/ Privacy Policy ← Back to Sign Up

Privacy Policy

Effective Date: 23 May 2026  ·  Last Updated: 23 May 2026  ·  Version 1.0

Your family's story is precious — and so is your privacy. This Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have. We comply with India's Digital Personal Data Protection Act 2023 (DPDPA), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable laws.

1. Who We Are (Data Controller / Fiduciary)

LegacyRoots AI ("we", "us", "our") is the Data Fiduciary under India's DPDPA and the Data Controller under GDPR for personal data processed through the LegacyRoots AI platform (legacyroots.ai).

Contact for privacy matters: privacy@legacyroots.ai

2. Personal Data We Collect

2.1 Data You Provide Directly

CategoryData ElementsPurpose
Account RegistrationFull name, email address, password (hashed), profile photo, phone number, date of birth, gender, bio, place of birthIdentity verification, account management, personalisation
Family Tree ProfilesNames, dates of birth/death, gender, relationship types, roles, biographical stories, milestones, achievements, letters, photos, videosCore service — building and displaying family trees
Memorial ProfilesDate of passing, cause of death (optional), eulogy, memorial photos, tribute messagesMemorial page creation and tribute management
Payment InformationBilling name, payment method details (card last-4, expiry — stored by payment processor), billing address, transaction IDs, subscription statusSubscription billing and payment processing
InvitationsEmail addresses of invited family membersSending tree-join invitations
Tributes (External Visitors)Contributor name, relationship to deceased, tribute text, IP addressPublic tribute submission and moderation
Support CommunicationsTicket content, attached files, email correspondenceCustomer support and complaint resolution
AI Feature InputsText prompts, names, and story fragments you provide when using AI toolsGenerating AI-assisted content

2.2 Data We Collect Automatically

2.3 Special Categories of Data

The Service may involve sensitive personal data including information about deceased persons (date and cause of death), family health history (if voluntarily disclosed in stories), and religious or cultural information (if included in biographical content). We collect this data only when you voluntarily provide it as part of your family record. You should only include sensitive data about third parties when you have their consent or are legally authorised to do so.

3. How We Use Your Data

Processing PurposeLegal Basis (GDPR)Legal Basis (DPDPA)
Providing and operating the core ServicePerformance of contractConsent / Legitimate use
Account authentication and securityLegitimate interests; Legal obligationLegitimate use
Subscription billing and payment processingPerformance of contract; Legal obligationConsent
Sending transactional emails (invitations, receipts, alerts)Performance of contractLegitimate use
Product improvement and analyticsLegitimate interestsConsent
AI feature processingPerformance of contract; ConsentConsent
Customer supportLegitimate interests; Performance of contractLegitimate use
Legal compliance and fraud preventionLegal obligation; Legitimate interestsLegal obligation
Referral programme trackingPerformance of contractConsent
Marketing communications (optional)ConsentConsent

4. Data About Third Parties in Your Family Tree

When you add information about other people (living or deceased) to your family tree, you act as a data controller or fiduciary for that data in your jurisdiction. By using the Service, you agree that:

5. Children's Privacy

LegacyRoots is not directed to children under 13. We do not knowingly collect personal data directly from children under 13. Family trees may contain profile information about minor family members (e.g., a grandchild added to the tree by a grandparent). Such profiles:

If you believe we have inadvertently collected personal data about a child under 13 without proper parental consent, please contact us immediately at privacy@legacyroots.ai and we will delete such data promptly.

6. Data Sharing and Disclosure

6.1 Within Your Family Tree

Data in a family tree is shared with all members of that tree according to their role. Family Keepers and Co-Keepers can see and manage all data in the tree.

6.2 Cross-Tree Linking

When you initiate or accept a cross-tree link request, a limited preview of your tree (tree name, member names) is shared with the requesting party to facilitate the linking decision. Full data sharing between trees occurs only after both parties accept the link.

6.3 Public Memorial Pages

If a Family Keeper makes a memorial page public, the following data becomes accessible to the general public: the deceased's name, photos, biographical story, memorial content, and approved tributes. You should not make a memorial page public if it contains information that should remain private.

6.4 Third-Party Service Providers

We share data with vetted processors/sub-processors who assist in operating the Service:

ProviderPurposeData SharedLocation
Google FirebaseAuthentication, database, file storage, cloud hostingAccount data, tree data, uploaded filesUSA (adequacy/SCCs apply)
Stripe Inc.Payment processing (international)Payment method details, billing addressUSA (SCCs / adequacy)
Razorpay Software Pvt. Ltd.Payment processing (India)Payment method details, billing addressIndia
AI Model ProvidersAI greeting cards, legacy writing assistanceText prompts you submit to AI featuresUSA
Email Delivery ProviderTransactional emails (invitations, receipts, support)Email address, nameUSA

All processors are bound by data processing agreements requiring them to process data only per our instructions and maintain appropriate security standards.

6.5 Legal Disclosures

We may disclose your data to government authorities, law enforcement, or courts when: (a) required by applicable law or valid legal process; (b) necessary to protect our legal rights; (c) necessary to prevent fraud or imminent physical harm. Where permitted, we will notify you of such requests.

6.6 Business Transfers

If LegacyRoots AI undergoes a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you before your data is subject to a materially different privacy policy and offer you the option to delete your account.

6.7 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes. (For California residents: we do not "sell" or "share" personal information as defined under CCPA/CPRA.)

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our service providers operate. For transfers of personal data from the EEA, UK, or Switzerland, we rely on: (a) EU Standard Contractual Clauses (SCCs); (b) the EU–US Data Privacy Framework (where applicable); or (c) other lawful transfer mechanisms. For Indian users, international transfers comply with DPDPA cross-border transfer provisions.

8. Cookies and Tracking Technologies

LegacyRoots uses the following technologies:

We do not use third-party advertising cookies or tracking pixels.

9. Data Retention

Data TypeRetention Period
Active account and tree dataFor the duration of your account plus 30 days post-deletion request
Payment records and billing history7 years from the transaction date (legal obligation)
Support tickets3 years from closure
Server access logs90 days
AI prompt inputsNot retained beyond the API call (not stored by us); subject to AI provider's retention policy
Deleted account dataPurged within 30 days of account deletion, except where legal retention applies
Public memorial data (if published)Retained until the Family Keeper or authorised next-of-kin requests removal
Backup copiesOverwritten within 90 days of deletion

10. Your Rights

Depending on your jurisdiction, you have the following rights over your personal data. To exercise any right, contact privacy@legacyroots.ai. We will respond within 30 days.

10.1 Rights for All Users

10.2 Additional Rights — EU/EEA/UK Users (GDPR/UK GDPR)

10.3 Additional Rights — Indian Users (DPDPA 2023)

10.4 Additional Rights — California Residents (CCPA/CPRA)

10.5 Data About Deceased Persons

Rights over data pertaining to deceased family members in your tree may be exercised by the Family Keeper, a designated Successor, or a verified next-of-kin upon submission of appropriate documentation.

11. Security

We implement industry-standard technical and organisational security measures to protect your personal data, including:

Despite these measures, no system is completely secure. We cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify affected users and relevant authorities as required by law.

12. Data Relating to Deceased Individuals

LegacyRoots is designed to preserve memories of both living and deceased family members. For deceased individuals:

13. AI Features and Data

When you use AI-powered features (greeting card generation, legacy writing assistance):

14. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will notify you by email and/or prominent notice in the Service at least 14 days before the changes take effect. The "Last Updated" date at the top of this document reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

15. Contact and Grievance Officer

For privacy-related questions, requests, or complaints: