Privacy Policy
What We Collect & Why
FamGlow collects the minimum information required to provide a personalized family display experience. The table below is a complete inventory of every category of personal data we collect, what we use it for, and whether it is stored in our database.
| Category | What we collect | Why we collect it |
|---|---|---|
| Account | Name and email address, provided via Google or Apple sign-in. If you sign in with Apple and choose "Hide My Email," we receive the private relay address Apple generates instead of your real email. | Authentication and account identification only |
| Family profile | Family name, timezone | Personalizing your display and formatting dates and times correctly |
| Kids | First name, and birth day and month only — never the birth year, so we cannot determine a child's age. No last name, no email address. | Personalizing kids' schedule display, birthday reminders, and school calendar matching |
| School information | School name and school district (if provided) | Used in our AI school calendar parsing feature to identify and extract relevant schedules |
| Location | Latitude and longitude (city-level, set by you) | Powering your weather widget via OpenWeatherMap. Stored in database. |
| Calendar events | Event titles, dates, times, locations, and descriptions from calendars you connect (Google, Apple, or subscription links) | Displaying your family calendar. Events are cached temporarily to keep your display fast (see Section 2). Descriptions are additionally used for AI trip insight generation (see Section 6). |
| Voice clips | A short audio recording, only when you actively use a voice feature (asking a question aloud, voice-adding shopping items, or speaking a photo caption) | Transcribed by our AI provider, then discarded. Voice audio is never stored (see Section 6). |
| Push notification token | A device registration token issued by your platform's push service (Google Firebase Cloud Messaging / Apple Push Notification service) | Delivering the notifications you enable. Deleted when you sign out or delete your account. |
| Family photos | Images you upload for your display background or photo slideshow | Displaying on your wall screen. Processed on-device before upload — we receive the processed image, not access to your camera roll. Never sent to any AI provider. |
| Document scans | Photos or PDFs of schedules, flyers, and calendars you choose to scan | Extracting activities, dates, fees, and supply lists via AI (see Section 6). The image itself is never stored — it is discarded as soon as extraction completes. Only the extracted text is saved. |
| Sports preferences | Favorite team, sport, and league | Powering your sports scores widget |
| News preferences | Selected news topics | Personalizing your news headlines widget |
| School calendar | URL or PDF you provide for school schedule import | Parsing into your kids' activity schedule via AI (see Section 6) |
| AI outputs | Generated trip insights, sports summaries, and parsed school schedules | Stored after generation to avoid unnecessary repeat AI calls. Deleted when you delete the associated data or close your account. |
| In-app analytics | Product usage events — page and feature name, feature interactions, activation milestones (e.g., connecting a calendar), timestamp, device type, and screen size, with limited non-sensitive event metadata. Stored in FamGlow's own database and linked only to your family account. | Understanding which features families use and where setup succeeds or stalls, so we can improve the product. Accessible to FamGlow admins only. Not shared with any third party and not used for advertising. |
| Diagnostic & error logs | When an operation fails, we record the name of the operation, an error message, technical error context, and a timestamp. This may incidentally include fragments of the data being processed at the moment of failure. | Detecting, diagnosing, and fixing bugs and outages (operational reliability). Accessible to FamGlow admins only. Never shared with third parties and never used for advertising. |
| Session tokens | Authentication token stored in browser local storage, mirrored to a cookie for iOS PWA compatibility | Keeping you signed in. Contains no personal data beyond a session identifier. |
| Device sessions | Display name you assign (e.g., "Living Room iPad") and per-device heartbeat timestamps | Letting you view and sign out individual devices from Settings, and enforcing display limits on your subscription plan |
| Subscription | Subscription tier and billing status (via Stripe) | Enforcing plan limits and processing payments. FamGlow never sees or stores your card details — these go directly to Stripe. |
| Server log data | IP address, browser type, and device type (collected automatically by our hosting infrastructure, Vercel) | Security monitoring and operational purposes only — not linked to your personal profile and not used for advertising or third-party analytics |
Calendar Access
Connecting your calendars (Google Calendar, Apple Calendar, or calendar subscription links) to FamGlow is optional. When you choose to connect one, we request access to read your calendar events. We use this access solely to display your upcoming events on your family wall display and phone app.
