Privacidad
Los datos de tu familia. Tus decisiones informadas.
La política de privacidad completa aparece a continuación en inglés. FamilyAtlas se ofrece actualmente en Estados Unidos y Canadá. La sección sobre los datos de ubicación está aquí en español.
Datos de ubicación, incluida la ubicación en segundo plano
FamilyAtlas accede a la ubicación precisa (como la latitud y longitud GPS) o aproximada y la recopila, según el permiso concedido en el teléfono. Los informes incluyen la hora de medición, la precisión y, cuando el teléfono los proporciona, la velocidad, la dirección y el nivel de batería. Estos registros están asociados al dispositivo vinculado y al perfil familiar.
FamilyAtlas recopila ubicación para compartirla con la familia, mantener el historial, emitir avisos de llegada y salida de lugares guardados, SOS y check-ins, y ofrecer funciones Driving Safety activadas, incluso cuando la aplicación está cerrada o no se utiliza. Se requiere permiso de ubicación y que la función correspondiente esté activada. Un padre o madre que elija expresamente Show my location para una recogida también puede compartir su posición en segundo plano durante esa recogida. Este permiso no permite que un teléfono apagado o una aplicación detenida por la fuerza envíe actualizaciones; los límites del sistema, los cambios de permisos y la conectividad pueden interrumpirlas.
Los informes se envían por HTTPS a los servidores de FamilyAtlas para estas funciones. Los familiares autorizados pueden ver posiciones y avisos según los ajustes de uso compartido del hogar; no es una fuente pública de ubicaciones. No vendemos la ubicación ni la utilizamos para publicidad o analítica. Nuestro proveedor actual de mapas OpenStreetMap recibe solicitudes de las zonas visualizadas; pueden revelar la zona y la dirección IP del dispositivo solicitante. Esto es distinto del envío de un informe de ubicación a FamilyAtlas. En una recogida, Arrival estimate only envía la última ubicación del padre o madre a FamilyAtlas y a su propio servidor de rutas después de iniciar expresamente una sesión de envío. El menor ve una estimación, sin la posición ni la ruta del adulto en esa vista. Show my location también puede mostrar la ruta por carretera. Ningún servicio público de rutas recibe estas coordenadas; no se guarda un historial de rutas de recogida y las estimaciones no incluyen tráfico en directo. Para detener: Pickup requests > Change pickup sharing > Just say I’m on my way.
El mapa familiar guarda la última posición. El historial solo se almacena si está activado, durante el plazo elegido para cada niño (0, 7 o 30 días); 0 significa que no se guarda un recorrido de posiciones. Los registros de velocidad relacionados siguen ese plazo, o se guardan 24 horas si no se conserva historial. Los lugares guardados y los registros SOS tienen plazos distintos y permanecen hasta su eliminación correspondiente o la eliminación de la cuenta u hogar. La recogida guarda solo la última posición, sin historial de ruta; el acceso termina al cerrar la recogida o tras un máximo de dos horas; las posiciones vencidas se borran en la siguiente limpieza programada, normalmente en 15 minutos.
Controla el uso compartido en Family location; elige cuánto tiempo se conserva el historial en la pantalla Location history de cada niño, y expórtalo o elimínalo en Settings > Privacy & Data. Puedes revocar los permisos de ubicación o ubicación en segundo plano en los ajustes del teléfono en cualquier momento; las funciones dependientes dejan de actualizarse o quedan limitadas. Desactivar el historial no desactiva por sí solo el uso compartido de la posición actual. Para solicitar una eliminación sin la aplicación, escribe a [email protected]; consulta la sección de eliminación inferior.
Last updated:
This policy explains what FamilyAtlas collects, why, who receives it, how long we keep it, and the choices and rights you have. It covers the FamilyAtlas apps for iPhone, Android and Wear OS, the parent dashboard, the FamilyAtlas browser extension, FamilyAtlas Guard, the FamilyAtlas agents for Windows and macOS, HomeControl for supported routers, and this website.
