Haunted Lineage Lab — Privacy Notice
Effective date: October 2, 2026 Version: 1.2
This Lab Privacy Notice explains how Haunted Lineage LLC d/b/a Haunted Lineage ("we," "us," or "our") handles information in the Haunted Lineage Lab, including lab.hauntedlineage.com, the Haunted Lineage Lab mobile app, and related features (together, the "Lab").
This notice adds to our main Privacy Policy. If the two conflict, this notice controls for the Lab. Capitalized terms not defined here have the meanings in the Lab Service Terms.
1. Two Kinds of Information, Two Different Roles
Information about you (account holders). This covers your account, subscription, and how you use the Lab. We decide how this information is used, as described in this notice.
Information you collect about other people. This covers clients, property owners, witnesses, and anyone else you document ("Third Parties"). You, or your team, decide what to collect and why. We store and process it on your behalf to provide the Lab. You are responsible for having a lawful reason to collect it and for getting any consent the law requires. See Section 5 of the Lab Service Terms.
2. What We Collect
Account and team information
- Name, username, email address, password (stored only in hashed form), profile details, and team membership and role.
- If your Lab account is connected to your Haunted Lineage website account, the details needed to keep the two in sync.
Billing information
- Plan, subscription status, purchase history, and billing contact details.
- Card details are collected, stored, and processed by Stripe. Stripe retains the payment method for renewals and confirmed upgrades. We store Stripe customer/subscription references, invoice identifiers, transaction amounts, and status, not your full card number or security code. Manage billing in Settings → Subscription & Billing.
Investigation data (Your Data)
- Case files, notes, timelines, investigation logs, equipment records, and research sources.
- Third-Party details you enter, such as names, contact information, property details, intake and questionnaire answers, and, if you choose to record them, health or physical-condition notes.
- Photos, audio, video, floor plans, and the transcripts and analysis results created from them.
- Signed documents and their signature audit records: signer names, typed or drawn signatures, time stamps, and related technical details.
Location information
- Precise GPS location, when you allow it, to tag cases and evidence, fill in addresses, and look up weather, geology, and time data.
- Addresses and coordinates you type in.
- An approximate location based on your IP address, used to center maps and address searches when GPS isn't available.
Voiceprints (biometric information). See Section 4.
Device and technical information
- Device type, operating system, browser, app version, IP address, sync status, error logs, and security logs.
- Usage and performance information collected by our own self-hosted analytics. The Lab does not currently use third-party analytics or advertising trackers. If that changes, we will update this notice first.
Information stored on your device. Offline caches may remain after synchronization, signing out, or server account deletion. Server deletion cannot erase offline devices. Clear site/app storage on shared devices when no longer needed; uninstalling or clearing storage may destroy unsynced work. Voiceprint withdrawals and expiry are reconciled on successful sync. We cannot recover data that never reached our servers.
3. How We Use Information
- To provide the Lab: storing, syncing, and displaying data; running analysis tools; preparing documents; and sending emails you ask us to send, such as signing requests and questionnaires.
- To manage accounts, teams, subscriptions, storage limits, and billing.
- To secure the Lab, prevent fraud and abuse, and fix problems.
- To send transactional account, purchase, upgrade, renewal, payment-problem, service, and security notices. Marketing is separate, requires opt-in, and can be unsubscribed from anytime.
- To improve the Lab, using our own analytics and diagnostics.
- To comply with the law and enforce our terms.
We do not sell personal information. We do not use Your Data for advertising. We do not use Your Data to train third-party AI models.
4. Voiceprints and Biometric Information
Some laws, such as the Illinois Biometric Information Privacy Act, treat voiceprints as biometric identifiers. This section is our written policy for them.
What it is. A voiceprint is a numerical profile created from a voice sample. The Lab uses it to recognize known speakers in recordings, for example to filter out investigators' voices during analysis.
Consent first. The speaker must read the disclosure, type their own name, and affirm separate electronic consent before creation. We record the signed name, disclosure version, consent time, and expiry with the voiceprint. Do not sign for another person. Legacy records without valid consent cannot be used or synchronized.
Purpose limit. Voiceprints are used only for speaker recognition inside the Lab, for you and your team.
No sale or profit. We do not sell, lease, trade, or otherwise profit from voiceprints.
Limited sharing. We do not share voiceprints with anyone except (a) members of your team, where a team feature requires it, (b) our hosting provider, which stores them on our behalf, or (c) when required by law or valid legal process.
Retention and destruction. We permanently destroy a voiceprint at the earliest of these:
- When confirmed deletion or consent withdrawal reaches the server;
- When deletion of the owning account completes; or
- When consent expires, six months after it was given. Expired records are blocked from use and sync; server cleanup runs at least hourly while running. Signing in, analysis, and syncing do not renew consent. New consent and a new voiceprint are required afterward.
Offline deletion requests remain pending until they reach the server. Successful sync removes withdrawn, missing, and expired server voiceprints from local copies. Independently offline devices cannot be erased remotely. Routine server backups must exclude voiceprints. An inadvertently backed-up copy must not be restored to use and must be removed when that backup expires. Public investigation retention never extends biometric consent.
To prevent a withdrawn voiceprint from being recreated by an offline copy, we keep only its opaque record identifier and expiry until the original consent would expire, without its voice sample, embedding, or signed name.
Security. Voiceprints are protected with at least the same safeguards we use for other sensitive information.
