About.Family is a family coordination app operated by IMR Solutions FZCO, a company registered in the United Arab Emirates ("we", "us", "our"). This policy explains what personal information we collect, why we collect it, who it is shared with and the choices you have. It applies to the About.Family apps for iOS and Android, the website at https://about.family, and the related services we run, invitations, shared wishlist pages, push notifications, the family map and the AI assistant.
In short: what your family creates in the app (events, expenses, tasks, notes) stays on your own phone. Our servers relay those changes between your family's devices: a change waits in the relay queue only until the other devices have collected it, and it is not written into a database of ours. Some things do live on our servers, because the feature cannot work otherwise, your account details, any wishlist you publish as a public link, your latest position if you switch on the family map, and the sign-in details of external calendars you connect. If you use the AI assistant, your messages and the family data needed to answer them are processed by an AI model that we host ourselves on rented cloud infrastructure, as described below. Delete the app and the data on that device goes with it. We do not sell your personal information and we do not use it for advertising.
1. Who we are
IMR Solutions FZCO is the controller of the personal information described in this policy. You can reach us at service@about.family.
2. Your agreement
By registering for About.Family and installing the app, you confirm that you are 18 or older, that you have read and accept this policy, and that you understand what you record is shared with the members of your family group according to the role each of them has. By accepting it you consent to us processing your personal data as this policy describes, including transferring it to the countries listed under "International transfers". Where the law asks for separate consent (location sharing, the microphone, the camera, website analytics) we ask you for it separately in the app or on the site, and you can withdraw it at any time without losing the rest of the service.
3. Where this policy applies
We offer About.Family in many countries. This policy is written to meet the data protection law that applies where you live:
European Union and EEA: the General Data Protection Regulation (GDPR). The grounds we rely on are listed under "Legal bases for processing".
United Kingdom: the UK GDPR and the Data Protection Act 2018.
United States: state privacy laws, including the California Consumer Privacy Act as amended by the CPRA. See "Additional information for California residents".
Canada: the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in Quebec, Law 25.
United Arab Emirates: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the law of the country where we are established.
Russia: Federal Law No. 152-FZ on Personal Data.
India: the Digital Personal Data Protection Act, 2023.
Wherever you live, you can exercise the rights described under "Your rights" by writing to service@about.family. If the law of your country gives you a stronger right than this policy describes, that stronger right applies.
4. Information we collect
Your family's calendar, expenses, tasks and notes are stored on your own phone. This section lists everything that reaches our systems at all: the account details that let you sign in, changes on their way to another family member's phone, and the few features that cannot work without a server.
- Account and profile data: the email address you signed up with, preferred display colour theme, role in the family (for example parent, child, helper), preferred language, the system's unique ID of the family you belong to, your invite code and your subscription status.
- Sign-in data: one-time codes we send to your email address to verify it, and the session tokens that keep you signed in.
- Family content you create: calendar events, reminders, tasks and checklists, expenses and budgets, receipt photos, shopping and wish lists, children's profiles, details of household helpers you add, locations you save, notes and mood entries. This content is stored on your device. When it needs to reach another family member's device, it is relayed through our synchronisation service: the change waits in the relay queue only until the recipient devices have collected it, and it is not written into our database. Messages you send in the family chat, and the files you attach to them, are relayed the same way and stay on the devices. If you add a wish item by pasting a product link, our servers open that link to read the item's title, price and picture. The queue holds a change only while another family device still has to collect it (usually a matter of milliseconds) and drops it once they have. It is never written into a database of ours, never read or reviewed by us, and never passed to anyone else. While a change is on its way from one family phone to another it is encrypted with HTTPS (the same protection your browser uses for online banking), so nobody who can see the network in between can read it. The storage behind the queue is encrypted at rest by the built-in tokenisation of the NoSQL store it runs on.
- Location data: if you turn on location sharing, the app sends your device location while you are using the app, so that your family map works. We do not track your location in the background: when the app is closed or minimised, no location is collected. Location points are stored on our servers together with the time they were recorded. Location sharing is optional and off until you enable it; you can switch it off at any time in the app or in your device settings.
- Photos, camera and files: images and documents you attach to events, receipts, tasks or wish items. They are read from your device only when you choose them.
- Connected calendars: if you link an external calendar, we store the credentials needed to keep it in sync: for Google Calendar, the access token Google issues after you give permission; for Apple iCloud Calendar, the app-specific password you create for us. We use them only to read and update events in the calendars you chose.
