Famino Logo Famino
GET IT ONGoogle Play SOON ONApp Store

1. Who We Are

The Famino application ("App") and this website are provided by:

Daniel Prause
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
Email: service@famino.app

(Hereinafter referred to as "we", "us", or "our".) We are the controller for the processing described here. Because of our size we are not required to appoint a Data Protection Officer, so please send all privacy questions to the address above.

2. Information We Collect

Famino is a family organization app that helps families plan their daily lives together, with a shared calendar, tasks, expenses, meal planning and recipes. To provide these services we collect and process the following types of information.

2.1 Account Information

You can use Famino in four ways:

If you start anonymously and later add a login method, your existing family data stays attached to the same account. We also store your app language (languageCode) on your account so that notifications and support replies reach you in the language you use.

Purpose: To create and manage your user account, authenticate you, and personalize your experience.

2.2 Family and Member Data

2.3 Child Accounts and Members Without an Account

2.4 Calendar Events

2.5 Tasks

2.6 Expenses and Budgets

2.7 Meal Plans, Recipes and Shopping Lists

2.8 Image Attachments

2.9 Device Calendar Access

2.10 ICS Calendar Import

2.11 Camera Access

2.12 Notifications

2.13 Subscription and Purchase Data

2.14 Bonus Time and Referral (discontinued)

The referral programme is no longer offered in the app. We still store bonus expiry dates on accounts that earned a bonus in the past, and a daily job clears them once they expire. We no longer read the Google Play Install Referrer.

2.15 Usage and Diagnostic Data

We use Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring and Firebase Remote Config.

2.16 Local App Settings

2.17 Home Screen Widget and Links

2.18 Event Card Scan (Premium feature)

2.19 Receipt Scan (Premium feature)

2.20 Recipe Import (Premium feature)

2.21 Holiday Country and Region

2.22 Weather Widget and Location (Premium feature)

2.23 Support Requests

3. Transparency About AI-Generated Content (EU AI Act)

Three optional Premium features use an AI system: the event card scan, the receipt scan and the recipe import. All three are provided by us on the basis of models operated by Mistral AI SAS (France, EU). We disclose this in line with Article 50 of Regulation (EU) 2024/1689 (AI Act).

4. How We Use Your Information

5. Legal Bases for Processing

Under Art. 6 (1) GDPR we rely on the following legal bases:

What we process Legal basis
Account, family and member data; calendar, tasks, expenses, meal plans, recipes and shopping lists; image attachments; push notifications and the home screen widget Art. 6 (1) (b) GDPR, performance of our contract with you
Subscription handling and purchase verification Art. 6 (1) (b) GDPR
Event card scan, receipt scan and recipe import (Premium) Art. 6 (1) (b) GDPR, the Premium feature you requested
Weather forecast and the location it needs Art. 6 (1) (b) GDPR, plus your consent under Art. 6 (1) (a) GDPR where your device asks for location permission
Support requests and their attachments Art. 6 (1) (b) and (f) GDPR, answering you and defending legal claims
Analytics, Remote Config, Crashlytics, Performance Monitoring, App Check and abuse prevention Art. 6 (1) (f) GDPR, our legitimate interest in a stable, secure and useful app
Keeping purchase records after a subscription ends Art. 6 (1) (c) GDPR, statutory retention duties under German commercial and tax law
Holiday country and region Stays on your device. If it were processing, Art. 6 (1) (a) GDPR, your consent

Where a processing operation rests on our legitimate interests, you may object under Art. 21 GDPR. Where it rests on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR).

6. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances.

6.1 Google and Firebase

We use Google Firebase services for our backend infrastructure:

  • Firebase Authentication, sign-in (anonymous, email and password, Google, Apple)
  • Cloud Firestore, cloud database for family, calendar, task, expense, recipe and support data
  • Firebase Storage, storage of image attachments and support attachments
  • Firebase Cloud Functions, server-side logic (region europe-west1)
  • Firebase Cloud Messaging, push notifications
  • Firebase App Check, protection against abuse
  • Firebase Crashlytics and Performance Monitoring, error reports and performance monitoring
  • Firebase Analytics and Remote Config, usage statistics and product configuration, see 2.15
  • Firebase Hosting, this website, which keeps standard server access logs

Google processes this data on our behalf as our processor. For in-app purchases, Google Play Billing is used. We do not receive or store your payment card details.

More information: Google Privacy Policy

6.2 What Your Family Members Can See

Famino is a shared workspace. Every member of your family can see the calendar events, tasks, expenses, budgets, shopping lists, meal plans and recipes created in it, including titles, descriptions, dates, locations, amounts, categories, assigned members, comments and any images attached, together with the display name and colour of whoever created them.

6.3 Google Maps Platform (Weather and Geocoding)

If you use the weather widget, your coordinates or the city name you entered are sent to the Google Maps Platform Weather API and, where a city name has to be resolved, to the Google Geocoding API, in order to obtain a forecast. Nothing else about you is sent, and nothing is sent when the weather widget is switched off. See 2.22.

6.4 Apple

If you sign in with Apple, Apple provides us with a user identifier and, at your choice, your name and email address or a private relay address. If you subscribe through the App Store, we exchange purchase receipts and subscription status with Apple, and Apple sends server notifications about your subscription directly to our endpoint. See 2.1 and 2.13.

