FamilyPlan family organizer app logo
FeaturesAI assistantGuidesPricingWeb beta
DEEN
FeaturesAI assistantGuidesPricingWeb beta
DEEN
Back to homepage

Privacy Policy for FamilyPlan

This privacy policy describes processing in the FamilyPlan Android and iOS apps, the web app and familyplan.cloud.

Updated: July 21, 2026

Controller

Mario Euchner
Adlerstraße 14
72574 Bad Urach, Germany
Email: support@familyplan.cloud

Scope and purposes

This policy applies to FamilyPlan on Android, iPhone and iPad, the web app at familyplan.cloud/app, public websites, email support and FamilyPlan support chats. FamilyPlan organizes family calendars, tasks, lists, meals, recipes, school, chat, budgets, points, rewards and voluntary location sharing.

We process data to provide and synchronize the service, perform contracts, honor active consent and device permissions, prevent errors and abuse, and comply with billing and legal obligations. Where legitimate interests are the legal basis, the interest is a secure, functional and accountable service.

Account, sign-in and Google OAuth

For registration, login and sessions, FamilyPlan processes email address, Supabase user ID, authentication provider, session and confirmation status, and technical timestamps. Family, membership and profile IDs assign content to authorized users.

When “Sign in with Google” is used, Supabase runs the OAuth flow with Google. Google processes the authentication request and provides approved basic identity data, particularly account identifier and email address. FamilyPlan never receives the Google password. The Google Privacy Policy also applies.

Supabase Auth, Database, Realtime, Storage and Edge Functions

FamilyPlan uses Supabase as its cloud platform. Supabase Auth manages accounts and sessions. The Postgres database stores family and feature data under role-based access rules. Supabase Realtime transmits authorized changes between devices. Supabase Storage stores private family and profile pictures in the “family-media” bucket.

Supabase Edge Functions handle protected server operations, including account deletion, synchronization, push registration and delivery, calendar sync, weather, the FamilyPlan Assistant, and Apple and Google Play purchase verification. Technically necessary request, timing, status and error data can arise. Family content, passwords and tokens should not be written unnecessarily to application logs. See the Supabase Privacy Policy.

Family content and child profiles

Depending on use, FamilyPlan stores family name, profiles, display names, profile pictures, roles and invitations, as well as calendar events, tasks, routines, reminders, shopping lists, chats, budget entries, recipes, meals, school schedules, holidays, points and rewards. Content is linked to a family and sometimes to profiles or accounts.

Parents can manage child profiles and family-friendly content. Child profiles have restricted areas and no parent actions. Please enter only data needed for family organization and avoid particularly sensitive information about children. FamilyPlan does not use child or family content for personalized advertising and does not sell it.

Precise and approximate location

Location features are voluntary. Android requests approximate or precise foreground location only after user action. The app then collects coordinates, horizontal accuracy, an “approximate” indicator and capture time, and can assign them to a family profile in Supabase. The current Android build does not request background location permission.

On iOS, the separate “Live in background” function can additionally be enabled when location sharing is active, iOS grants “Always” access, and the extra switch is on. Current locations and sharing requests are provided within the family under the configured sharing rules. Sharing can be revoked; affected current locations are removed when a family is left or deleted.

Google Maps SDK on Android

The Android app displays its family map using Google Maps SDK. Google states that the SDK automatically collects device and request metadata such as operating system, device model, brand and form factor, SDK build and version, result count and an internal usage attribution identifier. Google also processes IP address, stack traces, crash metrics and a pseudonymous Maps SDK identifier.

Depending on how the map is invoked, Google can collect map interaction events such as panning and zooming. Google describes this processing as operating, measuring and improving its services; according to Google, the internal usage identifier is not used to identify a person or for advertising attribution. See Google’s Maps SDK data disclosure guidance.

Local Android calendars and private imports

After explicit read permission, Android reads calendar instances in the selected import window: calendar and event ID, title, description, location, start, end and all-day status. FamilyPlan does not require write permission to the Android system calendar.

Selected imports are marked as a “private import” for the importing adult profile and synchronized to FamilyPlan. They are intended to be displayed only to that profile and are not automatically converted into shared family events. Only a deliberate import or sharing action turns an event into regular family content. Similar rules apply to local Apple calendar imports. Separately connected Google or Outlook calendars can use encrypted OAuth tokens in Supabase.

Notifications and local reminders

Android requests notification permission for local reminders. Events and tasks can contain a title, trigger time and advance interval; the app schedules the notification locally and restores it after device restart. Local reminders remain on the device until changed, deleted, signed out, or app data is removed.

For cross-device push, FamilyPlan can additionally process user-bound device tokens, platform, app version, last-seen time, delivery status and notification text through Supabase. User-bound tokens and delivery rows are deleted with the Auth account.

