Privacy policy
GeneaRoute is designed to keep private family research controlled, source-aware, and separate from public provider data.
Who operates GeneaRoute
Flygon LC operates GeneaRoute. Questions and privacy requests can be sent to privacy@flygonlc.com.
Data we process
We process account details, secure password hashes, session records with a coarse browser and device label but no stored raw IP address, optional encrypted authenticator secrets, hashed recovery codes, short-lived MFA challenge records, subscription and billing identifiers, API usage including per-key monthly route and AI-action caps and counters, research queries, research cases and tasks including user-selected Evidence Gap, evidence-quality, proof-standard, and Brick Wall Plans, private research coverage plans and their recorded online, manual, or offline results, researcher-entered source, information, evidence, and shared-origin classifications, private quality and analysis notes, recurring Research Watch settings and run history, customer-configured webhook endpoint URLs and encrypted signing secrets, sanitized project events and delivery history, saved evidence, project notes, uploaded GEDCOM contents, integrity-hashed and compressed private tree checkpoints with their restore ledger, staged agent change-set operations and human review reasons, project invitation email addresses, roles, delivery status, expiry and acceptance history, optional professional engagement labels, internal references, objectives, due dates, contracted minutes, researcher-entered time records and billable flags, optional private document analyses, AI research briefs and saved Connection Explanation plans, optional private DNA kit and match metadata, review-link metadata, family suggestions, support or privacy messages and their attachments, and security logs needed to provide the service.
Private project invitations
A project owner may invite an email address as an editor, contributor, or viewer. GeneaRoute stores the normalized recipient address, role, inviter, delivery status, expiry, and acceptance status. Resend receives the address and invitation contents to deliver the service email. Pending access expires after 14 days and can be resent or revoked by the owner. Access activates only when a GeneaRoute account controls and verifies the exact invited address. Invitations and their history are included in the project owner's account export and are deleted with the project or owner account, subject to limited security and legal records.
Professional Engagement Ledger
A Professional project owner may optionally record a client or matter label, internal reference, research objective, status, due date, contracted minutes, and time entries. Client email, payment-card information, and contract documents are not required by this feature. Project collaborators can see the ledger according to their project role; owners, editors, and contributors can record time while Professional access is active. An owner-configured Genealogy Event Hook may receive professional workflow IDs, status, due date, contracted minutes, work date, minutes, category, billable flag, and operation. Those event payloads exclude the client or matter label, internal reference, objective, time description, and researcher name. The ledger remains readable, exportable, and deletable after a downgrade and is included in the private research packet and account export. An owner can delete the ledger and all of its time entries at any time. It is also deleted with the project or owner account, subject to limited business and legal records.
Public and private sources
Public provider searches retrieve public profiles or records. GEDCOM imports and saved projects are private to the account by default. A user may intentionally create an unlisted review link. New links store a sealed snapshot of the shareable packet, its creation time, and a SHA-256 fingerprint so later project edits do not change what the recipient was invited to review. That view includes only deceased people marked Family or Public, their non-private claims, and linked citation details. It excludes living people, private people and claims, notes, media, AI prompts, DNA metadata, and account data. The recipient can download the same privacy-filtered snapshot as JSON while the link remains active. A visitor may optionally send the project owner a private correction, memory, or source. We store the visitor name, optional email, note, optional source link, a one-way network identifier used for abuse prevention, and moderation status.
DNA evidence metadata
A user may optionally keep a private research log containing a test-kit label, provider, test type, linked tree person, private notes, match label, shared centimorgans, segment counts, predicted relationship, hypothesis, and evidence summary. GeneaRoute can deterministically compare linked match endpoints with recorded and explicitly biological private-tree paths, including citation coverage and pedigree-collapse signals. This comparison is not sent to an AI provider. Private research-packet and proof-dossier exports include the entered match metadata and documentary correlation, so review those files before sharing them. GeneaRoute does not accept or store raw genotype files, chromosome data, DNA sequences, markers, or haplogroups, and it does not calculate genetic relationship probabilities. DNA metadata is excluded from public search, Commons publication, and family review links, but it can identify or imply sensitive information about living people. Enter it only with appropriate authority and use non-identifying match labels when possible.
