Skip to main content

    Privacy

    How We Handle Your Data

    GEDminer is built on a simple principle: your genealogical data belongs to you.

    Local-first by design

    Your GEDCOM file is parsed inside your web browser. The original file is never uploaded, transmitted, or stored on any server. Without an account, the personal details in your tree, including names, dates, relationships, notes, and sources, stay on your device.

    Your file stays on your device

    When you upload a GEDCOM file, it is parsed entirely inside your web browser using a background thread. Your original .ged file is never transmitted to any server. No copy of the raw file is made, stored, or logged anywhere outside your device. Once the tab or browser is closed (and you are not signed in), the parsed tree is removed from memory. When you use GEDminer without signing in, research changes - notes, dismissals and similar decisions - are not stored between visits by default. You can turn on "Remember anonymous changes" in Settings to keep them in this browser, and remove them again at any time from the same place. GEDminer may still remember basic application preferences such as your theme.

    What happens when you create an account

    If you register, the parsed analysis results - structured names, dates, places, and family relationships extracted from your file - are stored in a managed cloud database (encrypted in transit and at rest) so you can return to your work on any device. Your original GEDCOM file is still never stored or uploaded. Only the derived analysis data is persisted. Data is stored compressed in an isolated, per-user storage space protected by row-level security policies - only your account can access it through the app, and we do not view or use your data in the course of normal operations. Like any hosted service, infrastructure-level access technically exists, and would only ever be used where strictly necessary for security, debugging at your request, or to comply with legal obligations.

    Deleting your data (Right to Erasure)

    You can permanently delete your account at any time from the My Account page. Deletion runs immediately and removes: • All saved family tree analysis data • Your cloud storage files • Your research work saved to your account - notes, tags, DNA results, haplogroups and dismissals • Your user profile and preferences • Your email delivery records • Your authentication record The same research work is also erased from this browser's local storage as part of the deletion, and that erase is verified rather than assumed. In the rare case where the browser refuses to write (private mode, a full storage quota, a disk error), we tell you so and ask you to clear GEDminer site data from your browser to remove the leftover copy manually. Deletion removes your data from the cloud for every device, but it cannot reach into other browsers you have used: a leftover local copy on another device is only cleared when GEDminer next runs there and finds the account gone. If you want it gone sooner, clear GEDminer site data in that browser. Anonymised rather than deleted: if you have supported the project financially, the payment record itself is kept for accounting and tax purposes, but your name, email address, any message you sent and the raw payment payload are permanently cleared. What remains is the amount, currency, date and provider reference - nothing that identifies you. Account deletion is irreversible. If any stage fails, nothing is reported as complete and you can safely run the deletion again.

    Data portability

    Your original GEDCOM file remains on your device - you always have full ownership of your source data. The analysis results stored in the cloud are derived from your file and can be regenerated at any time by re-uploading the same GEDCOM. We do not lock you in. Your GEDCOM file, and everything derived from it, can be reproduced at any time by re-uploading it here or to any tool of your choice. One thing is worth knowing before you delete: research you created inside GEDminer - notes, tags, DNA results, haplogroups and dismissed suggestions - does not exist in your GEDCOM file, so it cannot be regenerated by re-uploading. Export what you want to keep from the export tools before deleting your account.

    Community comparison

    The tree health score shows how your tree compares with other GEDminer trees. This comparison is powered by anonymous, aggregate statistics that your browser contributes automatically when the Tree Health analysis runs - for anonymous visitors as well as signed-in users. There is no sign-in requirement and no separate opt-in step for it. What is sent: your four aggregate health percentages (overall, completeness, sourcing and consistency), how many individuals and how many families your tree contains, a one-way tree fingerprint computed locally from hashed identity signals, and the short-lived rate-limiting identifier described below. What is not sent: your GEDCOM file, names, dates, places, notes, sources, or any relationships or records that could be used to reconstruct your tree. Why: these numbers are what the anonymous community percentiles are calculated from, and the rate-limiting information keeps that shared dataset from being distorted by bulk automated submissions. Your tree is identified in the comparison pool by that one-way tree fingerprint, computed in your browser from hashed identity signals - each person contributes a hash of their name and birth or death year, and only a fixed-size sketch of those hashes is hashed again into the value that is sent. Raw names and dates are not part of the submission, and the fingerprint cannot be reversed into your data. We do not claim it carries no information at all: it is deliberately stable for the same tree, which is precisely what lets us recognise a repeat submission instead of counting it twice. Each submission is counted against a short-lived, rotating identifier. It is derived from your network address (or your account, if you are signed in) using a one-way keyed hash that also includes the current date. Your IP address is never stored - only the resulting identifier, which cannot be linked back to an address without our server-side key and changes every day. The rate-limiting records it drives are deleted by a scheduled hourly clean-up once they are more than two days old, whether or not anyone submits again; the identifier itself stays on the anonymous score row so we can keep one source from dominating the statistics. It is used solely for those submission limits.

    Cookies & analytics

    We do not use any client-side analytics scripts or tracking cookies. No third-party tracking scripts, advertising pixels, or social media beacons are loaded in your browser. Aggregate usage statistics (visitor counts, page views, approximate country, device type, and referrer source) are collected anonymously at the server level by our hosting provider for operational monitoring. No personal data or genealogical information is included in these statistics. No cookies are set for tracking purposes. Local storage is used for your application preferences (such as theme choice), for saved tree data if you choose to create an account, and - only if you opt in with "Remember anonymous changes" - for research changes made without an account. You can block the hosting provider's aggregate statistics with an ad blocker, and GEDminer will continue to work normally. GEDminer itself is a JavaScript application that parses and analyses your file in your browser, so it does need JavaScript enabled to run at all.

    Security measures

    Encryption in transit - All connections use HTTPS/TLS encryption • Encryption at rest - Database storage is encrypted at rest (AES-256) • Row-level security - Database access policies ensure users can only access their own data • Password safety - Passwords are securely hashed using industry-standard algorithms - we never see or store plaintext passwords • Isolated operations - Server-side operations (like account deletion) run in isolated, stateless functions with minimal permissions • Open standards - Authentication uses industry-standard JWT tokens

    Email & communications

    We only send emails you explicitly opt into. During registration, you can choose whether to receive occasional product updates. You can change this preference at any time from your My Account page. We will never share your email address with third parties or use it for marketing without your explicit consent.

    Data controller

    GEDminer is the data controller for any personal data processed through this service. For data subject requests, questions about how your personal data is handled, or to exercise your GDPR rights (access, erasure, portability, restriction, or objection), contact: Email: [email protected] We will respond to all requests within 30 days as required by law.

    Your rights under GDPR

    • Right to access - View all stored data via your dashboard and account settings.
    • Right to erasure - Delete your account and all data instantly from the My Account page.
    • Right to portability - Your source GEDCOM file stays on your device; you always have your original data.
    • Right to restrict processing - Use GEDminer without an account: analysis stays local, and research changes are not kept between visits unless you opt in.
    • Right to withdraw consent - Opt out of communications at any time from your account settings.

    Questions?

    If you have any questions about how your data is handled, email [email protected].

    Last updated: March 2026