Privacy Policy
Effective 2026-08-01.
The short version
Your family history stays on your machine. Heartwood has no accounts and no sign-in. We do not receive, host, or have access to your genealogical data, because it is never sent to us — that's an architectural fact about how the application works today, not just a promise. Anything that does leave your computer is itemized below, one path at a time, and every one of those paths is something you can decline. If that ever changes — for example, if we ever offer an opt-in, Twigly Labs-hosted sync service — this page will describe it in full before it exists, and it will never be the default.
Today, three things leave your computer, and this policy describes each one exactly: a check for a new version, a feedback message if you choose to send one, and — for people in the current beta — anonymized usage statistics, described in full below along with the toggle that turns it off.
What is stored, and where
Heartwood keeps everything in one folder on your
own computer. On macOS, that's
~/Library/Application Support/com.twiglylabs.heartwood.
(Heartwood is a macOS application today; a Windows build is planned,
and this section will be updated with the real Windows path once one
ships — we don't publish paths for platforms we haven't built yet.)
That folder holds your family files, the records and images you attach, your research notes, and the application's own logs. It is ordinary data on your own disk: you can back it up, copy it to another machine, or delete it, and you do not need us in order to do any of those things. If a future release lets you sync or back up through your own cloud storage, it will read and write only inside a folder in an account you control, and your data still will not pass through us.
Checking for a new version
So that fixes actually reach you, the application checks for a newer version about every six hours while it is running.
The check asks downloads.twiglylabs.com for one fixed
file listing the available versions. It carries no information about
you: there is no account and no identifier, and — worth being precise
— the request does not even tell us which version you are running.
Your copy downloads that list and does the comparison on your own
machine.
What we can see is what any web server sees when a computer asks it for a file: your IP address, the time of the request, and the basic technical details your computer's networking includes by default. An IP address is approximate location information, so we say so plainly rather than leave it implied. If a newer version exists, your copy then downloads the update itself from the same place.
The feedback form
Heartwood has a "Send feedback" form. It transmits only when you fill it in and press Send, and it sends exactly this:
- the message you typed;
- the application version;
- which kind of computer you are running it on (for example
darwin-aarch64); - your name and email address — only if you chose to type them into the two optional fields, and used only to reply to you.
Nothing else is attached: no logs, no diagnostic report, no file paths, no family-file names, and no part of your research. The form shows you the version and system values before you send, and there is no "include diagnostics" option to overlook. Messages arrive in our support tracker, where a person reads them.
Whatever you type into the message box is sent as you wrote it, so please avoid pasting details about living relatives unless you mean to share them.
Usage statistics
Heartwood records a small set of anonymized usage events to a plain-text file inside its own folder on your machine. For people using the current beta, those events are also sent to us in one daily batch (at most once every 24 hours), so we can find and fix rough edges while we still have time to before a wider release. This section says exactly what that means; we'd rather over-explain it than have you take our word for it.
During the beta this is on by default, but nothing is ever sent before you have seen and acknowledged an in-app disclosure notice that says plainly what is collected and links back to this page. Settings has an off switch that takes effect immediately: turning usage statistics off stops recording and permanently deletes everything queued, including anything not yet sent — the same as if it had never been collected. There is no separate "clear" action because turning it off already does that.
Those records are deliberately narrow. Every event comes from a published list, and every value is a fixed category, a version number, or a size range — never free-typed text. An event may record:
- Which feature was used — the name of the command or verb, whether it ran in the application or through a connected assistant, and whether it succeeded or failed.
- How long an operation took, and roughly how large the family file is — as a range such as "10,000–50,000 people", never an exact count.
- That an error occurred — its category and which part of the program it came from, never the error message itself.
- Basic environment — the application version, and your operating system family and major version.
- A random session number, generated fresh each time you start the application, never reused and never linked to you — enough to tell that two actions happened in one sitting, and nothing more.
Times are recorded only to the hour. There are no names, dates, places, notes, source titles, file names, or identifiers out of your family file, and no content fingerprints either — a fingerprint of a name is still personal information. There is no account, no email address, no hardware identifier, and nothing that ties one installation to another or to you.
