Skip to content
Legal

Privacy Policy

Last updated 26 September 2026

At a glance

  • We collect the minimum we need to run a household app: email, household content (events, lists, chores, budget), and basic device identifiers.
  • We do not sell or rent your data. We do not show ads. We do not train AI on your data.
  • Data is hosted by Supabase in the United States and protected by row-level security so only your household can read your data.
  • You can export or delete your account at any time from Settings > Account in the app.

1. Who is responsible

Famio (“Famio”, “we”, “us”) is the data controller for the personal data described in this Policy. Famio is operated from the Republic of Kenya. You can contact us about anything in this Policy at contact@famio.cc.

2. What data we collect

You give us:

  • Email address used for sign-in;
  • Display name, avatar (optional), household name, and the household’s join code;
  • Content you create: calendar events, lists, recipes, meal plans, chores, rewards, budget transactions, and notes;
  • Kid profile data (a display name, optional avatar, a PIN, and birth-date), entered by an adult household member.

Collected automatically:

  • Device push token (so we can send notifications you have enabled);
  • App version, operating system, language, device model, and approximate region (for diagnostics);
  • Crash and error reports (via Sentry, with personal data filtered out where possible);
  • Usage events showing which features you use, such as completing a chore or viewing the paywall — never the contents of your lists, chores, calendar events, or budget, and never your household name, display names, or birth dates;
  • Screen views, recorded by screen type rather than by specific record — for example, that you opened a budget screen, not which one;
  • Screen and session recordings, which we use to improve the user experience;
  • None of the usage events, screen views, or recordings above are collected on a kid’s own device, or while a kid profile is active on a shared device;
  • IP address and timestamps when you sign in or hit our API, kept only briefly for security and rate-limiting.
  • PostHog records page views, navigation and call-to-action clicks, sections and FAQ answers viewed, scroll depth, time-on-page milestones, application progress by field name, submission outcome, device and browser type, approximate country, and campaign attribution, together with a privacy-masked session replay. With only essential cookies these are held against an anonymous session rather than a visitor profile, and are never linked to your name or email address. Form values, names, email addresses, free-text answers, and children’s details are excluded and all form inputs are masked in replay.

From third parties:

  • From Paddle, Apple, or Google when you subscribe: subscription status and an opaque user identifier. Famio does not receive your full card details;
  • From your authentication provider (Apple Sign-In or Google Sign-In) if you choose social sign-in: an email and a name.
  • If you connect Google Calendar: your Google account identifier, email, and basic profile information, the names and metadata of calendars available to that account, and the event details from each calendar you choose to import. Event details can include titles, dates and times, recurrence, descriptions, locations, organisers, attendees, response status, colours, and links to the original Google Calendar event.

We do not collect: bank credentials, transaction feeds from your bank, precise location, content of your photo library, contacts, microphone, or camera roll, unless you explicitly attach a file to the Service.

Website measurement has no in-page off switch. In the UK, the EEA, Switzerland and Quebec nothing is stored or recorded until you choose an option; elsewhere it begins at the essential level on arrival, and you can opt out by contacting us. You can turn off mobile usage analytics in the app under Settings → Privacy & data, where screen recordings have their own separate switch. Crash reporting continues regardless, because we rely on it to keep Famio working.

3. How and why we use data

  • To provide the Service: sync your household, send notifications, restore your subscription on a new device;
  • To keep the Service safe: detect abuse, rate-limit, fight spam, and prevent unauthorised access;
  • To improve the Service: diagnose crashes, fix bugs, and prioritise features;
  • To communicate with you: send account, billing, security, and (if you opt in) product updates;
  • To comply with legal obligations (e.g. tax, accounting, lawful requests).

We do not use your data for advertising, profiling, or selling to third parties, and we do not use your content to train AI models.

Google Workspace API data

Connecting Google Calendar is optional. Famio requests read-only access and uses Google Calendar data only to let you choose calendars, import their events into your household, keep those imported events synchronised, and display the original event link. Famio does not create, edit, or delete events in Google Calendar.

When you choose to use Famio AI, relevant imported event details may be included in the household context sent to the Google Gemini Developer API paid service so it can answer your request or draft actions for your approval. Google processes that data on our instructions and, under its paid-services terms, does not use prompts or responses to improve its products. Famio does not use Google Workspace API data to create, train, or improve generalised AI or machine-learning models.

Famio’s use and transfer of information received from Google Workspace APIs adheres to the Google User Data and Developer Policy , including its Limited Use requirements. We do not sell this data, use it for advertising or credit decisions, or permit human access except with your explicit consent or when necessary for security or legal compliance.

