We’re welcoming 1,000 founding families. $100 per adult; bring your whole line.

Check eligibility — free

Built for sensitive
family records.

Heritage Passport helps you work with passports, vital records, lineage facts, addresses, and payment events. The security model is deliberately plain: protect uploads, limit access, avoid reselling sensitive data, and use established infrastructure for storage, payments, and abuse prevention.

TrustedSite monitored

The TrustedSite badge links to current site-security verification and monitoring context.

Verify the site →

Payments handled by Stripe

Stripe collects and processes card details. Heritage Passport does not store full card numbers.

Private Supabase storage

Account, case, and document records use private storage with encryption in transit and at rest.

Access and deletion rights

You can request access, correction, export, or deletion, subject to legal retention requirements.

Documents stay tied to your account and case.

Uploads use short-lived signed addresses, permitted file types, size limits, and a storage path that binds each object to the signed-in user, case, and document. Finalizing an upload re-checks case ownership and stored-file metadata before the document is registered.

What the app enforces

  • Authenticated upload gates

    Uploading and finalizing a document requires a signed-in user before any storage object is registered.

  • Owner-scoped checks

    Server checks confirm the case belongs to the user and the upload path matches that user, case, and document.

  • Short-lived file links

    Every private file view is permission checked and uses a signed link that expires after 60 seconds.

  • Guardrails before processing

    Uploads are restricted to supported image and PDF types, size limits, and abuse controls.

What we do not claim

  • No invented certifications

    We do not claim SOC 2, HIPAA, ISO 27001, or another certification unless current proof supports it.

  • No zero-knowledge promise

    Our server must read a document when you ask the product to extract facts or check the file.

  • No raw card storage

    Card entry and payment processing happen through Stripe, not a Heritage Passport card database.

Sensitive data is used for the service you requested.

Heritage Passport is not an advertising broker for identity records. Sensitive personal information is collected to provide the service, not sold or shared for cross-context behavioral advertising, and can be deleted on request subject to legal retention requirements.

Primary service providers

  • Supabase

    Authentication, Postgres database, and Storage infrastructure for account, case, document, and vault records.

  • Stripe

    Payment processing and signed payment-event verification; Stripe also handles card data directly.

  • Anthropic

    Document contents are sent only when the document-reading workflow runs to extract the facts that feature needs.

  • Cloudflare Turnstile

    Bot and abuse checks on public account-entry flows when Turnstile keys are configured.

Read the complete subprocessor list →

Retention and deletion

  • Vault documents

    After account closure, the Privacy Policy provides a 30-day download period before production deletion. Immediate document deletion can be requested.

  • Backups

    Deleted production data may remain in rolling backups for up to seven additional days.

  • Payment records

    Payment records may be retained for tax, accounting, fraud, and legal obligations.

Request access or deletion →

Privacy details live in the policies.

This page summarizes our security posture in plain English. The controlling terms for collection, sharing, retention, deletion, and account rights are the Privacy Policy and Terms of Service.

Read the Privacy Policy or Terms.

Sign in securely