In short
- We do not sell personal information, show ads, or use anyone's activity for advertising.
- FamilyAtlas is mainly a parental-supervision service. A parent decides which features run on a child's device, and the child's device shows that FamilyAtlas is active; an adult family member decides for their own devices. It is not designed to be hidden.
- Text messages, pictures and search words are checked on the child's device or computer. When something may be a safety concern, the alert is end-to-end encrypted so that only the parents' devices can read it.
- Some features send information to our servers so that parents can see it, such as locations, the web pages a child visits (without searches or other details in the address), app usage and screen time. Each is described below with how long it is kept.
- You can see, export and delete your family's information in Privacy & Data (in the app: Settings > Privacy & Data), or by emailing [email protected].
Who we are
FamilyAtlas is provided by Hiver Farm L.L.C., a company based in the United States (“FamilyAtlas”, “we”, “us”), which is responsible for the personal information described in this policy. FamilyAtlas is currently offered to families in the United States and Canada, and this policy is written for them. App stores, payment providers and the other companies named in “Who receives information” handle some information under their own policies too.
Our Privacy Officer is responsible for how we handle personal information. For any privacy question, or to use any of your rights, contact us at [email protected].
Whose information this policy covers
- Parents and guardians who create a FamilyAtlas account (“parents”).
- Children whose profiles a parent creates and whose devices a parent links (“children”).
- Adults protected by FamilyAtlas: an adult family member or a parent protecting their own devices, and an adult who links FamilyAtlas Guard to their family (each a “protected adult”).
- People whose information passes through a feature a parent turns on: emergency contacts who receive an SOS, people a child exchanges messages or calls with, and people using devices on a home network managed by HomeControl.
- Visitors to familyatlas.io.
What we collect and why
What FamilyAtlas collects depends on the devices you link and the features you turn on. For each area below we say what is collected, where it goes, who can see it and how long it is kept. The periods are also summarised in “How long we keep information”.
Account and family
Account: your email address, the name you give, a profile picture if you add one, your password (stored only as a one-way hash), language, two-step verification settings, your sign-in sessions and a security log of sign-ins (see “Security and abuse prevention”). Family: the family name, its parents, invitations (including the invited person's email address), and the family's settings and rules.
Child profiles: the name or nickname a parent enters, an age band (not a birth date), time zone and avatar choice. Children do not create their own FamilyAtlas accounts; their devices are linked to the profile by a parent. Adult profiles also record the relationship you choose and each consent the adult gives or withdraws.
We use this to provide the service, keep accounts secure and let parents manage their family.
Linked devices
For each linked phone, watch, tablet, computer or browser: its name, manufacturer, model, operating-system and FamilyAtlas versions, an installation identifier, when it last checked in, which protections and permissions are active, and its battery level and charging state. Notification tokens let us send notifications to parents' and children's devices. Parents see this so they know whether protection is working. When a device is unlinked, its record is hidden and its notification token deleted; the rest is kept until the family is deleted.
Location
Driving Safety (when turned on for a teen driver): trip distance and speed, speeding, hard-braking and rapid-acceleration events, phone activity on the travelling phone during a trip, possible crash detections with the measured impact force, and a weekly driving score. Trip details follow the location history window (24 hours if no history is kept); weekly scores are kept for 26 weeks.
Trip sharing: when a family member shares a trip, the destination, recent positions and estimated arrival are shared with the whole family and deleted 24 hours after the trip ends. With approximate sharing, other family members see only a broader area; the precise position is still stored for SOS and safety. Records of approximate-sharing periods are kept for up to 400 days after they end.
Saved places and pickup requests: place names, positions and arrival or departure events, and a child's pickup request (which can include the child's position and battery level), are kept until you delete them or the family. A parent's own Show my location position is erased when the pickup ends or at most 2 hours after sharing starts.