What we access: Event titles, dates, times, locations, descriptions, and attendee information from calendars you select. We do not access your contacts, Gmail, Google Drive, Google Photos, or any other Google service.
How it works: Google Calendar events are fetched live from Google's API and cached briefly (up to about 36 hours) so your display stays fast; Apple Calendar events are synced and stored while the connection is active. Cached and synced events are refreshed continuously and removed when you disconnect the calendar.
Attendee information: When an invitation on your calendar lists attendees, we compare those attendee details against your own family's profiles in memory, only to label the event with the right family member. Raw attendee names and email addresses are never stored — only the resulting family-member label is saved.
Disconnecting: You can disconnect your Google Calendar at any time from your FamGlow settings. Disconnecting immediately revokes FamGlow's access token. You can also revoke access directly from your Google Account at myaccount.google.com/permissions.
Children's Privacy
FamGlow is a family display tool designed for parents and caregivers to manage on behalf of their household. Children view the display but do not create accounts, enter data, or interact with FamGlow's services directly.
Age requirement: FamGlow requires users to be 18 years of age or older to create an account. By creating an account, you confirm that you are at least 18 years old.
What we collect about children: First name, and birth day and month — never the birth year. Because we do not store the year, FamGlow cannot determine a child's age. We do not collect last name, email address, or any other personally identifiable information about children.
School information: When a parent connects a school calendar or enters school name and district, this information is used to parse school schedules via our AI feature (see Section 6). School name and district are sent to our AI providers as part of this request. A child's name is never included in any AI call — names are replaced with placeholders before the request is sent.
COPPA: FamGlow is directed to adults (parents and caregivers) and is not intended for children under 13 to use independently. If you believe we have inadvertently collected information about a child without parental consent, please contact us at privacy@famglow.com and we will delete it promptly.
Photos
FamGlow handles two different kinds of images, and treats them very differently. Family photos are the pictures you display on your screen. Document scans are photos of schedules, flyers, and calendars you ask us to read.
Family photos
On-device processing: Photo selection and any initial processing occurs on your device before upload. We receive the processed image — we do not request access to your camera roll, photo library, or any photos beyond the specific images you choose to upload.
No facial recognition: FamGlow does not perform facial geometry analysis, facial recognition, or any form of biometric processing on photos. We do not collect biometric identifiers of any kind.
Storage: Uploaded family photos are stored securely in a private Cloudflare R2 storage bucket and displayed on your wall screen. Photos are deleted when you remove them from the app or when you close your account.
Document scans
When you photograph a schedule, flyer, or school calendar and ask FamGlow to read it, that image is sent to our AI provider to extract the activities, dates, times, fees, and supply lists it contains (see Section 6).
Never stored: Document scan images are processed and discarded. We do not save them to our database or file storage, and neither does our AI provider — these requests are sent with zero-retention enabled. Only the extracted information (for example, "Swim Lessons, Mondays and Wednesdays, starts August 31") is saved to your account, after you review and confirm it.
You review before anything is saved: Extracted events are shown to you as a draft. Nothing is added to your calendar until you confirm it.
No sharing: Neither family photos nor document scans are ever sold, shared with advertisers, used to train AI models, or accessed by FamGlow employees except in cases of a technical support request where you have explicitly granted access.
Location Data
FamGlow uses your location to display accurate weather information on your wall display. Location is set manually by you — FamGlow does not request GPS or device location permissions.
What we store: Latitude and longitude coordinates at approximately city-level precision, as entered or confirmed by you during setup.
How it is used: Your coordinates are sent to OpenWeatherMap to retrieve current weather and forecasts. OpenWeatherMap receives your coordinates and is bound by their privacy policy. Your location is not shared with any other third party.
Changing your location: You can update or remove your location at any time from your FamGlow settings. Removing it disables the weather widget.
AI Features
FamGlow uses AI to power a few specific features that add value beyond what a simple calendar or display can provide. AI use is limited to the features listed below, is rate-limited and cached, and we never use your data to train or improve AI models.
We minimize what we send. Children's names are replaced with placeholders (for example, "kid_1") before any AI request, and are never included in an AI call. Requests are sent with zero-retention enabled, meaning our AI providers do not store them.
