1. Who We Are
The Famino application ("App") and this website are provided by:
Daniel Prause
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
Email: service@famino.app
(Hereinafter referred to as "we", "us", or "our".) We are the controller for the processing described here. Because of our size we are not required to appoint a Data Protection Officer, so please send all privacy questions to the address above.
2. Information We Collect
Famino is a family organization app that helps families plan their daily lives together, with a shared calendar, tasks, expenses, meal planning and recipes. To provide these services we collect and process the following types of information.
2.1 Account Information
You can use Famino in four ways:
- Anonymously. We create a temporary account identified only by a random Firebase user ID. No name and no email address.
- With email and password. We store your email address and send you a verification email. Verification, password reset and welcome emails are generated by our Cloud Functions and delivered through an SMTP relay of Hostinger International Ltd. (see section 8).
- With Google Sign-In. Google provides your name, email address, Google user ID and profile picture.
- With Sign in with Apple. Apple provides a stable user identifier and, if you allow it, your name and email address. If you choose Apple's Hide My Email, we only ever receive Apple's private relay address and never your real one.
If you start anonymously and later add a login method, your existing family data stays attached to the same account. We also store your app language (languageCode) on your account so that notifications and support replies reach you in the language you use.
Purpose: To create and manage your user account, authenticate you, and personalize your experience.
2.2 Family and Member Data
- Information: Family name, family ID, member IDs, roles (owner, parent, child), invitation codes, calendar colors, display names.
- Purpose: To organize the family structure, assign content, and manage permissions.
2.3 Child Accounts and Members Without an Account
- Information: The child's name and the linked parent account (
managedByUserId). A family owner can also add members who have no account at all, in which case only a display name and a color are stored.
- Purpose: To let children take part without their own email address.
- Note: Child accounts have no independent login and can only be used through the managing parent. The adult who creates such an account decides what is entered about that child and stays responsible for it. See section 11.
2.4 Calendar Events
- Information: Title, description, start and end time, location, assigned family members, recurrence rules, reminder settings, optional image attachments (Premium), comments (Premium), private flag.
- Purpose: Shared scheduling within the family.
2.5 Tasks
- Information: Title, notes, due date, priority, status, assigned members, task list assignment, optional image attachments (Premium), comments (Premium).
- Purpose: Shared task management.
2.6 Expenses and Budgets
- Information: Amount, description, category, date, creating member, recurring expenses (Premium), budget data (Premium).
- Purpose: Shared expense tracking and budget management.
- Note: Expenses and budgets have no private flag. Everything entered here is visible to every member of your family. See section 6.2.
2.7 Meal Plans, Recipes and Shopping Lists
- Information: Recipe titles, ingredients, steps, servings, preparation times, planned meals per day, shopping list entries.
- Purpose: Shared meal planning and shopping within the family.
2.8 Image Attachments
- Information: Images you attach to tasks or calendar events (Premium). Images are compressed on your device before upload (max 1200px, 70% JPEG quality, target size below 100KB).
- Storage: Firebase Storage.
- Purpose: Visual supplement to tasks and events.
2.9 Device Calendar Access
- Information: When you enable device calendar import, the App reads events from the local calendars you select (for example Google, Samsung, iCloud).
- Purpose: To display external calendar entries inside Famino.
- Storage: Device calendar events are not stored in our cloud. They are read and displayed locally only.
2.10 ICS Calendar Import
- Information: The contents of an
.ics calendar file that you open with Famino.
- How it works: The file is parsed on your device. Nothing is uploaded while you are still choosing.
- What is stored: The events you then confirm are saved to your family calendar like any event you type in yourself. Their titles, times, locations, descriptions and any participants named in the file become visible to your family members and stay in the family calendar.
- Please note: Only import files whose contents you may share with your family.
2.11 Camera Access
- Information: Access to your device camera for taking photos for image attachments and for scanning printed event cards and receipts.
- Purpose: (a) Creating photo attachments for tasks and calendar events; (b) scanning printed event cards and receipts to pre-fill a new entry, see sections 2.18 and 2.19.
