1. Introduction
FamiVox is developed and operated by Kannaiyan Natesan ("we", "our", or "us"), an independent developer based in India. We are committed to protecting your privacy. This Privacy Policy explains what information FamiVox collects, why, how it is stored and used, and what controls you have.
For the purposes of applicable data protection laws — including the Indian Digital Personal Data Protection Act 2023 (DPDP) and the EU General Data Protection Regulation (GDPR) — Kannaiyan Natesan is the data fiduciary / data controller responsible for your personal data.
1A. Sharing Principles — Your Tree Stays Within Your Consented Audience
The most important thing to understand about FamiVox is the boundary on tree sharing:
- Tree sharing happens only with your explicit, informed consent. Every account starts fully private. No part of your family tree is exposed to any other user, the public web, search engines, advertisers, or analytics providers until you take an explicit action to enable a sharing path.
- Sharing is bounded to relatives and friends — not to the general public. Two consent paths exist, and only these two:
- Family Access: people you explicitly invite by email-OTP to view or contribute to your tree (relatives and friends you know personally).
- Cluster Trees: other users whose trees demonstrably overlap with yours through corroborated common ancestors or the same phone number saved on the same person — making them your discovered relatives within the FamiVox graph. This path is OFF by default and requires a deliberate opt-in with a permanence notice.
- Your tree is never published. There is no public directory, no anonymous-browse mode, no SEO-indexable tree page, and no way for a non-authenticated visitor (or an authenticated user who has not earned access through one of the two paths above) to see your tree.
- Your tree is never sold or licensed to third parties for advertising, marketing, training AI models, or genealogy data resale. We do not run advertising. We do not place behavioural trackers. We do not have an analytics partner with access to your tree content.
- Cross-user matches are evidence-bounded. Even with Cluster Trees enabled, your data only links to another user's data when our system has strong, specific evidence that you are referring to the same human. Random surname matches alone do not trigger a link.
Sections 5, 6, 7, and 8 below describe these mechanisms in detail.
2. Information We Collect
2.1 Account information
- Email address. Required to create an account and receive sign-in OTPs.
- Sign-in identity tokens. If you use Sign in with Apple or Sign in with Google, we receive an opaque identifier that lets us recognise you on return logins. We do not receive your social account password.
- Display name. Optional, used inside the App to label your tree to people you have invited.
- Profile photo URL. Optional.
2.2 Family tree data
- Person records. First name, optional birth and death years, gender, family relationships (parent / child / spouse / sibling), notes, photos, and any life events you choose to record.
- Address records (SharedAddress). Optional location and family-name labels you can attach to one or more persons.
- Phone numbers and email addresses. Only if you use the optional Contact Link feature. See Section 6 for details.
- Device contacts. If you grant contact-access permission, the App reads your device address book to help you find family members already on FamiVox and to link contacts to persons in your tree. See Section 6 for how we handle this data.
- Multilingual name tokens. Names you enter are transliterated into multiple Indian scripts (en, hi, ta, te) for cross-language search. The transliteration is performed by an AI service (Anthropic Claude) under our paid commercial agreement; the AI provider is contractually prohibited from using your data to train models.
2.3 Authentication and security data
- Refresh tokens. Stored encrypted in our database; valid for 30 days from issue. Used to keep you signed in across app launches.
- Passkey (WebAuthn) credentials. Public-key credential records stored in our database; the corresponding private key never leaves your device.
- Device install identifier. A random per-install identifier we generate and bind to your access tokens (DPoP) so that a stolen token cannot be replayed from a different device.
- Device attestation results. On supported platforms (iOS App Attest, Android Play Integrity) we verify the integrity of your device when you sign in to make sure the App is genuine and not modified.
- FCM push token. If you allow push notifications, your Firebase Cloud Messaging token is stored so we can send you match-suggestion alerts and family-invite confirmations.
