Your data & privacy
Krio Griot stores the research you entrust to it. This page explains exactly what is collected, why, and what you can do with it — including taking it with you or deleting it entirely.
What we collect
| Type | What it is | Why it's stored |
|---|---|---|
| Account information | Your name, email address, and a hashed (encrypted) version of your password. Phone number if you chose to provide one. | To authenticate you when you log in and to send transactional email (password resets, account notices). Your password is never stored in readable form. |
| Research content | People records, family connections, research questions, session logs, archive documents, DNA match data, and collections you create. | This is the core purpose of the platform. All research content is private to your account and is never shared, published, or used to train AI models without your explicit consent. |
| Uploaded files | Photographs, PDF documents, and other files you upload to Archives. | Stored under your account. Not indexed, not shared. You own them. |
| AI session transcripts | The full text of every AI research session, automatically saved to your research log. | Your research record. Searchable within your account only. |
| Usage data | Basic activity logs: when you logged in, which modules you used, how many documents you've scanned. No keylogging. No behavioral profiling. | To calculate plan limits (storage used, scans used) and to detect security anomalies like login attempts from unusual locations. |
How it's used
Where it lives
Your data is stored in a MySQL database hosted on Hostinger in the United States. Uploaded files are stored in the same hosting environment. Database connections are encrypted in transit. Passwords are hashed with bcrypt before storage — your actual password is never stored and cannot be retrieved.
The database is backed up daily. Backups are retained for 30 days. In the event of data loss, backups allow restoration to any point in that 30-day window. If a data loss event affects your account, you will be notified by email within 48 hours of discovery.
Your research data is not sold, licensed, or shared with third parties. The only data that leaves the platform is what you explicitly export or publish as a public collection.
Your rights
You can export your entire research database at any time from Account settings → Export data. The export is a ZIP file containing your people records, research log, and a list of your uploaded files. Format: JSON and CSV. No waiting period. No fee.
Go to Account settings → Delete account. Deleting your account removes all your research data, uploaded files, and account information from the active database within 24 hours. Backup copies are purged on their natural 30-day rotation — within 30 days of deletion, no copy of your data remains.
Everything you entered can be edited or deleted within the platform at any time. There is no version control on individual records — edits overwrite the previous value. If you need a history of changes to a record, use the notes field to document revisions.
If you need a copy of data that is not included in the standard export — security logs, account history, or anything else held by the platform — email privacy@kriogriot.com. Requests are fulfilled within 30 days.
Cookies and authentication
Krio Griot uses a JSON Web Token (JWT) stored in your browser's localStorage to maintain your login session. This token expires after 7 days and must be renewed by logging in again. No third-party tracking cookies are used. No advertising cookies are used.
If you clear your browser's local storage, you will be logged out of all sessions on that device.
Contact
For questions about your data or privacy, contact privacy@kriogriot.com. For general support, use the Report a problem link in the footer of any page.
This policy was last updated August 2026. Material changes will be communicated by email to all account holders before they take effect.