- Storage: Image attachments are compressed and uploaded to Firebase Storage. Scan photos are not stored by us. They are sent once for structured extraction and then discarded server-side (details in 2.18 and 2.19).
2.12 Notifications
- Information: One Firebase Cloud Messaging token (FCM token) per device you use, your notification preferences, and your app language (
languageCode).
- Purpose: Reminders for events and tasks, family notifications, and sending them in the language you use.
- Local reminders: Reminders that your device schedules on its own, for events and tasks, are generated locally and are not sent through our servers.
2.13 Subscription and Purchase Data
- What the store gives us: When you buy a subscription, the store hands the app a purchase receipt: a purchase token on Google Play, a signed transaction (JWS) on the Apple App Store.
- What we do with it: The app sends that receipt to our Cloud Function
verifyAndActivatePurchase (Firebase, region europe-west1), which asks Google Play or Apple to confirm that it is genuine and still valid.
- What we store: The resulting subscription state, meaning plan, base plan, validity period, trial status and the store's transaction identifiers (Google purchase token, Apple original transaction ID), on your user document and, for a family plan, on your family document.
- Notifications from the stores: Google and Apple also notify our servers directly when a subscription renews, lapses, is cancelled or refunded (Google Play Real-time Developer Notifications, Apple App Store Server Notifications). A daily job re-checks subscription status with both stores.
- Payment details: Payment is processed exclusively by Google Play or the Apple App Store. We never receive your card or payment details.
- Retention: We keep purchase records while your subscription is active and afterwards for as long as statutory retention periods under German commercial and tax law require.
2.14 Bonus Time and Referral (discontinued)
The referral programme is no longer offered in the app. We still store bonus expiry dates on accounts that earned a bonus in the past, and a daily job clears them once they expire. We no longer read the Google Play Install Referrer.
2.15 Usage and Diagnostic Data
We use Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring and Firebase Remote Config.
- Analytics records which screens you open and which actions you take, for example that a task, an expense, an event or a recipe was created, and whether it had a due date, a reminder or an assignee. It also records the onboarding steps you pass through. It never records the content of your entries: no titles, no descriptions, no amounts, no names.
- Account-level properties. We set three properties on your analytics profile: your role in the family, the size of your family, and whether you have Premium.
- Remote Config lets us switch product options on and off and run A/B tests on our subscription screen, for example which headline or which plans are shown.
- Crashlytics and Performance Monitoring collect crash reports and performance traces containing device model, operating system version and a stack trace.
- Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in a stable app and in understanding which features are actually used. You may object at any time under Art. 21 GDPR by writing to service@famino.app.
2.16 Local App Settings
- Information: Onboarding status, device calendar settings, display preferences, widget settings. Your holiday country and region selection is also stored here, see 2.21.
- Storage: SharedPreferences on your device.
- Purpose: To personalize your experience.
2.17 Home Screen Widget and Links
- Home screen widget. To draw the widget, the app copies the next few event and task titles, their times and locations, their colours, your app language and your Premium status into the shared widget storage of your device. Depending on your device settings these can be visible on your home screen or lock screen, including to anyone who can see your screen. Removing the widget clears that data.
- Links. Famino handles
famino.app links and app links so that invitations and notifications open the right screen. The link itself may carry an invitation code or a record ID.
2.18 Event Card Scan (Premium feature)
- Information: A single photo of a printed event card (invitation, notice, ticket) that you choose to capture.
- Purpose: To extract title, date, time, location and description automatically, so we can pre-fill a new calendar event for your review.
- How the photo is processed: The photo is compressed on your device and sent over an encrypted connection (HTTPS) to our Cloud Function
scanEventCard (Firebase, region europe-west1). The Cloud Function forwards the image to our sub-processor Mistral AI SAS (France, EU) for OCR and structured extraction. The structured result (event fields) is returned to the app.
- No persistent storage of the photo: We do not save the photo in Firebase Storage, in Firestore, or anywhere else on our side. Under our data processing agreement, Mistral AI processes the image on request, processes it within the EU, and does not retain it for training purposes.
