Legal
Last updated: 29 August 2026
StirpeAI is operated by Geyserich S.à r.l., a company registered in Luxembourg (RCS [NUMBER]), with its registered office at [ADDRESS], L-[POSTCODE] Luxembourg. We are the data controller for the information described here.
Questions, or to exercise any right below: privacy@stirpe.ai.
You upload photographs or scans of historical documents. We use artificial intelligence to transcribe, translate and interpret them, and to extract the people, places, dates and relationships they record. Those extractions build into a research graph across everything you have uploaded.
Your account. Your email address, and your name and profile picture if you sign in with Google. Anything you add to your profile: display name, country, research focus, biography. If you enable two-factor authentication, an encrypted secret. A log of significant actions on your account, with your IP address anonymised — we discard the final part of it before storing.
Your documents. The files you upload, and everything our analysis produces from them: transcriptions, translations, historical context, and the names, dates, places, relationships, occupations, social status, religious details and titles recorded in the document.
What you tell us. Corrections you submit, research notes, and messages you send us.
We do not collect payment information. We do not use advertising or tracking cookies.
| What we do | Why | Legal basis |
|---|---|---|
| Run your account and analyse your documents | To provide the service you signed up for | Performance of our contract with you |
| Keep security logs, apply rate limits, offer 2FA | To protect accounts and prevent abuse | Our legitimate interests |
| Retain transcriptions and extractions in a research corpus | To improve transcription of European archival handwriting — see below | Our legitimate interests, together with Article 89 GDPR and Articles 63–65 of the Luxembourg Law of 1 August 2018 on historical research |
| Handle information in documents revealing religious belief or ethnicity | This is inherent in parish and colonial records | Article 9(2)(j) — archiving and historical research, with the safeguards Luxembourg law requires |
This part matters, so we state it plainly.
Every analysis is also stored in a research dataset, together with any correction you make. We use it to build better models for reading old European handwriting — a problem no existing dataset solves well.
We keep this dataset indefinitely, including after you delete your account. When you delete your account, we sever the link between the dataset and you: your identity is removed, and what remains is a transcription of a historical document. European and Luxembourg law expressly permit retention for archiving and historical research purposes, and that is the basis we rely on.
We do not sell this dataset, and we do not share it with third parties.
StirpeAI is for historical documents. Our Terms ask you not to upload documents about living people. If a document you upload does name a living person, we handle it under the historical-research provisions described above. Any living person named in our corpus can contact us at privacy@stirpe.ai to exercise their rights.
We use these service providers. Each processes data only on our instructions under a contract.
| Provider | What for | Where |
|---|---|---|
| Anthropic | AI analysis of your documents | United States |
| Supabase | Database and file storage | [EU REGION] |
| Vercel | Hosting | United States |
| Resend | Sign-in links and emails | United States |
| Cloudflare | Domain routing | Global |
| Sign-in, if you use it | United States | |
| OpenStreetMap | Turning place names into map coordinates — place names only | Europe |
The current list is always at stirpe.ai/subprocessors.
Where a provider is outside the EEA, transfers are covered by the European Commission’s Standard Contractual Clauses.
We never sell your data, share it with advertisers, or disclose it to anyone else unless we are legally required to.
By default, your research is yours. Other users cannot see your documents, your analyses or your graph.
Two things are optional and off unless you turn them on:
Our administrator can access data in the course of operating and supporting the service. Administrator access is logged.
| Account details | While your account is open, and 30 days after you ask us to delete it |
| Uploaded files | Deleted when you delete your account |
| Transcriptions and extractions | Kept while your account exists. After you delete your account, kept only as described under “When you delete your account”; otherwise deleted. |
| Security logs | 12 months |
When you delete your account. We delete your account, your profile and your email address, and remove every link between you and the research you contributed. A record about a person is kept, no longer linked to you, only where we can establish that the person is no longer living. A transcription or translation is kept only where that is true of every person it concerns. A family record is kept if at least one of its members is. Place names are kept, as they do not concern any individual. Everything else is deleted with your account. Records of activity on your account are kept only in anonymised form.
You can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or provide it in a portable format. You can withdraw consent at any time where we rely on it.
Write to privacy@stirpe.ai. We reply within one month.
Two honest limits. Deleting your account removes you and your files, but the transcriptions stay in the research corpus without your identity attached — as explained above. And Luxembourg law lets us decline certain requests where meeting them would seriously damage the research purpose. We do not use that lightly, we record our reasoning every time, and we will explain it to you.
If you are unhappy with how we handle your data, you can complain to the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg — cnpd.public.lu.
Encryption in transit and at rest. Uploaded files held in private storage. Optional two-factor authentication. Uploads validated against their actual file contents. Rate limiting. Access logging. No system is perfectly secure; if a breach affects you and poses a high risk, we will tell you.
Only what the service needs to work — keeping you signed in, and remembering your cookie choices. Analytics run only if you agree.
We will post any change here and, if it is significant, email you.
Questions? privacy@stirpe.ai · Terms of Service · Subprocessors