Familya — Privacy Policy
Last updated: 7 September 2026
Published at https://familya.app/privacy
This policy explains, in plain language, what Familya does with your data. It is written for the General Data Protection Regulation (GDPR), which applies to us because we are established in Slovenia and our users are in the EU.
Data controller
MELD d.o.o., Legen 38, SI-2383 Šmartno pri Slovenj Gradcu
Registration number 8609233000 · VAT SI35492031
Email: support@familya.app
We have not appointed a Data Protection Officer; we are below the threshold that requires one. Write to support@familya.app for anything on this page.
The short version
- Familya stores what you put into it: your name and email, the family you belong to, your lists, calendar, chores, coins, chat messages and photos — plus your location only while you have location sharing switched on.
- We do not run ads, we do not use third-party analytics or advertising SDKs, we do not build profiles, and we do not sell or rent your data to anyone.
- Everything you create is visible only to the members of your own family, and to nobody else. We do not read it except in the narrow cases described under Who can see your data.
- You can delete a family from inside the app, and you can have your whole account erased by asking us.
What we collect, why, and on what legal basis
Everything below is data you or your family give us by using the app. We do not buy data about you from anyone, and Familya has no hidden collection.
Account data
| Data | Why | Legal basis |
|---|---|---|
| Email address | Signing in, resetting your password, and reaching you about your account | Performance of a contract (Art. 6(1)(b)) |
| Password | Stored only as an Argon2id hash — we never hold the password itself | Contract |
| Display name, optional nickname and colour | So your family can tell who is who | Contract |
| Language and time zone | Showing the app in your language and putting events on the right day | Contract |
Family data
| Data | Why | Legal basis |
|---|---|---|
| Which families you belong to, and your role in each (Admin, Parent, Child, Other) | Deciding what you are allowed to see and do | Contract |
| Invite codes you create or accept | Letting people join the right family | Contract |
Content you create
| Data | Why | Legal basis |
|---|---|---|
| Shopping lists and items | The feature itself | Contract |
| Calendar events (family or private) | The feature itself | Contract |
| Notes and reminders (family or private) | The feature itself | Contract |
| Chores, submissions, approvals, penalties | The feature itself | Contract |
| The ChoreCoin ledger — every credit and debit, with a reason and the balance after it | So a coin balance can always be explained and corrected | Contract |
| Rewards and redemptions | The feature itself | Contract |
| Chat messages and the photos attached to them | The feature itself | Contract |
| Polls (“Decisions”) and votes, including who voted for what | The feature itself — results are open by design, and the app tells you so | Contract |
| Weekly schedules and their entries | The feature itself | Contract |
Location — only when you switch it on
Location sharing is off by default and set per member. Nothing is recorded until you turn on the location-sharing switch yourself.
| Data | Why | Legal basis |
|---|---|---|
| Latitude, longitude, accuracy, and optionally speed, heading and your device’s battery level | Placing you on your family’s map | Your consent (Art. 6(1)(a)), given by turning the switch on |
Turning the switch off stops collection immediately: while sharing is off, the app’s position reports are discarded by the server and nothing is stored. You can also clear your own location history at any time from the app. Location points are deleted automatically after 7 days on our hosted service.
Technical data
| Data | Why | Legal basis |
|---|---|---|
| Push notification token, device platform, app version | Delivering reminders and chore notifications to your phone | Contract |
| Refresh tokens (stored as SHA-256 hashes) | Keeping you signed in without re-typing your password | Contract |
| Server logs: IP address, timestamp, the endpoint called, the response status | Security, abuse and rate-limit enforcement, and debugging | Legitimate interests (Art. 6(1)(f)) — running a service that is not trivially attackable |
We do not collect: advertising identifiers, contacts, your address book, browsing history, health data, payment data (there is nothing to pay for), or precise device fingerprints.
Who can see your data
- Your family. Everything shared inside a family is visible to the members of that family. Content you mark private (private calendar events, private notes, private schedules) is visible only to you — including to family Admins.
- Us. Our team can access the database only for support you have asked for, or to investigate a fault or abuse, and only as far as needed. We do not read family chats for any other reason and we do not use your content to train anything.
- Processors. Our hosted service runs on servers rented from
[TODO: HOSTING PROVIDER, e.g. Hetzner Online GmbH, Germany], inside the EU/EEA. Photos are held in our own S3-compatible object storage on the same infrastructure. If you have push notifications delivered while the app is closed, the notification title and body pass through Google Firebase Cloud Messaging (Google Ireland Limited) to reach your phone. - Nobody else. No advertising networks, no data brokers, no analytics vendors. We do not sell, rent or trade personal data, and we do not “share” it for cross-context behavioural advertising.
Transfers outside the EU/EEA. Our own infrastructure is in the EU. Firebase Cloud Messaging may involve transfers to Google in the United States under the EU Standard Contractual Clauses and the EU–US Data Privacy Framework. If your family’s server is configured without FCM — which is how Familya ships by default — notifications are delivered over our own connection and no third party is involved at all.
