Famileze

Your privacy

Your family’s life is nobody else’s business. Here is exactly how Famileze keeps it that way — in plain words.

Your family’s life is nobody else’s business. Famileze is built so that it stays that way.

Everything you keep in Famileze — photos, videos, notes, health records, letters — is encrypted on your device before it goes anywhere. It’s backed up to your family’s private cloud (and kept on your own computer too, if you use the free desktop app) — but always as scrambled text only your devices can unlock. We can’t read any of it.

There is no cloud AI and no general language model. The app runs on small tools on your own machine, so your family’s data is never sent away to be read or processed by anyone, including us. The one exception is dictation on the iPhone: iOS uses Apple’s own speech recognition, which may send that audio to Apple to turn into text.

When you sync your devices, the information is encrypted end-to-end. It travels — and is stored — as scrambled text that only your own devices can unlock; the relay that passes it along and the cloud that holds it can never read it.

Two things work differently, and we would rather tell you than let you assume. A newsletter you email out, and an email someone sends to your family address, are ordinary email — they cannot be scrambled end-to-end, because someone outside your family is at the other end. Incoming mail waits on the relay in readable form until your device collects it, and is deleted after 30 days at the latest. Everything else — your timeline, folders, calendar, health records, lists and letters — is encrypted end-to-end.

Nothing leaves your control by accident. You approve every filing, every calendar change and every send before it happens.

Anything you mark private (the 🔒 lock) is never shared with a co-parent. It stays yours alone.

Your data belongs to you. You can back it up, export it, and take it with you at any time — and if you ever stop paying for the service, the copy on your phone (and on your computer, if you use the free desktop app) keeps working.

Read the full privacy policy ›

Privacy policy

In force from 18 August 2026 · Famileze

This is the full privacy policy for the Famileze apps and famileze.app. The plain-English version above is a summary of it and is written to be true — but this is the document that governs, and it is the one that spells out the parts a summary skips.

1. Who is responsible for your data

Sol Coast Construction Pty Ltd, trading as Famileze, of PO Box 4673, SCMC QLD 4560, is the data controller for the personal information described in this policy. In this policy “we”, “us” and “Famileze” mean Sol Coast Construction Pty Ltd.

You can reach us about anything in this policy at support@famileze.app. We answer privacy requests ourselves — there is no ticket queue and no third-party helpdesk holding your message.

Famileze is available in all jurisdictions. This policy is written to meet the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU General Data Protection Regulation (GDPR), and United States state privacy law including the California Consumer Privacy Act as amended by the CPRA. Where those laws differ, we apply the one that gives you the most protection, to everyone — wherever you live.

2. The short version

3. The two kinds of data in Famileze

It matters which of these you are asking about, because our answers are genuinely different for each.

Family content is everything you put into the app: photos, videos, voice captions, notes, calendar entries, to-do and shopping lists, folders, children’s names and details, health records, artwork, and keepsake letters. This is encrypted on your device with a key only your family’s devices hold. What reaches our servers is ciphertext. We cannot read it, we cannot search it, we cannot hand it to anyone, and we cannot recover it for you if you lose your family key.

Service data is the small amount of ordinary information needed to run a paid, synchronising service: who the account is, which devices belong to it, whether the subscription is current, and the messages you send us. We can read this. It is listed in full in section 5.

4. Family content — what end-to-end encryption means here

Family content is encrypted on your phone or computer using AES-256-GCM before it is uploaded. The key is generated on your device when you create your family, and is shared with your other devices and with a co-parent only through a pairing or invite flow that we cannot read: an invite bundle is itself encrypted under a key derived from a short access code (PBKDF2-SHA256, 210,000 iterations on the phone; scrypt on the desktop app) that is handed over separately and never reaches our servers.

The practical consequences, stated plainly:

We can see, and do use, the metadata that storage inevitably produces: how many encrypted objects an account holds, how large they are, and when they were written. We use this to enforce your storage allowance and to keep sync working. It does not tell us what is inside them.

Under the GDPR, some of what you store — health records about your family, for example — is special category data. You provide it under Article 9(2)(a), by choosing to use those features. Because it is encrypted before it reaches us, we process it only as unreadable ciphertext.

5. The service data we hold, and why

This is the complete list. If something is not here, we do not collect it.