SOS: when someone raises an SOS, we store the time, position, accuracy and battery level and alert the parents. If the family has added emergency contacts, we send them a text message (and, if chosen, a phone call) through our telephony provider, Twilio. The text includes the person's name, the time and a Google Maps link to their position; the call says only their name. When a contact is added, they receive a verification text naming the parent who added them. We keep emergency contacts' names, phone numbers and relationship, SOS events and a record of the messages sent until you delete them or the family. SOS is on by default for children; an adult turns it on for themselves.
Screen time and apps
On a child's Android phones and computers, FamilyAtlas records which apps are installed, how long each app is used per day and hourly totals; in Strong Mode, also which permissions each app requests and holds. On iPhone, app usage stays on the device. We use this to apply time limits, schedules and app rules, to rate apps for age suitability and to show parents screen time. Daily usage, installed-app lists and permission lists are kept until you delete them or the family.
To do this, FamilyAtlas uses system features that a parent enables on the child's device. On Android: Usage Access, an Accessibility service, a device-administrator or Device Owner (“Strong Mode”) role that can also list and manage the permissions of other apps, a local VPN that filters website lookups, and a notification-listener service and a second Accessibility service used for YouTube supervision. On iPhone: Apple's Screen Time (Family Controls) framework and a local network filter for website lookups. On computers: the FamilyAtlas agent for Windows or macOS.
YouTube supervision on Android (when a parent turns it on): the titles, channels and identifiers of videos watched in the YouTube app and how long they played. Kept for 7 days.
Web activity and filtering
Web filtering on phones and Windows computers works on the device: it checks the name of each website (the domain) the device looks up. We store daily counts per website name — how many lookups there were and how many were blocked or alerted — so parents can see them. They are kept for 0, 7 or 30 days, as the family chooses (7 by default). On a Mac, blocked names are added to the computer's hosts file and no counts are sent.
To answer lookups the filter allows, phones forward them to a public DNS resolver: Cloudflare (1.1.1.1) and, as a fallback, Google (8.8.8.8); on Android the network's own resolver is tried first. On Windows, lookups go only to Cloudflare over an encrypted connection; on a Mac, the computer's usual resolver is used. These companies see the website names looked up and the device's network address, as any DNS resolver does.
FamilyAtlas browser extension (Chrome and Edge, on computers and Chromebooks): while the family's page-history setting is on (it is on by default), the extension sends the address of each page a child opens without the part after “?” (which can hold searches or personal details), the page title (not for messaging sites), the time and whether the page was blocked. On YouTube it also records video titles and identifiers. Parents see this as browsing history. It is kept for 0, 7 or 30 days, as the family chooses (7 by default). Search words are not stored on our servers: where the FamilyAtlas agent is installed on the computer, they are checked there and only a possible safety concern is sent, as an encrypted alert.
Page checks and picture checks (if a parent turns them on) read a page's text or pictures on the child's computer only. The text is scored and discarded; pictures go only to the FamilyAtlas agent on the same computer. Neither is sent to us; only the result, such as “page blocked” or “picture blurred”, is added to that visit in the browsing history.
The extension also includes FamilyAtlas Guard's protections (see “FamilyAtlas Guard”). When it stops something in a linked child's browser — or an adult's who shares security alerts — the kind of threat, how serious it was, the brand it imitated and whether the warning was passed (never the address) are sent to the parents as an alert and, while page history is on, noted on that visit. The alert record is kept for 90 days; the note on the visit follows the browsing-history window.
Safety monitoring
If a parent turns on safety monitoring for a child and accepts the monitoring consent, FamilyAtlas checks text messages (only in the Android version downloaded directly from us), the words in pictures, search words typed in a browser on a computer with the FamilyAtlas agent, photos and videos (on the Google Play version, only pictures the child chooses; on computers, a chosen folder) and, on Windows, voice chat in games the parent selects. Models that run on the device do the checking. The text, pictures and audio being checked stay on the device and are discarded after checking, except that for an alert the nearby messages are kept on the device until the alert expires, so a parent can ask for more context. When turning safety monitoring on, a parent chooses the areas it covers (messages, photos and videos, the browser); a device checks only the areas chosen, and our server refuses an alert from any other area. No child content is used to train models. Safety monitoring is never available for adults.