5. Where Processing Happens
- On your device. Several analysis features, such as some speech detection and audio models, run entirely on your device.
- On our servers. Synced data is stored and processed on servers we control. These are hosted by GTHost in a data center in Toronto, Ontario, Canada. Some features, such as server transcription and file conversion, run on these servers. They do not send your audio to outside AI companies.
6. Who We Share Information With
Your team and public data. Team members can see shared data based on role. Marking investigation data public can make data exposed by public-access features accessible without login; obtain the necessary permission first. Public data survives automatic retention cleanup and account closure, but is not immutable. Investigators with access may deliberately delete recordings, sensitive information, other items, or the whole investigation using the applicable confirmations. Administrators may also delete it, including through delete-all.
Service providers that work for us:
| Provider | Purpose | What they receive |
|---|---|---|
| GTHost | Server hosting | All synced Lab data (stored on our servers in their data center) |
| Stripe | Payment processing | Billing details and payment card information |
| SendPulse | Email delivery (SMTP relay) | Recipient email addresses and email content |
| Our own mail server | Email delivery | Recipient email addresses and email content |
Services the Lab contacts directly to provide a feature. When you use these features, your device sends them the information they need, usually coordinates, an address, or your IP address:
| Service | Used for |
|---|---|
| OpenStreetMap Nominatim; Photon (Komoot) | Address search and reverse lookup |
| U.S. Census Bureau Geocoder | Census tract lookup |
| Esri ArcGIS; OpenStreetMap | Map tiles |
| National Weather Service (weather.gov) | Weather conditions |
| Macrostrat | Geology data |
| timeapi.io | Time synchronization |
| ipinfo.io | Approximate location when GPS is unavailable |
These services have their own privacy policies.
We may also share information:
- when required by law, or to protect rights, safety, or property; and
- as part of a merger, acquisition, or sale of assets, under the same protections as this notice.
7. How Long We Keep Information
| Information | How long we keep it |
|---|---|
| Active account data | While your account is active |
| Deleted private investigations | Eligible for permanent cleanup after 7 days; explicit permanent deletion can occur sooner |
| Private investigation data after paid access ends | 45-day renewal/export grace period, then may be deleted; explicit authorized deletion can occur sooner |
| Investigations containing public data | No automatic age-, subscription-, account-closure-, or quota-based deletion; investigators with access may deliberately delete items or the case, and administrators may explicitly delete data or use delete-all |
| Data after account deletion | Login and owned voiceprints removed; shared/public data retained and linked published content may be reassigned |
| Voiceprints | See Section 4 |
| Internal server backups | Not guaranteed to exist or to include your data; kept only as server capacity allows |
| Billing records | As long as tax and accounting law requires |
| Website access logs | 7 days (1 week) |
| System logs, including security and error logs | 60 days; excludes investigation evidence logs, signature audit records, and billing records |
These are maximum periods, not promises to keep anything. Data can be lost earlier because of failures or events beyond our control. Keep your own backups. See Section 4 of the Lab Service Terms.
8. Security
We use industry-standard safeguards, including encrypted connections (HTTPS), hashed passwords, access controls, and commercially hosted infrastructure. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you as required by law.
9. Your Choices and Rights
- Access and export. You can view your information in the Lab and export case data and a full data archive.
- Correction. You can update your profile and Your Data in the Lab.
- Deletion. Delete your account or voiceprints in the Lab or contact us. Investigators with access may deliberately delete investigation data, including public data, using the applicable confirmation prompts. Shared/public records are not automatically removed when an account closes; delete mistaken or sensitive items before closure, or contact support afterward. Retained billing/legal records are not necessarily deleted with your login.
- Withdraw voiceprint consent. Delete the voiceprint at any time. It is destroyed as described in Section 4.
- Device permissions. You can turn off location, camera, and microphone access in your device settings. Some features will stop working.
- State privacy rights. Depending on where you live, you may have more rights, such as the right to know, correct, delete, or appeal. Contact us to make a request. We will verify your identity before acting on it.
- Requests about information an investigator collected. If an investigator or team entered information about you, contact them first. If you contact us, we may forward your request to them, because they control that information.
10. App Permissions
| Permission | Why the Lab asks for it |
|---|---|
| Location | Tag cases and evidence; look up addresses, weather, geology, and time |
| Camera | Capture photos, video, and QR codes |
| Microphone | Record audio and create voiceprints, with consent |
| Storage / files | Import and export evidence and documents |
11. Age Requirement
The Lab is for people 18 and older. We do not knowingly collect information from anyone under 18 who has a Lab account. Information about minors should be entered only by an adult investigator who has a parent's or guardian's permission.
12. Where Data Is Stored
Haunted Lineage LLC is based in the United States. Synced Lab data is stored on servers in Toronto, Ontario, Canada, and may be accessed from the United States to run and support the Lab. Some service providers, such as Stripe and SendPulse, may process information in other countries. Information stored in another country is subject to that country's laws, including lawful requests from its authorities. By using the Lab, you understand that your information will be transferred to and processed in Canada and the United States.
13. Changes to This Notice
If we change this notice in a material way, we will tell you in the Lab or by email before the change takes effect. The effective date and version number at the top show the latest version.
14. Contact
Privacy questions or requests: site@hauntedlineage.com Haunted Lineage LLC, 1664 South Sharp Ave, Marshall, Missouri 65340