Self-hosting. Familya’s backend is open and can be run by anyone. If your family uses a server that someone else operates, that operator is the controller of your data, not us, and this policy does not govern it.
Children
Familya is designed for families, and it is normal for children to use it. We handle that honestly rather than pretending otherwise.
- A child does not sign up alone. A Child account exists inside a family that an adult created. The adult creates the invite, decides the role, and can change the role, remove the member, or delete the whole family. In the sense of the GDPR, the parent or guardian provides and controls the child’s account, which is how we meet Art. 8 (GDPR-K) and the US Children’s Online Privacy Protection Act (COPPA) for children under 13.
- We collect no more from a child than from an adult, and less in practice: a name, an email address for signing in, the family they belong to, and whatever they write or complete in the app.
- No behavioural advertising, ever. There are no ads in Familya, for anyone. There is no advertising ID, no ad SDK, and no profiling of any member, child or adult.
- Location sharing is opt-in per member and can be turned off at any moment, by the member themselves and by a family Admin who can remove the member. It is off until somebody deliberately switches it on, and no history survives more than 7 days.
- Photos are private to the family. They are streamed through our API after a membership check, never given a public URL, and are deleted from storage when the message is deleted.
- Chat is closed. There is one thread per family, and only members of that family can read or post in it. There is no way for a stranger to contact a child through Familya: joining requires an invite code created by a family Admin.
- A parent or guardian may ask us at support@familya.app to see, correct or erase everything held about their child. We will act on it as described under Deleting your data.
If you believe a child has an account without a parent’s involvement, write to support@familya.app and we will remove it.
How long we keep things
| Retention | |
|---|---|
| Your account and content | For as long as your account exists |
| Family content after the family is deleted | Erased immediately and permanently — deleting a family cascades to its lists, events, notes, chores, ledger, rewards, chat, polls and schedules |
| Chat photos | Erased from object storage when the message is deleted, or when the family is deleted |
| Location points | 7 days, then deleted automatically; or immediately, when you clear your history |
| Refresh tokens | Until they expire (60 days), are used, or you sign out |
| Notifications | 30 days |
| Server logs | 30 days |
| Records we must keep for legal reasons (e.g. a record of a deletion request) | As long as the law requires, and no longer |
Security
- Passwords are hashed with Argon2id. We never store or transmit them in a readable form, and we cannot tell you what your password is.
- All traffic between the app and our server is over HTTPS/TLS.
- Access tokens are short-lived (30 minutes) and refresh tokens are single-use: using one invalidates it and issues a new pair.
- Every request is authorised against your membership of the family in question, on the server. Anything outside your families answers 404 — the API will not even confirm that a resource you cannot see exists.
- Photos live in a private bucket, are never public, and are served only after a membership check.
- Uploads are type-sniffed from their actual bytes, so a file renamed to look like an image is rejected.
No system is perfect. If we ever suffer a personal data breach that is likely to put you at risk, we will notify the Slovenian Information Commissioner within 72 hours and tell affected users without undue delay, as Art. 33–34 require.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy;
- rectify anything inaccurate — most of it you can simply edit in the app;
- erase your data (“right to be forgotten”);
- restrict or object to processing that we base on legitimate interests;
- data portability — a machine-readable export of the data you provided;
- withdraw consent at any time where we rely on it, which for us means location sharing: flip the switch off, and it stops. Withdrawing consent does not affect what was lawful before.
To exercise any of these, email support@familya.app from the address on your account. We will answer within one month, as Art. 12(3) requires, and we will not charge you for it.
You also have the right to complain to a supervisory authority. In Slovenia that is the Informacijski pooblaščenec (Information Commissioner), Dunajska cesta 22, 1000 Ljubljana, https://www.ip-rs.si. You may also complain to the authority in your own EU country.
Deleting your data
Delete a family (in the app). A family Admin can delete a family from Family settings → Danger zone → Delete family. This is permanent and immediate: every list, event, note, reminder, chore, coin ledger entry, reward, chat message, photo, poll and schedule belonging to that family is destroyed for every member.
Leave a family (in the app). Family settings → Leave family removes you from it. The family’s shared content stays with the family; you lose access to it.
Delete your account. Email support@familya.app from the address on your account and ask us to delete it. We verify it is you, then erase your user record, your private content, your device and push tokens, and your sessions, and we remove you from every family you belong to. If you are the last Admin of a family, we will tell you first so you can hand the role over or confirm the family should be deleted too. We complete deletions within 30 days and confirm by email when it is done.
Backups are kept for 30 days and are overwritten on a rolling basis; deleted data disappears from them within that window.
Changes to this policy
If we change anything that matters, we will update the date at the top and — for a material change — tell you in the app or by email before it takes effect. Older versions are available on request.
Contact
support@familya.app
[TODO: LEGAL ENTITY NAME], [TODO: REGISTERED ADDRESS, SLOVENIA]