When something may be a safety concern, the child's device sends an alert that is end-to-end encrypted to the parents' devices. It can contain the flagged item with the message before and after it and the app it came from. Pictures are never sent: for a flagged picture or video only a description is sent. Our servers store only the encrypted alert, which we cannot read, and its details (which child and device, severity, times, whether it was read, saved or dismissed, and a parent's helpful or not-helpful answer). A parent may ask for a little more context, up to five messages either side, which the child's device sends the same way.
Encrypted alerts are deleted after 30 days unless saved (the family can choose 1 to 30 days); dismissed alerts 7 days after dismissal; saved alerts at most 365 days after saving. Other safety events (for example from websites and apps) are kept for 30, 90 or 365 days (90 by default). Weekly counts of lower-level signals stay on the child's device for 8 weeks.
Safety alerts need a recorded consent from a parent for each child, listing the areas covered (messages, photos and videos, browser, apps and sites, location). A parent can withdraw it at any time in the app; safety alerts stop and the child's device removes its notification. Other features, such as call and text records or location, have their own switches. While monitoring is active, an Android child device shows a persistent notification, and the child's FamilyAtlas screen lists what is monitored.
Messages and pictures checked on a child's device can contain information about the people the child talks to. That information stays on the device unless it is part of an encrypted alert or of the call and text-message records described below.
Calls and text messages (only in the FamilyAtlas Android version downloaded directly from us; not in the Google Play or App Store versions): if a parent turns this on for a child, or an adult turns on contact safety for themselves, the app reads the call log, text-message log and contacts on the phone to record who the person communicates with — the contact's name as saved on the phone and a scrambled identifier of the number, never the number itself — the time, the call duration, the length of a message (not its content) and any risk categories. Parents can keep a watch list of people with their own notes, and can block incoming calls from them (Android 10 and later). Off by default; records are kept for 0, 7 or 30 days (30 by default). Watch-list, trusted and blocked entries are kept until you remove them.
Connected accounts (not currently offered): if this becomes available and a parent connects a child's Gmail, Google Drive, Outlook, OneDrive or Dropbox account, our servers would read new messages and files through the provider's interface, check them in memory, and keep only the result and the item's identifier, not the content. Access could be removed at any time in the app or in the provider's account settings. FamilyAtlas's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Family features
Chores, rewards, the time bank, skills and badges, team quests, the family calendar, reminders, the family agreement, requests a child sends (for example to unblock a site or for more time, with an optional short message), the family activity feed, the notification inbox and weekly email reports. These contain what family members write into them, such as chore titles and notes, event titles, notes and places, and the names typed to sign the agreement. The activity feed is kept for 30, 90 or 365 days (90 by default); the rest is kept until you delete it or the family.
HomeControl (home network)
HomeControl is an optional plug-in for supported routers, such as the GL.iNet Brume 2, that applies family rules to the whole home network. It sees every device on that network, including guests' devices. Devices' hardware addresses stay on the router; it sends us a scrambled device key, the name and type a device announces on the network, its manufacturer and model, whether its address is randomised, and when it was last seen. A parent can assign a device to a family member.
To show activity and apply rules, it sends us: for devices assigned to a child or shared, website names and counts and active minutes per day (kept 7 days); hourly data usage (kept until the device or family is deleted); threats it detected (7 days) and security findings such as VPN use (35 days); open ports while they are detected; speed and connection-quality results (35 days); and — only if a parent turns on connection history — the remote addresses, ports and protocols each device connected to (7 days). Router audit records and support reports a parent sends are kept until the family is deleted.
Lookups the router does not answer itself go to your internet provider's DNS resolver, or, if you turn on encrypted DNS, to Cloudflare, Quad9 or Google. The router checks the connection by contacting Cloudflare and Google, and installing the plug-in downloads software packages from GL.iNet's package server. If FamilyAtlas answers a home network's lookups from our servers, we store that network's public IP address while it is registered and daily counts of the websites looked up; lookups we do not answer are passed to Cloudflare.