The table below documents every AI-powered feature in FamGlow, what data is sent, which provider processes it, and how the output is stored.
| Feature | What triggers it | Data sent | Provider | Output stored? |
|---|---|---|---|---|
| Trip insights | You tap "Generate insight" on a detected trip event | Calendar event title, dates, times, and description for the specific trip event | Perplexity | Yes — stored until you delete the trip or close your account |
| Sports summary | Sports widget loads for a team with no cached data (cold start only) | Team name, sport, league — no personal data | Perplexity | Yes — cached for 24 hours, then automatically expires |
| School schedule parsing | You import a school calendar URL or PDF | School name, school district, and the URL or PDF content you provided | Perplexity | Yes — parsed schedule stored as kids' activities until you delete them or disconnect |
| Schedule & flyer scanning | You photograph a schedule, flyer, or calendar and tap scan | The image you scanned. No names — children's names are replaced with placeholders before the request. | Google (Gemini), via Vercel AI Gateway | The image is never stored. Extracted events are saved only after you review and confirm them. |
| Schedule questions ("Ask") | You ask a question about your family's schedule, typed or spoken | Your question and the matching schedule records — with family members' names replaced by placeholders. The answer itself is computed by FamGlow's own scheduling engine; AI only words it. | Anthropic (Claude), via Vercel AI Gateway | No — answers are shown to you and not stored |
| Voice transcription | You actively use a voice feature (tap the microphone, or speak after the optional wake word) | The short audio clip of what you said — nothing else. No names or account details accompany the audio. | Google (Gemini), via Vercel AI Gateway | No — the clip is transcribed and immediately discarded. Voice audio is never stored by FamGlow or the provider. |
| Trip itineraries | You tap "Plan this trip" on a trip | The trip's destination, dates, and travel style — no family member names | Anthropic (Claude), via Vercel AI Gateway; every place the AI names is verified against OpenStreetMap before being shown | Yes — cached until the trip changes or you delete it |
Our AI subprocessors: AI requests are processed by Anthropic, Google, and Perplexity AI under their respective API terms. Requests to Anthropic and Google are routed through the Vercel AI Gateway with zero data retention enabled, meaning the provider does not store them. Under our API agreements, data sent for inference is not used to train their models.
Spoken answers are generated on your device. When FamGlow reads an answer aloud, the voice is synthesized entirely by your device's built-in speech engine. Producing the spoken answer sends nothing to FamGlow or any AI provider, and no additional data is collected. You can turn spoken answers off for any device in Settings → Voice & microphone.
Asking through Siri (iOS). If you ask FamGlow a question through Siri ("Hey Siri, ask FamGlow…"), your voice is captured and transcribed by Apple's Siri — not by FamGlow, and not by the AI providers above. Apple's handling of Siri audio is governed by Apple's privacy policy. FamGlow receives only the text of your request, answers it exactly as described in the "Schedule questions (Ask)" row above, and returns the answer as text for Siri to display and speak on your device. FamGlow never receives, stores, or transmits Siri audio.
When AI runs: AI features are triggered by your actions, or run on a schedule you have turned on in Settings. We never generate AI content for a feature you have not enabled, and you can turn any scheduled AI feature off at any time. Every AI-powered feature is listed in the table above — FamGlow does not use AI for profiling, advertising, or any purpose beyond those listed features.
Third-Party Services
FamGlow relies on a small number of trusted third-party services to operate. Each is listed below with the data they receive and why.