When events are sent, the batch travels over an ordinary HTTPS request to a Twigly Labs relay, carrying no account, no cookie, and no identifier beyond your IP address as seen by that one request — the same exposure described above for the version check. The relay checks every batch against our published schema and accepts only what matches it. You can inspect exactly what is queued on your machine at any time, before it is ever sent.
If what is collected is ever widened — a new kind of event, or a new field — you will be shown the disclosure again and asked to acknowledge it before anything under the wider schema is sent. Crash reports, if they are offered, will be a separate question — saying yes to one is not saying yes to the other. Outside the beta, usage statistics default to off, exactly as they did before this section was rewritten.
Mailing list
The beta waitlist on the beta signup page is a mailing list, separate from the application and from anything described above. If you sign up, here is exactly what that involves.
We store your email address and your subscription state (for
example, pending confirmation, confirmed, or unsubscribed). Nothing
else about you is collected through that form. The list is hosted by
our processor, Buttondown, and mail is sent through Postmark from
news.heartwood.family.
Signing up uses double opt-in: after you submit the form, you'll get a confirmation email, and you're only added to the list once you confirm. Every email we send carries a one-click unsubscribe link that works immediately, no login required. You can also ask us to delete your email address entirely at any time using the contact address below, and we will.
We never sell or share your email address, and it is never used for anything other than beta-admission and waitlist-related email.
Diagnostics
There is no in-app control that generates or displays a diagnostics summary — a general troubleshooting screen used to render one in-app, but it showed internal event names and counts to family historians, and it was removed. If a support conversation genuinely needs more detail than a description, we'll ask you directly, explain exactly what a diagnostic bundle contains, and walk you through producing it yourself from a terminal command; the application never generates or sends one on its own. The bundle format is written to hold technical detail and internal identifiers only — never names, dates, places, or the contents of your files — and you read it before you decide whether to share it.
Connecting an AI assistant
Heartwood can be connected to an AI assistant so that it can read and help with your research. This one is worth understanding clearly.
When you make that connection, the assistant you chose can read the evidence in the family file you have open, and what it reads goes to whoever operates that assistant, under their privacy policy rather than this one. If the assistant runs on your own computer, nothing leaves at all. Either way the connection is made on your machine and Twigly Labs is not in the path: we do not receive, host, or have access to that exchange, and we cannot see what you asked or what it read. The choice of assistant, and the trust that goes with it, is yours.
Sharing with other researchers
If and when research-sharing features ship, the plan is for sharing to happen directly between you and the researcher you choose, over storage you both control. Any option that would route sharing through infrastructure we operate would be opt-in, off by default, and described here in full before it existed — this page is the place that promise gets kept, not a marketing page.
What we never do
- We do not sell or rent your information.
- We do not show advertising, and we do not profile you for it.
- There are no third-party trackers or analytics anywhere — not in the application, and not on this website. Every script this site loads is our own, self-hosted, and does not talk to any other server; see the itemized egress list above for the complete set of things that do leave your machine.
- We do not train models on your data. We could not: we do not have it.
- The application never fetches records from genealogy platforms on your behalf. You bring documents to it yourself.
Children
Heartwood is a research tool intended for adults and is not directed at children. We do not knowingly collect personal information from anyone of any age — there are no accounts, and nothing personal reaches us except a feedback message you choose to send. Family history necessarily involves recording information about relatives, including children and living people; those records stay on your machine, and how you handle them is yours to decide.
Your choices
Because your research never reaches us, the usual requests — show me my data, export it, delete it — are things you carry out yourself, directly, without asking us. Delete the folder described above and nothing of yours remains anywhere else. Turn usage statistics off in Settings whenever you like, which deletes the local queue immediately too. If you sent us a feedback message and want it removed, ask and we will remove it.
Changes to this policy
If this policy changes — for example when cloud-storage sync is added, if usage statistics default to off again after the beta, or before what we collect is ever widened — we will update this page and describe the change plainly before it takes effect, not after.
Contact
Questions about this policy, or a request to remove a feedback message you sent: email Twigly Labs at brad@twiglylabs.com.