Windows and macOS agents
The FamilyAtlas agents for Windows and macOS apply the family's rules and report app usage, device health and, on Windows, website counts and safety alerts; on an adult's computer they apply only threat protection. The Windows agent sends the computer's DNS lookups to Cloudflare's encrypted DNS service. The Windows agent and the Android app download the on-device safety models from Hugging Face, which sees the device's network address. The macOS agent looks up the addresses of search engines' SafeSearch servers through Google's public DNS.
FamilyAtlas Guard
FamilyAtlas Guard is a separate browser extension that protects the person using the browser, often an adult. It needs no account and does not record or send the pages you visit. Known dangerous sites are checked against a list downloaded to your browser; look-alike addresses and page tricks are detected in your browser. Counts of what it stopped, and scrambled fingerprints of the passwords you ask it to protect, stay in your browser. Downloading the list sends us an ordinary web request with your network address and nothing about what you visit.
Family alerts (optional): if you choose Link with my family and agree, Guard shows a code that a family member enters or scans in their FamilyAtlas app. From then on Guard sends that family the name you chose, when Guard last checked in, its version and, for each thing it stopped, when it happened, how serious it was, the kind (for example “fake site” or “remote-control program download”), whether you continued past the warning, and the name of an imitated brand from Guard's own list. Never the address, the page, your searches, what you typed or any password. The family's parents are notified. Events are kept for 90 days. You can turn family alerts off in Guard at any time, and your family is told; a parent can also remove the link.
Payments and referrals
Subscriptions are sold through the App Store, Google Play or, on the web, Stripe, and managed through RevenueCat. We keep the plan, store, status and expiry, and the identifier, type and time of each payment event RevenueCat reports, linked to a random family identifier. We never receive card details. Referral rewards use a scrambled reference to the purchase. Payment events are kept for up to 24 months. When a family is deleted, its subscription record goes with it and its payment events are deleted within 30 days.
Product events, error reports and crash reports
Diagnostics and crash reports are off until a parent turns them on; the app asks, with no answer pre-selected. A parent can change this at any time in Settings > Privacy & Data > Diagnostics and crash reports; the setting also applies to the family's linked devices, which learn the change when they next connect. Crash reports from children's devices are used only to find and fix errors in FamilyAtlas; they are never used to contact a child, build a profile or advertise, and they go only to our own servers.
Product events: the parent app reports that a screen was opened and fixed setup, permission, rule, plan and help events, with the app version, operating-system version and platform, linked to the parent's account. Help searches send only a result-count range, never the search text. Kept for 14 months.
Error reports: the dashboard, the browser extension and the desktop agents can send technical error reports with fixed error categories, software versions, names from an approved list of our own modules and functions, and fingerprints. No names, emails, content, addresses or locations. Kept for 90 days.
Mobile crash reports: when diagnostics are on, the parent's FamilyAtlas app on iOS and Android sends crash reports to Google Firebase Crashlytics. A child's phone or watch, and an adult family member's device, never use Crashlytics; their crash reports go only to our own servers. Crashlytics reports include technical installation identifiers, device and operating-system information, native crash traces, the app edition, setup stage and build number. We do not attach names, emails or FamilyAtlas account identifiers; the app cannot fully filter native crash traces. Google begins deleting crash traces and associated identifiers after 90 days. Turning the setting off, signing out or unlinking deletes unsent reports but cannot recall reports already sent.
There is no advertising or third-party analytics SDK in the FamilyAtlas apps. The Android app includes Google's on-device ML Kit text recognition, which under Google's terms can send usage metrics to Google. Our team receives aggregate service reports by email with counts and fixed technical categories, not names, account identifiers or content.
Security and abuse prevention
To protect accounts we keep records of sign-ins and security events with a shortened one-way hash of the network address (180 days), temporary sign-in lock counters keyed by a scrambled email address or by the network block, such as the first three parts of an IPv4 address (2 days), and web-server logs with network addresses and requested paths until newer logs overwrite them. Device pairing uses a short-lived scrambled network identifier to prevent abuse.
