii staff except where required for technical support or legal compliance.

While no system can guarantee absolute security, Ancestorii is designed with privacy-first principles and follows modern security practices. If we become aware of a data breach that affects your personal data, we will notify you and the relevant supervisory authority in accordance with our legal obligations.

10.International Data Transfers

Some of our third-party service providers are based outside the United Kingdom. Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office, adequacy decisions, or equivalent protections as required by UK data protection law.

11.Cookies & Tracking

Ancestorii uses essential cookies required for the platform to function, including authentication session cookies that keep you logged in. These are strictly necessary and do not require consent.

We may use analytics cookies or similar technologies to understand how the platform is used in aggregate. Where non-essential cookies are used, we will obtain your consent before setting them.

Ancestorii does not use advertising cookies or tracking pixels. We do not serve ads on the platform, and we do not share browsing data with advertising networks. Our Stories does not use cookies or tracking to profile reading behaviour or personalise content.

12.Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you have the following rights in relation to your personal data:

Right of access: you may request a copy of the personal data we hold about you, including any strike records, content review outcomes, and interaction data from Our Stories.

Right to rectification: you may request correction of any inaccurate or incomplete personal data. You can also update most information directly through your account settings.

Right to erasure ("right to be forgotten"): you may request deletion of your personal data. You can delete your account at any time, which will permanently remove your personal data, uploaded content, published stories on Our Stories, and all associated interactions in accordance with our retention policy.

Right to restrict processing: you may request that we limit how we process your data in certain circumstances, such as while a dispute about accuracy is being resolved.

Right to data portability: where technically feasible, you may request a copy of your data in a structured, commonly used, machine-readable format.

Right to object: you may object to processing based on legitimate interests, including content moderation. We will cease processing unless we can demonstrate compelling legitimate grounds.

Right to withdraw consent: where processing is based on consent (such as AI Story Assistance), you may withdraw that consent at any time through your account settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at support@ancestorii.com. We will respond to your request within one month, as required by law. If your request is complex, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for it.

If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

13.Data Retention

Your personal data and uploaded content are retained for as long as your account remains active. We retain data to provide you with continuous access to your memories, family library, and published stories.

Upon account deletion, your personal data, profile information, uploaded content, published stories on Our Stories (and all associated likes, comments, and shares), and private family library content will be permanently removed from our systems within 30 days. Content you uploaded to a shared family space will also be removed.

Strike records are retained for the lifetime of the account. Upon account deletion, strike records are permanently removed alongside all other personal data.

Order records (including shipping addresses and transaction details) are retained for up to six years after the date of the transaction, in accordance with UK tax and accounting requirements. Certain data may be retained for a longer period where required by law, after which it will be securely deleted.

Backups of our database may retain copies of deleted data for a limited period as part of our disaster-recovery processes, after which they are overwritten.

14.Children's Privacy

Ancestorii is not intended for use by children under the age of 16 without the consent of a parent or legal guardian. We do not knowingly collect personal data from children under 16 without parental consent.

If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data without consent, please contact us at support@ancestorii.com.

Ancestorii is designed to preserve family memories, which may include photographs and stories involving children. The responsibility for uploading and managing such content lies with the adult account holder, who must have the appropriate legal authority to share that content.

15.Communications & Marketing

By creating an account, you consent to receive transactional and service-related emails that are necessary for the operation of the Service. These include welcome emails, onboarding guidance, order confirmations, shipping updates, family invitation notifications, family activity alerts, community standards notifications, strike warnings, suspension notices, and account security notices.

We may also send periodic product updates or feature announcements. These are infrequent and relate directly to the Service. You may opt out of non-essential communications at any time by following the unsubscribe link in any email or by contacting us.

Ancestorii does not send marketing emails on behalf of third parties, and we do not share your email address with third parties for marketing purposes.

16.Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our data practices, or legal requirements. When we make material changes, we will notify you via email or through a prominent notice on the platform.

The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

Previous versions of this Privacy Policy are available upon request.

17.Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or how Ancestorii handles your information, please contact us at:

Ancestorii Ltd
Email: support@ancestorii.com

We aim to respond to all enquiries within five working days.

This Privacy Policy was last reviewed and updated on 22 May 2026. Previous versions are available upon request.