Privacy Policy | Roots Archive

Privacy Policy

Last Updated: June 2026
At Roots Archive, we believe that your family’s history is sacred. Our business model is fundamentally opposed to monetizing your personal data. This Privacy Policy outlines our strict commitment to protecting the historical records, photographs, documents, and storage credentials you entrust to our platform.

1. Our Core Privacy Promise

Roots Archive was created with a strong moral responsibility toward family history, private memories, and personal records. The site owner considers user privacy a matter of trust and dignity, not merely a technical feature.

Our promise: We do not sell, rent, trade, or monetize your family history, uploaded documents, photographs, or personal archive content. The site owner is committed to keeping user data private and treating family records with respect.

At the same time, this policy is written with technical honesty. Some features require storage credentials, user metadata, and external storage integration. Where technical access is possible, we explain it clearly instead of hiding it behind vague language.

2. Information We Collect

We believe in data minimization. We only collect information necessary to render your family tree, secure your account, manage your archive, and provide external storage features.

  • Account Information: Your email address, username, profile information, and securely hashed password used to authenticate your workspace.
  • Genealogical Data: Names, family relationships, birth dates, death dates, places, notes, historical records, family documents, and other information you voluntarily add to your archive.
  • Media and Archive Files: Photographs, scanned documents, certificates, family records, and other media files you upload or link to your family tree.
  • Bunny.net Storage Metadata: Storage zone names, storage zone IDs, region codes, file paths, storage usage, quota information, upload timestamps, file names, MIME types, file sizes, and related technical metadata.
  • User-Owned Bunny.net Credentials: If you choose to use your own Bunny.net storage, we may store the storage zone name, storage zone password or AccessKey, optional read-only password, storage endpoint, region, and optional public CDN base URL you provide.
  • Site-Provided Bunny.net Credentials: If you use the native site-provided storage option, the platform may assign you a Bunny.net Storage Zone created under the site owner’s Bunny.net account.
  • Technical Data: IP address, browser type, device information, session data, security logs, login attempts, and standard connection metrics used for security, abuse prevention, fraud prevention, and platform reliability.

3. How We Use Your Information

The data you input is used exclusively to provide, secure, and maintain the Roots Archive platform.

  • We use your family data to display and manage your family tree, archive pages, profiles, media, and relationships.
  • We use storage metadata to connect your account to the correct Bunny.net storage source.
  • We use technical logs to protect accounts, prevent abuse, and maintain platform stability.
  • We use email addresses for login, account recovery, important security notices, and essential platform communication.
  • We do not analyze genealogical data for targeted marketing.
  • We do not sell, rent, or share your family history with third-party data brokers.
  • We do not use your personal photographs, documents, or family records to train external Artificial Intelligence models without explicit opt-in consent.

4. Bunny.net External Storage

Roots Archive may use Bunny.net Storage to store image and media files externally instead of storing all files directly inside the WordPress media library. This helps reduce WordPress storage load, improve performance, and provide scalable media handling.

4.1 Native Provided Bunny.net Account

By default, the platform may provide a native Bunny.net storage account for users. In this mode, the site owner’s Bunny.net account creates or assigns a storage zone for your account. The system may automatically provision a Bunny.net Storage Zone when you register or when you open the Bunny.net Storage settings page.

For native provided storage, administrators may be able to view technical details including storage zone name, zone ID, region, storage usage, storage-zone password or AccessKey, read-only password, and related account mapping metadata.

4.2 User-Owned Bunny.net Account

If you are concerned about privacy or prefer to control your own storage, you may disable the native provided storage account and enter your own Bunny.net Storage Zone credentials. This allows your files to be stored under your own Bunny.net storage zone rather than under the site owner’s provided storage zone.

If you choose this option, you should enter a Bunny.net Storage Zone Password / AccessKey for the specific storage zone you want to use. You should avoid entering your main Bunny.net Account API Key unless you fully understand the risks, because a main account API key may allow broader account-level changes.

