Privacy Policy
Last updated: draft, unpublished.
What we collect
| Data | Why | Kept for |
|---|---|---|
| Email address | Sign-in and account recovery | Until you delete your account |
| Precise location | To show your family where you are, while you have sharing on | 30 days |
| Device identifiers | To register the device and let you revoke it | Until you revoke it |
| Battery level, permission state | So your family can tell why a location may be old | With the location record |
| Saved places | Arrival and departure alerts you set up | Until you delete them |
| Access audit records | So you can see who viewed your location | 90 days |
When we collect location
Only when all of the following are true: you signed in, you joined a family, you turned location sharing on, and you granted the operating-system permission. If any one of those stops being true, collection stops.
The app collects in the background so your family can see you have arrived safely without you opening it. Sharing status is always visible in the app, and a live session shows an unmissable indicator to the person being located.
Who can see your location
Only members of a family you joined, and only while your sharing is on. Pausing sharing hides your position from everyone immediately. Leaving a family, or being removed, ends access at once.
We do not sell location data. We do not share it with advertisers or data brokers. We do not use it to build advertising profiles.
How it is protected
- Encrypted in transit with TLS.
- Coordinates are additionally encrypted by the application before storage, under keys held in AWS KMS.
- Precise coordinates are never written to our application logs, crash reports, metrics, or push notifications.
- Every access to your location is authorised against family membership and recorded.
Your controls
Pause sharing, control who sees you individually, revoke a device, delete your history, delete your account, and review who has viewed your location — all from Settings in the app. See deleting your account.
Service providers
Amazon Web Services (hosting and storage, United States), Apple (push notifications and sign-in), Sentry (crash reporting, with location data scrubbed before transmission), and RevenueCat (subscription management) once subscriptions are enabled.
Children
Creating an account requires entering a date of birth, and an account is not created for anyone who says they are under 13. That date is checked and then discarded — it is not stored on your account, not logged, and not returned by anything.
Nobody verifies it. It is what you tell us, and we do not claim to know anyone's age. We also do not offer a separate child account type, and this policy does not yet make the disclosures a service directed to children requires. Serving children under 13 lawfully requires verifiable parental consent, which we have not built. These remain open questions below and must be resolved before launch.
Contact
Open questions for counsel
- COPPA: should children under 13 be permitted at all? They cannot create an account today. If they must be able to, what verifiable parental consent applies, and is 13 the right floor in every market?
- GDPR/UK GDPR: lawful basis, controller/processor roles between family members, and whether an EU representative is needed.
- CCPA/CPRA and other US state privacy laws: disclosures, opt-out rights, and whether any transfer counts as a "sale" or "share".
- Whether location history triggers heightened "sensitive personal information" duties.
- Law-enforcement request handling and user-notification policy.
- Retention justification for the 30-day history and 90-day audit windows.
- Liability framing where one family member locates another.