Privacy Policy.
Famli keeps your family's schedule, documents, and day-to-day logistics in one place. This policy explains what we collect to do that, how we use and share it, how long we keep it, and the choices and rights you have.
Questions? Email us at support@famli.io, or write to the postal address in Section 15.
1. Information we collect
1.1 Account information
When you create an account we collect your name, email address, and a password (stored only as a bcrypt hash; we never store plaintext passwords). If you register as a provider, we also collect your business name, vertical category, timezone, and business contact details. If you enable multi-factor authentication, we store the factors needed to verify you.
1.2 Family and child information
Family Hub accounts are created and controlled by a parent or legal guardian. Information a parent may provide about a child includes:
- First name and date of birth (used for age-appropriate features);
- Allergies, medical notes, and dietary restrictions (optional, used for the Emergency Card);
- Emergency contact details for other adults the parent designates (see Section 1.9);
- Activity history, homework, practice logs, pickup assignments, and similar records generated by use of Famli;
- Photos and milestone notes a parent chooses to add to a child's timeline (optional).
This information powers calendar aggregation, homework tracking, the Emergency Card, and the child's activity timeline. See Section 2 for how we handle children's information under COPPA.
1.3 Activity and usage content
We collect the content you create in Famli: calendar events, bookings, practice logs, homework, budget entries, documents, and messages within your family group. This content is scoped to your family or business account and is not shared across accounts except as described in Section 5.
1.4 Documents
The Document Vault lets you upload files (for example medical records, waivers, registration forms). Files are stored encrypted with our cloud storage provider (see Section 5) and are accessible only to members of your family account.
1.5 How we read schedule imports, and when AI is used
Typed, pasted, and structured imports (for example spreadsheets/CSV and structured text) are read entirely on Famli's own servers using a rules-based reader. In those cases nothing you submit, including your child's name, is sent to any third party. The majority of imports today are read this way.
When an input cannot be read confidently on our servers — such as free-form written notes, voice notes, or photos and scanned images — Famli falls back to a third-party AI provider to interpret it (see Section 4). On that fallback:
- for voice notes, the audio is transcribed to text by your device's or browser's built-in speech service (for example, Apple on iPhone or Safari, or Google on Chrome or Android). That speech service — not Famli — receives the audio; Famli receives only the resulting text. Your device or browser maker's privacy terms govern that transcription. Once Famli has the text, the text rules below apply;
- for text (and the transcript of a voice note), we replace your child's name as it appears in their Famli profilewith a placeholder before the content is sent to our AI provider, so the AI provider does not receive that profile name. Because these imports are your own free text, other details you include — a nickname, a last name, an address — are sent as written;
- for photos and scanned images, the content is sent as-is and may include your child's name or face; these cannot be pseudonymized the way text can;
- the content is used only to extract the schedule or activity details you asked for.
AI import is an optional feature you choose to use, and you can avoid third-party AI (and the speech service) entirely by importing in a typed, pasted, or structured format. When Famli uses AI fallback or a voice note, we ask for your consent as described in Section 2.4.
1.6 Payment information
When you subscribe, our payment processor collects your billing details and payment method directly. Famli never receives or stores full card numbers. For providers who collect payments through Famli, funds are processed via our payment processor's connected-accounts service under that processor's own terms.
1.7 Device and technical data
We automatically collect IP address, browser type, device identifiers, operating system, app version, and interaction/event data for security, fraud prevention, performance monitoring, and analytics. On mobile, if you enable notifications we collect a push token from the platform's push notification service to deliver notifications.
1.8 Location data (opt-in)
Our Activity-Scoped Location Sharing feature collects real-time precise geolocation during pickup and drop-off windows only, and only for members who opt in. Location is shared only with family members assigned to the same pickup and is used solely to show ETA and arrival status. Precise geolocation is treated as Sensitive Personal Information (see Section 8). We do not build a location history; real-time location is discarded when the pickup window ends (typically 15 minutes after the scheduled time).