| Provider | Role | Data they receive | Their privacy policy |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Your account identity and all family data you create in FamGlow, so we can store and secure it (US region). | supabase.com/privacy |
| Vercel | Website hosting, application functions, scheduled jobs, and AI request routing (AI Gateway) | Standard request metadata (timestamps, status codes, durations) to serve and operate the app. AI requests — including document scans — are routed through Vercel's AI Gateway to reach our AI providers; Vercel does not store their content. | vercel.com/legal/privacy-policy |
| OAuth sign-in, Calendar API access, AI inference (Gemini), and push notification delivery (Firebase Cloud Messaging) | Name and email (sign-in); calendar events from calendars you choose to connect; document scans and voice clips for AI features (see Section 6) — with children's names replaced by placeholders; a device push token for notification delivery | policies.google.com/privacy | |
| Apple | Sign in with Apple, push notification delivery on Apple devices, and Siri request handling on iOS — Siri passes FamGlow only the text of your request | Sign-in authentication only. Apple tells us your name and email (or a private relay address if you choose "Hide My Email") — we receive no other Apple account data. Siri asks arrive as text only. | apple.com/legal/privacy |
| Anthropic | AI inference for schedule questions and trip itineraries (Claude models, via Vercel AI Gateway) | Pseudonymized schedule questions and trip planning requests as documented in Section 6 — no account identifiers, no family member names, zero data retention | anthropic.com/legal/privacy |
| Perplexity | AI inference for trip insights, sports summaries, and school schedule parsing | Data specific to each AI feature as documented in Section 6 — no account identifiers | perplexity.ai privacy policy |
| OpenStreetMap (Nominatim) | Geocoding for trip features — turning a destination name into map coordinates | The destination or place name being looked up — no account identifiers or personal data | osmfoundation.org privacy policy |
| Cloudflare | Private object storage for family photos (Cloudflare R2) | The photo image files you upload, stored in a private bucket and served to your display via short-lived signed links. | cloudflare.com/privacypolicy |
| Resend | Transactional email (alerts and notifications) | Recipient email address and message content for the emails we send you. | resend.com/legal/privacy-policy |
| Stripe | Payment processing (if/when paid plans are active) | Your payment details (card number, billing address). FamGlow never sees or stores your card data — it goes directly to Stripe. | stripe.com/privacy |
| OpenWeatherMap | Weather data | Your latitude and longitude (see Section 5) | openweathermap.org/privacy-policy |
| Highlightly | Live sports scores and schedules | The team, sport, and league you follow — no personal or account data | highlightly.net |
| Unsplash | Background photography | API requests only — no personal data sent. Photo URLs are retrieved and displayed. | unsplash.com/privacy |
We do not use advertising networks, behavioral analytics platforms, marketing automation tools, or data brokers. FamGlow does not sell your information to any third party and does not share it with any party not listed above.
Data Security
We take reasonable and appropriate measures to protect your personal information from unauthorized access, loss, misuse, alteration, or destruction.
Encryption in transit: All data transmitted between your device and FamGlow's servers is encrypted using TLS (Transport Layer Security).
Encryption at rest: Your data is stored on Supabase's infrastructure, which uses industry-standard encryption at rest. Authentication tokens are handled via secure cookies where possible.
Access controls: FamGlow enforces family-level data isolation at the database query level. No user can access another family's data. Internal access to production data is restricted to essential operations only.
Third-party security: Our subprocessors (Supabase, Vercel, Cloudflare, Google, Apple, Anthropic, Perplexity, Resend, Stripe, OpenWeatherMap, OpenStreetMap, Unsplash) maintain their own security programs appropriate to their role. Stripe is PCI-DSS certified for payment processing.
Vulnerability reporting: If you discover a security vulnerability in FamGlow, please report it responsibly by emailing privacy@famglow.com. We will acknowledge your report within 48 hours and work to resolve confirmed issues promptly.
Data breach notification: In the event of a security breach affecting your personal information, we will notify affected users within 72 hours of becoming aware of the breach. Notification will be sent to the email address on your account and, where required by applicable law, to relevant regulatory authorities.
Cookies & Technical Data
FamGlow uses a minimal set of technical mechanisms to keep you signed in and the app functioning correctly. We do not use advertising cookies, tracking pixels, or third-party behavioral analytics tools.
Authentication: When you sign in, we store an authentication token in your browser's local storage. On iOS PWA installations, this token is also mirrored to a strictly-necessary browser cookie solely to maintain your session across app restarts. This cookie contains no personal data beyond a session identifier, is not used for tracking, and is deleted when you sign out.
In-app analytics: FamGlow records product usage events within the app — the pages and features you use, key interactions, and activation milestones such as connecting a calendar — along with timestamps, device type, screen size, and limited non-sensitive metadata about each event. This data is stored directly in FamGlow's own database — it does not use cookies, third-party pixels, or external analytics services. It is used exclusively by FamGlow admins to understand feature usage and improve the product, and is never shared with any third party or used for advertising.
Diagnostic & error telemetry: When something goes wrong in the app, FamGlow automatically records technical diagnostic data — the operation that failed, an error message, technical context about the failure, and a timestamp — to help us detect, diagnose, and fix bugs and outages. This may incidentally include fragments of the data being processed at the moment of failure. Diagnostic logs are stored in FamGlow's own database, are accessible to FamGlow admins only, and are never shared with any third party or used for advertising.