- What we log: Only non-content telemetry (your user ID, app locale, request duration, model confidence score, image size in kB). We explicitly do not log the photo, the extracted text, or any of the event fields.
- Access control: Premium users only. Usage is rate-limited to 30 scans per user per hour to prevent misuse.
- Legal basis (GDPR): Art. 6 (1) (b) GDPR, processing is necessary to provide the Premium feature you requested.
- Your control: You decide every time whether to scan a card; you can always enter events manually instead.
2.19 Receipt Scan (Premium feature)
- Information: A single photo of a printed receipt, invoice or bill that you choose to capture, plus the list of your own expense category IDs and names (read server-side from your family's data, so we can suggest a matching category).
- Purpose: To extract amount, date, merchant, suggested category and a short description automatically, so we can pre-fill a new expense for your review.
- How the photo is processed: The photo is compressed on your device and sent over an encrypted connection (HTTPS) to our Cloud Function
scanReceipt (Firebase, region europe-west1). The Cloud Function reads your family's expense category list from Firestore, forwards the image together with the category names and IDs to our sub-processor Mistral AI SAS (France, EU) for OCR and structured extraction, and returns the structured result to the app.
- No persistent storage of the photo: We do not save the photo in Firebase Storage, in Firestore, or anywhere else on our side. Under our data processing agreement, Mistral AI processes the image on request, processes it within the EU, and does not retain it for training purposes.
- What we log: Only non-content telemetry (your user ID, app locale, request duration, model confidence score, image size in kB, category count, whether a category was matched). We explicitly do not log the photo, the merchant name, the amount, or any of the extracted expense fields.
- Access control: Premium users only. Usage is rate-limited to 30 scans per user per hour.
- Legal basis (GDPR): Art. 6 (1) (b) GDPR.
- Your control: You decide every time whether to scan a receipt; you can always enter expenses manually instead.
2.20 Recipe Import (Premium feature)
- Information: The recipe URL you paste, and the readable text of that public web page (structured data, visible text, preview image link). We do not send any of your family data.
- Purpose: To extract title, ingredients, steps, servings and preparation time automatically, so we can pre-fill a new recipe for your review.
- How the page is processed: The app fetches the public page and reduces it to plain text on your device. That text is sent over an encrypted connection (HTTPS) to our Cloud Function
importRecipe (Firebase, region europe-west1), which forwards it to our sub-processor Mistral AI SAS (France, EU) for structured extraction. The structured result is returned to the app.
- No persistent storage of the page: We do not store the page text on our side. Under our data processing agreement, Mistral AI processes the request within the EU and does not retain it for training purposes.
- What we log: Only non-content telemetry (your user ID, app locale, request duration, text length). We explicitly do not log the page text or any of the extracted recipe fields.
- Access control: Premium users only, rate-limited per user.
- Legal basis (GDPR): Art. 6 (1) (b) GDPR.
- Your control: You decide every time whether to import a recipe; you can always enter recipes manually instead.
2.21 Holiday Country and Region
- Information: The country and, optionally, one or more regions (for example federal states or provinces) that you select yourself.
- Only on your request: We ask for this only at the moment you switch the holiday display on in the calendar. If you never enable it, no country or region is recorded at all. For the holiday selection we do not use GPS, your device location, your IP address or any other automatic means to determine where you are; you pick country and region yourself from a list. (Location is used only for the optional weather widget, see 2.22.)
- Purpose: Solely to decide which regional public holidays and observances are shown in your calendar and home screen widget. We do not use this selection for anything else: no analytics, no advertising, no profiling.
- Storage: Exclusively on your device (SharedPreferences). The selection is never transmitted to us, to Firebase or to any third party, and it is not part of your family data.
- How the holidays are looked up: The holiday dates ship inside the app as local data files. Displaying them requires no server request, so your selection never leaves the device.
- Legal basis (GDPR): As the selection stays on your device and is not transmitted to us, we do not process it. Should it be considered processing, it rests on your consent under Art. 6 (1) (a) GDPR, given by enabling the feature.