- AI assistant data: the assistant is a helper inside the app. It finds things for you and creates entries such as events, tasks and expenses. It is not a general-purpose chatbot, and it is not the newest or most capable model on the market. It runs only when you open it and send a request, typed or dictated. Dictation is converted to text by the speech-recognition service built into your device operating system (Apple or Google), under their own privacy terms. To answer you, personal data is sent to the assistant: your message, your recent conversation with it, your timezone and the family data the request needs. That can include family members' profiles (names, email addresses, birthdays and any health or personal notes you have added), children's profiles, calendar events and tasks, expenses, wish lists, mood entries, saved places and (if you have location sharing on) current family locations. It is sent as it appears in the app; it is not anonymised first. The reply is generated by an open-source language model that we run ourselves on our own servers, and update from time to time. Your data is not sent to any third-party AI service, and the developer of the model never receives it. On your instruction the assistant can also create, change or delete entries in your family data. Anything you send to the assistant is stored on that service so that it can follow your conversation. Using the assistant means you agree to this policy applying to that data as well.
- Push notification data: a device notification token issued by Apple Push Notification service or Firebase Cloud Messaging, so we can deliver reminders and family alerts.
- Device and diagnostic data: device model, operating system and version, app version, language and region, and records of in-app events and errors (for example "event created", "sign-in failed"). We use this to keep the app working and to understand which features are used.
- Support and feedback: the content of messages you send us, including feedback submitted from inside the app, and the contact details you use.
- Website data: when you visit our website we process your IP address, browser type, pages visited and referring page, through Google Analytics cookies. If you open a shared wishlist link and reserve a gift, we store the name you enter and, if you provide one, your email address, so the list owner's family can see that the item is taken.
5. How we use your information
- To create and maintain your account and your family group, and to verify who you are when you sign in.
- To synchronise the content your family creates between the devices of the people you have invited.
- To send the notifications and reminders you have set up, and important service messages such as security or billing notices.
- To provide the optional features you switch on, the family map, shared wishlist pages, invitations and the AI assistant.
- To keep the service secure: detect and prevent fraud, abuse and unauthorised access, and to investigate incidents.
- To fix problems, measure how features perform and improve the app.
- To handle your support requests and respond to your questions.
- To meet legal obligations and to establish, exercise or defend legal claims.
We do not sell your personal information, we do not share it with advertisers or data brokers, and we do not build advertising profiles. We do not use the content of your family data to train our own AI models.
6. Legal bases for processing
Where the EU or UK General Data Protection Regulation applies to you, we rely on the following legal bases.
- Performance of a contract: to give you the service you signed up for: your account, synchronisation between family devices, notifications and the features you use.
- Your consent: for optional features you switch on yourself, in particular the AI assistant, location sharing, connected calendars, access to your microphone, camera and photo library, push notifications, and analytics cookies on the website. You can withdraw consent at any time, without affecting processing that already took place.
- Our legitimate interests: to keep the service secure and reliable, to prevent abuse, to understand how features are used in aggregate, and to improve the product. We balance these interests against your rights and privacy.
- Legal obligation: where we must keep records or respond to lawful requests from competent authorities.
7. Data you have to provide, and automated decisions
Some information is necessary for the service to exist: an email address to create and secure your account, and the content you choose to record. Without it we cannot give you an account or synchronise anything between your family's devices. Everything else (your photo, location sharing, microphone and camera access, push notifications) is optional, and the app works without it.
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you. The AI assistant acts on the instructions you give it: it can create, change or delete entries in your own family data, and you can review and undo what it does.
8. Who can see your information
- Your family members. Everyone you invite into your family can see the shared content their role allows, for example calendars, tasks and, depending on your settings, expenses and locations. Choose carefully who you invite.
- Helpers and external people. Nannies, drivers and other helpers you add receive restricted access: our servers do not deliver adult-only content such as finances, wish lists and private family tasks to them.
- Anyone with a shared link. A wishlist you publish gets a public web address. Anyone who has the link can open the list and reserve items, without signing in. Do not put anything in a published list that you would not want a stranger to read.
- Service providers. The companies listed in the next section, acting on our instructions.
- Authorities and legal successors. We may disclose information if we are legally required to, to protect our rights or someone's safety, or in connection with a merger, acquisition or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy.
9. Service providers we use
- Google (Firebase Cloud Messaging, Google Sign-In, Google Calendar, Google Maps, Google Analytics): push notification delivery, optional sign-in, the calendar sync you enable, server-side address lookup, and website analytics.
- Apple: push delivery to iOS devices, on-device and Apple-hosted speech recognition, the iCloud calendar sync you enable, and App Store distribution.
- Microsoft 365: delivers our emails: sign-in codes, invitations and replies to your messages. Microsoft processes the recipient address and the content of those emails.
- Geoapify: address search and geocoding when you look up a place in the app; your search text is sent to them.