Performance & boot diagnostics: To diagnose intermittent problems and measure how quickly the app loads, FamGlow records technical traces of the app's startup sequence — which internal operations ran, their timing, status and error codes, and retry counts. These traces are designed to contain no personal information: no names, email addresses, family members' names, calendar or activity details, or photos. They capture only structural and numerical signals — for example, “a data request was rate-limited, retried, and returned 5 records.” Any family identifier is stored only as an irreversible cryptographic (hashed) value. These performance traces are stored in FamGlow's own database (Supabase), are used solely for debugging and aggregate performance analysis, are never sold or shared for any other purpose, and are retained for 30 days.
Server log data: Our hosting infrastructure (Vercel) automatically collects standard server log data when you use the app, including your IP address, browser type, device type, and pages accessed. This data is used for security monitoring and operational purposes only and is not linked to your personal profile or used for advertising.
Your Rights
Regardless of where you live, you have the following rights with respect to your personal information held by FamGlow.
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may update or correct inaccurate information directly in your FamGlow account settings, or by contacting us.
- Deletion: You may request that we delete your personal data. You can delete your account from your FamGlow settings, which triggers deletion of all associated personal data within 7 days (see Section 11 for backup retention details).
- Portability: You may request a copy of your data in a structured, machine-readable format.
- Objection: You may object to certain processing of your personal data. Because FamGlow does not engage in marketing profiling or behavioral advertising, there is limited scope for this right — but we will honour any reasonable objection.
- Withdrawal of consent: Where processing is based on your consent (such as Google Calendar access), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that occurred prior to withdrawal.
- Device sign-out: You can view all devices where FamGlow is signed in and end any session remotely from Settings → Sessions.
To exercise any of these rights, email privacy@famglow.com. We will respond within 30 days. For account deletion and data export requests, we may verify your identity by sending a confirmation to the email address on your account before processing your request.
California residents (CCPA): If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising your rights. To exercise these rights, email privacy@famglow.com.
Data Retention
We retain your personal data only for as long as necessary to provide the service and as required by law.
While your account is active: We retain all data associated with your account — including family profile, kids' names, schedule data, preferences, AI outputs, and uploaded photos — for the duration of your account.
Calendar events: Retained only as a short-lived cache. Google Calendar events are fetched live and cached for up to about 36 hours; Apple Calendar events are synced and stored while the connection is active. Cached and synced events are removed when you disconnect the calendar or close your account. AI-generated trip insights derived from event descriptions are stored until you delete them or close your account.
Voice clips and document scans: Never retained. Voice audio is transcribed and immediately discarded; scanned document images are processed for extraction and immediately discarded. Only the resulting text you confirm is saved.
Sports cache: AI-generated sports summaries are cached for 24 hours, then automatically deleted.
In-app analytics: Product usage events and session data are retained for up to 90 days, after which they are automatically purged.
Diagnostic & error logs: Technical error and diagnostic logs are retained for up to 90 days, after which they are automatically purged.
When you delete your account, all personal data is permanently removed from our active systems within 7 days. Residual copies in encrypted backup systems may persist for up to 30 days before being automatically overwritten as part of our standard backup rotation. Aggregated, non-identifiable operational data (e.g., total number of active families) may be retained indefinitely.
Changes to This Policy
We may update this Privacy Policy at any time as FamGlow evolves. When we make changes, we will:
- Update the effective date at the top of this page
- Notify you of material changes that affect how your data is used — by email (at the address on your account), an in-app notification, or an in-app prompt to accept the updated policy
Continuing to use FamGlow after changes take effect constitutes your acceptance of the updated policy. If you do not agree with the changes, you may stop using FamGlow and delete your account at any time.
Business transfers: If FamGlow or its assets are acquired by or merged with another company, your personal data may be transferred as part of that transaction. We will notify you by email or in-app notification before your data becomes subject to a different privacy policy, and you will have the option to delete your account before any transfer takes effect.
Governing law: This Privacy Policy and any disputes arising from it are governed by the laws of the State of New Mexico, United States, without regard to conflict of law provisions.
Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
FamGlow LLC
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110
United States