Privacy Policy
Effective September 23, 2026
FamilyDash (“FamilyDash,” “we,” “us”) is a shared family dashboard for chores, calendars, groceries, and meals. This policy explains what we collect, why, and the choices you have. Plain English; no dark patterns.
1. What we collect
When you sign up and use FamilyDash, we collect:
- Account info — your name and email address (from Google sign-in, Sign in with Apple, or magic-link sign-in via email).
- Household data you create — household name, member names and roles (parent / adult / child), child PINs, chores and chore completions, allowance and rewards, grocery items, meal plans, and saved recipes.
- Calendar feed URLs — when you connect an Apple, Outlook, or other calendar by ICS link, we store the feed URL and cache events from it.
- Google Calendar (opt-in, optional) — if you choose to connect your Google Calendar via the “Connect Google Calendar” button, we request the
calendar.readonlyscope and store an OAuth refresh token on our servers (encrypted at rest in Supabase). We use this to list your Google calendars (so you can pick which to display) and to read events from the calendar(s) you select, then mirror them read-only into your FamilyDash dashboard. We never create, modify, or delete events in your Google Calendar. You can disconnect at any time from FamilyDash Settings, or by revoking access in your Google Account — the refresh token is deleted on disconnect. See the “Google user data” section below for our Limited Use commitment. - Location for weather— the city you pick at sign-up, stored as a latitude/longitude, a timezone, and a label such as “Taunton, England, GB”. We use it for local weather, to show times in your timezone, and to choose sensible defaults for your region (temperature units, 12- or 24-hour clock, the first day of the week, and the currency your chore rewards are shown in). Just the city; never a street address.
- Third-party connections you authorize — Stripe customer and subscription identifiers (when you subscribe to FamilyDash Pro on the web), App Store subscription identifiers via RevenueCat (when you subscribe in the iOS app), and Kroger OAuth tokens for the small number of households that connected a Kroger account before that integration was withdrawn.
- Push notification subscription — if you enable reminders, we store the browser push endpoint or Apple push token for that device.
- Usage events— first-party analytics like which features you used and when, used to improve the product. Recorded by our own servers, tied to your account, and never shared with an advertising network — with one exception on the website, described under “Ad measurement” in section 2: we tell Meta when a new household signs up or starts a free trial. We do not sell this data.
- Recipe images you upload — when you scan a recipe from a photo or social media link, the image is sent to OpenAI for text extraction and is not retained beyond the request.
- Emails you forward for calendar import (Pro, opt-in)— if you forward an email to your household’s FamilyDash import address, its text is sent to OpenAI to extract the event and then discarded; only the extracted event is kept.
- Voice conversations (Ask FamilyDash) — when an adult in your household presses the microphone, audio from that device is streamed to OpenAI for the length of the conversation so it can understand the request and reply, and a text transcript of the exchange is sent to OpenAI to decide which action to take (for example, adding a grocery item or an event). FamilyDash does not store recordings or transcripts of these conversations; we keep only how long each conversation lasted and the names of the actions it performed. The microphone is on only during a conversation you start and turns off when it ends, and anyone speaking near the device during that time may be captured. Only adult accounts can start a conversation; kid sign-ins never see the microphone.
2. How we use it
- To provide the FamilyDash service to you and your household.
- To sync your calendar feeds, weather, and grocery integrations.
- To send push notifications and event reminders you opt into.
- To process subscription payments (via Stripe or the App Store).
- To improve the product and understand which features are valuable.
- To detect abuse and protect the service.
We do not sell your personal information. We do not run third-party advertising networks inside FamilyDash.
Advertising audiences. To keep FamilyDash’s own ads away from people who already use it, and to find households like yours, we may share a hashed (one-way scrambled) copy of your email address with the advertising platforms we advertise on — Meta, Pinterest, and Google. They match it against their own accounts; they never receive your name, your household’s content, or how you use FamilyDash. We do this only for adult accounts in the United States and Canada, never for children, and you can turn it off at any time under Settings → Advertising audiencesor by unsubscribing from our product emails. Under California law this may count as “sharing” personal information for cross-context behavioral advertising; that same switch is your opt-out.