AI processing
When a user explicitly agrees to Evidence Q&A, the question and minimized project evidence are sent through Flygon LC's Vercel AI Gateway to the selected model provider. GeneaRoute automatically excludes living and unknown-status people, their dependent claims and relationships, and unrelated sources from that evidence snapshot. The question itself is sent as the user writes it. The model can reference only supplied source IDs or URLs; GeneaRoute filters unsupported references, attaches the exact saved online or offline sources after generation, and records a hash of the evidence snapshot used. When a signed-in user requests a WikiTree Connection Explanation, GeneaRoute sends only the already privacy-filtered public deceased route steps, their reported relationships, dates, places, and certainty labels. Profile URLs are withheld from the model and attached deterministically after generation. If the user selects a project, GeneaRoute stores the explanation privately as an explicitly unproven research hypothesis, route context, and verification tasks. It does not add or change a person, fact, relationship, or public profile. Separately, Evidence Lens and document-to-tree review can send a private image, PDF, text document, or user-supplied transcription through Flygon LC's Vercel AI Gateway only after the user gives an explicit acknowledgment. Document analyses, quoted candidate claims, review decisions, and token metadata are saved privately so the result survives a refresh and remains exportable. AI output is instructed to flag uncertainty and never apply a claim or relationship automatically. A fact, alternate name, or relationship is added only after the user matches the affected people and accepts it, but the underlying AI output can still be incomplete or wrong.
A Brick Wall Plan is optional and consent-gated. It sends one private research case, its supplied hypotheses, evidence, searches, tasks, source metadata, and FAN Club appearances through Vercel AI Gateway. GeneaRoute refuses a living focus person and omits linked living associates. The plan, references, token metadata, and consent time are stored privately and remain exportable. Repository suggestions require verification. Plans never edit the tree; only human-selected strategies can become private tasks.
Tree Triage source search and deterministic commands work without AI. Optional source synthesis and ambiguous chat interpretation use Flygon LC's Vercel AI Gateway only when the user checks the private-processing acknowledgment for that request. GeneaRoute blocks AI and external public-provider routing while the highlighted person is marked living; only private GEDCOM and GeneaRoute's internal Commons index are checked for that person. For a deceased focus, the optional AI workflow sends only selected facts, public provider matches, public source links, limited triage counts, and the user's message as applicable, and excludes private provider matches, private GEDCOM details, private candidate names, unrelated tree people, notes, media, DNA metadata, and source excerpts. Each permitted attempt stores a metadata-only receipt containing the feature, model, status, token counts, consent time, sent and excluded data categories, and a SHA-256 hash of the minimized AI input. The receipt does not store another copy of the prompt or output and remains included in the account export.
Subprocessors, payments, and vendors
Stripe processes payment card details. GeneaRoute stores Stripe customer and subscription identifiers, not complete card numbers. Railway hosts the application and database. Resend delivers verification, password reset, and service emails when configured. Cloudflare R2 stores private copies of inbound support and privacy-request attachments, and Cloudflare Turnstile may process limited browser and network signals to protect signup and account recovery from automated abuse. Vercel AI Gateway routes optional AI requests. Connected genealogy providers process searches under their own terms.
Research Watches
A Research Watch periodically sends its saved query to the public or account-connected providers selected by the user. GeneaRoute stores a private baseline of provider record identifiers and a run history so it can distinguish later, never-seen possible matches. Alert emails report a count and the watched sources, not the full provider records. Watches consume normal search allowance, can be paused or deleted, and never change the family tree automatically.
Genealogy Event Hooks
A project owner may configure a customer-controlled public HTTPS endpoint to receive sanitized tree, research, family-suggestion, and agent-review events. Delivery payloads include project, event, aggregate, and change identifiers plus limited state metadata. They exclude names, notes, citations, excerpts, DNA details, private files, and living-person attributes. GeneaRoute encrypts each endpoint signing secret, reveals it only at creation or rotation, signs the exact outgoing body, follows no redirects, blocks private and reserved network destinations, and keeps bounded retry and response-status history. The customer controls the destination and is responsible for its security, retention, recipients, and lawful processing. Pausing or deleting an endpoint stops future delivery; deleting it also deletes its delivery history.
Research Coverage Matrix
The matrix stores a private plan for repositories, record groups, jurisdictions, date windows, queries, selected providers, name variants, objectives, and result summaries. A user can reconcile a line to a GeneaRoute research-journal run or record a manual or offline archive result. Planning and manual entry do not send the coverage matrix to an AI provider. Only a separate routed search sends its query to the providers the user selects. Coverage progress documents recorded work; it does not certify an exhaustive search, prove an unavailable collection was checked, or prove that no historical record exists after a zero-result search. Coverage is included in private research packets and account exports, so review those files before sharing them.
Family Group Evidence Sheets
A sheet is generated on request from the people, recorded parent and partner relationships, facts, and citations already stored in a private project. This deterministic export is not sent to an AI provider and does not change the tree. GeneaRoute assigns a child to a recorded union only when both parent links exist; otherwise the child remains visibly unassigned. Sheets can contain living-person and private data, so review them before downloading, printing, or sharing.
Evidence Maps
An Evidence Map is generated on request from one private-tree person, that person's claims and relationships, their citation links, and researcher-entered shared source-origin labels. This deterministic graph is not sent to an AI provider and does not change the tree. Its edges show recorded project links, not proof, reliability, source independence, or historical truth. Maps can include living-person and private details and can be downloaded as JSON, Markdown, or Graphviz DOT, so review them before sharing.
