1. The short version
FamHead is made for households, not advertising. We use the information needed to run your account, connect you to your household, keep the app safe, and deliver notifications.
Private household content is encrypted on a member’s device before it is sent to FamHead. We are not designed to see it in readable form. Some information must remain readable for FamHead to work, including your profile name, household membership, member role, dates, technical device information, profile photo, and Home photos.
2. Who is responsible for your data
The data controller for FamHead is [legal name of operator], [registered address]. You can contact us at [privacy contact email].
If we appoint a data-protection representative or data-protection officer, we will add their details here.
3. Information we process
| Information | Why we use it | Encrypted as private household content? |
|---|---|---|
| Account information from Sign in with Apple and Firebase Authentication, such as a provider identifier, Firebase account ID, and the name or email Apple provides | To create and protect your account and let you sign in | No |
| Your profile name, profile-photo reference, and profile photo | To identify you to household members | No |
| Household name, member names, roles, membership status, invitations, and dates | To create and manage households and control access | No |
| Tasks, decisions, shopping-list items, outcomes, and other private household text | To provide shared household features | Yes |
| Voice recording while you use voice input, and the text it produces | To turn your spoken request into a task, decision, or shopping item | The recording and transcription are processed on-device; text is encrypted before it is shared |
| Home photos and their references | To show the rotating Home header to your household | No |
| Device and notification information, such as an app/device record, push-notification token, notification preference, and service timestamps | To send notifications only to the right devices and protect the service | No |
| Security and service information, such as authentication, App Check, error, network, and abuse-prevention information | To keep the service secure, troubleshoot, and prevent misuse | No |
| Messages you send to support | To answer you and improve support | No, unless you choose to encrypt it before sending it |
A note about content encryption
When we say “encrypted”, we mean FamHead turns private household content into protected data on a household member’s device before it is stored in Firebase or used for a notification. The app needs a household secret kept on authorized members’ devices to make that content readable again.
This does not make every part of FamHead invisible. We and our service providers can still process the readable account, membership, photo, notification-routing, and technical information listed above. Current household members can read private content in the app. A member may also copy, capture, or share it outside FamHead.
4. How we use information
We use the information above to:
- create and secure accounts;
- create, join, and manage households;
- store and sync household features;
- provide profile and Home photos to authorized household members;
- send notifications you choose to receive;
- detect, prevent, and investigate security or abuse issues;
- respond to support requests; and
- meet legal obligations.
We do not sell personal information. We do not use private household content to target advertising.
Where a law requires a legal basis, we generally process information to provide the service you ask us for, to meet legal obligations, with your consent where needed (for example, system permissions), or for legitimate interests such as keeping FamHead secure and reliable. [Legal counsel: confirm the lawful bases for each country and feature before publication.]
5. Who receives information
Your household
Current household members receive the profile, membership, and shared information needed to use the household. They can read private household content once their authorized device can decrypt it. They can also see profile and Home photos, which are not encrypted as private household content.
Service providers
We use Google Firebase and related Google Cloud services to operate FamHead. They provide account authentication, database synchronization, cloud storage, server functions, app security checks, hosting, and push-notification delivery. Google generally acts as a processor for Firebase customer data under its Firebase data-processing terms.
Apple provides Sign in with Apple, device operating-system services, and Apple Push Notification service. Your device may also ask Apple for microphone, photo-library, notification, or on-device speech permissions when you use those features.
We share only what is needed for those services to work. They may process information in countries other than the one where you live. See section 7 for more on international transfers.
Other situations
We may disclose information if reasonably necessary to comply with the law, enforce our rights, protect people or the service, or as part of a merger, sale, or reorganisation. If that happens, we will protect the information as required by law.
6. Notifications
If you allow notifications, FamHead stores a token that lets Firebase Cloud Messaging and Apple Push Notification service reach your device. A notification may include a generic message and protected data the FamHead app can use to show a private preview. Do not rely on a lock-screen notification as a private place: its visibility also depends on your device settings and anyone who can see your device.
You can turn notifications off in FamHead or in your device settings.
7. International transfers
FamHead uses Firebase/Google and Apple services that may process information outside your country. Firebase Authentication is operated from the United States, and other Firebase services can use Google’s global infrastructure unless a specific data location is selected.
When a transfer needs safeguards under applicable law, we will use the appropriate contractual, adequacy, or other lawful safeguards. [Replace this paragraph with the confirmed hosting/data-region and transfer wording before public release.]
8. How long we keep information
We keep account, profile, household membership, device, and photo information while your account and the relevant household remain active. We delete or anonymise information when it is no longer needed, subject to legal, security, backup, and technical requirements.
The current app lets you delete your account and, if you are the owner, delete a household. Account deletion removes your profile, device records, profile photos, and household membership. Shared encrypted history may remain with the household after you leave, so the household’s record continues to make sense. Household deletion removes the household’s shared data from FamHead’s active service.
Deleting from FamHead cannot remove screenshots, copies, exports, or content a person has already saved. It also cannot erase data temporarily retained in security logs or backups before their normal expiry.
[Insert precise retention periods for support messages, security logs, deletion receipts, and backups. Confirm how and when Firebase service logs and backups expire.]
9. Your choices and rights
Depending on where you live, you may have the right to ask for access to, correction of, deletion of, or a copy of your personal data. You may also have a right to object to or limit certain processing, or to withdraw consent where we rely on it.
You can update your profile, manage notifications, leave a household, or use the in-app deletion controls. For other requests, email [privacy contact email]. We may need to verify your identity before acting on a request.
You may also have the right to complain to the data-protection authority where you live. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). [Add the relevant EU/UK or other authority details if FamHead is offered there.]
10. Children
FamHead is not intended for children below [minimum age] without the permission required by applicable law. We do not knowingly collect personal information from children in breach of applicable law. If you think this has happened, contact us at [privacy contact email].
11. Security
We use authentication, access controls, encryption for private household content, app-integrity checks, and other reasonable measures to protect FamHead. No system can be guaranteed perfectly secure. Please protect your device, account, and household invitations, and contact us promptly if you believe your account has been compromised.
12. Changes to this Privacy Policy
We may update this policy when FamHead or the law changes. If a change is important, we will give reasonable notice in the app, by email where available, or by another clear method. The latest version will show its “Last updated” date.
13. Contact
[legal name of operator]
[registered address]
[privacy contact email]