2.4 Audit and operational logs
- Every state-changing action (account create, person added, share invite issued, account deleted, etc.) is logged to a private audit pipeline.
- Audit records contain your user ID, the action taken, the time, and an IP address. IP addresses are encrypted using AWS KMS before being stored and can only be decrypted by us in response to a security incident or a lawful legal request.
- We do not log the content of your tree (names, relationships, photos) into the audit pipeline.
2.5 Usage and technical data
We collect minimal technical data required for the App to function: device platform (iOS / Android / macOS / Windows), App version, language preference, and approximate request timing. We do not use third-party analytics or behavioural tracking services. We do not place advertising trackers.
3. How We Use Your Information
- To create and maintain your family tree on your devices and on our cloud backend.
- To authenticate you across sessions and devices.
- To enable relationship search across the persons you have access to.
- To allow you to share your tree with specific people you invite.
- If you opt in to Cluster Trees, to automatically link your persons with other users' persons when there is strong evidence they refer to the same human (see Section 5).
- To deliver push notifications and emails you have opted into.
- To detect abuse, debug issues, and improve the App.
- To comply with legal obligations.
4. Legal Basis for Processing
- Consent: You consent when you create an account, when you turn on Cluster Trees sharing, when you link a contact, and when you accept push notification or location permissions.
- Contractual necessity: Processing is necessary to provide the App you signed up for.
- Legitimate interest: Security, abuse detection, debugging, and preventing fraud.
- Legal obligation: Where law requires retention or disclosure.
5. Cluster Trees and Cross-User Matching
FamiVox supports an optional feature called "Share my data anonymously" / Cluster Trees. The setting defaults to OFF and never auto-activates. Nothing about your tree leaves your account until you explicitly enable it from Settings → Data Sharing, and the App displays a clear permanence notice before flipping the toggle.
When and only when you turn this setting on, the persons you add to your tree from that point forward become candidates for automatic cross-user matching, subject to these strict bounds:
- Match scope is restricted to demonstrable relatives. A cross-user match only fires when our system has strong evidence — a corroborated ancestor chain, the same phone number saved on the same person by both of you, or the same email — that two persons across two trees are the same human. Random surname matches alone do not trigger a link. This is by design: Cluster Trees is a discovery-of-extended-family feature, not a public-profile system.
- Linked persons form multi-user SharedTree clusters. Within a cluster you will see contributions from other users on overlapping branches, and they will see yours. The cluster is bounded — random users with no evidence of relatedness do not appear in your cluster, and you do not appear in theirs.
- When other users see persons you contributed, you appear to them as "Contributor #N" using a one-way hash, not your name, email, phone number, or account identifier.
- Your tree is never made public. There is no anonymous-browse mode and no SEO-indexable view. Even another opted-in FamiVox user cannot see your tree unless they share a cluster with you through the evidence-based matching above.
- Sharing is treated as permanent by design — see Section 7 for the two narrow exits.
If you do not want any of this to happen, do not turn the setting on. You may use the App with the toggle OFF and still share your tree directly with specific people you invite (Section 8 / Family Access).
6. Device Contacts, Phone Numbers, and Email Addresses
6.1 Device Contact Access
FamiVox may request permission to read your device address book. This is entirely optional — the App works without it. If you grant permission:
- What we read: Contact names, phone numbers, and email addresses from your device address book.
- What stays on your device: Raw contact information (names, phone numbers, email addresses) is stored only on your device in an encrypted local database. It is never sent to our servers in readable form.
- What we send to our servers: Only one-way cryptographic hashes (SHA-256) of phone numbers and email addresses. These hashes allow us to check whether any of your contacts are already on FamiVox, without revealing the actual phone numbers or emails to our servers. The hashing is irreversible — we cannot recover the original phone number or email from the hash.
- Cross-device sync: If you link a contact to a person in your tree, the link data (name, phone, email) is encrypted on your device using AES-256-GCM with a key that only your devices possess. The encrypted blob is stored on our servers so your other devices (e.g. desktop) can download and decrypt it. Our servers cannot decrypt this data — only your devices can.