Identity reviews
The Identity Resolution Lab compares two private profiles using the claims, citation links, family relationships, living status, and FAN Club appearances already stored in the project. A researcher may save a same-person or different-people conclusion, its reason statement, the evidence snapshot, and a hash used to detect later changes. This deterministic comparison is not sent to an AI provider. GeneaRoute requires a current same-person review before its web workspace will merge the profiles.
Cross-provider identity mappings and world-tree bridges
The Cross-Provider Identity Hub compares one private tree person to one provider profile already saved in the project. GeneaRoute stores the human same-person or different-people decision, its reason statement, and a comparison snapshot used to detect later tree, citation, or saved-profile changes. The comparison is deterministic and is not sent to an AI provider. A mapping does not copy provider claims into the private tree. A Reviewed World Tree Bridge can start only from a current same-person mapping between a deceased private person and a public WikiTree profile. GeneaRoute sends WikiTree only the reviewed public start key, public target key, and route mode. The private person ID, facts, citations, notes, files, DNA metadata, research history, and review reason are not included in that provider request. The resulting path is stored only in the current browser response unless the user separately asks the Connection Explainer to save a private research plan.
Source Integrity Monitor
When a user checks or monitors a cited public URL, GeneaRoute retrieves that public resource from its current host, blocks private and local network destinations, and stores cryptographic content fingerprints, response metadata, availability status, and check history. Fetched page contents are not retained by the monitor. A user may save a reason statement when accepting a changed fingerprint as the new baseline. Recurring checks can be disabled, and deleting the source deletes its monitor history.
Tree checkpoints
The Tree Time Machine stores a compressed private snapshot of people, relationships, claims, sources, citation links, places, and place aliases, plus a cryptographic integrity hash, counts, name, description, and restore history. It excludes uploaded files, DNA metadata, discussions, research cases, billing records, provider credentials, and other non-tree workspace data. A comparison is deterministic and is not sent to an AI provider. Guarded restore updates only records and citation links that still exist with the same identifiers; it refuses automatically after structural additions or removals. A restore requires a human reason, is recorded in an immutable ledger, and prevents deletion of the checkpoint used for that restore. Users can download portable checkpoint JSON, and deleting the project or account deletes its checkpoints subject to any legally required business records.
Agent change sets
An API key or compatible agent can save a private proposed batch of new people, facts, sources, relationships, and citation links. The proposal, rationale, local references, exact field preview, citation coverage, content fingerprint, proposing key identifier, label and masked prefix, status, human review reason, reviewer, and applied identifiers remain in project history and the account export. The raw key is never stored. Proposing and listing a batch does not change the tree. Only a signed-in project owner or editor can accept or reject it. Acceptance first verifies that the proposed contents still match the stored fingerprint, then applies the entire batch atomically or applies none of it. Applied audit rows retain the proposal and key identifiers. GeneaRoute does not send these deterministic operations to an AI provider unless the user separately invokes an AI feature.
Retention and controls
Account data is retained while the account is active and as needed for security, billing, dispute resolution, and legal obligations. Evidence classifications are entered by the researcher and are not inferred as a reliability score. Private quality notes are excluded from no-account family review links but included in the account owner's structured export. Review links and their sealed snapshots expire after the period selected by the user and can be revoked immediately. The snapshot remains in the owner's account export and is deleted with the project or account. Suggestions already submitted remain in the owner's private project until dismissed or the project or account is deleted. Users without an active subscription can permanently delete their account and private workspace data from the workspace. Billing records that Flygon LC must retain may remain with Stripe or in limited business records.
Living people and children
Do not publish living-person details or enter another person's DNA match metadata without appropriate authority. GeneaRoute is not directed to children under 13. Paid subscriptions must be purchased by an adult or an authorized organization.
Security
Passwords are stored using salted one-way hashes, sessions use secure HTTP-only cookies, and customer API keys and review-link secrets are stored as hashes. Account owners can review coarse browser and device labels, distinguish the current browser, and revoke one or every other active session. Optional authenticator MFA stores the TOTP secret encrypted at rest and stores recovery codes only as one-way hashes. MFA login challenges expire after ten minutes, stop after five unsuccessful attempts, and reject reuse of a previously accepted TOTP time step. Enabling or disabling MFA revokes other sessions. Paid checkout requires a verified email, current legal acceptance, and MFA. Password reset does not disable MFA. Access checks are enforced close to private data. Anyone who receives an active review address can open its privacy-filtered contents, so users should revoke a link that reaches the wrong person. No online service can promise absolute security.
Changes
Material changes will be posted here with a revised effective date. Continued use after a change means the updated policy applies going forward.
Effective September 1, 2026. Product policy, not a substitute for advice from privacy counsel.
