Start your tree
Data and privacy

Your data, in plain words

Parenthèse is free, has no ads, and sells nothing. This page explains what the app stores, why, who can see it, and how to get your data back or erase it. It is written from the code, not from a privacy policy template.

Who is responsible

Ilies Allali, who designs and hosts Parenthèse. For any question or request about your data, just send an email to pro.allali.ilies@gmail.com.

What Parenthèse stores

Your account. Your email address and your password, stored as a hash (bcrypt), so no one can read it back, including me. The date the account was created and the last tree you opened, to take you back to it when you log in. The first name asked for at sign-up is not sent to the server, it stays in your browser.

Your trees. The name, the description, the sharing address, the settings, and the two access passwords (visitor and contributor), which are also hashed.

The people. What you enter for each of them (first name, last name, birth name, dates and places of birth and death, occupation, region, nationality, sex, notes, portrait). And the unions and parent-child links that connect them.

The media. Photos, videos, audio recordings, documents, GPS tracks, quotes and YouTube links attached to a person, with their caption and source. A photo can be up to 5 MB, any other file up to 20 MB. On top of that come the annotations placed on the tree itself, such as text, drawings, stickers and photos.

Contributions. When someone suggests a change, Parenthèse keeps the suggestion, the state before and after, who submitted it (a member's email address, or “Contributor” for access by password) and the decision made.

The tree's log. Every creation, change and deletion is dated and attributed to an account or to an access by password. The owner can view it. It is there to know who changed what.

Visits. Each time a tree is opened, it is recorded with the date, the type of device (phone, tablet or computer), the account if there is one, and the first name if the person gave it when opening the tree. The IP address is not kept. Only a fingerprint that cannot be reversed is used to count distinct visitors. The owner of the tree can see these visits. They are erased after one year.

Technical logs. Like any web server, the Parenthèse server records the requests it receives (IP address, page requested, errors) to run and troubleshoot the service.

Why

To make the tree work, and nothing else. No profiling, no advertising, no reselling, no sharing with third parties other than the two technical service providers named on this page. Viewing a shared tree does not require an account, the link and a password are enough.

Who can see what

A tree is never public. The app blocks search engines from indexing it, and none of its content is visible without the link and a password.

One detail. Even before typing the password, the person who opens the link sees the tree's name and its description, nothing else, and nothing about the owner. So don't put anything in the description that you don't want to show to whoever has the link.

An access password opens a 24-hour session. An account session lasts 7 days, or less if you log out.

Where it is hosted, and for how long

On a server rented from Hostinger, which I manage. The database (PostgreSQL) and the media files are stored there. The files sit in a folder outside the web, and are only served to someone with a valid access session for the tree. Traffic between you and the site and the app goes over HTTPS.

Backups of the database and the media are kept for 14 days, then deleted. Data you erase in the app can therefore still exist in a backup for two weeks.

Your data is kept for as long as your account exists.

Audience measurement

Parenthèse uses PostHog to count visits and see what gets used. PostHog is hosted in the United States, and the usage data described here is sent there.

Here is what is measured, and nothing more. On the website, page views, scrolling, clicks on the “Start your tree” buttons, with where they came from (previous page, mobile or computer). In the app, opening the account screen, creating an account or a tree, and for shared trees, opening them, the time spent and the type of content viewed (text, photo, video), with the role, visitor or contributor. The tree is identified there by a scrambled code, never by its name.

There is no automatic capture of clicks or pages. No tree content (name, person, photo) is sent. When you are logged in to your account, a technical account identifier (never your email address) links your visits together. A cookie is set on parenthese.io and its subdomains to recognize the same visit across the site and the app.

Your rights

Keeping your data at home

The code of Parenthèse is public, under the PolyForm Noncommercial 1.0.0 license. A family that would rather not entrust anything to anyone can install Parenthèse on its own server. It then has everything (database, files and backups) without going through me. The code and the instructions are on github.com/IliesAllali/parenthese.

Last updated

September 14, 2026. This page changes when the code changes.

A tree your family views through a link

One account, one family name, two passwords. You stay in control of who sees what.

Start your tree