Google Play Billing, Apple StoreKit and purchase verification

The Android app loads subscription offers through Google Play Billing. Google Play processes payment and store-account data under its own rules. FamilyPlan receives product and package ID, purchase token, optional order ID, purchase time, acknowledgement and subscription state. The app also provides pseudonymous hashes for account and family to Google Play.

The Supabase Edge Function “google-play-transaction-sync” verifies purchase token, product, package, user and family server-side through the Google Android Publisher API and stores the necessary entitlement and verification status. On iOS, FamilyPlan processes corresponding StoreKit, transaction, restore and Apple Server Notification data. FamilyPlan does not receive full payment details such as credit card numbers. Store privacy: Google and Apple.

FamilyPlan Assistant and cloud processing

The FamilyPlan Assistant processes the visible text input and a permission-filtered, task-relevant family context through the authenticated “family-assistant” Supabase Edge Function. The function uses OpenAI server-side to generate answers and proposals. Proposals are stored in FamilyPlan only after explicit confirmation.

Optional cloud history stores private Assistant threads, messages, proposals and technical run data for the relevant account, family and adult profile. Users can delete individual or all chats or disable cloud history. Voice input is transcribed on-device; under the reviewed implementation, audio is not sent to Supabase or OpenAI. See the OpenAI Privacy Policy.

FamilyPlan support chat and email support

Support uses a Chatwoot widget embedded from support.familyplan.cloud. In the Android app it loads only when support is opened. For cloud sessions, Supabase user ID and email are set together with platform, app version, build, language and auth mode. Messages and attachments submitted by the user are also processed. Family content is not transferred automatically.

The Chatwoot widget also loads on public familyplan.cloud pages and can process technically necessary cookie, browser, IP and session data there. For email support, we process sender address, content and technical communication metadata. Never send passwords, PINs, live locations or unnecessary child, chat, calendar or budget data.

Website hosting and audience measurement

Public pages are hosted by Hostinger. Hosting and security logs can contain IP address, time, requested URL, referrer, browser/device data and status code.

For simple first-party audience statistics, FamilyPlan sends page path, language, referrer host and device class (desktop, tablet, mobile or unknown) to a Supabase Edge Function. The project does not use an advertising ID, full referrer path or third-party advertising tracking for this. Public pages also link to external social profiles; the destination platform’s privacy rules apply only after a click.

Recipients, processors and international transfers

  • Supabase: Auth, Postgres Database, Realtime, Storage and Edge Functions.
  • Google: OAuth, Google Play/Billing and Android Publisher API, Google Maps SDK.
  • OpenAI: server-side processing of filtered Assistant text and context.
  • Apple: App Store, StoreKit, Apple sign-in, platform permissions and, where used, calendar/weather services.
  • Hostinger and email infrastructure: website hosting and support communication; Chatwoot is operated under the FamilyPlan support domain.

Storage duration and retention periods

  • Family content remains until the relevant item or family is deleted or the account-deletion rules apply. Shared content can remain neutralized for a continuing family.
  • Current locations remain until revoked, overwritten, the family is left/deleted or the account is deleted; the backend does not configure another periodic location deadline.
  • Assistant run diagnostics are automatically deleted after 30 days. Assistant chats remain until user deletion, cloud-history deactivation or account/family deletion.
  • Where applicable under German law, tax-relevant records are retained for ten years (books/records), eight years (accounting vouchers) or six years (other tax-relevant records) from the legally defined starting point (section 147 of the German Fiscal Code).
  • The current project configures no fixed automatic deletion period for deletion audits, website page views, support emails or Chatwoot conversations. They are reviewed in relation to purpose and law when the purpose ends or upon a valid request.
  • Deleted data can remain in Supabase backups until scheduled backup rotation; no fixed backup period is evidenced in the repository at present.

Account and data deletion

In the web app, “Settings” → “Data & account” → “Delete account” starts account deletion. Individual content, Assistant history, location sharing, memberships or a whole family can also be removed without full account deletion. An external, securely verified deletion request can be initiated by email.

Complete steps, data effects and the current Storage-media limitation are available on the public FamilyPlan account-deletion page.

Your rights and complaints

  • Access, correction, deletion and restriction of processing.
  • Data portability where legally applicable.
  • Objection to processing based on legitimate interests.
  • Withdrawal of consent for the future.

You may also complain to a data protection authority. The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg is generally the competent authority for the controller.

FamilyPlan family organizer app logo

The family-friendly everyday planner for calendars, tasks, shopping, school and shared routines.

Download on the App Store

Legal

PrivacyTermsData deletionLegal notice

FamilyPlan

AI family assistantFamilyPlan web betaAndroid testingFamily calendar appTasks app for kidsFamily shopping listFamily meal planner

Contact

FamilyPlan guidesAbout FamilyPlanSupportkontakt@familyplan.cloud

Social

Instagram profileInstagramFacebook pageFacebookTikTok channelTikTok
© 2026 FamilyPlan. All rights reserved.