Draft · pilot version · not yet reviewed by a lawyer
Privacy policy
Last updated October 1, 2026
What FamHuddle collects, why, how long we keep it, who helps us run it, and how you delete it.
The short version
- FamHuddle is for parents. Children never sign in; a child is a first name and their activities.
- We read the messages you forward only to propose your family's plan, and you confirm every change.
- Forwarded messages are deleted after 30 days. The plan stays until you delete it.
- No sale of family data, no advertising trackers, no third-party analytics during the pilot.
- Delete your account or your whole family from Settings at any time.
Who we are
FamHuddle is a family planning app on iPhone, Android and the web. This policy covers the website, the web app and the mobile apps during the pilot. The service is run by NetCORE Investment Group, Inc. ("we").
What we collect, why and for how long
Everything we hold, in one table. Retention periods are the published values; nothing is kept longer.
| ID | Data | Why | How long | Who helps |
|---|---|---|---|---|
| D01 | Adult name, email and timezone | Sign-in, and times in your family's timezone | Until you delete your account | Supabase |
| D02 | Children's first names or nicknames, and a colour | Organise the plan by child | Until you delete them or the family | Supabase |
| D03 | Messages and attachments you forward, upload or paste | Read them to propose plan items | 30 days | Postmark, Railway, Anthropic, Supabase |
| D04 | The line a proposal was read from | Show you why FamHuddle proposed something | 180 days, then blanked; the plan item stays | Supabase |
| D05 | Your plan: activities, times, places, driving and packing | The service itself | Until you delete it or close the account | Supabase |
| D06 | History of who changed what, and when | So both adults can see what happened | With the plan; if an adult leaves, their first name stays on history and their email is removed | Supabase |
| D07 | Your own photo, if you add one | Show the other adults who is driving | Until you remove it; deleted within a day | Supabase (private storage, links valid for one hour) |
| D08 | Problem reports you send, with an optional screenshot | Fix what went wrong | 30 days | Supabase; read by our team |
| D09 | Device notification tokens | Send reminders and the evening Huddle | Until you sign out, leave the family or delete your account | Expo, Apple, Google |
| D10 | Private calendar link | Show your plan in your own calendar app | Until you turn it off | Supabase |
| D11 | Usage events (feature names and small properties, never message text) | Understand what works | 400 days | Supabase |
| D12 | Error reports, scrubbed of message text and names | Fix errors | 30 days | Sentry |
| D13 | Backups | Recover from failure | 7 days | Supabase |
| D14 | Ride links: the name you give the caregiver, and the name they type when they answer | Ask for a ride and show the family who took it | With the plan | Supabase |
| D15 | Chores, packing ticks and any reward points, with the date each was for | The child's own list on a paired family screen | With the plan | Supabase |
| D16 | A paired family screen: its name, which children it shows, when it last synced | Run the screen and let you remove it | Until you remove the screen or the family | Supabase |
| D17 | An optional four-digit PIN per child, stored hashed | Let siblings switch a paired screen between them | Until you change or remove it | Supabase |
| D18 | Pilot applications from famhuddle.app | Choose and contact the pilot families | Until 90 days after the pilot ends, or sooner with the link in your confirmation email | Supabase, Postmark |
The pilot join form (D18) asks for your first name, email, how many children have activities, where your announcements arrive, your phone type, how you heard about FamHuddle (and the partner link you came from, if any), and an optional "hardest part of your week". Nothing about a child. Vercel's firewall sees your IP address to limit repeated sends; we don't store it.
What we don't collect
No children's birth dates, school rosters, photos of children, location tracking, medical records or payment card details.
How AI reads your messages
A message you forward is cleaned (signatures and quoted reply chains removed) and sent, one message at a time, to an AI model that proposes plan items. The model is provisionally Anthropic's Claude. Its output is only ever a proposal: nothing reaches your plan until an adult confirms it.
Name removal is not perfect, so a name in a message may reach the model. Anthropic's commercial terms say it may not train models on content we send it.
Who we share it with
Only the services that run FamHuddle, all in the United States:
| Service | What it does for FamHuddle |
|---|---|
| Supabase | Database, sign-in, private file storage and queues (US West) |
| Vercel | Hosts the website and web app; short request logs |
| Railway | Runs the worker that reads messages and sends notifications (US West) |
| Postmark | Receives forwarded email and sends our email |
| Anthropic | Reads one cleaned message at a time to propose plan items |
| Sentry | Error reports, scrubbed of message text and names |
| Expo | Relays push notifications to phones |
| Apple and Google | Sign in with Apple or Google, and push delivery |
| OpenStreetMap (Nominatim) | Turns a place name into map coordinates; receives the place text only |
We don't share family data with advertisers, data brokers or analytics companies. Inside your family, only the adults you invite can see your plan; anyone you give a calendar link can read that feed until you turn it off. A caregiver you send a ride link to (a grandparent, another parent) sees the child's first name and that one ride: the activity, its date, time and place, and which leg. Nothing else about the family. The link works for 72 hours, stops once answered, and you can withdraw it at any time. We don't create an account for them, don't store their contact details and don't send them anything. The calendar link shows minimal detail by default; packing, fees and driver notes appear only if you turn them on. Removing an adult or turning off a link takes effect at once. We disclose data to authorities only when the law requires it. If the company is ever sold or merged, we'll tell you before your data moves, and this policy keeps applying to it.
Your choices
- Delete your account: Settings, then confirm with your email. You're signed out at once; other adults keep their own accounts.
- Delete the whole family: the last adult to leave takes the family with them. Live data is gone within a day, and from backups within 7 days.
- Export: Settings, then Your data, then request an export. It's ready within a day and stays available to download for 7 days, as a ZIP file with your family's data (
export.json) and your photo, if you added one. - Turn off the calendar link, remove an adult, remove your photo or withdraw a problem report at any time.
- Never forward anything: you can add everything by hand instead.
- Without the app: sign in on the web at app.famhuddle.app and delete from Your account; the steps are at famhuddle.app/delete-account. If you're stuck, support@famhuddle.app will walk you through it.
Wherever you live, you can see, correct, export or delete your data, and we don't sell it or share it for advertising. That includes the rights California law gives its residents. Ask in the app or at privacy@famhuddle.app, and we'll never treat you differently for asking.
Children
FamHuddle is for parents and guardians. Children don't have accounts, don't sign in and don't use the app. A parent may enter a child's first name or nickname, a colour and their activities, and nothing more. FamHuddle is not directed to children under 13.
A parent can pair a shared family screen, such as a tablet, and choose which children it shows. On it a child sees their own day and ticks off their own packing and chores, and nothing else: no messages, no adults' details, no settings. The child has no account there either, and the screen sends no usage data that names a child. A parent can see and remove every paired screen in Settings.
How we protect it
- Every family's data is separated by database rules, and a test that tries to cross between families runs on every change.
- Files are in private storage and shared only through links that expire.
- Message text is kept out of error logs and usage events.
- You sign in with an email link or with Apple or Google; there are no passwords to leak.
Our database host encrypts all data at rest (AES-256) and in transit (TLS).
Cookies
The website sets no cookies. The web app uses only the cookies it needs to keep you signed in. The details are in our cookie policy.
Changes to this policy
When we change this policy we update the date at the top. If a change matters to how your data is used, we'll email pilot families before it takes effect.