Privacy Policy
Last updated 14 September 2026
Your vault is private. We collect the little we need to run the service, we store it encrypted, we do not sell it, we do not advertise, and there are no tracking cookies on this site. You can export everything or delete everything, yourself, at any time. Famvaults is also a free beta, and section 4 is honest about what that means for your privacy.
1Who is responsible
Famvaults, based in Singapore, is the data controller for account information and for the operation of the service. You can reach us at hello@famvaults.com.
For the content inside a vault, the vault owner is the one who decides what is collected, about whom, and who sees it. In data protection terms they are the controller of that content and we process it on their behalf, on their instructions. We did not choose what is in your family’s vault and we have no way to review it. See section 5, which matters more than it might first appear.
2What we collect
- Account information — your email address, a display name if you give one, and an encrypted password hash. We never see your actual password.
- Vault content — the articles, photographs, family tree entries and files you and your members create. Where a vault passphrase is set, wiki articles reach us already encrypted and we hold only ciphertext.
- Membership records — who belongs to which vault, at what access level, and the status of invitations.
- Technical logs — our host records requests (IP address, timestamp, page) for a short period, to keep the service running and to investigate abuse.
We do not collect payment details, because nothing is sold. We do not buy data about you, and we run no advertising.
3Cookies, and the absence of tracking
Famvaults sets cookies for exactly one purpose: keeping you signed in. They are strictly necessary for the service to function, which is why you are not asked to consent to them.
There are no analytics, advertising, or social-media tracking cookies, and no third-party scripts run on these pages. Our display typeface is served from our own domain rather than from Google Fonts, so loading a page does not disclose your visit to a third party.
4What being a beta changes
Famvaults is unfinished software offered free of charge, and a privacy policy that did not say so would be describing a different product. Specifically, while the beta runs:
- Email addresses are not verified. An account can be opened with any address, including one that is not the registrant’s. The address on an account is therefore a label rather than something we have confirmed. Joining an existing vault still requires a signed invitation from its owner, so this does not expose anyone’s vault.
- End-to-end encryption covers wiki articles. Where a vault passphrase is set, article titles and text are sealed in your browser and we cannot read them. Family tree entries, chat messages, the daily questions a family writes for itself, and photographs arenot yet end-to-end encrypted: they are encrypted in transit and at rest by our providers, which means we could in principle access them. We will update this page when that changes, rather than claim it early.
- Password resets are unreliable. We do not yet run our own mail domain, so reset emails go through a shared pool and are often delayed or filed as spam. If you cannot reset, write to us.
- Our practices are still developing. We hold no security certification (no SOC 2, ISO 27001, HIPAA business associate agreement, or PCI scope) and cannot enter compliance commitments of that kind. See section 6.
- We may end the beta. If we do, account holders get at least 30 days’ notice and the export tools keep working throughout, after which vaults may be deleted.
5Information about other people
This is the part most family archives overlook. A vault is, by its nature, full of personal information about people who are not you — relatives, children, and people who have died. Some of it may be sensitive: health, religion, ethnicity.
If you create or upload that information, you are responsible for having a proper legal basis to do so, and for meeting the obligations that come with it. In practice that means: tell living relatives what you are recording about them, do not publish anything they have asked you not to, take particular care with information about children, and remove anything a person reasonably objects to. Where data protection law treats you as the controller of that content, those duties are yours and we cannot discharge them for you.
If you believe a Famvaults vault holds information about you and you want it removed, contact us. We will pass the request to the vault owner and help resolve it — but because vaults are private, and in the case of wiki articles encrypted with a key we do not hold, we usually cannot find, read, correct or delete the specific content ourselves. The owner has to act, and we will press them to.
6What should not be kept here
Famvaults is built for a family’s own records. It is not a certified, audited or regulated system, and we can offer no compliance assurance for one. Please do not store:
- payment card numbers, bank credentials, or passwords to other services;
- national identity, passport or tax numbers you have no family reason to keep;
- medical, legal or financial records that a law, a contract or an employer requires to be held in a certified, audited or regulated system;
- anything you are under a professional duty of confidence to protect — a client's, a patient's, or an employer's records;
If you store such records anyway, you do so on your own assessment and at your own risk, and the responsibility for any consequence is yours. The Acceptable Use Policy says the same thing from the other direction.