Important: User-owned Bunny.net credentials entered into the platform are still technically stored in the WordPress database. The site owner intends to keep them private, but any credential stored in a website database may technically be accessible to site administrators, server administrators, or database administrators.

4.3 Storage Credentials

Bunny.net storage credentials may include storage zone names, storage zone passwords, AccessKeys, read-only passwords, API endpoints, region codes, and public CDN base URLs. These are used only to connect the platform to the correct Bunny.net storage location.

You are responsible for rotating or regenerating Bunny.net keys if you believe they have been exposed, copied, misused, or entered into an unsafe place. If you stop using Roots Archive or change your storage setup, you should review and rotate your Bunny.net credentials from your Bunny.net dashboard.

4.4 Public CDN and Pull Zone Links

Bunny.net files may be delivered through a public Pull Zone or CDN URL if configured. If a public CDN URL is active, anyone with the file URL may be able to access the file, depending on your Bunny.net configuration.

You should not upload highly sensitive, confidential, identity-related, medical, legal, copyrighted, or private family documents unless you understand the public-link behavior and have configured your storage appropriately.

4.5 Storage Regions and Third-Party Infrastructure

Bunny.net is a third-party infrastructure provider. Files, metadata, logs, and CDN traffic may be processed or stored through Bunny.net systems and regions depending on the storage zone, replication settings, CDN configuration, and Bunny.net account settings.

By using Bunny.net storage through Roots Archive, you acknowledge that Bunny.net may process storage and delivery data as part of providing its infrastructure services.

5. WordPress Storage vs. External Storage

Roots Archive may store some content in WordPress and some content externally. The intended design is to avoid storing large media files unnecessarily inside the WordPress media library when external Bunny.net storage is available.

  • WordPress may store: User accounts, family tree data, metadata, storage mappings, file references, public URLs, storage zone identifiers, upload records, and configuration values.
  • Bunny.net may store: Image files, media files, remote paths, storage objects, and CDN-delivered assets.
  • WordPress may not always store the original file: In external storage mode, WordPress may keep only the reference, URL, or metadata needed to display the file.
  • External deletion may be separate: Removing a WordPress record does not always guarantee the file is immediately deleted from Bunny.net unless a specific remote delete operation is performed.

6. Administrator Access and Privacy Commitment

Roots Archive is operated with a strong moral commitment to privacy. The site owner intends to keep user data, family records, uploaded files, and storage details private.

However, for technical support, security, storage management, account recovery, abuse prevention, and system maintenance, administrators may technically have access to certain account, metadata, and storage configuration details.

  • Administrators may see storage mode, storage zone names, storage zone IDs, usage, quota, and storage errors.
  • Administrators may see native provided Bunny.net storage credentials because those zones are created and managed by the site owner.
  • If users enter their own Bunny.net storage credentials, those credentials may be stored in the WordPress database and may technically be visible to administrators depending on the system design.
  • Administrators are expected to access user data only when necessary for legitimate platform, support, security, or maintenance reasons.

7. Upload Records, Metadata, and Logs

Even when files are stored externally, the platform may retain metadata about those files. This may include file name, file size, MIME type, upload date, storage path, public URL, user ID, storage source, and storage usage.

These records are used to display files, manage quotas, diagnose storage issues, investigate abuse, support users, and maintain the integrity of the archive.

Administrative upload lookup tools may allow administrators to search upload records by user ID for support or troubleshooting. This does not necessarily mean the file itself is stored in WordPress.

8. Data Security and Storage Protection

We use reasonable technical safeguards to protect your data, including HTTPS/TLS encryption in transit, account authentication, role-based access controls, and security-conscious handling of storage credentials.

Where encryption at rest is available through hosting, database, server, or storage-provider infrastructure, it may be used as part of the platform’s security posture. Security is continuously improved, but no online platform can guarantee absolute protection against all possible risks.