- Your control: You can change or clear the selection at any time in the holiday settings, and switching the holiday display off stops it from being used. Uninstalling the app removes it from your device.
2.22 Weather Widget and Location (Premium feature)
- Information: If you enable the weather widget, you can either grant Famino access to your device location or type in a city name. In the first case we read your coordinates (latitude and longitude) while the app is open.
- How it is processed: Your coordinates, or the city you typed, are sent over HTTPS to our Cloud Function
getWeatherForecast (Firebase, region europe-west1), which forwards them to the Google Maps Platform Weather API and, if you entered a city name, to the Google Geocoding API, in order to obtain a forecast.
- What we store: To keep the number of requests low we cache the forecast together with the coordinates, the resolved place label, your timezone and your app language in your own user document. The cache expires after 3 hours, and we allow at most 4 live refreshes per day.
- Nothing else: We do not use your location for anything else: no analytics, no advertising, no profiling. We never share it with anyone other than Google as described here.
- Your control: You can revoke location access at any time in your device settings and keep using the widget with a city you enter manually. Turning the weather widget off stops the processing.
- Legal basis (GDPR): Art. 6 (1) (b) GDPR for the feature you requested; where your operating system asks you for location permission, that permission is your consent under Art. 6 (1) (a) GDPR.
2.23 Support Requests
- Information: When you contact us from within the app, we store your message, your user ID, your display name or email address and your app language in our database, so that you and we can follow the conversation in the app.
- Attachments: You may attach up to three images, for example screenshots. These are uploaded to Firebase Storage into a folder that belongs to your account. Please avoid sending screenshots that show other people's personal data where you can.
- Email copy: A notification copy of your message is additionally sent by email to our support mailbox, which is hosted by Google (Gmail).
- Who reads it: Our support team reads and answers tickets through an internal administration tool operated by us.
- Retention: We keep support conversations for as long as we need them to handle your request and any follow-up questions or legal claims. You can ask us at any time to delete a conversation. We delete your ticket attachments immediately when you delete your account.
- Legal basis (GDPR): Art. 6 (1) (b) and Art. 6 (1) (f) GDPR.
3. Transparency About AI-Generated Content (EU AI Act)
Three optional Premium features use an AI system: the event card scan, the receipt scan and the recipe import. All three are provided by us on the basis of models operated by Mistral AI SAS (France, EU). We disclose this in line with Article 50 of Regulation (EU) 2024/1689 (AI Act).
- Where AI is used: Only in the three features named above, and only when you actively start them. Everything else in the app, meaning calendar, tasks, expenses, meal planning and reminders, works without AI.
- What the AI produces: Structured field suggestions read from the image or page you provided. For the two scans, short free-text fields (title, description) may be summarised and written in your app language, which means they are generated text rather than a literal copy.
- You always review first: No AI result is saved automatically. The extracted fields are shown to you for checking and editing before anything is stored, and the screen says so.
- Machine-readable marking: When you save a scanned or imported entry, we store a provenance record with it (
aiProvenance) that names the feature, the model and exactly which fields you accepted unchanged from the AI output. If you rewrite a field, it is removed from that record; what you wrote yourself is never marked as AI-generated.
- Which models: We currently use Mistral's OCR model for reading images and a small Mistral chat model for structuring the result. We may move to a newer version of these models; the provenance record always names the model that was actually used.
- Onboarding videos: The short example scenes shown on the welcome screen are AI-generated. They are illustrations, not recordings of real people or events, and are labelled accordingly in the app.
- No chatbot, no profiling: The app contains no conversational AI assistant, no emotion recognition and no biometric categorisation. AI is not used to make decisions about you.