This website and the early-access list
familyatlas.io is hosted by Cloudflare, which processes visitors' network addresses to serve the site. Google Analytics runs only after you accept analytics cookies; it uses its own cookie identifiers and technical connection data, is never linked to a FamilyAtlas account, and keeps event-level data for two months. Withdraw consent with Cookie settings in the footer. Some pages (for example the blog) load fonts from Google Fonts, which receives your network address. Links to Amazon for supported routers are affiliate links; Amazon sets its own cookies if you follow one.
Early-access list: we store the email you enter, your consent version, and the sign-up, confirmation and unsubscribe dates, and email you only about early access and launch. The list is separate from family accounts and contains no child data. Sign-ups never confirmed are deleted after 30 days. After you unsubscribe we keep your address only so we do not email you again; ask [email protected] to delete it entirely.
If you email us, we keep the conversation as long as needed to help you.
How we use information and your consent
We use information only to provide and protect FamilyAtlas, as described above. How we ask for consent:
- Creating an account and using FamilyAtlas: you agree to this policy. When a parent sets up a child's profile and devices, the parent consents on the child's behalf. An adult added to a family turns each protection on themselves.
- Precise and background location, safety monitoring, the call and message features, Guard family alerts, website analytics and early-access emails: we ask before each starts — with an in-app switch, an operating-system permission or a recorded consent. You can withdraw it at any time; it stops future collection.
- Messages to emergency contacts during an SOS: sent because a parent added the contacts and the person raised an SOS.
- Security, preventing abuse and fraud, backups, diagnostics and fixing errors: needed to run a safe, working service.
- Payment and tax records: required by law.
Safety models flag possible concerns automatically. They make no decision with legal or similarly significant effects; a parent decides what to do. We do not use personal information for advertising, sell it, or use children's content to train models.
Children's privacy
FamilyAtlas is used by parents to supervise their children. A parent creates a child's profile and links the child's devices. We collect a child's information only at a parent's direction, for the features the parent turns on, and only to provide those features. Safety monitoring needs a recorded parent consent for each child.
Parents can review their children's information in the app, export it, delete specific history, a child's profile (which removes everything recorded about that child and unlinks their devices) or the whole family (which removes every child profile), and stop further collection at any time by turning features off or unlinking the child's device. In the United States these are a parent's rights under the Children's Online Privacy Protection Act; in Canada a parent or guardian consents for a child, including, in Quebec, for a child under 14. Children's information is not sold, used for advertising or shared, except with the service providers listed below that help run FamilyAtlas and, during an SOS, with the emergency contacts a parent added.
Children can see that FamilyAtlas is active on their devices. Parents with questions about their child's information can contact [email protected].
Who receives information
Your family: parents see what this policy describes for their family and children; a child sees their own information and, where the family shares it, family members' locations. An adult family member's information is shared with the family only for the protections that adult turns on. A protected adult's Guard events go only to the family they linked with. When a parent protects their own devices, their security alerts and device health go to them, and to other parents only if they choose them.