- No third-party sharing: Your contacts are never shared with third parties, advertising networks, or analytics services.
- You can revoke contact access at any time in your device Settings. Previously synced hashes remain on our servers until you delete your account.
6.2 Contact Link (Attaching a Contact to a Tree Person)
The optional Contact Link feature lets you attach a phone number or email to a person in your tree. Phone and email function as deterministic matching signals: if another user has saved the same phone number on a person in their tree, our system treats that as strong evidence the two records refer to the same human and may automatically link them subject to your share setting.
- You may not link the phone number of a person under 13 years old; the App will refuse the operation.
- You must not link the contact details of a living adult without their knowledge and consent. The App requires you to confirm consent for living people.
- The App enforces a per-user rate limit (currently 10 contact links per hour) to discourage misuse.
- Phone numbers stored via Contact Link are normalised to E.164 format and stored alongside non-reversible attestation records.
7. Permanent Sharing Model and Your Two Exits
Sharing your tree to the community graph is treated as a contribution akin to an open-source code commit or a Wikipedia edit. By design, you cannot retroactively un-share data through a single toggle. There are two narrow exits:
- Person soft-delete. If you delete a person you created, and you are the only user who has contributed that person to the community graph, the GlobalPerson is removed from the community graph along with your edge. If other users have also contributed that person, your edge is removed but their contribution stays — they continue to see that person from their side.
- Account deletion with a choice. When you delete your account you choose between:
- Donate — your shared contributions remain in the community graph, but your
userIdis replaced with an anonymised hash. Your direct contact details (email, FCM token, refresh tokens) are deleted. - Delete-where-possible — anything you alone contributed is deleted. Anything co-contributed by other users stays without your edge.
- Donate — your shared contributions remain in the community graph, but your
Personal account data is deleted within 30 days of an account-delete request, except where retention is required by law.
8. Family Access (Direct Sharing with Specific People)
Separate from Cluster Trees, you can directly invite specific people you know — typically relatives or close friends — to view or contribute to your tree. This path is consent-driven on both sides:
- You initiate the invite by selecting a specific person in your tree and entering an email address.
- The invitee receives a one-time password (OTP) by email and must explicitly accept the invite at sign-in. They can decline; declined invites expose nothing.
- You can revoke an invite or remove a member's access at any time via Settings → Family Tree Access. Revocation is immediate.
- Family Access is bounded to the people you invited. Invitees cannot share your tree onward to others without going through their own Family Access invite flow.
9. Data Storage, Location, and Security
- Your data is stored on managed cloud infrastructure (AWS) in the ap-south-1 (Mumbai) region in India.
- All data is encrypted in transit using TLS, with certificate pinning enforced by the mobile app to prevent man-in-the-middle interception.
- All data is encrypted at rest using AWS-managed encryption.
- Per-user encryption keys are used for sensitive cached payloads on your device.
- Authentication uses asymmetric cryptography (KMS-signed JWTs, DPoP per-request proofs, optional WebAuthn passkeys) to make stolen-token replay attacks infeasible.
- IP addresses recorded in audit logs are encrypted with AWS KMS before storage; they can only be decrypted by us in response to a security incident or a lawful legal request.
10. Data Sharing with Third Parties
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. We do not use behavioural tracking.
We use the following trusted third-party services to operate the App:
- Amazon Web Services (AWS) — cloud infrastructure (Lambda, DynamoDB, S3, CloudFront, EventBridge, KMS, EC2 hosting our Neo4j database) in the ap-south-1 (Mumbai) region.
- Anthropic Claude — name transliteration for multilingual search. Operates under a paid commercial agreement that prohibits training on your data.
- Firebase Cloud Messaging (Google) — push notification delivery.
- Apple App Attest / Google Play Integrity — device-integrity attestation only at sign-in.
