Silsilah: Family Tree Silsilah: Family Tree
Get the app
← Back to home

Privacy Policy

Last updated: 30 August 2026

This Privacy Policy explains how Silsilah: Family Tree ("we," "our," or "us") handles information when you use our app for iPhone, iPad, Mac and Android ("App"). We are committed to protecting your privacy.

1. Summary

Silsilah: Family Tree is built to work without us. We run no backend server. There is no account to create, no sign-in, no analytics, no advertising, and no tracking of any kind. We never receive your family tree, and we could not hand it over to anyone if we were asked, because we never hold it.

Your family data lives in the App's own storage on your device. There are exactly three ways it can move somewhere else, and you start all three:

  • You export an encrypted archive - a .silsilah file locked with an 8-character code that you choose to send to someone (Section 6.1).
  • You use Nearby Share - a direct Bluetooth or Wi-Fi transfer to a relative's device standing next to you, with no server in between (Section 6.2).
  • Your device backs itself up - Apple's iCloud/Finder backups and Android's Auto Backup can include the App's data, in your own cloud account, under your own control (Section 7).

Everything below is the detail behind those three sentences.

2. Information We Collect

To be precise about the word "collect": we collect nothing. Nothing in this section reaches us. The App records the following on your device, at your direction.

2.1 Information You Provide

When you use the App, you may provide:

  • Names, nicknames, gender, dates of birth and death, and blood type
  • Photographs of family members
  • Relationships - parents, children, spouses, siblings, and marriage status (married, separated, divorced, widowed)
  • Social connections - friends, colleagues, neighbours and acquaintances
  • Biographical details - occupation, workplaces, education, hobbies, and free-text notes
  • Contact details you choose to record - phone numbers, email addresses, and social-media handles

All of this information is stored locally on your device only.

2.2 Contacts Access

Contacts access is entirely optional. The App only requests it when you tap "Import from Contacts" on the Add Relative screen, and only after you take that action - we do not read your contacts at any other time.

When you use this feature, you select a single contact from your device's contact list. The App uses the system contact picker on both platforms, so the App itself never sees your full contact list - on Android it does not hold the READ_CONTACTS permission at all. From that one contact, we copy only the following fields, and only into fields on the form that you have left empty:

  • Given name and family name
  • Phone number
  • Email address
  • Job title and organization name
  • Birthday
  • Contact photo

No other contacts, and no other fields, are read or copied. This information is never uploaded to any server - the App has no backend of any kind. It is written directly into the App's local database on your device, alongside the rest of your family tree, exactly like any relative you enter by hand.

You can revoke Contacts access at any time from your device's system settings (for example, System Settings > Privacy & Security > Contacts on macOS, or Settings > Privacy & Security > Contacts on iOS). Revoking access only disables the "Import from Contacts" shortcut; any information already copied into your family tree remains in the App until you edit or delete it yourself.

2.3 Camera and Photo Library

You can give a relative a photo by taking one with the camera or choosing one from your photo library. Both are optional, both are requested only at the moment you use them, and the resulting image is copied into the App's own storage on your device. The App does not read your photo library in the background, does not scan it on launch, and does not read location or other metadata out of your photos for any purpose of ours.

A separate, optional feature analyses photos on-device to suggest look-alikes - see Section 4.

2.4 Automatically Collected Information

We do not collect usage analytics, crash reports, or any telemetry from the App. The App contains no analytics SDK, no advertising SDK, and no crash reporter.

2.5 Identifiers Stored on Your Device

The App stores a small number of technical values locally. None of them are sent to us, and none of them identify you to any third party:

  • A Nearby Share peer ID - a random identifier created the first time you use Nearby Share, so a relative's device can recognise yours across a transfer. It is described in Section 6.2 because, unlike the others, it is broadcast to nearby devices while you are actively receiving.
  • Purchase entitlements - a local flag recording that you bought "Remove Limit" or "Unlimited Share". The store, not this flag, is the source of truth.
  • Your settings - App Lock preference, language choice, and graph display options.

2.6 Crash & Problem Reports

Because we deliberately include no analytics, crash reporters, or tracking of any kind, we have no automatic way of knowing when something goes wrong. If the App crashes or misbehaves, we rely on you to tell us. Please email a short description of the problem (and, if you wish, your device model and OS version) to reports@silsilah-familytree.com.

Anything you choose to include in such an email is provided voluntarily by you and is used solely to investigate and fix the problem. This manual process is a direct consequence of our commitment to total privacy: no tracker means no silent reporting on your behalf.

3. In-App Purchases

The App is free to download and includes a free tier. One-time, non-subscription purchases remove the free-tier limits. Purchases are processed entirely by Apple (on iOS and macOS) or Google Play (on Android). We do not receive or store your payment information, and we never see your name, card details, or billing address - the store tells the App only whether an entitlement is active. Please review the respective store's privacy policy for details of how it handles your purchase.

4. On-Device Photo Analysis & Face Data

Silsilah offers an optional on-device feature ("Search Similar Photos") to help you find photos in your device's photo library that feature a selected relative.