Service providers that process information for us:
| Provider | What it receives | Where |
|---|---|---|
| Hetzner Online | Our servers and database: all service information | Germany |
| Cloudflare | Website hosting; encrypted database backups; website lookups from children's devices; optional encrypted DNS and connection checks from routers | United States and worldwide |
| Firebase Cloud Messaging (notification tokens and notification text); Firebase Crashlytics (crash reports); ML Kit on Android devices (usage metrics under Google's terms); Google Analytics on this website after consent; Google Fonts on some website pages; public DNS as a fallback resolver, and router DNS lookups if a family chooses Google for encrypted DNS | United States | |
| Apple | Apple Push Notification service (notification tokens and text); App Store purchases | United States |
| Amazon Web Services (Amazon SES) | Email addresses and our emails: verification codes and password-reset links, sign-in notices, family invitations, weekly reports with children's profile names, counts and most-used apps, early-access emails | United States |
| Twilio | Emergency contacts' phone numbers; verification texts naming the parent who added them; SOS text and voice messages with the person's name and position | United States |
| RevenueCat, Stripe, Google Play, App Store | Subscription and payment information | United States |
| OpenStreetMap Foundation | Map tiles for the areas viewed in the app, with the viewing device's network address | United Kingdom |
| Hugging Face | Downloads of on-device safety models, with the device's network address | United States |
| Quad9 | Router DNS lookups, only if a family chooses Quad9 for encrypted DNS | Switzerland |
| GL.iNet | The router's network address when the HomeControl plug-in is installed | GL.iNet's servers |
| Google (Chrome Enterprise), Samsung Knox | Device identifiers and rules, only if a family manages Chromebooks or Galaxy Watches through them | Provider's region |
Notification text, such as a child's first name, a place name or a chore title, passes through Google and Apple to reach your devices.
We may also disclose information when the law requires it, to protect someone's safety, or as part of a merger or sale of our business, in which case this policy continues to protect it and we will tell you. We do not sell personal information or share it for targeted advertising.
Where information is stored
We are based in the United States, our servers are in Germany, and several of the providers above are in the United States or other countries. Information about families in Canada is therefore stored and processed outside Canada, where it may be accessible to courts, law-enforcement and national-security authorities under the laws there. Our providers process it only for us, under contracts that require them to protect it.
How long we keep information
| Information | Kept |
|---|---|
| Your account | Until you delete it (deleted at once), or 7 days after the owner asks to delete the family |
| Family, child profiles and rules | Until the family is deleted; deleted 7 days after a family deletion request |
| Current location | Latest position only |
| Location history and driving trips | 0, 7 or 30 days, as the family chooses; off by default (trips 24 hours if no history is kept) |
| Weekly driving scores | 26 weeks |
| Trip sharing | 24 hours after the trip ends |
| Approximate-sharing period records | Up to 400 days after they end |
| A parent's pickup position | Erased when the pickup ends or at most 2 hours after sharing starts |
| Saved places, arrivals, pickup requests, SOS events, emergency contacts and SOS messages | Until deleted, or until the family is deleted |
| Website counts and browsing history | 0, 7 or 30 days, as the family chooses (7 by default) |
| YouTube app history (Android) | 7 days |
| Screen time, app lists and app permissions | Until deleted, or until the family is deleted |
| Call and message records (Android direct version) | 0, 7 or 30 days (30 by default); watch-list, trusted and blocked entries until you remove them |
| Encrypted safety alerts | 30 days (family can choose 1–30); dismissed: 7 days; saved: up to 365 days |
| Other safety events and the activity feed | 30, 90 or 365 days (90 by default) |
| Chores, calendar, reminders, requests, agreement, notification inbox | Until deleted, or until the family is deleted |
| HomeControl | Sites, minutes, threats and connection history 7 days; security findings and speed tests 35 days; open ports while detected; data usage until the device or family is deleted; audit records and support reports until the family is deleted |
| FamilyAtlas Guard events | 90 days |
| Product events | 14 months |
| Error reports | 90 days (Crashlytics: Google begins deleting after 90 days) |
| Sign-in and security records | 180 days; sign-in lock counters 2 days; server logs until newer logs overwrite them |
| Early-access list | Confirmed: until you ask us to delete it; never confirmed: 30 days |
| Payment records | Subscription record until the family is deleted; payment events up to 24 months, and deleted within 30 days of the family's deletion |
| Website analytics | Event-level data 2 months |
| Backups | Backups are encrypted. Off-site backups are kept up to 90 days; the copy taken on our server before each update is kept 14 days |
Deleted information can remain in backups until they expire or are removed, and is not restored from them except to recover the service.
