Security Policy
Famaly holds some of the most personal information a household has — photos of your children, family conversations and your family's whereabouts. This policy describes the measures we take to keep that information safe. It should be read together with our Privacy Policy.
1. Encryption and secure connections
- All traffic between your device and our servers is encrypted in transit using TLS, so it cannot be read or tampered with along the way;
- Passwords are never stored in plain text — they are salted and hashed using an industry-standard algorithm;
- Sign-in sessions use short-lived access tokens with rotating refresh tokens; if a refresh token is ever replayed, all of that user's sessions are revoked automatically.
2. Photo, video and file storage
- Files your family uploads (chat attachments, milestone photos and videos) are stored in a private cloud storage bucket that is not publicly accessible;
- Files are only ever served through short-lived signed links that expire within minutes, generated only for authenticated members of your family group;
- File uploads are restricted to approved file types and size limits.
3. Family-scoped access control
- Every piece of family content — chat, calendar, chores, meals, child profiles, location — is scoped to your family group. Our systems check family membership on every request;
- Location information and safety alerts are only ever shared with members of your own family group;
- Shared chat channels are visible only to their members, and joining a channel from outside a family requires an invite code from the channel's creator.
4. Location data minimisation
- Fine-grained location history is automatically deleted after approximately 48 hours;
- Only a reduced set of summary points is retained (up to approximately 90 days) to power history views, then automatically deleted;
- Location sharing is opt-in and controlled through your device's permission settings.
5. Infrastructure and backups
- The Services are hosted with reputable major cloud providers (including Google Cloud and MongoDB Atlas) that maintain independently audited physical and network security;
- Databases are backed up regularly, and backups are stored securely with access limited to authorised personnel;
- Database access is restricted by network-level allow-listing and credentialed access;
- We keep our software dependencies up to date and review our technology partners' security and privacy practices before engaging them.
6. Access control and personnel
- Access to production systems and Personal Information follows the principle of least privilege — personnel can access only what they need to do their job;
- Personnel are required to use strong, unique passwords and multi-factor authentication where available, and receive training on data handling and breach reporting;
- Any suspected breach must be reported immediately to the privacy officer.
7. Children's data
- Information about children is provided and controlled by their parents or guardians;
- Children's photos, videos and records are protected by the same private storage, signed-link and family-scoping measures described above;
- Parents and guardians can review, edit or delete their children's information at any time;
- We never disclose children's information to third parties except as needed to provide the Services or as required by law.
8. Security incident management
We maintain an incident response process covering detection, containment, investigation and response. If an incident occurs we will act promptly to isolate affected systems, assess the scope and remediate the cause. Where a data breach is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
9. Your part in keeping your family safe
- Choose a strong, unique password and never share it — Famaly is not responsible for loss arising from a shared password;
- Only invite people you trust into your family group, and revoke invites you no longer need;
- Sign out on shared devices, and remove family members' access promptly when circumstances change;
- Contact us immediately at support@famaly.ai if you suspect unauthorised access to your account.
10. Reporting a vulnerability
If you believe you have found a security vulnerability in Famaly, please report it to support@famaly.ai with enough detail for us to reproduce it. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that you do not access or modify other users' data in the course of your research.
11. Changes to this policy
We may update this policy from time to time. We will notify users of material changes by email, a notice on our website or a notice in the Services. Continued use of the Services after a change constitutes acceptance.
12. Contact
Security questions or reports: support@famaly.ai