Privacy Policy
Bamsawali (वंशावली) records family lineage — which means it holds information about you, your ancestors and your living relatives. This policy explains what we collect, why, who else can see it, and how to have it removed.
Last updated 28 September 2026
1. Who we are
Bamsawali is a community genealogy platform for Nepali families, operated by brihatech. It lets members of a Samaj record their family tree — ancestors, descendants, marriages, gotra and thar — preserve family history, and find how they are related to other members.
This policy covers the Bamsawali mobile app, the website at www.bamsawali.com, and the services behind them. It applies whether you browse as a guest or sign in as a member. If you administer a Samaj through our admin portal, this policy covers your account there too.
2. Family records and other people
Genealogy is unusual among apps: most of what a family tree contains is information about people other than the person entering it. Bamsawali is built on that reality, so we want to be direct about it.
- You may add records about relatives. When you build your tree you can create entries for parents, grandparents, spouses, children and more distant kin — including people who have never used Bamsawali.
- Others may add a record about you. A relative or a Samaj data-entry volunteer may create an entry describing you before you ever open the app. When you later sign in, you can claim that entry as your own.
- Records about deceased ancestors are historical genealogical data. We treat them as part of the community record rather than as living persons' personal data.
- Only add what you may share. If you record details about a living relative, you are responsible for having a reasonable basis to do so. Do not add sensitive information about someone who would object to it.
3. Information we collect
Account and identity
- Phone number. Members sign in with a phone number and a one-time code (OTP) sent by SMS. We store the number in international format and the time of your most recent sign-in.
- Google account details. If you choose Sign in with Google, we receive your Google account identifier, your verified email address, and your name and profile picture as Google provides them. We never receive your Google password.
- Session data. Short-lived access tokens and longer-lived refresh tokens that keep you signed in, along with the record of which sessions are active so they can be revoked.
Your profile and family tree
- Your name in Nepali and in English, gender, and a profile photo or chosen avatar.
- Dates of birth — and, for deceased persons, of death — which may be recorded in Bikram Sambat or in the Gregorian calendar, and at whatever precision is known (a full date, a month, a year, or an approximation).
- Genealogical attributes such as gotra, thar (surname), and place or region associated with the family.
- Family relationships: parents, spouses and marriages, children, and the position of a person within their generation.
- Your Samaj and Kul Samiti membership, your role within it, and any membership or Samaj-registration application you submit.
- Photographs you upload for yourself or for people in your tree.
Content and communications
- Conversations with the in-app AI assistant, by text or by voice. Voice input is streamed to our AI provider for the duration of the conversation so it can respond.
- Disputes, corrections, proposals and other requests you send to your Samaj administrators, and any message you send us directly.
Technical information
- A device notification token, so we can deliver push notifications to your device.
- Standard server logs: IP address, request time, app or browser version, and operating system, kept for security and for diagnosing faults.
- Aggregate, non-identifying usage statistics for the public website.
4. Device permissions
The app asks for a permission only at the moment a feature needs it, and every one of them can be declined — the rest of the app keeps working.
- Camera and photo library — to attach a photograph to your profile or to a person in your tree. We access only the images you pick.
- Microphone — only while you are speaking to the AI assistant in voice mode. Audio is captured while that conversation is open and is not recorded in the background.
- Notifications — to tell you about activity in your Samaj, such as a membership decision or a change to your family tree.
- SMS auto-fill (Android) — with your one-time consent, Android hands the app the single OTP message we just sent, so the code fills itself. This uses Android's SMS User Consent API: the app holds no SMS permission and cannot read any other message in your inbox.
5. How we use information
- To create your account and verify that it is you signing in.
- To build, display and navigate family trees, and to work out how two members are related.
- To let your Samaj administrators verify membership and review proposed changes to the community record.
- To answer your questions through the AI assistant, drawing on the genealogical context you already have access to.
- To send you service messages — one-time codes, membership decisions, and notifications you have opted into.
- To keep the service secure: rate-limiting sign-in attempts, detecting abuse, and investigating faults.
- To improve the product using aggregate usage patterns, not individual browsing histories.
We do not use your family data to train third-party AI models, and we do not sell personal information to anyone.
7. Who can see your entries
Bamsawali is a community platform, not a private notebook. What you record is visible to the community it belongs to:
- Members of your Samaj can see the people and relationships recorded in that Samaj's tree, including your own entry once you have claimed it.
- Samaj and Kul Samiti administrators can additionally see and edit membership records and the entries under their care, and can see the contact details you registered with.
- Your personal tree — the private tree you build for yourself before or alongside joining a Samaj — is visible only to you until you choose to connect it to a Samaj tree.
- Guests browsing without an account see only demonstration content and whatever a Samaj has chosen to publish openly.
9. How long we keep information
We keep your account information for as long as your account exists. One-time codes expire within minutes. Sign-in sessions expire on their own and are revoked immediately when you change your phone number. Server logs are kept for a limited period for security and troubleshooting.
Genealogical records are intended to last: a family tree is only useful if it survives. When you delete your account we remove your personal account data as described in the deletion request page, and we will confirm to you exactly what was removed and what, if anything, remains as part of the shared community record.
10. Your choices and rights
- See and correct your data. Your profile and the people in your tree are editable in the app at any time.
- Change your phone number. This requires verification of both the old and the new number, and signs out every other session.
- Turn off notifications in the app or in your device settings.
- Get a copy of your data. Write to us and we will provide the personal data we hold about you.
- Delete your account and data — see the next section.
- Object or complain. If you believe we have handled your information wrongly, write to us and we will investigate.
To exercise any of these, write to [email protected]. We may ask you to verify control of the phone number or email address on the account before we act, so that no one else can make the request in your name.
11. Deleting your account
You can request deletion of your Bamsawali account and its associated data at any time, and you do not need to open the app to do it. The Delete your account page explains what is removed and gives you a form to send the request. We complete deletion requests within 30 days.
12. Security
Traffic between the app and our servers is encrypted in transit. Sign-in tokens are short-lived and are stored in the device's encrypted storage. Sign-in attempts and one-time codes are rate-limited, and every session can be revoked. Administrative accounts are separated from member accounts and hold their own permissions.
No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the relevant authorities as required.
13. Children
Bamsawali accounts are not intended for children under 13, and we do not knowingly create accounts for them. Sign-up requires a phone number or a Google account.
A family tree will, however, contain children — an adult recording their household will naturally add their sons and daughters. Those entries are genealogical records created and controlled by an adult member, not accounts, and they carry no contact details or sign-in credentials. A parent or guardian can ask us to correct or remove any such entry at [email protected].
Our Child Safety Standards set out what we prohibit, how to report child sexual abuse or exploitation, and how we respond to such a report.
14. International transfers
Bamsawali serves a community based largely in Nepal, but some of the providers listed above operate infrastructure in other countries. Your information may therefore be processed outside Nepal. We use established providers who offer appropriate contractual safeguards for those transfers.
15. Changes to this policy
We may update this policy as the product changes. The date at the top of this page always reflects the current version. If a change materially affects how we handle your information, we will make it prominent in the app rather than relying on this page alone.
16. Contact us
Questions about this policy, or about the information we hold on you, go to [email protected]. Bamsawali is operated by brihatech, brihatech.com.