How we protect information
All connections between FamilyAtlas apps, devices and our servers are encrypted, except standard DNS from a home router if a family chooses Classic DNS, and the app's setup of a router over the home network. Safety alerts are end-to-end encrypted, and the keys that open them stay in the secure storage of parents' devices (Android Keystore, iOS Keychain). Passwords, sign-in tokens and verification codes are stored only as one-way hashes; two-step verification secrets and connected-account tokens are stored encrypted; off-site backups are encrypted; and access to our servers is restricted. No system is perfectly secure; if a breach affects your information, we will tell you as the law requires.
Your choices and rights
In the app you can turn features and collection off, choose how long history is kept, export your family's information, delete specific history, a child's profile, your account or the whole family, and turn diagnostics off. You can withdraw device permissions in the phone's settings at any time.
Depending on where you live, you also have the right to:
- know what we hold about you and get a copy, including in a portable format;
- have inaccurate information corrected;
- have information deleted;
- restrict or object to some uses, including uses based on our legitimate interests;
- withdraw consent at any time;
- not be treated differently for using these rights;
- appeal our answer, and complain to a privacy regulator.
To use a right, email [email protected] from your account's email address (or the address you gave us) and say what you want. We will verify your request before acting and answer within 30 days (45 days in California), extended only where the law allows. You may use an authorised agent. The in-app export covers your family's main information, with location history in approximate form; for a copy of everything we hold — including chores, reminders, the notification inbox, emergency contacts, Guard and HomeControl records — email us.
If you are not satisfied, you can complain to a privacy regulator: in Canada, the Office of the Privacy Commissioner of Canada or your provincial commissioner (in Quebec, the Commission d'accès à l'information); in the United States, your state attorney general or the Federal Trade Commission.
Regional information
United States, including California: in the past 12 months we collected identifiers (such as email address and device identifiers), personal records, commercial information (subscriptions), internet and other activity (browsing history, app usage), precise geolocation, inferences (such as safety flags and app age ratings) and, inside encrypted alerts, limited contents of communications. Sources: you, your devices, and your children's devices at your direction. We use them for the purposes in this policy. We do not sell or share personal information for cross-context behavioural advertising and have not done so, so there is nothing to opt out of; we use sensitive information, such as precise location, only to provide the service. You have the rights listed above, including to know, delete and correct, and not to be discriminated against.
Other US states: residents of states with consumer privacy laws (for example Colorado, Connecticut, Virginia, Texas and Oregon) have the same rights to access, correct, delete and get a copy of their information, and to appeal our answer; email us to use them.
Canada: we handle personal information under the Personal Information Protection and Electronic Documents Act and the provincial laws that apply, including Quebec's Act respecting the protection of personal information in the private sector. You can ask for access to and correction of your information, withdraw consent subject to legal or contractual limits, and ask how our providers handle it. In Quebec you can also ask for your information in a structured, commonly used format, and our Privacy Officer is the person in charge of the protection of personal information.
Browser extensions
FamilyAtlas's use of information received from the Chrome extension APIs, in the FamilyAtlas browser extension and in FamilyAtlas Guard, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The information is used only to provide the features described in this policy; it is not sold, used for advertising or creditworthiness, or read by people except to keep the service secure, comply with the law or with your consent.
Delete your FamilyAtlas account or data
You can request deletion without installing the app. Email [email protected] from your account email address and say whether you want to delete your account, your whole family, a child's profile, or specific history. Do not send your password. We will verify account ownership before acting.
In the app, open Settings > Privacy & Data. Other parents can choose Delete my account; the family owner must delete the family to remove their account. A family deletion can be cancelled for 7 days and then removes its child profiles, rules, history, device links and corresponding product-event and error records. Other parents keep their own accounts. Deleting only a parent account leaves the rest of the family's records in place.
You can also delete selected history while keeping your account. Apple, Google or other payment providers may keep their own transaction records under their policies. Deleting an account does not cancel a store subscription; manage it in its store.
Changes to this policy
When this policy changes we update this page and the date at the top. If a change is significant, we will also tell parents in the app or by email before it takes effect.
Contact
Hiver Farm L.L.C. (FamilyAtlas), United States. Privacy Officer: [email protected].