Privacy Policy
Last updated 6 September 2026
Your vault is private. We collect the little we need to run the service, we store it encrypted, we do not sell it, we do not advertise, and there are no tracking cookies on this site. You can export everything or delete everything, yourself, at any time.
1Who is responsible
Famvaults, based in Singapore, is the data controller for account information and for the operation of the service. You can reach us at hello@famvaults.com.
For the content inside a vault, the vault owner decides what is collected and who sees it. We process that content on their behalf. See section 4, which matters more than it might first appear.
2What we collect
- Account information — your email address, a display name if you give one, and an encrypted password hash. We never see your actual password.
- Vault content — the articles, photographs, family tree entries and files you and your members create.
- Membership records — who belongs to which vault, at what access level, and the status of invitations.
- Technical logs — our host records requests (IP address, timestamp, page) for a short period, to keep the service running and to investigate abuse.
We do not collect payment details, because nothing is sold. We do not buy data about you, and we run no advertising.
3Cookies, and the absence of tracking
Famvaults sets cookies for exactly one purpose: keeping you signed in. They are strictly necessary for the service to function, which is why you are not asked to consent to them.
There are no analytics, advertising, or social-media tracking cookies, and no third-party scripts run on these pages. Our display typeface is served from our own domain rather than from Google Fonts, so loading a page does not disclose your visit to a third party.
4Information about other people
This is the part most family archives overlook. A vault is, by its nature, full of personal information about people who are not you — relatives, children, and people who have died. Some of it may be sensitive: health, religion, ethnicity.
If you create or upload that information, you are responsible for having a proper basis to do so. In practice that means: tell living relatives what you are recording about them, do not publish anything they have asked you not to, take particular care with information about children, and remove anything a person reasonably objects to.
If you believe a Famvaults vault holds information about you and you want it removed, contact us and we will pass the request to the vault owner and help resolve it.
5Who can see your vault
Only you and the members you invite. Isolation is enforced in the database itself, per row, so a request for another family’s content returns nothing rather than relying on the application to remember to check.
Photographs and images live in private storage. They are never served from a public address; each view is granted a link that expires after four hours, so a copied link stops working.
Publishing a vault to the open web is switched off for the entire beta. No vault is reachable by a stranger or indexed by a search engine.
Our staff do not read vault content. Access is limited to the small number of people who maintain the service, and only where necessary to fix a fault you have reported or to meet a legal obligation.
6Where it is stored, and who processes it
Your data is held by the providers below. Each is bound to process it only on our instructions. This means some data is transferred outside Singapore; those transfers rely on the providers’ standard contractual clauses.
Database, authentication, and file storage — this is where your vault lives.
Hosting. Serves the application and keeps short-lived request logs.
Delivers transactional email — invitations, password resets. Nothing marketing.
7How long we keep it
Vault content is kept until you delete it. Deleting your vault removes its content and files from our live systems immediately, and from backups within 30 days.
Technical logs are kept for a short period, typically under 30 days. Where the law requires us to retain something longer, we keep only that and nothing more.
8Your rights
Under Singapore’s Personal Data Protection Act — and under the GDPR if you are in the UK or EEA — you may ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your data;
- restrict or object to how we use it;
- withdraw consent, where we relied on it.
Two of these you can exercise immediately, without asking us: export your entire vault from Settings, and delete it from the same page.
For anything else, email hello@famvaults.com. We will respond within 30 days. If you are unhappy with our response you may complain to your local data protection authority — in Singapore, the Personal Data Protection Commission.
9Security, honestly stated
Data is encrypted in transit and at rest. Access between vaults is blocked at the database row level. File storage is private and served only through short-lived signed links. Passwords are hashed by our authentication provider and are never visible to us.
No service can promise perfect security, and Famvaults is a beta. If we discover a breach affecting your personal data, we will notify you and the relevant authority as the law requires. Please tell us at once if you find a vulnerability — we will not pursue anyone who reports one in good faith.
10Changes
If we change this policy in a way that materially affects you, we will notify account holders before it takes effect. The date at the top of this page always reflects the current version. See also our Terms of Service.