4. How We Use Your Information
- To provide, operate, and maintain the Famino App and its features
- To authenticate you and manage your account
- To manage your subscription and provide access to Premium features
- To synchronize your family data via Firebase
- To enable shared calendar, task, expense, meal and recipe management
- To send push notifications (reminders, family notifications) in your language
- To show the home screen widget
- To show the weather forecast if you enable the weather widget
- To answer your support requests
- To improve the App, diagnose technical issues, and ensure stability
- To personalize your experience (for example settings and calendar colors)
5. Legal Bases for Processing
Under Art. 6 (1) GDPR we rely on the following legal bases:
| What we process |
Legal basis |
| Account, family and member data; calendar, tasks, expenses, meal plans, recipes and shopping lists; image attachments; push notifications and the home screen widget |
Art. 6 (1) (b) GDPR, performance of our contract with you |
| Subscription handling and purchase verification |
Art. 6 (1) (b) GDPR |
| Event card scan, receipt scan and recipe import (Premium) |
Art. 6 (1) (b) GDPR, the Premium feature you requested |
| Weather forecast and the location it needs |
Art. 6 (1) (b) GDPR, plus your consent under Art. 6 (1) (a) GDPR where your device asks for location permission |
| Support requests and their attachments |
Art. 6 (1) (b) and (f) GDPR, answering you and defending legal claims |
| Analytics, Remote Config, Crashlytics, Performance Monitoring, App Check and abuse prevention |
Art. 6 (1) (f) GDPR, our legitimate interest in a stable, secure and useful app |
| Keeping purchase records after a subscription ends |
Art. 6 (1) (c) GDPR, statutory retention duties under German commercial and tax law |
| Holiday country and region |
Stays on your device. If it were processing, Art. 6 (1) (a) GDPR, your consent |
Where a processing operation rests on our legitimate interests, you may object under Art. 21 GDPR. Where it rests on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3) GDPR).
6. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances.
6.1 Google and Firebase
We use Google Firebase services for our backend infrastructure:
- Firebase Authentication, sign-in (anonymous, email and password, Google, Apple)
- Cloud Firestore, cloud database for family, calendar, task, expense, recipe and support data
- Firebase Storage, storage of image attachments and support attachments
- Firebase Cloud Functions, server-side logic (region europe-west1)
- Firebase Cloud Messaging, push notifications
- Firebase App Check, protection against abuse
- Firebase Crashlytics and Performance Monitoring, error reports and performance monitoring
- Firebase Analytics and Remote Config, usage statistics and product configuration, see 2.15
- Firebase Hosting, this website, which keeps standard server access logs
Google processes this data on our behalf as our processor. For in-app purchases, Google Play Billing is used. We do not receive or store your payment card details.
More information: Google Privacy Policy
6.2 What Your Family Members Can See
Famino is a shared workspace. Every member of your family can see the calendar events, tasks, expenses, budgets, shopping lists, meal plans and recipes created in it, including titles, descriptions, dates, locations, amounts, categories, assigned members, comments and any images attached, together with the display name and colour of whoever created them.
- Private events. Marking a calendar event as private hides it from the other members in the app. It is still stored on our servers, and no other content type (tasks, expenses, budgets, recipes) has a private flag at all.
- Invitations. Anyone you invite gains this access from the moment they join, so only invite people you would show these entries to.
- Leaving a family. Members who leave a family stop seeing its content, but the entries they created remain with the family. If you want them removed, delete them before you leave, or ask the family owner.
- Anonymous accounts. If you started anonymously and later added a login method, the family data created before that stays attached to the same account.
6.3 Google Maps Platform (Weather and Geocoding)
If you use the weather widget, your coordinates or the city name you entered are sent to the Google Maps Platform Weather API and, where a city name has to be resolved, to the Google Geocoding API, in order to obtain a forecast. Nothing else about you is sent, and nothing is sent when the weather widget is switched off. See 2.22.
6.4 Apple
If you sign in with Apple, Apple provides us with a user identifier and, at your choice, your name and email address or a private relay address. If you subscribe through the App Store, we exchange purchase receipts and subscription status with Apple, and Apple sends server notifications about your subscription directly to our endpoint. See 2.1 and 2.13.