Ad measurement. When you sign up or start a free trial on the website, we tell Meta that it happened, so our ads there can learn which ones bring families to FamilyDash. The report comes from the Meta pixel in your browser and from our own server, and contains a hashed copy of your email address, your country, your browser’s IP address and user agent, and Meta’s own cookie identifiers if your browser has them — never your name, your household’s content, or anything you do in FamilyDash after that. It covers adults signing up on the website in the United States and Canada only: never the iOS app, never children, never visitors from the EU/EEA, the UK, or Switzerland. The Advertising audiences switch turns it off too.
3. Children’s data
FamilyDash is designed for parents to share with their children inside their own household. Parents create child profiles and assign PIN-based access. We collect only the data you, as the parent, choose to enter — typically a child’s first name, age (optional), and chore/allowance activity. We do not collect any data directly from children outside the household account a parent controls; a child profile has no email address and cannot create an account of its own. Parents can delete a child profile at any time from Settings.
FamilyDash is not directed to children under 13 as standalone users. The service is intended for use under the supervision of a parent or guardian who has agreed to these terms.
4. Service providers we share data with
We use the following providers to operate FamilyDash. Each receives only the data needed for its function:
- Vercel — application hosting, and cookieless page analytics and performance measurement (Vercel Analytics and Speed Insights).
- Supabase — database and storage.
- Google — sign-in (OAuth), and (if you opt in) Google Calendar API read-only access via the
calendar.readonlyscope for the Family Calendar feature. See the “Google user data” section below. - Apple — Sign in with Apple, push notifications to the iOS app, and App Store subscriptions (with RevenueCat, which tells us whether an App Store subscription is active).
- Resend — sign-in and service emails (magic links, the daily digest if you turn it on, invitations).
- Stripe — subscription billing on the web. We never see or store your full card number.
- Meta, Pinterest, and Google Ads— advertising platforms that receive a hashed email address for audience matching, as described in section 2, unless you opt out. Meta also receives the sign-up and trial reports described under “Ad measurement” in section 2. Nothing else about you is sent to them.
- OpenAI— recipe scanning from images and links, event extraction from forwarded emails, and the Ask FamilyDash voice assistant (live audio and transcripts, for the duration of a conversation). Per OpenAI’s API terms, content sent through the API is not used to train their models.
- Cloudflare — receives the emails you forward for calendar import and hands them to our servers.
- Instacart— only when you press “Shop on Instacart”: the items on your grocery list are sent to Instacart to build your shopping link. Instacart does not tell us what you bought. Available in the US and Canada only.
- Impact.com — reports Instacart affiliate orders to us in aggregate. It receives no personal data from FamilyDash; there is no tracking pixel.
- Kroger — only for households that connected a Kroger account before the integration was withdrawn; those tokens are held until deleted and are not used.
- OpenWeatherMap and Open-Meteo — weather data and city lookup. We send only the lat/lon or city name you configured.
- Photon (komoot, OpenStreetMap data) — city lookup when Open-Meteo has no match for the town you type. We send only the search text, from our server.
- Google Analytics, the Pinterest tag, and the Meta pixel — site analytics and ad measurement, on the web only. Never loaded inside the iOS app, and never loaded for visitors in the EU/EEA, the UK, or Switzerland. See the next section.
5. Cookies, analytics, and similar technologies
Strictly necessary.A session cookie keeps you signed in, and a separate one keeps a child’s PIN sign-in. Your browser’s local storage holds per-device preferences you set yourself — theme, text size, card layout, calendar view, and the board lock — plus a one-line note of whether analytics may load in your region. None of these identify you to anyone else.
First-party analytics. Our own servers record the usage events described in section 1, tied to your account. Vercel Analytics and Speed Insights measure page views and load times without cookies or cross-site identifiers.
Marketing measurement. On the website (not in the iOS app) we load Google Analytics, the Pinterest tag, and the Meta pixel so we can tell which of our ads and pages bring families to FamilyDash, and we set a first-touch attribution cookie (fd_attr, 30 days) recording the campaign or referring site that brought you here. That cookie is deleted the moment you finish signing up; the campaign it names is stored against your household so we can see which marketing works.
If you are visiting from the EU, the EEA, the UK, or Switzerland, we do not load Google Analytics, the Pinterest tag, or the Meta pixel, we do not send Meta sign-up or trial reports, and we do not set the attribution cookie. We decide that from the country your connection comes from, before any of them can run. The only cookies you will see are the strictly necessary ones, which is why FamilyDash has no cookie banner. The native iOS app never loads any third-party analytics or advertising trackers anywhere.