More information: Apple Privacy Policy

6.5 Mistral AI (Event Card Scan, Receipt Scan and Recipe Import)

Mistral AI SAS, 15 Rue des Halles, 75001 Paris, France, acts as our sub-processor for OCR and structured extraction in three Premium features that you start explicitly: the event card scan (2.18) sends a single photo; the receipt scan (2.19) sends a single photo together with your family's expense category names and IDs; the recipe import (2.20) sends the reduced text of the public recipe page you chose. Under our data processing agreement, processing takes place within the EU and Mistral does not retain this content for training. Nothing is sent to Mistral outside of these explicit user actions.

More information: Mistral AI Privacy Policy

6.6 Our Support Mailbox and Administration Tool

Support messages you send from the app are copied by email to our support mailbox, which is hosted by Google (Gmail). We read and answer tickets through an internal administration tool that we operate ourselves and that writes replies back into your ticket. See 2.23.

6.7 Legal Requirements

We may disclose your information if required to do so by law, or in the good faith belief that such action is necessary to comply with a legal obligation, protect our rights, prevent fraud, or protect the safety of users.

6.8 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of such a transaction.

7. Data Storage and Security

7.1 Cloud Storage

Your data is stored on Google Firebase servers (Cloud Firestore, Firebase Authentication, Firebase Storage). Data transfer is encrypted (HTTPS/TLS).

Server-side security measures:

  • Firestore Security Rules restrict access to authenticated requests and family-scoped data
  • Firebase Storage Rules allow only authenticated users to upload (size limit, image formats only)
  • Firebase App Check protects against unauthorized API access
  • Cloud Functions with rate limiting and spam protection
  • Critical fields (familyId, isPremium, roles) can only be changed server-side via Cloud Functions
  • Server-side validation and content size limits

7.2 Additional Field Encryption

Beyond transport encryption, some content is encrypted with AES-256-GCM before it is written to our database, using a key generated for your family:

This is not end-to-end encryption. The family key is generated and held on our servers so that new members and our server-side features can read the data; a copy is cached in your device's secure storage (Android Keystore, iOS Keychain). Expenses, budgets, recipes, meal plans, shopping lists, image attachments and support messages are not field-encrypted, and metadata such as dates, amounts, categories and assignments is not encrypted either.

7.3 Local Storage

Onboarding status, device calendar settings and app preferences are stored locally in SharedPreferences, protected by your operating system's security mechanisms.

7.4 Image Attachments

Images are compressed on your device and transferred encrypted (HTTPS) to Firebase Storage. Storage security rules ensure that only authenticated users can access them.

7.5 Your Responsibility

While we work to protect your information, no security system is impenetrable. You are responsible for safeguarding the credentials of the account you sign in with, and for deciding whom you invite into your family.

8. Data Retention and Deletion

9. Your Rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and the right to object to processing based on our legitimate interests (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).

You can delete your account and all of your data directly in the app, in Settings under Advanced settings, Delete account. The deletion is carried out immediately and cannot be undone. To exercise any other right, write to service@famino.app. We answer within one month.

You also have the right to lodge a complaint with a supervisory authority (Art. 77). The supervisory authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
www.ldi.nrw.de

You may also contact the supervisory authority of your own place of residence.

In addition, you can do the following directly in the app:

10. Third-Party Services

11. Children

Famino is meant to be set up and run by an adult. A parent can create child accounts and members without an account for their own household. The parent chooses the name and any details and remains responsible for what they enter about their child.

We do not ask children for an email address, we do not let child accounts sign in on their own, and we never use children's data for advertising, for profiling, or for analytics beyond the family-size counter described in 2.15.

Where consent is the legal basis, EU law (Art. 8 GDPR) sets the age between 13 and 16 depending on the country. Below that age the parent must consent, which they do by creating the account. Outside the EU we apply 13 years (COPPA).

A parent can delete a child account or a family member at any time in the app, which erases that member's data. If you are a parent or guardian and believe that a child's information reached us without your knowledge, please contact us at service@famino.app.

12. International Data Transfers

Our Cloud Functions run in the European Union (region europe-west1). Our Firestore database runs in Google's European multi-region eur3 (Belgium and the Netherlands). Our file storage for uploaded images (Firebase Storage) is currently hosted by Google in the United States (region us-central1); we plan to move new uploads to an EU region and will update this policy when that is done. Our sub-processor Mistral AI processes the AI scan features within the EU.

Some of our providers are US companies whose support and infrastructure teams may access data from outside the EU. Transfers to Google LLC and Apple Inc. take place on the basis of the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework and, in addition, the Standard Contractual Clauses contained in our data processing agreements with them.

13. What We Do Not Do

14. Reporting Content

If someone in a family you belong to uploads an image or writes a comment that does not belong there, contact us at service@famino.app. We will look into it and can remove content and, where necessary, accounts. You can also remove a member from your family yourself if you are its owner, and you can leave a family at any time.

15. This Website

This section covers famino.app itself, not the App.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date at the top of this policy and, in some cases, by showing a notice inside the App.

17. Contact

If you have questions or concerns about this Privacy Policy, please contact us at:

Daniel Prause
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
Email: service@famino.app