5. Children & kid profiles

Famio includes “kid profiles” — managed by an adult household member — for family use. We treat data linked to a kid profile as children’s data and process it only on the basis of verifiable parental consent, in accordance with the Data Protection (General) Regulations under Kenya’s Data Protection Act, 2019; COPPA in the United States; GDPR Article 8 (where applicable); and equivalent local laws.

  • The adult creating the kid profile confirms they are the parent or legal guardian of that child, or that they have the parent’s consent.
  • Kid profiles see only the data their household admin allows — no money tab, no other people’s private events, no settings.
  • We do not show kids any ads and we do not sell, rent, or share kids’ data with third parties.
  • We do not condition a child’s use of the Service on the disclosure of more data than is reasonably necessary.
  • A parent may at any time review the data linked to a kid profile, request its deletion, or revoke consent by deleting the profile from Settings > Household or by emailing contact@famio.cc.

If we learn we have collected children’s data without verifiable parental consent, we will delete it promptly.

6. Who we share data with

We use a small set of trusted processors. Each is bound by a data-processing agreement and acts only on our instructions:

  • Supabase Inc. — database, authentication, file storage. Hosted in the United States.
  • RevenueCat, Inc. — subscription management. Receives a pseudonymous user ID and your subscription status; never your name or content.
  • Paddle.com Market Ltd. — merchant of record for web subscriptions, including checkout, tax, receipts, refunds, and subscription management.
  • Apple Inc. & Google LLC — billing, app distribution, push notifications. They act as independent controllers under their own privacy policies.
  • Google LLC (Gemini Developer API paid service) — processes content you deliberately submit to Famio AI and the relevant household context needed to answer or draft actions. Google does not use paid-service prompts or responses to improve its products.
  • Functional Software, Inc. d/b/a Sentry — crash and error reporting, with personal data filtered.
  • PostHog, Inc. — product analytics and session replay. Receives the usage events, screen views, taps and recordings described in Section 2; a tap is recorded as which control on which screen, never the text shown on it. Never receives kid-profile activity.
  • Brevo (Sendinblue SAS) — support and application receipts, plus marketing email for people who consent. Receives your email and the attributes needed for the relevant conversation or message.
  • Upstash, Inc. — short-lived request-rate counters used to protect public forms from abuse.
  • Expo, Inc. — push delivery transport and over-the-air updates.
  • Doppler, Inc. — secrets management for our infrastructure (never sees your content).

We may also disclose data when (i) required by law or valid legal process from a competent authority (including under the Kenya Data Protection Act, 2019), (ii) to protect rights, property, or safety of users or the public, or (iii) in connection with a merger, acquisition, or asset sale — in which case we will notify you and any new owner remains bound by this Policy.

We do not sell or “share” personal information as defined by the CCPA/CPRA.

7. International transfers

Famio is operated from Kenya and your household’s data is stored in the United States. Personal data may be transferred to, and processed in, other countries where our processors (such as Supabase, RevenueCat, Paddle, Apple, Google, Sentry, PostHog, Brevo, Upstash, and Expo) operate.

  • For Kenyan users: we transfer data outside Kenya only where the receiving country has comparable safeguards, or under appropriate contractual safeguards, as permitted by section 48 of the Kenya Data Protection Act, 2019.
  • For EU/UK users: because your data is stored in the United States, every transfer leaves the EEA and UK. We rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum where applicable, and on supplementary technical measures including encryption in transit and at rest.

A copy of the relevant safeguards is available on request.

8. How long we keep data

  • Account & household data: until you delete your account.
  • Connected Google Calendar data: until you remove that connected calendar or delete your account. Removing it deletes the events imported through that connection. Encrypted OAuth credentials are retained only while needed to keep a selected calendar connected.
  • After account deletion: up to 30 days in active systems and a further 60 days in encrypted backups, after which data is purged. We may retain limited records longer where required for legal, tax, or accounting reasons.
  • Crash and diagnostic logs: 30–90 days.
  • Sign-in and security logs: up to 12 months.
  • Early-access applications, from when that form was open: kept only to send the product updates you consented to receive. You may unsubscribe or request deletion at any time.

9. How we protect data

  • Encryption in transit (TLS) and at rest (AES-256 at the storage layer);
  • Row-level security in our database so household data is only readable by authenticated members of that household;
  • Strong password hashing for email/password accounts (Argon2 / bcrypt as managed by Supabase Auth);
  • Principle of least privilege for staff access, with audit logging;
  • Routine dependency scanning, infrastructure hardening, and penetration testing.

No system is 100% secure. If you suspect a security issue, please email contact@famio.cc.

10. Your rights (Kenya — DPA 2019)

If you are in Kenya, the Data Protection Act, 2019 gives you the right (under Part IV of the Act) to:

  • Be informed of the use to which your personal data is to be put;
  • Access your personal data in our custody;
  • Object to the processing of your personal data;
  • Correction or deletion of false or misleading data about you;
  • Withdraw consent and request deletion of data we hold about you.

