HOUSEMARK / YOUR ACCOUNT
Privacy Policy
About HOUSEMARK
HOUSEMARK is a mobile family identity and social service. This policy describes how the service handles your information. Updated: 8 October 2026.
Account and identity information
We store your email address, display name, date of birth for adult eligibility, accepted terms version and account status. Password accounts use Argon2 password hashes. Google or Apple sign-in stores the provider identity and email when supplied. Apple authorization grants needed for account revocation are encrypted on the server. We keep hashed session and verification/reset tokens, device-session labels and expiry/revocation records. Optional information includes a profile photo, native name and current location entered by you.
Family, membership and social information
We process House and branch membership requests, invitations, self-placement claims, relationships, review history, visibility settings, family records, community and Circle memberships, posts, replies, event details, follows, reports, blocks and appeals. A surname match is a search aid and does not establish kinship. Living-person and minor records use server-enforced privacy controls. Choose an audience carefully: public content can be seen or copied by others. Private or selected-audience content is checked by the server on each request.
Evidence, archives and historical sources
Uploads can contain photos, documents, audio, video and private credential or family evidence. The server quarantines files, scans them for malware, validates supported formats and processes media before making it available. Image metadata is stripped during processing. Evidence is available to its owner and authorized reviewers, rather than being published with an achievement. Historical claims, place photos and imported reference records retain provenance where supplied. Public-source data is a reference and can be incomplete or disputed; corrections can be requested through support.
Standing and sponsored visibility
Reviewed credentials may become achievements with the visibility you selected. Credential values contribute to House Standing only where aggregate consent is enabled, the credential remains eligible and membership is active. We store store-product identifiers, transaction identifiers, purchase/verification dates and sponsorship expiry or revocation. Apple and Google process payments; HOUSEMARK does not collect payment-card details. Sponsored placement is labeled and does not change earned Standing.
Devices, notifications and service records
If you allow push, the server stores a push token against your device session and sends generic notifications and app routes through Firebase Cloud Messaging. Apple push delivery is configured through Firebase. Your saved preferences control supported notification types and scopes. The app caches permitted responses and media locally; logging out clears account caches and session storage. Request IP information and operational or security logs help protect and run the service. Audit records document administrative actions. HOUSEMARK does not implement an advertising identifier or cross-app tracking system.
Storage and service providers
PostgreSQL stores application records; private MinIO storage holds uploaded objects, exports and managed catalog/source files. Typesense holds a derived directory that excludes living-person names from genealogy indexing. Redis carries queues and temporary security state. Configured SMTP delivers verification/reset email; Google and Apple verify their sign-in and purchase flows; Firebase delivers push. A professional-registry lookup sends the reference you provide to that registry and supplies evidence for manual review. A registry match does not verify that the account belongs to the named professional. Contact support with questions about storage locations and service providers.
Retention, export and deletion
Account and contribution records are retained while needed to provide the service unless removed through applicable controls. You can generate Download My Data in Profile. Export access expires seven days after generation and maintenance removes its live object. Quarantined uploads are bounded by upload allowances and rejected after exhausted processing retries or 24 hours of staleness. Delete Account revokes sessions immediately and queues deletion of account identity, memberships, personal family records, authored posts/replies, contributed archive records and owned media. The worker revokes Apple authorization when applicable. Minimized security/audit records and anonymized transaction records can remain. Protected backups use the configured retention schedule, with a 30-day default; deleted data can remain in backups until expiry. Retention exceptions may apply to records required for security or legal obligations. A restoration must reapply outstanding deletion and expiry jobs before public service resumes.
Your choices and contact
Use Profile to edit privacy, notifications, connected accounts and blocked users; download data; or delete your account. Report content in the app and contact [email protected] for privacy requests, corrections or access problems. Do not email passwords or private evidence unless support provides an approved secure route. HOUSEMARK is intended for adults; family archives may contain minor records, which receive restricted disclosure controls. Contact support to exercise applicable data rights.