6. Google user data (Limited Use)
FamilyDash’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data we obtain through the https://www.googleapis.com/auth/calendar.readonly scope (the list of your Google calendars and the events in the calendars you choose to display) is used only to render your Google Calendar events inside the FamilyDash family dashboard. We do not transfer this data to anyone else except as needed to provide that feature (e.g. to our database host, Supabase, for the cache), and we do not transfer it to any third-party advertising or analytics service. We do not use this data for advertising. We do not use it to develop, improve, or train generalized AI / ML models. We do not allow humans to read your calendar data except (a) with your explicit consent for a specific purpose (such as troubleshooting), (b) for security investigations or to comply with applicable law, or (c) where the data has been aggregated and anonymized for internal operations.
You can revoke FamilyDash’s access to your Google Calendar at any time from your Google Account’s Third-party apps with account access page, or by disconnecting the calendar from FamilyDash Settings. Either action causes us to delete the stored OAuth refresh token and stop syncing events.
7. Data retention and deletion
We retain your data for as long as your account is active. You can delete your household and account at any time from Settings, or by emailing us at the address below. When you delete your account, we remove your data from our production database within 30 days. Encrypted backups are rotated within 90 days.
8. Security
We use TLS in transit, encrypted-at-rest databases, role-scoped access keys, and per-household data isolation. No system is perfectly secure; if we ever learn of a breach affecting your data, we will notify you promptly.
9. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to opt out of certain processing. You can exercise most of these rights from Settings, or by contacting us. The advertising-audience opt-out in section 2 is a switch in Settings, and a request by email works just as well. If you are in the EU, the EEA, the UK, or Switzerland, section 11 sets out your rights in full.
10. International users
FamilyDash is operated from the United States, and the providers in section 4 store and process your data there. If you use FamilyDash from outside the US, your data will be transferred to and processed in the US. Section 11 explains the safeguards for that transfer if you are in the EU, the EEA, the UK, or Switzerland.
11. If you are in the EU, the EEA, the UK, or Switzerland
Who is responsible. FamilyDash is a sole proprietorship operated by its founder from La Vista, Nebraska, USA, and is the controller of your personal data under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection. Contact us at the address in section 13 for anything in this section.
Why we may process your data. We rely on the following legal bases:
- Performance of a contract— everything needed to run your household’s dashboard: your account, the household data you enter, calendar syncing, weather for your city, reminders, and billing.
- Consent — the optional connections you switch on yourself: Google Calendar access, push notifications, forwarding emails for import, the voice assistant, and any marketing email. You can withdraw consent at any time by disconnecting the feature in Settings or using the unsubscribe link, without affecting the rest of the service.
- Legitimate interests — the first-party usage events we use to understand and improve the product, keeping the service secure and detecting abuse, and sending service messages about your account. We do not use these interests in a way that overrides your rights, and you may object (below).
- Legal obligation — keeping billing and tax records for as long as the law requires.
Your rights. You have the right to access the personal data we hold about you, to have it corrected, to have it erased (deleting your account from Settingsdoes this), to receive a copy in a portable format, to restrict or object to processing based on our legitimate interests, and to withdraw consent. Email us and we will respond within one month. You also have the right to lodge a complaint with your data protection authority: in the EU or EEA, the supervisory authority of the country where you live; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner.
International transfers.Your data is stored and processed in the United States by the providers listed in section 4. Where a provider is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, we rely on that certification; otherwise we rely on the European Commission’s standard contractual clauses (and the UK addendum) that the provider commits to in its data processing terms.
Children.We do not offer accounts to children. A parent creates and controls each child profile, decides what is entered about the child, and can delete it at any time. We do not rely on a child’s consent for anything.
Advertising audiences. The hashed-email audience matching described in section 2 is not done for accounts in these regions.
Cookies and automated decisions. As set out in section 5, we load no third-party analytics or advertising trackers and set no marketing cookies for visitors from these regions, so nothing on FamilyDash requires your consent before it runs. We make no decisions about you by automated means that have legal or similarly significant effects.
12. Changes to this policy
If we make material changes, we will update the effective date above and notify you in-app or by email. Continued use of FamilyDash after the changes means you accept the updated policy.
13. Contact
Questions, requests, or deletion: familydashapp@gmail.com.