7Who can see your vault
Only you and the members you invite. Isolation is enforced in the database itself, per row, so a request for another family’s content returns nothing rather than relying on the application to remember to check.
Photographs and images live in private storage. They are never served from a public address; each view is granted a link that expires after four hours, so a copied link stops working.
Publishing a vault to the open web is switched off for the entire beta. No vault is reachable by a stranger or indexed by a search engine.
Our staff do not read vault content. Access is limited to the small number of people who maintain the service, and only where necessary to fix a fault you have reported or to meet a legal obligation. For wiki articles under a vault passphrase this is not merely a promise: we hold no key and could not read them if we were asked to.
Encryption cannot, however, protect against a device someone else can use, a passphrase that is easy to guess, or a member you invited who turns out to be the wrong person to trust. Who holds access to your vault is your decision.
8Where it is stored, and who processes it
Your data is held by the providers below. Each is bound to process it only on our instructions. This means some data is transferred outside Singapore; those transfers rely on the providers’ standard contractual clauses. We use these providers’ free or standard tiers, and their availability is outside our control.
Database, authentication, and file storage — this is where your vault lives.
Hosting. Serves the application and keeps short-lived request logs.
Delivers transactional email — invitations, password resets. Nothing marketing.
If we add a processor, this list changes in the same release. We may also disclose information where the law requires it — a valid court order, for instance — and will tell you unless we are prohibited from doing so.
9How long we keep it
Vault content is kept until you delete it. Deleting your vault removes its content and files from our live systems immediately, and from our providers’ backups within 30 days. Deletion is permanent: we cannot restore a vault for you afterwards, and for encrypted articles we could not read them back even if the rows survived.
Technical logs are kept for a short period, typically under 30 days. Where the law requires us to retain something longer, we keep only that and nothing more.
10Your rights
Under Singapore’s Personal Data Protection Act — and under the GDPR if you are in the UK or EEA — you may ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your data;
- restrict or object to how we use it;
- withdraw consent, where we relied on it.
Two of these you can exercise immediately, without asking us: export your entire vault from Settings, and delete it from the same page. Those tools are the fastest route and they do not depend on us answering an email.
For anything else, email hello@famvaults.com. We aim to respond within 30 days; where a request is complex, or where it concerns content inside someone else’s vault and we must reach its owner, we may need longer and will tell you why, to the extent the law allows. We may ask you to confirm your identity before acting, so that we do not disclose a family’s records to the wrong person. If you are unhappy with our response you may complain to your local data protection authority — in Singapore, the Personal Data Protection Commission.
Requests about content inside a vault are usually the vault owner’s to answer, for the reasons in section 5. We will forward them and help.
11Security, honestly stated
Data is encrypted in transit and at rest. Wiki articles under a vault passphrase are additionally encrypted in your browser, under a key we never receive. Access between vaults is blocked at the database row level. File storage is private and served only through short-lived signed links. Passwords are hashed by our authentication provider and are never visible to us.
No service can promise perfect security, and Famvaults is a beta run by a very small team. We do not warrant that the service is secure or error-free, and you should weigh that before entrusting it with something irreplaceable. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires. Please tell us at once if you find a vulnerability — we will not pursue anyone who reports one in good faith.
12Children
Accounts are for people aged 13 and over. Famvaults is not directed at children, and we do not knowingly collect account information from anyone younger. Family records naturally describe children, and often should — that is the vault owner’s responsibility under section 5, and it deserves more care than any other kind of entry.
If you believe a child has opened an account, or that a vault holds information about a child that should not be there, write to hello@famvaults.com and we will act.
13Changes
If we change this policy in a way that materially affects you, we will notify account holders before it takes effect. The date at the top of this page always reflects the current version. See also our Terms of Service, which set out what the beta does and does not promise, and the limits of our liability.