FamilyLoop

Privacy Policy

Effective August 4, 2026 · version 2026-08-04

What we store

Account details (username, display name, email, a hashed password), your family's content (events, event schedules, lists, dates, photos and their thumbnails), notification and reminder preferences, push subscriptions, session tokens, and operational logs. When guests interact with something your family shared — RSVPing to an event or claiming a checklist item, or adding a photo to a shared album — we store the name they enter, their response or photo, and the email address they optionally provide; photo uploads from guests also store a hashed removal token so only their device can take the photo back. When anyone downloads a full-quality photo from a shared album, we record it in an audit log your family can rely on (who, when, and shortened, hashed network details — never a raw address). We also keep a short-lived log of the transactional emails we send (recipient, subject, and whether delivery succeeded) so organizers can confirm invitations and reminders went out. If a member uses an AI-assisted feature like reading a schedule photo, we keep a usage record — who used it, when, and how much processing it took — but never the photo itself. Photos are stored in our cloud storage; everything else lives in our database.

What we don't do

We don't sell your data, share it with advertisers, mine it for marketing, or use your family's content to train anything. There are no ads and no third-party analytics in the app. Your data exists to run your family's organizer — nothing else.

Privacy modes, and where each applies

Every family chooses a custody mode for its photos. In managedmode, your family's encryption key is held by us so your account is always recoverable. In zero-knowledge mode, the key is derived from your family passphrase in your browser and never sent to us; we store only wrapped (encrypted) copies we cannot open. In zero-knowledge mode we cannot read your protected photos and cannot recover them if your passphrase and recovery code are lost.

Calendar events, schedules, lists, and invitations work differently in both modes: our servers process that content, because the features depend on it. We read event details to build the invitations we email, list items to send the reminders you set, and responses to show your family who's coming and what's still needed. Guests without accounts can view what you share with them through secure links, which also requires the server to read that content. This is the same boundary drawn by other privacy-focused products: collaboration features that reach outside the app cannot be end-to-end encrypted. We protect this content instead with encryption in transit and at rest, strict family-by-family isolation that we test on every release, and the retention and deletion promises below. The family owner can change photo custody modes in Settings; every change requires explicit confirmation and is recorded where you can see it.

Photo metadata

Photos often carry hidden metadata from your camera, like the date taken and sometimes the location. We keep that metadata with your stored originals so features like photo timelines work, and it never leaves your family: every copy served to anyone — album views, thumbnails, and full-quality downloads alike — is re-encoded with that metadata removed. Full-quality downloads are off by default, are only available at all if your family turns them on for an album, and every one is recorded in the audit log described above.

Schedule photos you ask us to read

The calendar import can read a photo of a schedule — a fridge flyer, a practice list, a school calendar — and turn it into events for your review. This only happens when a member chooses it for a specific photo. The photo is processed by an AI reader running inside our own private cloud environment under enterprise privacy terms: it is not used to train any model and is not shared beyond that single processing step. We use the photo only to extract the dates, we don't save it, and nothing goes on your calendar until you review and confirm the results. Family admins can see the usage record described above.

Guests without accounts

People you invite don't need a FamilyLoop account. When they RSVP or claim a checklist item, we store what they submit and show it to your family and to other guests of the same event (for example, "Claimed by the Johnsons"), so everyone can see what's covered. A guest who provides an email address chooses whether to receive event changes, cancellation notices, and reminders about items they claimed; they can change that choice or their response anytime through their personal link, and organizers can remove a guest's response. If your family sets an access code on a shared album, anyone you give the link and code can view that album and add photos to it; their additions become part of your family's album, count toward your storage, and can be removed by your family (or by the guest, from the device they uploaded with). Guest records are deleted with the event, album, or family they belong to.

Email

We send transactional email only: invites, RSVP links and confirmations, event notifications you've opted into, event and checklist reminders that you set (or that an organizer or family admin set for you — which you can always change or turn off yourself), reminders for birthdays and other dates you follow, digests you've enabled, password resets, and signup decisions. No marketing mail. Each send is recorded in the delivery log described above.

Cookies

Three cookies, all essential: a session cookie that keeps you signed in, a device cookie for paired wall displays, and — only after a guest enters an album access code — an album cookie that remembers the unlock on that device for 30 days. No tracking cookies.

Who can see what

Your content is visible to members of your family, to guests you explicitly share with (event invites, schedules and checklists attached to those events, shared albums, shared lists), and to paired displays your family admin set up. Albums come in two kinds: event albums, and keepsake albums attached to birthdays, school years, and other dates. If your family shares a dates list with another family, that family sees the dates — and, only if you also turn on album sharing for that list, its keepsake albums, which they can view and add photos to. Anyone holding an album link and its access code can do the same for that one album; people who got in with only a code see photos attributed to "Family" rather than your members' names. Turning sharing off or removing an album cuts off followers immediately; someone who entered a code may keep access on that device until the 30-day album cookie expires, so to fully revoke, clear the code too. Guests of the same event can see each other's response names and claimed items, but never your family's other content. Event owners and family admins can view the email delivery log for their events. The instance operator administers approvals and infrastructure; in managed mode the operator technically holds the key that protects your photos, and in zero-knowledge mode they do not.

Retention and deletion

Deleted photos first move to your family's trash, where any member can restore them for 30 days; after that they are permanently removed. A deleted family similarly has a short window in which its owner can restore it before it is permanently purged. Everything else you delete is removed from the live database immediately. Removed content then leaves backups as they expire on their retention schedule. Removing a family member removes their membership and content as described in the product. Deleting a family deletes its calendar, lists, photos, memberships, guest records, and email delivery logs; deleting an event deletes its guest records and delivery logs with it. Email delivery logs are also automatically deleted after 90 days regardless. Security and consent records may be retained after deletion as proof of what was agreed and when.

Your records

Your accepted terms, privacy policy versions, and any privacy-mode changes are recorded and visible to you in Settings under "Your agreements."

Changes

If this policy changes materially, we'll post the new version with a new version date and ask you to accept it where required.

Contact

Privacy questions or deletion requests: use the support page.