Effective September 6, 2026

Privacy without fine print.

Family Tree begins as a private local archive. Cloud sync happens only when you choose to sign in and enable it.

Information stored by the app

You may enter names, relationships, dates, places, occupations, life stories, memories, and photographs. This information is stored inside the app’s protected container on your iPhone or iPad. It leaves the device only when you explicitly export a backup or choose cloud sync.

Photos, import, and export

The app accesses only the photographs or files you choose through Apple’s system pickers. A backup leaves the app only when you explicitly export or share it. When you import an archive, the app asks for confirmation before replacing the local family tree.

Accounts and cloud sync

You can sign in with Apple or Google. Firebase Authentication processes an account identifier and may receive your name and email address from the provider. When you enable sync, Google Firebase stores your family profiles, relationships, memories, photographs, and a user identifier.

This data is linked to your account only to authenticate you, protect the archive, synchronize devices, and connect a family tree when you choose that feature. Family Tree creates local recovery copies before applying downloaded changes and asks you to review competing edits.

Read-only family tree sharing

You may invite one other signed-in account to open a separate read-only family tree. Each participant continues to own and edit only their own private library. Accepting an invitation does not import people, relationships, memories, or photographs into the other account. Either participant can end the share, which removes access without modifying either private tree.

Service diagnostics

TestFlight and App Store builds use Firebase Analytics to measure coarse app flows and Firebase Crashlytics to diagnose crashes and unexpected errors. These services receive screen, sync, operation, and coarse failure-category data. Family Tree does not send family profiles, names, photographs, memories, account identifiers, invitation codes, or free-form error messages as custom telemetry.

Firebase Auth and Firestore may process diagnostic information that is not linked to you. The Google Sign-In SDK declares account and device-related information, coarse location, usage data, and other technical data for app functionality and service analytics. Family Tree does not use this information for advertising and does not track you across apps or websites. Google processes this information under its own privacy policy.

Apple may process App Store downloads, purchases, and optional diagnostic information under Apple’s own policies and your device settings. That processing is controlled by Apple, not by Family Tree.

Deleting your data

You can delete individual people and memories inside the app. A signed-in user can also open Cloud sync and delete their cloud account. After fresh Apple or Google authentication, the app deletes the Firebase Authentication account, personal cloud records, uploaded photographs, and access to connected shared trees.

The local archive remains on the device so an accidental account deletion does not erase the only copy. Deleting the app removes that local archive. Export a backup first if you want to keep a portable copy.

Children’s privacy

Family Tree is not directed to children and does not knowingly create accounts for them. Family information can include details about children when an adult chooses to record and synchronize them. The account holder controls that content and can delete it from the cloud in the app.