Your data & privacy

Your research belongs to you

Krio Griot stores the research you entrust to it. This page explains exactly what is collected, why, and what you can do with it — including taking it with you or deleting it entirely.

Data collected by the platform

Type What it is Why it's stored
Account information Your name, email address, and a hashed (encrypted) version of your password. Phone number if you chose to provide one. To authenticate you when you log in and to send transactional email (password resets, account notices). Your password is never stored in readable form.
Research content People records, family connections, research questions, session logs, archive documents, DNA match data, and collections you create. This is the core purpose of the platform. All research content is private to your account and is never shared, published, or used to train AI models without your explicit consent.
Uploaded files Photographs, PDF documents, and other files you upload to Archives. Stored under your account. Not indexed, not shared. You own them.
AI session transcripts The full text of every AI research session, automatically saved to your research log. Your research record. Searchable within your account only.
Usage data Basic activity logs: when you logged in, which modules you used, how many documents you've scanned. No keylogging. No behavioral profiling. To calculate plan limits (storage used, scans used) and to detect security anomalies like login attempts from unusual locations.
What we do not collect: browsing history outside the platform, device contacts, location data beyond what you enter into a record, or any data from third-party data brokers.

What your data is used for

Providing the service Your research data is used to power the research workspace you log into. That's it.
Transactional email Your email address is used to send account confirmations, password resets, and important notices about your account. We do not send marketing email unless you opt in explicitly — and opting out stops it immediately.
Security Login timestamps and IP addresses are kept for 90 days to detect unauthorized access to your account. They are not shared with advertisers or third-party analytics.
AI research sessions The content of your research sessions is sent to an AI model to generate research responses. Your data is not used to train AI models and is not retained by the AI provider beyond the duration of the session.

Storage and security

Your data is stored in a MySQL database hosted on Hostinger in the United States. Uploaded files are stored in the same hosting environment. Database connections are encrypted in transit. Passwords are hashed with bcrypt before storage — your actual password is never stored and cannot be retrieved.

Backups

The database is backed up daily. Backups are retained for 30 days. In the event of data loss, backups allow restoration to any point in that 30-day window. If a data loss event affects your account, you will be notified by email within 48 hours of discovery.

Third-party access

Your research data is not sold, licensed, or shared with third parties. The only data that leaves the platform is what you explicitly export or publish as a public collection.

What you can do with your data

Export your data

You can export your entire research database at any time from Account settings → Export data. The export is a ZIP file containing your people records, research log, and a list of your uploaded files. Format: JSON and CSV. No waiting period. No fee.

Delete your account

Go to Account settings → Delete account. Deleting your account removes all your research data, uploaded files, and account information from the active database within 24 hours. Backup copies are purged on their natural 30-day rotation — within 30 days of deletion, no copy of your data remains.

Correct your data

Everything you entered can be edited or deleted within the platform at any time. There is no version control on individual records — edits overwrite the previous value. If you need a history of changes to a record, use the notes field to document revisions.

Request your data

If you need a copy of data that is not included in the standard export — security logs, account history, or anything else held by the platform — email privacy@kriogriot.com. Requests are fulfilled within 30 days.

How your session is maintained

Krio Griot uses a JSON Web Token (JWT) stored in your browser's localStorage to maintain your login session. This token expires after 7 days and must be renewed by logging in again. No third-party tracking cookies are used. No advertising cookies are used.

If you clear your browser's local storage, you will be logged out of all sessions on that device.

Questions about your privacy

For questions about your data or privacy, contact privacy@kriogriot.com. For general support, use the Report a problem link in the footer of any page.

This policy was last updated August 2026. Material changes will be communicated by email to all account holders before they take effect.