- OpenStreetMap and unpkg: the family map is drawn with OpenStreetMap map tiles and the Leaflet library loaded from the unpkg content delivery network. While the map is open, your device requests the tiles for the area you are viewing, which reveals your IP address and that map area to those services. Our servers also use OpenStreetMap's geocoder to resolve places.
- Retailer websites: when you add a wish item from a product link, our servers fetch that page from the retailer's site to read its title, price and picture.
- Elastic: the analytics and error-logging platform where in-app events and diagnostics are stored.
- Hosting and infrastructure providers: operate the servers that run our API, synchronisation service, AI assistant relay and databases.
Service providers may only process your information on our instructions and for the purposes described here.
10. International transfers
We are based in the United Arab Emirates and our servers stand in the United Arab Emirates, Germany, Russia, the United States and India, with providers operating in those and other countries. This means your information may be transferred outside the country you live in. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and take steps to make sure your data keeps an equivalent level of protection. You can ask us for a copy of the safeguards we use by writing to service@about.family.
11. How long we keep your information
- Account and profile data: for as long as your account exists. After you delete your account we remove or anonymise it, except where we must keep records to meet a legal obligation.
- Synchronisation events: held in the relay queue only until every device in your family has collected them, and never written into our database. Anything still uncollected expires after two weeks at the most.
- Location points: kept only for as long as they are needed to power the family map. Turning location sharing off stops new points being collected, and deleting your account removes the points stored for you.
- Connected calendar credentials: until you disconnect the calendar or delete your account.
- AI assistant conversations: your conversation history is stored on your device; requests pass through our AI assistant service only for as long as it takes to generate the reply.
- Published wishlists and reservations: until you delete the list or the item, or delete your account.
- Diagnostics and analytics events: kept for a limited period in our logging platform and then deleted automatically.
- Support correspondence: kept for as long as needed to deal with your request and for a reasonable period afterwards.
Copies may persist for a short time in encrypted backups before they are overwritten on their normal cycle.
12. How we protect your information
Traffic between the app and our servers is encrypted in transit with HTTPS (TLS). Access to production systems is restricted to the people who need it, and authentication uses short-lived tokens.
What that means in practice: your family's content lives on your devices. Our synchronisation service is a relay rather than a store, it carries changes between the devices in your family and keeps each change only until they have collected it. The exceptions that do live on our servers are listed in "Information we collect". No online service can promise perfect security, and we will tell you and the competent authority about a personal data breach where the law requires it.
13. Your rights
Depending on where you live (including under the GDPR, the UAE Personal Data Protection Law and the California Consumer Privacy Act) you have some or all of the following rights.
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your information, including by deleting your account.
- Receive your data in a portable, machine-readable format, or ask us to transfer it.
- Object to or restrict processing that is based on our legitimate interests.
- Withdraw consent you have given, for example for location sharing or analytics.
- Not be discriminated against for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of.
- Complain to your local data protection authority if you believe we have handled your data unlawfully.
To exercise any of these rights, write to service@about.family. We answer within 30 days and may need to verify your identity first.
14. Additional information for California residents
The categories of personal information we have collected in the last twelve months are listed in the section "Information we collect": identifiers, contact details, account credentials, commercial information (your subscription), internet and device activity, precise geolocation, audio and visual information you provide, and the content you create. We collect it from you and from your device, and we disclose it for business purposes to the service providers listed above.
We do not sell personal information and we do not share it for cross-context behavioural advertising, including that of anyone we know to be under 16. Precise geolocation is treated as sensitive personal information under California law; we use it only to show your position to the family members you have chosen, never to infer characteristics about you, so the right to limit its use does not change how we handle it. You may exercise your rights to know, correct, delete and opt out through the addresses in the "How to contact us" section, and you may use an authorised agent, we will ask for proof of their authority and verify your identity before we act.
15. Deleting your account
You can delete your account from the app's profile settings, or by writing to service@about.family from the address associated with your account. Deleting your account removes your profile, your membership of the family, your stored location points and the content that belongs to you, and revokes the tokens on your devices. Content that other family members created stays with them. Data stored locally on your device is removed when you uninstall the app.
16. Children
About.Family is designed for adults who organise family life. Accounts are for people aged 18 or over, or the age of majority where you live. Information about children in the app (names, ages, schedules, activities, wishes) is entered by a parent or guardian, who is responsible for deciding what to record and for the consent of the other adults involved. We do not knowingly collect personal information directly from children, we do not show them advertising and we do not profile them. If you believe a child has created an account without a parent's involvement, write to service@about.family and we will remove it.
18. Changes to this policy
We update this policy when the service changes or the law requires it. The date at the top always shows the current revision. If a change materially affects how we handle your personal information, we will tell you in the app or by email before it takes effect.
19. How to contact us
For privacy questions, data requests and anything else, write to service@about.family.