To exercise any of these rights, email contact@famio.cc. We will respond within the statutory timeframe under the Act.

If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner (ODPC) ( www.odpc.go.ke ).

11. Your rights (EU / UK — GDPR)

If you are in the EU, UK, or EEA when you use the Service, the GDPR and UK GDPR give you the right to:

  • Access your personal data (Art. 15) and receive a copy in a portable format (Art. 20);
  • Rectify inaccurate data (Art. 16);
  • Erase your data (Art. 17 — the “right to be forgotten”);
  • Restrict processing (Art. 18);
  • Object to processing based on legitimate interests (Art. 21);
  • Withdraw consent at any time (Art. 7);
  • Lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner’s Office ( ico.org.uk ); in the EU, the authority of your country of residence.

To exercise any right, email contact@famio.cc. We will respond within 30 days (or notify you if we need an extension).

12. Your rights (California — CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, the sources, purposes, and categories of recipients;
  • Request a copy of your personal information collected in the previous 12 months;
  • Request deletion of your personal information;
  • Correct inaccurate personal information;
  • Limit the use of sensitive personal information (note: we do not use sensitive personal information beyond what is necessary to provide the Service);
  • Opt out of the “sale” or “sharing” of personal information for cross-context behavioural advertising — we do not sell or share, so there is nothing to opt out of;
  • Not be discriminated against for exercising these rights.

Categories of personal information collected (CCPA categories): identifiers (email, user ID), commercial information (subscription status), internet activity (app interactions, diagnostics), and geolocation at the country level only. We do not collect biometric, audio, visual, or precise-location data.

Submit a CCPA request via contact@famio.cc. We will verify your identity through your account email. You may use an authorised agent if you provide a signed permission and we can verify your identity.

13. Your rights (Canada — PIPEDA)

If you are in Canada, the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial laws (Quebec Law 25, Alberta PIPA, British Columbia PIPA) give you the right to access and correct your personal information, withdraw consent, and complain to the Office of the Privacy Commissioner of Canada ( priv.gc.ca ).

14. Other regions

  • Brazil (LGPD): the rights of access, correction, anonymisation, deletion, portability, and information about sharing apply.
  • Australia (Privacy Act): the Australian Privacy Principles apply; you may complain to the OAIC.
  • South Africa (POPIA), Nigeria (NDPA), South Korea (PIPA), Japan (APPI), and other jurisdictions: we honour requests in line with local law.

15. Your choices

  • Notifications: manage them in Settings > Notifications in the app, or in your device’s OS settings.
  • Social sign-in: you can revoke Apple or Google sign-in from your Apple/Google account at any time.
  • Google Calendar: remove a calendar and its imported events from Calendar > Connected calendars. You can also revoke Famio’s access in your Google Account; revoking access stops future synchronisation but does not itself delete data already imported into Famio.
  • Marketing email: opt out via the unsubscribe link in any marketing email; this does not stop transactional emails (security, billing, service notices).
  • Delete account: Settings > Account > Delete account.

16. Cookies & similar technologies

You choose between two options on the cookie banner, and both of them allow a privacy-masked recording of your visit. Only essential cookies stores a visitor and session identifier so pages can be connected into one visit and that visit can be replayed; it creates no visitor profile, sets no advertising cookies, and is never linked to your name or email address. Accept all cookies additionally allows a visitor profile and lets a visit be connected to your account if you go on to sign up, and allows our advertising measurement. In the UK, the EEA, Switzerland and Quebec nothing at all is loaded or stored until you choose; everywhere else measurement begins at the essential level on arrival and the banner lets you change it. You can change your mind or opt out at any time by contacting us, and we honour Global Privacy Control.

We do not use advertising cookies or cross-site advertising trackers. In the app, we use device storage (AsyncStorage, SecureStore) to keep you signed in and cache household data for offline use.

17. Automated decision-making

We do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

18. Data-breach notifications

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law — including the Kenyan Data Commissioner under section 43 of the Data Protection Act, 2019, and equivalent authorities under GDPR/UK GDPR Articles 33 and 34, US state breach-notification laws, and PIPEDA — and we will notify affected users without undue delay.

19. Changes to this policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date and, for material changes, notify you via in-app notice or email at least 14 days before they take effect.

20. Contact us & complaints

For any question about this Policy or your data, email contact@famio.cc.

If you are not satisfied with our response, you may complain to your local data protection authority — for example the ODPC in Kenya ( odpc.go.ke ), the ICO in the UK, your EU member-state authority, or your state attorney general in the US.