  • Collection & Processing: When you voluntarily use "Search Similar Photos", Silsilah processes photos locally - on iOS and macOS using Apple's Vision framework (VNDetectFaceRectanglesRequest and VNGenerateImageFeaturePrintRequest), and on Android using Google's ML Kit Face Detection. The ML Kit model is bundled inside the App itself, so no photo, and no part of a photo, is sent to Google or downloaded from it in order to run the scan.
  • Use: Feature prints are used strictly on-device to rank local photos by visual similarity so you can easily locate additional family photos to attach to your offline family tree. Matches are suggestions for you to confirm or reject, never assertions of identity.
  • Sharing & Disclosure: Silsilah has no servers, no tracking, and no analytics. Face data and feature prints are never uploaded, transmitted off-device, or shared with any third party. They are not included in the .silsilah archives you share.
  • Storage & Retention: On macOS, feature prints exist only in memory during the active search session and are discarded immediately when the scan completes. On iOS, feature prints are cached locally on your device in the App's sandboxed Caches directory (Library/Caches/faceprints.cache) to accelerate subsequent local searches. On Android, detection runs against the photos you are reviewing and results are held for the review session.
  • Deletion: Local cached feature prints are automatically cleared when a relative's photo is removed, when app data is reset, or when you delete the App from your device.

5. App Lock / Biometric Data

When you enable App Lock, the App uses biometric authentication frameworks (Apple's LocalAuthentication framework on iOS and macOS, or Android's BiometricPrompt API) to authenticate you via Face ID, Touch ID, fingerprint scanner, or your device passcode/PIN. Biometric data is managed entirely by your device's secure hardware enclave and operating system. We do not access, store, or transmit any biometric information, and the App never receives your passcode - only a yes-or-no answer from the operating system.

6. Sharing Your Family Tree

Sharing is the one part of Silsilah where family data deliberately leaves your device. It never passes through a server of ours. Everything in this section happens only when you start it.

6.1 Encrypted .silsilah Archives

You can export part or all of your tree as a single .silsilah file. Before the file is written it is encrypted with AES-256-GCM, using a key derived from an 8-character share code by PBKDF2-HMAC-SHA256 with 210,000 iterations. Without the code, the file is unreadable.

  • You choose what goes in. Category filters let you include or exclude family, friends, colleagues, neighbours and acquaintances, and you can choose whether photos travel with the file.
  • The code is yours alone. The App generates it on your device and shows it only to you. We never see it, it is never sent anywhere, and we cannot recover or reset it. If you lose the code, the archive cannot be opened by anyone, including us.
  • Anyone with both the file and the code can read it. Send them separately - the code by a different channel than the file - and only to people you intend to have the data.
  • Receiving works the same way in reverse. An archive someone sends you is decrypted on your device and merged into your tree, with duplicate detection that asks you before combining people.

6.2 Nearby Share (Bluetooth & Wi-Fi)

Nearby Share hands an encrypted archive directly to a relative's device in the same room - over Bluetooth Low Energy and, where available, your local Wi-Fi network. It works with no internet connection, and no data reaches us or any other server at any point.

To make this work, a device that is waiting to receive advertises a small amount of information over Bluetooth so the sender's device can find it. While, and only while, you have the receiving screen open, nearby devices scanning for the same service can see:

  • A display name - taken from your own profile name and device, for example "Aisha's iPhone". If you have no profile name set, only the device type is used.
  • A random peer ID - a UUID generated on first use and kept on your device so repeat transfers with the same relative work smoothly. It contains nothing about you and is not linked to any account.
  • Your platform - iOS, macOS or Android.

When a sender offers you a file, the offer includes the file name, its size, a checksum, and the sender's display name, so you can decide before anything is transferred. Nothing is received until you accept. Close the receiving screen and the advertising stops. Your family data itself is never advertised - only the archive you accept is transferred, and it stays encrypted with the share code throughout.

This feature needs Bluetooth and local-network access, and on Android versions 11 and earlier the operating system additionally requires location permission for any Bluetooth scanning. Silsilah does not use, request, derive, or store your location, and declares its Bluetooth scanning as never being used for location. See Section 8.

6.3 Sending Through Other Apps

Once an archive exists as a file, you can hand it to any app on your device - WhatsApp, AirDrop, email, a messaging app, or your own cloud storage. At that moment the file leaves Silsilah's control and becomes subject to the privacy policy and retention rules of whatever service you chose. The file remains encrypted, but treat any service you send it through as a place a copy will exist. The App also opens external links you tap, such as a relative's WhatsApp number or social-media profile; those open in the relevant app or your browser, and the operator of that service decides what happens next.

7. Device Backups

Your device's own backup system may include the App's data. This is your backup, in your account, and we have no access to it - but you should know it exists, because it is the one route by which family data leaves your device without you making a deliberate choice inside the App.

