GeneaDesk
Privacy

GeneaDesk Privacy Policy

GeneaDesk processes only the data needed for sign-in, quotas, abuse protection and account operation. Genealogy material stays local in the browser.

GD
Data we process

GeneaDesk Cloud data

Account

Your verified email address and Google account subject identifier when Google sign-in is used.

Installation and session

A hash of a random installation identifier, the GeneaDesk device identifier and a hash of the session token. GeneaDesk does not create a hardware fingerprint.

Quotas and security

Aggregate download counters, job reservations, offline event identifiers, OTP login records and a hashed request-source identifier used for abuse protection.

Local data

What stays in Chrome

GeneaDesk stores language and delay preferences, task-resume state, the last verified FamilySearch scan, the installation identifier, the signed offline entitlement and the pending offline-usage queue locally. The GeneaDesk session token is kept only in memory using chrome.storage.session and is cleared when Chrome closes or the extension is reloaded or updated.

Google sign-in

The Google token is used only for sign-in

During Google sign-in, Chrome provides GeneaDesk with a short-lived Google access token. The backend uses it only to verify identity and create a GeneaDesk session. The Google access token is not stored in the GeneaDesk database.

What we do not send

Genealogy content stays local

GeneaDesk Cloud does not receive FamilySearch images, genealogy document contents, FamilySearch cookies, passwords or full URLs of viewed documents. Scan handling and downloading happen locally in Chrome.

Installation quota

Protection against quota bypass

Quotas are checked for both the account and the extension installation. Changing accounts in the same installation does not reset quota usage. This uses only a hash of a random installation key, not computer hardware data.

Retention

How long data is kept

OTP

One-time login-code records are removed after about 24 hours.

Usage

Hourly aggregates are kept for up to 30 days, daily aggregates for up to 365 days, and completed job reservations for up to 90 days.

Sessions and audit

Expired or revoked sessions are cleaned up, and administrator audit records are kept for up to 365 days.

Providers

External services

GeneaDesk uses Cloudflare for the API and database, Google for sign-in, and Resend to send one-time email codes. Optional project support opens the external BuyCoffee website only after the user clicks the support link.

Chrome Web Store Limited Use

Limited use of data

Use of information received from Google APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only for the GeneaDesk features described in this policy and is not sold, used for advertising, or shared for marketing profiling.

Your data

Access and deletion

You can request an export or deletion of account data. Until self-service is added, requests are handled manually after identity confirmation using the verified email address. Send requests to support@geneofy.pl from the email address associated with your GeneaDesk account.

Update

Policy version

Effective October 2, 2026. This policy will be updated if GeneaDesk changes the data it processes or its functionality.