More information: Apple Privacy Policy
6.5 Mistral AI (Event Card Scan, Receipt Scan and Recipe Import)
Mistral AI SAS, 15 Rue des Halles, 75001 Paris, France, acts as our sub-processor for OCR and structured extraction in three Premium features that you start explicitly: the event card scan (2.18) sends a single photo; the receipt scan (2.19) sends a single photo together with your family's expense category names and IDs; the recipe import (2.20) sends the reduced text of the public recipe page you chose. Under our data processing agreement, processing takes place within the EU and Mistral does not retain this content for training. Nothing is sent to Mistral outside of these explicit user actions.
More information: Mistral AI Privacy Policy
6.6 Our Support Mailbox and Administration Tool
Support messages you send from the app are copied by email to our support mailbox, which is hosted by Google (Gmail). We read and answer tickets through an internal administration tool that we operate ourselves and that writes replies back into your ticket. See 2.23.
6.7 Legal Requirements
We may disclose your information if required to do so by law, or in the good faith belief that such action is necessary to comply with a legal obligation, protect our rights, prevent fraud, or protect the safety of users.
6.8 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of such a transaction.
7. Data Storage and Security
7.1 Cloud Storage
Your data is stored on Google Firebase servers (Cloud Firestore, Firebase Authentication, Firebase Storage). Data transfer is encrypted (HTTPS/TLS).
Server-side security measures:
- Firestore Security Rules restrict access to authenticated requests and family-scoped data
- Firebase Storage Rules allow only authenticated users to upload (size limit, image formats only)
- Firebase App Check protects against unauthorized API access
- Cloud Functions with rate limiting and spam protection
- Critical fields (familyId, isPremium, roles) can only be changed server-side via Cloud Functions
- Server-side validation and content size limits
7.2 Additional Field Encryption
Beyond transport encryption, some content is encrypted with AES-256-GCM before it is written to our database, using a key generated for your family:
- Calendar events: title, description and location
- Tasks: title and notes
- Comments on events and tasks: the comment text
This is not end-to-end encryption. The family key is generated and held on our servers so that new members and our server-side features can read the data; a copy is cached in your device's secure storage (Android Keystore, iOS Keychain). Expenses, budgets, recipes, meal plans, shopping lists, image attachments and support messages are not field-encrypted, and metadata such as dates, amounts, categories and assignments is not encrypted either.
7.3 Local Storage
Onboarding status, device calendar settings and app preferences are stored locally in SharedPreferences, protected by your operating system's security mechanisms.
7.4 Image Attachments
Images are compressed on your device and transferred encrypted (HTTPS) to Firebase Storage. Storage security rules ensure that only authenticated users can access them.
7.5 Your Responsibility
While we work to protect your information, no security system is impenetrable. You are responsible for safeguarding the credentials of the account you sign in with, and for deciding whom you invite into your family.
8. Data Retention and Deletion
- Account data is retained as long as your account exists.
- Family data (calendar, tasks, expenses, recipes, meal plans) is retained as long as the family exists. When a family is deleted, all associated data is removed.
- Calendar events, expenses, recipes and meal plans are never deleted automatically. They stay until you, another member of your family or the family owner deletes them, or until the account or family is deleted.
- Completed tasks are deleted automatically 90 days after you marked them as done, together with their comments and attached image. Open tasks are never deleted automatically.
- Images attached to one-off calendar events are removed automatically 3 years after the event took place. The event itself and its comments stay.
- Child accounts and members without an account are removed when the family is deleted, and a parent can delete them individually at any time.
- Invitations expire automatically after 7 days.
- Support conversations are kept as long as needed to handle the request; you can ask us to delete them, and their attachments are deleted immediately when you delete your account.
- Weather forecast caches expire after 3 hours.
- Purchase records are kept while the subscription is active and afterwards for as long as statutory retention periods require.
- Expired bonuses and free trials are cleared by a daily cleanup job.
- When you delete your account we immediately remove your entries, your comments, your uploaded images and your support attachments, and we remove your user ID from entries assigned to you.
9. Your Rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), and the right to object to processing based on our legitimate interests (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future (Art. 7 (3)).
