Privacy Notice
Shared history, handled carefully
Notice version 2026-08-24 · Last updated August 24, 2026
Who operates Our Story
GBEC, LLC operates Our Story. Its mailing address is 8 The Green, Suite #8218, Dover, DE 19901, United States. The monitored inbox for privacy, custody, and notice questions is contact@our-story.co.
Information the product handles
Account data includes the identity, email address, display name, and authentication records needed to sign in and participate. Our Story uses an opaque internal account ID so family content does not depend on a reusable authentication-provider ID.
Family archive data can include people and relationships, living-person status, dates and places, records, memories, photographs, audio, citations, evidence, narratives, invitations, roles, claims, and activity attribution.
Billing data includes the internal sponsor and plan state, Stripe customer and subscription identifiers, paid-period dates, consent versions, and usage totals. Payment-card details are collected and managed in Stripe-hosted Checkout and the Stripe Customer Portal, not in Our Story's application database.
How information is used
Information is used to authenticate members; operate, secure, and support family vaults; enforce roles and privacy choices; process uploads, exports, and requested AI work; meter plan allowances; manage billing and custody; send service notices; and carry out account, privacy, and deletion requests.
When a member requests an AI action, the content needed for that narrative, extraction, OCR, or transcription job is sent to the configured AI service. AI is available only when both the product release switch and the vault entitlement allow it. Completed results can be shared with authorized members of that vault.
Who can see or process information
Family content is visible to members of that family according to their role and the vault's privacy settings. Owners manage membership. A Professional sponsor can manage assigned client vaults until handoff; an accepted handoff makes the recipient an owner without transferring payment details.
The launch service uses Clerk for identity, Stripe for hosted billing, Resend for service email, Neon for relational data, Vercel for application and private object hosting, and configured AI services for member-requested AI work. Each receives the information needed for its part of the service.
The current application contains no third-party advertising integration. Service providers and authorized support processes are not family members and do not receive family ownership or custody rights.
Storage, metering, and service records
Uploaded original bytes count toward the visible storage allowance. Generated variants are metered internally. Soft-deleted media continues counting until its 30-day purge. Private full-vault export ZIPs expire after seven days and do not count against the family's storage allowance.
Security, webhook, outbox, consent, audit-attribution, and billing records are kept as needed to operate and reconcile the service. Stripe customers, invoices, and transaction records can be retained for financial-record obligations after product access ends.
Account deletion
Account deletion removes the login, access, direct identifiers, memberships, pending claims, and person claims. It revokes pending invitations created by that account and cancels queued work initiated by it. A later sign-up with the same email creates a new account with no inherited access.
Deletion does not automatically erase shared people, relationships, records, memories, media, evidence, narratives, or completed family decisions. Historical contributions that remain in the vault use a non-identifying tombstone and render as “Former family member.”
Vault deletion and custody recovery
A vault scheduled for deletion becomes read-only and enters a 30-day recovery period. Members are notified. An existing editor may submit a reverified custody claim; other members have seven days to contest it. An uncontested eligible claim restores ownership, while competing claims pause purging for support review.
Purging first removes the complete private object prefix, including unregistered objects, and then removes or tombstones relational family data. Failed object cleanup pauses database deletion so private files are not silently orphaned. Nonpayment alone never starts the vault-deletion clock.
Backup and recovery copies
Deletion from the active product does not immediately erase backups, security logs, or provider recovery copies. Those copies are not available through normal product interfaces and age out through the applicable backup and provider-retention cycles. Our Story does not promise immediate backup erasure or storage forever.
Your controls and requests
Owners can export GEDCOM data and request a full-vault ZIP while access is active or read-only. Members can use account settings to review membership impact and delete their account after reverification.
Account deletion is not permission to silently rewrite shared genealogy. A signed-in family member can separately request review, correction, restriction, or redaction of information about a living person. An open request pauses destructive vault purging until review is complete.
Submit a living-person privacy requestQuestions
Contact contact@our-story.co about privacy, custody, or this notice. See the Terms of Service for product and subscription terms.