1.9 Information about other people you provide
When you add an emergency contact, coach, or other individual, you provide their name and contact details. You confirm you have their permission to share this with us. Those individuals may contact support@famli.io to access or delete the information you gave us about them.
2. Children's data (COPPA)
Famli is designed to comply with the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. §§ 6501–6506, and the FTC's amended Rule at 16 C.F.R. Part 312 (in force, with full compliance required as of April 22, 2026).
2.1 No accounts for children under 13
Children under 13 cannot create their own accounts. All Family Hub accounts are created and controlled by a parent or legal guardian ("Parent"). We do not knowingly collect personal information directly from a child.
2.2 What we collect about children, and why
See Section 1.2 for the complete list of fields a Parent may provide about a child. We collect only what is reasonably necessary to operate the features the Parent chooses to use, and never condition a child's participation on providing more than is necessary.
2.3 The third parties that receive children's information, and the purpose
We disclose a child's personal information only to the following categories of third parties, and only for these purposes:
| Recipient | Purpose |
|---|---|
| Infrastructure and storage processors | To host and store your account so Famli functions |
| Communications processors (for transactional notifications and push) | To deliver transactional notifications you request |
| AI processors — only if you use AI features on child content (see Section 4) | To parse content you submit into calendar events (see Section 4) |
| Kids' activity providers you explicitly link to your family | To connect your child to bookings/records at that provider |
| Coaches or instructors you choose to show the Emergency Card to | Handoff of allergy/medical/contact information at your direction |
| Law enforcement or authorities | When required by law or to protect safety |
We do not sell or rent children's information, and we do not share it for advertising, marketing, or behavioral profiling.
2.4 Parental consent and control
A Family Hub account is created and controlled by a parent or legal guardian. When you sign up, you check a box confirming that you are the parent or legal guardian of any children you add, and that you consent to Famli collecting their information as described in this policy (see Sections 1.2 and 2.2). We record that agreement.
Before Famli collects information about a child, we obtain your verifiable parental consent by email, a method recognized under COPPA. When you go to add your first child, we send a single-use confirmation link to your account email address. You open it and confirm that you are the parent, and only then can a child be added to your family. You do this once for your family, not once for each child. We keep a record of the confirmation, including when you gave it and which version of this policy was in effect.
A child never creates an account or gives us information directly. You control your child's profile and can review, correct, or delete your child's information at any time (see Section 2.6), and we keep it only as described in Section 2.7.
Optional features that involve disclosure. Some features that use a child's information are optional and stay off until the Parent chooses to use them. If you use AI-powered import (Section 4), content that cannot be read on our own servers falls back to our AI providers, OpenRouter and Google (Gemini), to produce the result you asked for. AI fallback for photos and scanned images discloses the content to the AI provider as-is, which may include your child's name or face; text and voice-transcript fallback is sent with your child's profile name replaced by a placeholder. Your consent below covers these disclosures to OpenRouter and Google (Gemini). Voice notes are transcribed by your device's or browser's speech service (Apple or Google), which receives the audio; your consent below covers that transcription. If you link your family to a kids' activity provider, the child's information needed for that connection is shared with the provider you chose. Using these optional features results in the disclosures described; you can use Famli's core features without them.
2.5 How children may interact with Famli
Some features let a child interact with content the Parent set up, for example viewing the family calendar on a shared device, tapping "done" on a practice log, or seeing a badge. Children do not create accounts, do not provide additional personal information, do not communicate with anyone outside the family group, and are never shown targeted advertising or behavioral profiling.
2.6 Parental rights
As the Parent you may at any time:
- Review the personal information we have collected about your child;
- Correct or update it from Family Settings;
- Delete your child's profile and associated information;
- Refuse further collection by deleting the profile;
- Stop using the optional features that involve disclosure (AI import and provider linking) at any time, which ends the associated disclosure;
- Make any of these requests by emailing support@famli.io, and we respond within 30 days.