  • iOS, iPadOS and macOS: if iCloud Backup is on, or you back up to a computer, the App's database and photos are included, encrypted, in that backup in your Apple account. You can exclude Silsilah in Settings > [your name] > iCloud > Manage Storage > Backups.
  • Android: if Google's Auto Backup is on, the App's data can be included in your Google account backup, subject to Google's size limits. You can turn this off in Settings > Google > Backup, or per-app where your device offers it. Your purchase entitlements are deliberately excluded from backup and transfer so that they are always re-checked with Google Play rather than restored onto a device that never paid.

What lands in a backup is governed by Apple's or Google's privacy policy, not ours.

8. Permissions the App Requests

Every permission below is optional, is requested only at the moment a feature needs it, and can be revoked in your device settings. Revoking one disables that feature and nothing else.

  • Camera - to take a profile photo for a relative.
  • Photo library - to choose a profile photo, and for the optional "Search Similar Photos" feature.
  • Contacts (iOS and macOS) - to import a single contact you pick. Android uses the system picker and requests no contacts permission at all.
  • Face ID / biometrics - to unlock the App when App Lock is on.
  • Bluetooth - to discover and transfer to a nearby device during Nearby Share.
  • Local network (iOS and macOS) - to transfer the archive over Wi-Fi to a device on the same network during Nearby Share.
  • Approximate/precise location (Android 11 and earlier only) - required by that version of Android for Bluetooth scanning. Silsilah never reads, uses or stores your location.
  • Internet (Android) - declared for the local, direct device-to-device transfer described in Section 6.2 and for opening links you tap. The App has no server to contact.

9. Data Storage and Security

All Family Data is stored in the App's private storage on your device - using Apple's SwiftData framework on iOS and macOS (with a local JSON cache copy), and a Room/SQLite database with Jetpack DataStore preferences on Android. Photos are stored as files in the App's own sandboxed storage. Other apps on your device cannot read any of it.

We recommend enabling device-level encryption and a device passcode, both of which are on by default on modern phones, and turning on App Lock inside Silsilah for a second layer.

We do not have access to your data and cannot recover it if your device is lost or reset. Please keep your own backups - either your device's backup (Section 7) or an exported archive whose code you have stored safely.

10. Information About Other People

A family tree is, by its nature, mostly information about people who are not you. When you record a relative's name, birthday, photograph or contact details, you are making a decision about someone else's personal information, and you are the one making it - we neither see it nor have any way to act on it.

Please record only what those people would reasonably expect you to keep, be careful about what you include when you share a tree with someone else, and use the category filters in Section 6.1 to leave out anyone who should not travel with the file. If a relative asks you to remove their details, you can edit or delete them in the App at any time; because we hold no copy, that deletion is complete once you make it.

11. Children's Privacy

The App is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 - in fact we collect no personal information from anyone, of any age. If you believe a child under 13 has provided personal information through the App, please contact us and we will take appropriate action.

Family trees often include children as recorded relatives. Information you enter about a child stays on your device under your control, exactly like every other entry, and the responsibilities in Section 10 apply to it with particular care.

12. Your Rights

Since all your data is stored on your device, you have full control:

  • To view your data: it is accessible within the App at all times.
  • To correct your data: edit any person at any time; changes take effect immediately and completely.
  • To delete your data: delete individual people in the App, use Settings → Delete All Data, or delete the App from your device. Remember to check your device backup (Section 7) if you want every copy gone.
  • To export your data: use the share feature to export an encrypted .silsilah archive (Section 6.1). On Android you can also export the whole tree as a plain JSON backup file.

If you reside in the European Economic Area (EEA), the United Kingdom, Indonesia, or another region with privacy legislation, you may have additional rights under applicable law (for example the GDPR or Indonesia's Personal Data Protection Law). Because we operate no server and hold no copy of your data, most such rights - access, rectification, erasure, portability - are exercised directly in the App, immediately and without asking us. For anything else, contact us and we will help as far as we are able.

13. Data Retention

Data is retained on your device until you delete it through the App or uninstall the App. We do not retain copies of your data on any server, because we operate none. Archives you have exported or sent persist wherever you put them - in your files, in a chat, or on a relative's device - until you or they delete them; we cannot reach or revoke them.

14. Third-Party Services

The App contains no analytics, advertising, tracking, or crash-reporting service of any kind. On iOS and macOS it uses no third-party libraries at all. The components it does rely on are listed below; each provider's own privacy policy applies to what that provider does:

  • Apple StoreKit and Google Play Billing - to sell and verify the one-time in-app purchases.
  • Apple Vision (iOS/macOS) and Google ML Kit Face Detection (Android) - on-device face detection for "Search Similar Photos". The ML Kit model is bundled in the App and runs offline.
  • Apple LocalAuthentication and AndroidX Biometric - App Lock.
  • Open-source Android components - Jetpack (Room, DataStore, Compose, Navigation), Hilt, Coil for image display, and Timber for local debug logging. These run entirely on your device and send nothing anywhere.

Apps you choose to send an archive through - WhatsApp, your mail app, cloud storage - are not part of Silsilah and are covered by Section 6.3.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this document when we do so. Continued use of the App after changes constitutes your acceptance of the updated policy.

16. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us at support@silsilah-familytree.com.

© 2026 Silsilah: Family Tree. Terms of Use · Support · Home