You can delete your account and all of your data directly in the app, in Settings under Advanced settings, Delete account. The deletion is carried out immediately and cannot be undone. To exercise any other right, write to service@famino.app. We answer within one month.
You also have the right to lodge a complaint with a supervisory authority (Art. 77). The supervisory authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4
40213 Düsseldorf
Germany
www.ldi.nrw.de
You may also contact the supervisory authority of your own place of residence.
In addition, you can do the following directly in the app:
- Access and correction: view and edit your data in the App.
- Deletion of single records: delete individual entries in the App.
- Manage permissions: control camera, calendar, location and notification access in your device settings.
- Manage subscription: manage your subscription in the Google Play Store or the Apple App Store.
- Leave family: leave a family at any time, except as its owner.
- Disable device calendar: switch device calendar import off at any time in the App settings.
- Log out: log out from the App menu at any time.
10. Third-Party Services
- Google Firebase: Firebase Privacy and Security
- Google Sign-In: Google Privacy Policy
- Sign in with Apple: Apple Privacy Policy
- Google Play Billing and Apple In-App Purchase: payment processing for Premium subscriptions
- Google Maps Platform (Weather API, Geocoding API): weather forecast for the optional weather widget
- Google Gmail: our support mailbox
- Hostinger International Ltd. (Cyprus, EU): SMTP relay that delivers our transactional emails (verification, password reset, welcome); it processes the recipient address and the email content for delivery
- Mistral AI (France, EU): sub-processor for the event card scan, receipt scan and recipe import features, invoked only when you use them. Mistral AI Privacy Policy
11. Children
Famino is meant to be set up and run by an adult. A parent can create child accounts and members without an account for their own household. The parent chooses the name and any details and remains responsible for what they enter about their child.
We do not ask children for an email address, we do not let child accounts sign in on their own, and we never use children's data for advertising, for profiling, or for analytics beyond the family-size counter described in 2.15.
Where consent is the legal basis, EU law (Art. 8 GDPR) sets the age between 13 and 16 depending on the country. Below that age the parent must consent, which they do by creating the account. Outside the EU we apply 13 years (COPPA).
A parent can delete a child account or a family member at any time in the app, which erases that member's data. If you are a parent or guardian and believe that a child's information reached us without your knowledge, please contact us at service@famino.app.
12. International Data Transfers
Our Cloud Functions run in the European Union (region europe-west1). Our Firestore database runs in Google's European multi-region eur3 (Belgium and the Netherlands). Our file storage for uploaded images (Firebase Storage) is currently hosted by Google in the United States (region us-central1); we plan to move new uploads to an EU region and will update this policy when that is done. Our sub-processor Mistral AI processes the AI scan features within the EU.
Some of our providers are US companies whose support and infrastructure teams may access data from outside the EU. Transfers to Google LLC and Apple Inc. take place on the basis of the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework and, in addition, the Standard Contractual Clauses contained in our data processing agreements with them.
13. What We Do Not Do
- We do not sell your data.
- We show no advertising and use no advertising identifiers.
- We do not build behavioural profiles about you.
- We do not use your family content to train AI models.
- We do not use your location for anything other than the weather widget you switched on.
- We do not ask for your date of birth.
14. Reporting Content
If someone in a family you belong to uploads an image or writes a comment that does not belong there, contact us at service@famino.app. We will look into it and can remove content and, where necessary, accounts. You can also remove a member from your family yourself if you are its owner, and you can leave a family at any time.
15. This Website
This section covers famino.app itself, not the App.
- Language choice: We store the language you pick in your browser under the key
faminoLang. This is strictly necessary to show the site in the language you chose and is not used for tracking.
- No analytics: We use no analytics, no tracking pixels and no advertising cookies on this website.
- Hosting: The site is hosted on Firebase Hosting, which keeps standard server access logs (including IP address) for operation and security. Legal basis: Art. 6 (1) (f) GDPR.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date at the top of this policy and, in some cases, by showing a notice inside the App.