2.7 Children's data retention
We retain a child's personal information only as long as needed for the feature in use, while the child remains in the family account, or as required by law. On deletion of a child's profile (or removal of the child from the family), directly identifying information (name, date of birth, allergies, medical notes, photos) is deleted from active systems within 30 days and from backups on our standard backup-rotation cycle (no longer than 90 days). We do not retain children's information indefinitely.
2.8 Information-security program
We maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the sensitivity of children's information, and we review it at least annually.
2.9 California and other minors (opt-in)
We do not sell or share (for cross-context behavioral advertising) the personal information of any minor. Should we ever contemplate doing so, we would first obtain opt-in consent from the Parent (or, for a minor aged 13–16, from the minor) as required by California and other state law.
2.10 COPPA contact
Questions about our children's-information practices: support@famli.io, or the postal address in Section 15.
3. How we use your information
- Provide, operate, secure, and maintain Famli;
- Aggregate family calendars from connected providers;
- Send transactional messages (booking confirmations, reminders, digests) and, where you have opted in, other communications;
- Process payments and manage subscriptions;
- Understand and improve Famli through analytics;
- Detect, prevent, and respond to fraud, abuse, and security threats;
- Comply with law and enforce our Terms.
4. AI sub-processors
Most imports never reach an AI provider (see Section 1.5). When an input cannot be read on our own servers, we transmit the content to the providers below under their terms of service and our enforced zero-data-retention configuration, solely to generate the output you asked for. Our current AI sub-processors — which may change as our systems evolve — are listed and dated at https://famli.io/subprocessors, and we will notify account holders before adding or changing an AI sub-processor that receives children's content.
| AI provider | Role | Data it receives | Retains / trains on your data? | Processing location |
|---|---|---|---|---|
| OpenRouter | AI gateway that receives the fallback content and routes it to Google's Gemini under zero-data-retention terms | The fallback content. For photos and scanned images this may include your child's name or face. For text and voice transcripts, the content is sent with your child's profile name replaced by a placeholder. | No. Routed under zero-data-retention terms: not stored and not used to train models. | United States (gateway) → EU zero-data-retention endpoint |
| Google (Gemini API) | Interprets the fallback content | Same as above | No. Not used to train and not retained under the zero-data-retention terms applied to our requests (processed via Google Vertex AI, which does not train on submitted content). | European Union (Google Vertex AI, EU region) |
| Device / browser speech service (Apple, Google) | Transcribes voice notes to text, invoked through your device or browser | The audio of a voice note, which may include your child's voice | Governed by the device or browser maker's own terms | Determined by your device/browser maker |
We do not sell this content and use it only to perform the feature you requested.
5. All third-party service providers
We share limited data with outside providers, each bound by contract and its own privacy terms. They fall into the categories below. The full list of every named provider, and where our AI providers are barred from training on your content, is at https://famli.io/subprocessors, which we update when providers change.
| Category | Purpose | Data categories |
|---|---|---|
| Hosting, storage, and infrastructure | Run and store your account so Famli works | All account, family, and uploaded-file data; IP addresses in security logs |
| Payments | Process subscriptions and provider payouts | Name, email, payment method, transaction data |
| Transactional email | Deliver the emails and digests you request | Recipient email address and message content |
| Error monitoring | Detect and fix crashes and performance problems | Technical data, which may include user/account identifiers |
| Product analytics (only with your consent — Section 6) | Understand and improve Famli | Usage events linked to your account when you are signed in |
| AI features (Section 4) | Parse content you submit into calendar events | Content you submit to AI features |
| Push notifications | Deliver push notifications you enable | Device push token |
We do not use advertising cookies and do not sell your data to ad networks.
6. Cookies and analytics
- Strictly necessary cookies are required for authentication, session management, and content personalization (for example the
fh_audiencecookie, which records whether you are browsing as a provider or a family). These cannot be disabled. - Analytics cookies. We use a third-party product analytics provider. These load only after you give consent through our cookie banner, and you can withdraw consent at any time. Dismissing the banner does not grant consent; analytics stays off until you actively accept it.
