Privacy Policy
FamHub is a shared organizer for one family: groceries, a weekly schedule, to-dos and pets. This page explains what FamHub keeps, why, who helps us run it, and how to delete it. "We" and "us" means FamHub.
The short version
- We keep what your family puts into FamHub, so every family device sees the same lists.
- No ads. No analytics or tracking tools. We don't sell or share your data for advertising.
- You can delete the whole account from the app, any time: Settings → Delete family account.
What we store
When your family uses FamHub with an account, we store:
- Your family's login. The email address and password the whole family signs in with. The password is stored hashed by our login provider, so we can't read it.
- Your family's name.
- Members. The names you give each person, their color, and the avatar or photo you choose. You can also mark a member as a kid.
- What you add. Groceries (with quantities, notes, store links and prices you record), events, to-dos, lists, pets and pet care logs. Photos you add to a member or pet are stored with them.
- Notification settings. If you turn notifications on, we store this device's push address (an Apple device token, or a web push address from your browser), which member it belongs to, and which kinds of notifications you want.
- Messages you send us through the support form: your email address and the message.
- The iPhone waitlist. If you joined it on our website, your email address.
What stays on your device
- A random device ID. FamHub makes one up the first time it opens. It isn't linked to your phone's hardware and it isn't sent to us.
- A copy of your family's data, so the app works offline and opens fast.
- Barcode scans. The camera picture is read on your device. Only the barcode number leaves it (see "Lookups you start" below). Recent results are remembered on the device.
- Siri. On iPhone, FamHub keeps member names and open to-dos in the phone's own storage so Siri can understand "assign the dishes to Sam." That copy isn't sent to us. What you say to Siri is handled by Apple under Apple's privacy policy.
- Reminders the app schedules on your iPhone are set up by the phone itself.
Who helps us run FamHub
These companies process data for us, only to provide the service:
- Supabase runs our database, the family login, sign-in emails and our small server functions.
- Vercel hosts the website and the web app. Like any web host, it sees IP addresses and keeps standard request logs.
- Apple Push Notification service delivers notifications to iPhones. On the web, your browser's push service (for example Apple, Google or Mozilla) does the same. A notification carries a short line, such as a to-do title or the grocery item that ran out.
Lookups you start
Some features ask an outside service for product details. They only run when you use them:
- Scanning a barcode sends the barcode number to Open Food Facts. If they don't know it, our server asks UPCitemdb.
- Typing a grocery name sends what you type to Open Food Facts to suggest products. Product pictures load from Open Food Facts too.
- Turning on "Pull from Kroger" sends what you type to Kroger, through our server, to show products and prices.
- Pasting a product link sends that link to Microlink to fetch the product's name and picture.
- Order online opens the store's website or app. What happens there is covered by that store's privacy policy.
When your device talks to Open Food Facts or Microlink directly, they can see your IP address. None of these lookups include your family's name, members or email.
Who can see your family's data
Anyone who signs in with your family's email and password sees everything in the family, on any device. Personal to-dos only show on the devices of the member who made them, but they're still part of the family account. Our database rules keep each family's data to that family's login.
We don't look at your family's data except to help when you ask, or to keep the service working.
Keeping it safe
Data travels between your device and our services over encrypted connections (HTTPS). Supabase encrypts the stored data at rest. No system is perfect, so please pick a strong password for your family.
How long we keep it
We keep your family's data for as long as the account exists.
- Delete the account: in the app, go to Settings → Family account → Delete family account, and type DELETE. This permanently deletes the login and everything in it, for every device, plus any waitlist entry with the same email. Our database provider may keep backups for a short time before they're overwritten.
- Log out of one device: Settings → Log out of family clears the family from that device and leaves the account alone.
- Support messages are kept while we need them to help you. Ask and we'll delete them.
Children
A family account is meant to be created and run by a parent or another adult. Kids can be added as members. A member is just a name, a color and an avatar or photo the family picks. Kids don't get their own login or email, and we don't knowingly collect personal information directly from children.
Your choices
You can see, change and delete everything your family added right in the app. For anything else, like a copy of your data or a question about this policy, write to us on the support page.
Changes
If we change this policy, we'll post the new version here and update the date at the top.