Privacy Policy

Last updated September 2026. This is a draft pending formal legal review and may change.

The short version. We collect your account details, your conversation with the interview, any documents you upload, and information about people you invite to contribute. We use AI providers (including Anthropic's Claude) to run the interview and do background research, and a small number of infrastructure providers to host and email you. We don't sell your data or use it for advertising. You can delete your data or close your account at any time.

What we collect

Account information

Your email address, username, and a securely hashed password (we never store your password itself). If you enable two-factor authentication, we store the secret needed to verify your codes.

Your conversation and family history content

Information we don't collect

We don't run advertising trackers, don't sell personal information, and don't use your family stories to train third-party AI models beyond the processing needed to generate your own responses.

How we use it

Who else handles your data

We use a small number of service providers to run MyOrigins.io:

We may also disclose information if legally required to, or where we believe in good faith it's necessary to protect someone's safety or investigate fraud. If our business is ever sold or transferred, your data may transfer with it, subject to this policy.

A note on other people's information

Family history is inherently about more than one person. Your account may contain facts, stories, or documents about relatives - living or deceased - who are not MyOrigins.io users themselves. If you invite someone to contribute, we use their name and email solely to deliver that invitation and, if they accept, to create their own contributor session. We do not independently verify or supplement that information from other sources.

We don't yet have automated tools to detect or restrict sensitive information about living third parties (for example, a living relative's home address or health history) that you or a contributor might enter. Please use judgment about what you record concerning people who haven't consented to being part of your project - this is an area we intend to improve.

Security

Traffic to the Service is encrypted with HTTPS. Passwords are hashed, never stored in plain text, and two-factor authentication is available. Access to your account requires your credentials (and, if enabled, a second factor). No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur.

How long we keep it

We keep your data until you delete it or close your account. From your Account page, you can delete all of your data while keeping your login, or permanently close your account, which deletes everything associated with it. Deletion is immediate and cannot be undone. Some records held by our service providers (for example, email delivery logs at Resend) follow their own retention schedules and may survive deletion on our end.

Your choices

Depending on where you live - California, Colorado, and a growing number of other states, or the EEA and UK - you may have statutory rights to access, delete, correct, or port your personal information. We honor these requests from everyone, regardless of where you live. Email support to make one.

Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has used the Service, email us and we will delete the data.

Changes to this policy

We may update this policy as the Service evolves. The "last updated" date above reflects the current version. If a change materially reduces the protection of information we already hold, we'll make a reasonable effort to notify affected users by email.

Contact

Live, Love, Learn, Leave a Legacy LLC
livelovelearnleavealegacy@gmail.com