When you are signed in, product analytics events are associated with your account, including your user ID, email, and name. This is pseudonymous, account-linked data, not anonymous data. We use it to understand and improve Famli, not for advertising, and we aggregate analytics for long-term reporting after 12 months.
You can manage cookie choices any time via the "Cookie Preferences" control in the site footer.
7. Your rights and choices
7.1 Everyone
You can access and update your account information in-app, close your account (Section 10), and contact support@famli.io for help exercising any right below. We provide at least two ways to submit requests: email to support@famli.ioand the in-app "Privacy Request" form. We honor browser Global Privacy Control (GPC) signals as opt-out requests where applicable.
7.2 United States state privacy rights (California and other states)
Depending on your state (including California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others), you may have the right to: know/access the personal information we collect; correct it; delete it; obtain a portable copy; opt out of "sale," "sharing"/targeted advertising, and certain profiling; limit the use of Sensitive Personal Information; and appeal a denial. We do not sell your personal information and do not share it for cross-context behavioral advertising.
Notice at Collection (California). We collect the categories described in Section 1, including Sensitive Personal Information (precise geolocation from location sharing, and health information such as a child's allergies/medical notes), from you and your use of Famli, for the business purposes in Section 3, and disclose them to the service providers in Sections 4–5. We retain each category per Section 9. You may exercise the right to limit use of Sensitive PI and the "Do Not Sell or Share" choice at this Privacy Request form (even though we do not sell or share).
8. Sensitive information
We treat the following as sensitive and apply heightened protection: precise geolocation (location sharing), and health-related information (a child's allergies, medications, and medical notes). We use it only to provide the specific feature you enabled and never for advertising.
9. Data retention
| Data | Retention |
|---|---|
| Account data | While your account is active; deleted within 30 days of account closure, except where law requires longer |
| Child profile and child-specific data | While the child is in the family account; identifying fields deleted within 30 days of profile deletion (backups within 90 days) |
| Documents | Until you delete them or close your account |
| Family messages | Retained for the life of your family account; deleted when the associated thread is removed or when you close your account (within 30 days of account closure) |
| Location data | Real-time only; not persisted beyond the active pickup window |
| Analytics | Aggregated after 12 months |
| Payment records | Retained ~7 years to meet financial/tax compliance |
| Consent records (parental consent, policy agreement, cookies, auto-renewal) | Retained at least 3 years for legal proof |
10. Account closure and deletion
You may close your account in Settings. On closure we delete your data within 30 days, except records we must retain by law (for example payment/tax records) or in de-identified aggregate form. Deletion of a child's profile follows Section 2.7.
11. Data security
We use TLS in transit, encryption at rest for sensitive data, bcrypt password hashing, optional multi-factor authentication, per-account data isolation, and a written information-security program reviewed at least annually. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and regulators as required by applicable law.
12. International data transfers
Family data is stored and primarily processed in the United States. The one exception is the optional AI-fallback feature (Section 4), where content is processed by our AI sub-processor in the European Union. Famli is directed to users in the United States; we do not offer it to, or target, individuals in the European Economic Area or the United Kingdom. No additional international-transfer step is required for this US-to-EU processing.
If you access Famli from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
13. Mobile app disclosures
Our mobile apps' Apple App Store and Google Play "data safety" disclosures reflect the collection and sharing described in this policy, including AI processing, account-linked analytics, location, and push tokens.
14. Changes to this policy
We may update this policy. We will post the updated version with a new "Last Updated" date and, for material changes, notify you by email or in-app at least 30 days in advance. For any material change to how we collect, use, or disclose a child's information, we will notify the Parent and, where required, obtain the Parent's renewed consent before the change applies to that child. Continued use alone is not treated as consent for those changes.
15. Contact us
- Privacy questions / requests: support@famli.io
- Postal address: Famli LLC, 1500 N Grant St # 11190, Denver, CO 80203