  • Users should use strong passwords and keep account access private.
  • Users should not share Bunny.net credentials publicly.
  • Users using their own Bunny.net storage should rotate credentials if they suspect exposure.
  • Users should avoid uploading content they would not want accessible through a public URL unless private access controls are properly configured.

9. Your Rights and Control

You retain ownership of your family data, media, and digital archive content. Roots Archive is a platform for organizing and preserving your records, not a buyer or owner of your family history.

  • Access: You may access your account and archive content through the platform.
  • Correction: You may edit inaccurate family tree information and uploaded metadata where the platform allows editing.
  • Export: You may request or use available export tools for your family tree and archive data where supported.
  • Deletion: You may request account deletion or remove content where available. Some deleted data may persist temporarily in backups, logs, caches, or third-party storage until those systems expire or are cleared.
  • Storage Choice: You may choose between native provided Bunny.net storage and your own Bunny.net storage credentials if this feature is enabled for your account.
  • Credential Control: If you use your own Bunny.net storage, you control the underlying Bunny.net account and may rotate, revoke, or delete your storage credentials directly from Bunny.net.

10. Deletion, Remote Files, and Backups

Deleting a record from Roots Archive may remove the database reference, but external storage behavior may vary depending on the feature used.

  • Deleting a local WordPress record may not automatically delete the corresponding Bunny.net object unless remote deletion is specifically performed.
  • Removing a local Bunny.net assignment does not necessarily delete the remote Bunny.net Storage Zone.
  • If you use your own Bunny.net account, you are responsible for deleting files directly from Bunny.net if you want complete removal from your own storage.
  • Deleted data may remain temporarily in backups, logs, caches, CDN nodes, or provider systems before permanent expiration.
  • Public CDN caches may continue serving files for a period of time even after origin files are removed, depending on cache configuration.

11. Data Sharing and Third Parties

We do not sell your personal data or family history. We may use trusted infrastructure providers only when necessary to operate the platform.

  • Hosting Providers: Used to run the website and database.
  • Bunny.net: Used for external storage, file delivery, and CDN-related functionality when Bunny.net storage is enabled.
  • Email Services: May be used for account emails, password resets, notifications, and security messages.
  • Security Tools: May be used to detect abuse, unauthorized access, spam, malware, or suspicious activity.

Third-party providers may process limited technical data necessary to provide their services. We do not authorize third parties to use your family archive content for unrelated marketing or data brokerage purposes.

12. User Responsibilities

Users are responsible for the content they upload and the credentials they provide.

  • Do not upload content that violates the privacy, copyright, or legal rights of others.
  • Do not upload malware, harmful files, abusive content, or illegal material.
  • Do not upload sensitive documents unless you understand the privacy and public URL implications.
  • Do not share your account password or Bunny.net credentials with unauthorized persons.
  • If you use your own Bunny.net storage, ensure your Bunny.net configuration, access keys, Pull Zones, and CDN settings match your intended privacy level.

13. Children and Family Records

Family trees may include information about minors or relatives who did not personally create an account. Users should be thoughtful and respectful when adding living persons, children, private photographs, identity documents, or sensitive biographical information.

You are responsible for ensuring that the information you add is appropriate, lawful, and respectful of family members’ privacy.

14. Security Incidents

If we become aware of a security incident that materially affects user data, account security, or stored credentials, we will take reasonable steps to investigate, contain the issue, and notify affected users when appropriate.

If you believe your account, archive, or Bunny.net credentials have been exposed, contact the site owner and rotate your passwords or Bunny.net keys as soon as possible.

15. Policy Updates

As we enhance our security measures, Bunny.net integration, storage architecture, and platform features, we may occasionally update this policy. We will notify active account holders of material changes where appropriate.

Our core promise will remain: we will not sell your family data, and we will continue treating family history as private, personal, and worthy of respect.

Roots Archive

Where your family's story takes root.