WhatWhy we have it
An account identifier — a random string. Creating an account captures no name.To tell one family’s encrypted storage from another’s.
A hashed access token for each device, and its role (admin, co-parent, or archive).To authenticate your devices and enforce what each is allowed to do.
Device identifiers, last-seen timestamps and app version for the devices on the account.So the app can show you “this device last synced at…”, and so we can diagnose a device that has quietly stopped working.
Subscription status — the plan, whether it is trialling, active, cancelled or lapsed, the paid-until date, and the processor’s own identifiers. From Stripe this includes the billing email address you gave Stripe. From Apple it is a transaction identifier only, with no email.To know whether the hosted service is paid for. We never see or store your card number.
One email address for the account, given when you set your family up. We ask for it because there is one thing the app itself cannot tell you: if your subscription ends and you have stopped opening Famileze, the date the copies we hold come down. It identifies your account. It can never unlock it. It cannot be used to sign in, to re-pair a device, to recover a lost family key, or to obtain any access to your archive — not by you, not by us, and not by anyone claiming to be you. It is not a contact and it is not a mailing list: it is a field on the account record, no newsletter can reach it, and it is deleted when the account is deleted.To send one dated notice before cloud copies are removed, and so we can talk to you about your account if you write to us. No marketing.
Your email address, if you joined the launch waitlist on famileze.app, together with the date, the browser user-agent string, and any referral tag in the link you followed.To tell you when Famileze is available. Consent-based, and you can have it removed at any time.
Your email address and whatever you write, if you contact support@famileze.app.To answer you. Support mail is forwarded to the operator’s own inbox.
Connection metadata — IP address, timestamp and request path — logged at the network edge by Cloudflare. Cloudflare’s own logs also derive a rough location from the IP address; Famileze never reads it, and the app never asks your device for your location.Security, abuse prevention and debugging. We do not join this to your family content, and it is not used to build any profile of you.

There is no analytics or telemetry software in the Famileze apps. No Google Analytics, no Firebase, no Sentry, no advertising SDK, no crash reporter that phones home. We do not know which screens you open or which features you use, and we have chosen not to find out. The website is a separate matter — it counts page visits, and section 14 says exactly how.

6. Where end-to-end encryption stops — the honest exceptions

Three parts of Famileze move information between your family and the outside world. Encryption that only your devices can undo is impossible in each case, because someone outside your family is at the other end. We would rather say so here than let you assume otherwise.

a. Email sent to your family address. Each family gets an address of the form famileze-<id>@famileze.app, so you can forward a school notice or a doctor’s letter into your archive. That message arrives as ordinary email from outside your family, so it reaches our relay in readable form. We store it — including its attachments — for up to 30 days, so your devices can collect it, and it is then deleted automatically. During that window it is technically readable by us. We do not read it, and the message becomes end-to-end encrypted family content once your device has pulled it in. If this matters to you, do not use the email address; nothing else in the app depends on it. You can also restrict the address to a list of senders you nominate, in the app’s settings.

b. Newsletters you send. When you email a newsletter to grandparents, that is ordinary email to people outside your family. Its contents, the recipients’ email addresses, and any photos you included pass through our relay and our email provider in readable form so that they can be delivered. Recipient addresses come from the contacts you keep in the app; they are transmitted for the send and are not retained by us as a marketing list. A scheduled newsletter is held until it is sent, and its record is deleted once every recipient has been accounted for.

c. Pages you choose to publish. If you use the share feature — for a recipe, say — the app publishes that one page to a web address with a long random identifier. Anyone who has the link can open it, without signing in. It is stored unencrypted, because a web page has to be, and it is deleted automatically after about a year. Nothing is ever published unless you tap share.

Everything else — the timeline, folders, calendar, health records, lists and letters — is end-to-end encrypted as described in section 4.

7. Who else touches your data

We use four providers. We have no others, and none of them is an advertising company or a data broker. One of them, Cloudflare, also counts visits to this website — section 14 says exactly what that records, and none of it identifies you.

ProviderWhat they doWhat they can see
Cloudflare (US, global network)Runs the relay and stores your encrypted archive.Ciphertext, the service data in section 5, and connection metadata.
Resend (US)Delivers newsletters and carries email sent to your family address.The contents of those emails, and the addresses involved. Nothing else.
Stripe (US / Ireland)Takes payment for subscriptions bought outside the App Store.Your name, email and payment details, which they hold as their own controller. We never receive your card number.
Apple (US / Ireland)Distributes the iPhone app, takes payment for subscriptions bought in it, and provides the speech recognition behind the iPhone app’s 🎙 dictation.Your Apple Account details, which they hold under their own privacy policy. We receive a transaction identifier and a subscription status — no name and no email. Audio you dictate goes to Apple, not to us (section 14).

These providers are located in, or route through, the United States and other countries, so using Famileze involves an international transfer of the limited data above. For users in Ireland and the EEA we rely on the European Commission’s Standard Contractual Clauses, incorporated in each provider’s data processing terms. For users in Australia this is a cross-border disclosure for the purposes of Australian Privacy Principle 8, and we take reasonable steps to ensure these recipients handle the information consistently with the APPs. Your family content, being encrypted before it leaves your device, crosses those borders as ciphertext.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have never done so. We will disclose personal information if we are legally compelled to — and if that happens, what we are able to disclose about your family content is ciphertext we cannot decrypt.

8. How long we keep things

ItemKept for
Your encrypted archiveAs long as the account exists, and your photographs stay with us for good even if it does not. We cannot store full-quality photos and videos endlessly, so if a subscription ends there is one window: ~45 days from your last payment — a 14-day grace period in case a card simply failed, then 31 days — and after that the full-quality originals we hold are removed and the archive is treated as abandoned. What survives is not nothing, and it is not a thumbnail: every photograph stays at up to 1600 pixels — enough to fill a phone screen and to print a 5×7 — along with every caption, date, folder and record, for as long as we run the service. You can open Famileze years later and your whole family story is still there. Videos are the exception, and we would rather say so plainly than let you find out: videos are not kept. A film is hundreds of times the size of a photograph, and we will not pretend otherwise by keeping a single frame and calling it your video — the moment stays in your timeline with its caption and date, saying the video was not saved. Before that date you have two ways to take everything with you, both of which keep the full-quality files: install the free Famileze desktop app for Mac or Windows and bring the whole archive onto your own computer, or, from the phone, save your photos and videos straight to its camera roll. Reading your archive and bringing it home stay open for the whole period; what closes when a subscription lapses is writing — no new moments, and no sending email or newsletters. The exact date for your family is shown in the app, and we email the account address once, before it, saying what will be removed.
Sync messages between your own devicesDeleted once every device has collected them, and in any case after 14 days.
Videos published for phone playbackKept while your account is — the same as your photos, with no shorter clock of its own. The difference comes only if a subscription ends: photographs stay at 1600 pixels for good, and videos do not stay at all. See the first row.
Email sent to your family address, and its attachments30 days, then deleted automatically. Your family address isn’t a second inbox — that’s deliberate. Only senders you’ve allowed can reach it, which is what keeps spam out, and everything that arrives is there to be filed: a date into the calendar, a recipe or a photo into its folder, a letter for the kids. So we hold it only long enough for you to file what matters and let the rest go. Replies to your newsletter arrive here too, so close family can comment or add a letter you can keep.
Pages you publish with the share featureAbout a year, then deleted automatically.
A co-parent invite24 hours, or until it is claimed.
Account and subscription recordsWhile the account exists, and afterwards only as long as tax and financial record-keeping law requires (in Australia, five years for transaction records).
The account’s email addressWhile the account exists. Deleted with it.
Waitlist email addressesUntil launch, or until you ask us to remove yours.
Support correspondenceUp to two years, so we have context if you write again.
Cloudflare edge logsAs Cloudflare retains them — days, not years.

9. Children

Famileze is a product for parents. It is about children, which is not the same thing as being used by them.

This is designed to be consistent with the United States Children’s Online Privacy Protection Act, the GDPR’s provisions on children’s data as applied in Ireland, and the Australian Privacy Act. If you believe a child has provided personal information to us directly, write to support@famileze.app and we will delete it.

10. Our legal bases (EEA and Ireland)

11. Your rights

If you are in Ireland or the EEA, you have the right to access your personal information, to have it corrected, to have it erased, to restrict or object to our processing of it, to data portability, and to withdraw consent. You may lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.

If you are in Australia, you may ask for access to the personal information we hold about you and ask us to correct it, under Australian Privacy Principles 12 and 13. If you are unhappy with how we have handled a privacy matter, write to us first — we will respond within 30 days — and if you are still unsatisfied you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

If you are in the United States, you have the right to know what personal information we have collected and why, the right to delete it, the right to correct it, and the right not to be discriminated against for exercising any of them. We do not sell or share personal information, so there is nothing to opt out of, and we do not use sensitive personal information to infer characteristics about you. We extend these rights to residents of every US state, whether or not that state’s law obliges us to.

How to exercise any of them: email support@famileze.app. We will verify that the request comes from the account holder — usually by asking you to write from the address associated with your subscription, or to confirm a detail only the account holder would know — and we will respond within 30 days. Exercising these rights is free; we may charge only for a repeated or manifestly excessive request, and we will tell you before we do. You may use an authorised agent, who must provide your written permission.

One honest limitation. A right of access obliges us to give you the personal information we hold. For your family content, what we hold is ciphertext we cannot decrypt, so that is what we could give you — which would be useless. The real answer is better: your family content is already in your hands, and the app will export the whole archive as ordinary photo and text files, on your phone or on the free desktop app, whenever you want it. That is data portability without asking anyone’s permission, and it is deliberate.

12. Deleting your account

Use the deletion option in the app’s settings. That is the route, and it is deliberately the only one: it removes your account record, your device tokens, your subscription record beyond what tax law requires us to keep, and every encrypted object belonging to your family. Backups and logs age out on the schedules in section 8.

You can write to us and we will help you find it, but we cannot delete an account for you, and we will not try. The email address on your account identifies you to us; it does not authorise anything. We have no key to your archive, no way to confirm that whoever is writing is the family that owns it, and no console that could delete it on your behalf. If we could be talked into deleting a family’s archive by someone who knew their email address, that would be a way to destroy a family’s photographs, not a convenience — and it is irreversible for exactly the reasons in the next paragraph.

Two things worth knowing. First, deleting the account does not delete the copies on your own devices — those are yours, they keep working, and you delete them the way you delete anything else on your phone or computer. Second, deletion is irreversible: because we cannot read your archive, we cannot inspect it first, cannot restore it afterwards, and have no copy set aside.

Cancelling a subscription is not the same as deleting an account. If you cancel, the time you have already paid for runs to its end, your archive stays where it is, and the app on your devices keeps working.

13. How we protect it

No system is perfectly secure, and we will not claim otherwise. If a data breach occurs that is likely to cause you serious harm, we will notify you and the relevant regulator — within 72 hours of becoming aware where the GDPR applies, and as soon as practicable under the Australian Notifiable Data Breaches scheme.

14. Cookies, tracking, and AI

famileze.app sets no advertising or tracking cookies, and no cookie at all for analytics. Cloudflare may set a cookie strictly necessary for security and bot management. There are no tracking pixels and no advertising scripts.

The website counts visits. The apps do not. famileze.app runs Cloudflare Web Analytics, which loads one script from static.cloudflareinsights.com. It is cookieless: it stores nothing on your device, sets no identifier, and cannot recognise you when you come back or follow you to any other site. What it records is the page, the site that referred you, your country, your device type, browser and operating system, and how long the page took to load. It tells us how many people read a page and roughly where in the world they were. It cannot tell us who they are, and we have no way to connect it to a Famileze account. There is nothing like it in the iPhone or desktop app — section 5.

The apps store data on your own device — in the browser’s local storage and database on the phone, and in ordinary files on the desktop app. That is your device’s storage, not ours, and it is not transmitted anywhere except as encrypted sync.

There is no cloud AI and no large language model anywhere in Famileze. The features that look clever — reading dates out of a school email, recognising text in a photograph, suggesting a folder — run entirely on your own device as small, purpose-built tools, and nothing about them is sent away to be interpreted. Your family content is never used to train any machine learning model, ours or anyone else’s, and we could not do so even if we changed our minds, because we cannot read it. We do not respond to “do not track” signals: there is no cross-site tracking here for them to switch off.

Dictation on the iPhone is the one exception, and it is not our software. When you tap 🎙 in the iPhone app, iOS transcribes what you say using Apple’s own speech recognition, and Apple may send that audio to its servers to do it. That is Apple’s service, under Apple’s privacy policy — we never receive the audio, and the text that comes back is encrypted into your archive like anything else you type. If you would rather nothing left the phone, type instead. Dictation in the desktop app is different: it runs a small speech model inside the app on your own computer, and the audio never leaves the machine.

15. Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects how your information is handled, we will tell you in the app before it takes effect, rather than relying on you to notice. Previous versions are available on request.

If Famileze were ever sold or transferred, your information would move with it, and you would be told in advance and given the opportunity to export your archive and close your account first. Your family content would transfer as ciphertext; a buyer would acquire no more ability to read it than we have.

16. Contact

Sol Coast Construction Pty Ltd
PO Box 4673, SCMC QLD 4560
support@famileze.app

We read every message ourselves.

Questions about your data?

Email us