- Apple / Google identity providers — only if you choose to sign in with Apple or Google.
- Amazon SES — sending OTP and family-invite emails.
- GitHub — code hosting (no user data).
These services process data only as necessary to provide their functionality and are bound by their own privacy policies and data processing agreements.
We may also disclose information when required by a valid legal process, court order, or to protect against fraud or harm.
11. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate information in your tree at any time directly inside the App.
- Delete your account and associated personal data, with the choice between Donate and Delete-where-possible for shared contributions (Section 7).
- Export your family tree data on request.
- Object to specific kinds of processing, where applicable.
- Withdraw consent at any time for processing that is based on consent (e.g. Cluster Trees sharing — though see Section 7 for what "withdrawal" means in practice).
- Lodge a complaint with the Indian Data Protection Board or your local supervisory authority if you believe your rights have been violated.
To exercise any of these rights, please contact us at support@famivox.com. We will respond within 30 days.
12. Moderation and Reporting
You may report inappropriate content within the App. Reports are stored in a moderation queue accessible only to authorised moderators. Reports are confidential. If multiple distinct users report the same content within 24 hours, that content may be automatically hidden pending moderator review. Moderator actions (hide, unhide, blacklist) are themselves audit-logged.
13. Children's Privacy
FamiVox is not directed at children under 13. We do not knowingly collect personal information directly from children under 13. The App refuses to link a contact (phone or email) to a person under 13 years old. If you believe a child has provided us with personal information directly, please contact us so we can take appropriate action.
You may add a child as a person in your family tree (this is a normal genealogy use case) but you are responsible for what you record about that child and you must not link contact details for them.
14. Data Retention
- Account and family-tree data: retained while your account is active.
- Refresh tokens: 30 days from last use, then expire.
- OTP codes and short-lived nonces: minutes to hours, then expire.
- Device attestation challenges: short-lived, expire after sign-in.
- Audit logs: retained for as long as required to investigate security incidents or as required by law (typically 1 year, KMS-encrypted).
- Backups: encrypted snapshots retained on a rolling basis (typically 7 days).
- On account deletion: personal account data deleted within 30 days; community-graph contributions handled per your Section 7 choice.
15. International Data Transfers
Your data is primarily stored in the ap-south-1 (Mumbai) region. Some operational data — such as push notification metadata going through Firebase — may transit through other regions operated by Google in the course of normal delivery. By using the App you consent to these transfers.
16. Security Measures and Limitation of Liability
We take security seriously and apply industry-recognised measures to protect your data — including TLS in transit with certificate pinning, AWS-managed encryption at rest, KMS-encrypted IP addresses in audit logs, per-request DPoP token binding, optional hardware-backed passkey credentials, device-integrity attestation at sign-in, and encrypted backups.
However, no system is perfectly secure. FamiVox is provided free of charge, on an "as is" and "as available" basis. While we take all essential security precautions, the developer shall not be held liable for any loss, corruption, unauthorised access, or unintended exposure of your data, including data lost through events beyond our reasonable control such as cloud-provider outages, third-party security incidents, force-majeure events, or compromises of your own device or sign-in credentials. To the maximum extent permitted by applicable law, you use the App at your own risk and waive any claim for damages arising from data loss or breach.
This limitation does not affect your statutory rights under the Indian Digital Personal Data Protection Act 2023 or other applicable laws. Mandatory legal protections that cannot be waived continue to apply. See also Section 15 (Limitation of Liability) of the Terms of Service for the parallel disclaimer.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App, on this website, or via email. The "Last updated" date at the top of this policy reflects the latest revision. Continued use of the App after changes constitutes acceptance of the updated policy.
18. Contact Us
If you have questions about this Privacy Policy or our data practices, including to exercise any of your rights, please contact:
Kannaiyan Natesan
Developer / Data Fiduciary, FamiVox
Email: support@famivox.com