Privacy at Heraldia
Heraldia is a surname research and artistic-emblem service, not a genealogy database. It stores only what is needed to reduce model cost, restore a local draft, protect the service and create links that a visitor explicitly chooses to share.
What is sent to AI providers
The surname and optional family geographic or period context are sent to the configured research provider. The resulting visual brief is sent to OpenAI for image generation.
Family context is treated as a statement from the visitor. It is not evidence of origin, ancestry, lineage membership, nobility or heraldic rights.
Shared surname research
Public-record surname research is cached by normalized surname and generated-content language and may be reused for every visitor requesting that language. Family context is removed before this shared copy is stored.
The language toggle translates the interface. New research is generated in the selected language, while existing generated research and emblem descriptions are never automatically translated when the toggle changes.
Research becomes eligible for refresh after 30 days. A permanent surname page may retain the latest available version so its URL does not disappear while research is refreshed.
Generated emblems and sharing
A canonical surname-and-style image may be stored internally and reused to reduce image-generation cost. It contains no family context and does not receive a public personal page by default.
A personal variation is not stored on the server unless the visitor chooses Share. That action creates a public, unguessable link. Public share links are retained so links do not break; removal can be requested through the contact page below.
Data kept in the browser
The current draft's research and metadata may be saved in localStorage. PNG files are kept as local blobs in IndexedDB instead of base64 text. If an emblem was shared, Heraldia first attempts to restore it from its public URL and uses the local blob as a fallback.
Starting a new search clears the local draft and its image blobs only; it does not delete a public link that was already created.
Rate-limit data
The client IP address is transformed with a keyed HMAC before storage. Heraldia stores only the resulting identifier and request counters. The original IP address is not stored in the rate-limit table, and rows older than seven days are removed during normal limit checks.
The site owner may temporarily authorize a trusted browser for production testing with a server-only secret. The browser receives a signed, secure, HTTP-only cookie that expires after 12 hours; the secret itself is not stored in the browser. This access changes quotas and cooldowns only and does not expose visitor data.
Security and access
Supabase tables use row-level security and deny direct browser access. Elevated database and OpenAI keys remain on the server. Emblem files are stored in a private bucket and are served only through Heraldia after the shareability check succeeds.
Questions or removal requests can be sent through the Carlos Tarmeno contact page.
Back to Heraldia