Last updated: February 2026
WebGeno ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our genogram builder application ("the Service").
Please read this policy carefully. By using the Service, you consent to the practices described in this Privacy Policy.
We use the collected information to:
When using the free tier without cloud features, your genogram data is stored locally on your device. We do not have access to locally stored data.
Professional tier users who enable cloud storage benefit from end-to-end encryption. Your genogram data is encrypted on your device using AES-256-GCM encryption before being transmitted to our servers. The encryption keys are derived from your password and never leave your device. This means only you can decrypt your data - WebGeno administrators cannot access your genogram content, even if legally compelled.
Data is also encrypted in transit using TLS and at rest on servers provided by Supabase.
We implement appropriate technical and organizational measures to protect your data, including encryption, access controls, and regular security assessments. However, no method of transmission over the Internet is 100% secure.
We use the following third-party services:
These services have their own privacy policies, and we encourage you to review them.
Our Professional tier includes AI-powered genogram generation and editing. When using these features:
Privacy-by-Design Limitations: Our automatic name detection may not identify all names, particularly uncommon, foreign, or misspelled names. Users are responsible for verifying that all personal identifiable information is properly anonymized before AI processing. We provide manual tagging tools ([brackets] and Ctrl+B) to help you identify names our system may have missed.
Alignment with EU Regulations: Our AI features are designed with privacy-by-design principles aligned with GDPR and the EU AI Act's transparency requirements. The anonymization process ensures that identifiable client information does not leave your device in readable form.
We do not sell your personal information. We may share your information only in these circumstances:
You have the right to:
Important limitation regarding encrypted data: Cloud-stored genograms are protected by end-to-end encryption (AES-256-GCM). Encryption keys are derived from your password and never leave your device. This means we cannot access, read, or provide copies of your encrypted genogram content — not even if you request it or if legally compelled. If you lose your password and recovery phrase, your encrypted data cannot be recovered by anyone, including WebGeno. We can only provide access to non-encrypted account data (email, subscription status, usage metadata). You are responsible for exporting your genogram data directly through the application while you have access.
To exercise your rights regarding non-encrypted data, please contact us at the email address provided below.
We retain your personal data for as long as your account is active or as needed to provide the Service. After account deletion, we may retain certain information as required by law or for legitimate business purposes for up to 30 days.
Locally stored genogram data remains on your device and is under your control.
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
Your information may be transferred to and processed in countries outside your country of residence. Specifically:
For transfers from the European Economic Area (EEA) to countries without an EU adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the appropriate safeguard mechanism. You may request a copy of the applicable SCCs by contacting us at support@psychologysmarttools.com.
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
Our specific legal bases for processing are:
This marketing website (psychologysmarttools.com) uses Google Analytics (G-YT86T6S5VS) via Google's gtag to understand how visitors use the site. Google Analytics may set cookies in your browser. You can opt out via your browser settings or the Google Analytics opt-out browser add-on.
The WebGeno application itself does not use cookies or Google Analytics. The application uses browser localStorage exclusively for:
localStorage data remains on your device and is never transmitted to third parties for advertising purposes. You can clear it at any time through your browser settings, which will log you out of the Service.
We use Sentry for error tracking and performance monitoring. Sentry receives technical error data (stack traces, browser type, OS) but does not use cookies and does not receive personal health data or genogram content.
We use the following sub-processors to deliver the Service:
All sub-processors are bound by data processing agreements and are required to handle your data in accordance with applicable privacy laws. We review sub-processors periodically and will update this list when sub-processors change.
When mental health professionals and other users input client data into WebGeno, they act as data controllers and WebGeno acts as a data processor. If your professional practice, institutional policy, or applicable law (including GDPR Article 28) requires a formal Data Processing Agreement, you may request one by contacting us at support@psychologysmarttools.com. We will provide a DPA at no charge.
Genograms may contain sensitive health, psychological, and family information. You are responsible for:
WebGeno's end-to-end encryption for cloud storage is designed to support compliance efforts, but we make no warranty that use of WebGeno satisfies any specific regulatory requirement in any jurisdiction.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Our notification will include:
For all data protection enquiries — including exercising your GDPR rights, requesting a Data Processing Agreement, or raising a concern about how we handle your data — please contact our Data Protection Officer:
Email: support@psychologysmarttools.com
You also have the right to lodge a complaint with your local data protection supervisory authority at any time. In Portugal, this is the CNPD (Comissão Nacional de Proteção de Dados) at www.cnpd.pt.
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
If you have any questions about this Privacy Policy or our data practices, please contact us at: