Appearance
Privacy policy
Draft — not yet reviewed. Do not publish.
Famify is an app for organising a household's chores. This describes exactly what it stores, who else sees it, and how to get rid of it.
What is collected
Identity. A display name and a username for each member. A password, stored only as an argon2id hash — never the password itself. A household name and a join code. A language preference. One email address per household, belonging to the Owner, used for account recovery and nothing else. Members other than the Owner have no email address on file.
Activity. Quests and their titles, descriptions, categories and due dates. Submissions, including any note written when a quest is handed in. Rewards recorded as owed or paid, with their amount, currency and label. Character level, XP, gold and appearance. Streaks, achievements and the counters behind the statistics screens. Goals, their objectives, and each participant's progress.
Device. Push notification tokens, which identify a device rather than a person, and each member's notification preferences.
Photographs of objects, not people. A goal can carry a photo of the prize being saved for — the bike, the tent. Nothing in Famify asks for or stores a photograph of a person.
Security state. Failed sign-in counts and lockout timers, hashed and expiring password-reset codes, and session records. Session tokens are stored as SHA-256 hashes; the raw token is never kept.
Free-text fields
Several fields accept whatever someone types: a quest's title and description, a submission note, a reward's label, a household or display name. Their purpose is names and activity, but their contents cannot be guaranteed — a person can type anything into them. We describe them as free text rather than claim to know what they hold, and support staff never quote them back.
What is not collected
No date of birth. No postal address. No phone number. No location or GPS data. No contacts. No photographs of people. No advertising identifier. No analytics or tracking SDK. No third-party ad network.
Who else receives it
| Who | What they receive | Why |
|---|---|---|
| DigitalOcean | Everything above | Hosting and the database |
| Cloudflare R2 | Prize photos | File storage |
| Expo | Device tokens and notification text | Delivering push notifications |
| Resend | The Owner's email address, verification and recovery codes | Sending those emails |
| RevenueCat | Purchase and subscription state | Billing for Premium |
| Bugsink | Crash reports | Diagnosing crashes — self-hosted by us, so this data reaches no third party |
Crash reports are stripped of credentials and names before they leave the app, and are deleted after thirty days.
How long it is kept
Everything else is kept until the household is deleted. There is no automatic expiry.
Deleting your account
Settings → Delete account, inside the app. It asks for your password first.
Deleting erases your personal details — your name, email, password, device tokens and preferences — and permanently removes your character, your items, your streak and your achievements.
Some records are deliberately kept. A reward record saying one member paid another is partly the other person's record of what they earned, so it stays, pointing at an account that no longer identifies anyone. Erasing it would destroy the history of someone who did not ask for anything. The same reasoning applies to a goal you set up that other people are still working toward: the goal continues, and its prize photo stays, unless nobody else is part of it.
If you are the household's Owner, you are asked to hand the household to another Game Master. If you decline, or there is nobody to hand it to, the household and everything in it is deleted along with your account. The app says which of the two is about to happen before it happens.
Children
Accounts are created by the household's Owner, an adult, who chooses who joins. A child in Famify has a display name, a username, a language, push tokens and their own activity. No contact details, no photograph, no date of birth.