Privacy and your data
Live location, maps and arrival alerts are disabled. Saved places contain static addresses. The assistant cannot close families, transfer ownership or enable ownership recovery. Only the creator can enable administrator recovery requests; acceptance requires a 14-day wait and a final eligibility check. The creator can cancel before acceptance.
- Where data lives: the server, database and push tokens are in Norway. Photos and files are in a private EU (Finland) bucket and are only reachable through short-lived signed links.
- Visibility: each person sees only what their membership and the family's visibility settings allow. The same rules apply in the app, the assistant, the public API and MCP.
- Export: Export my data, next to the privacy policy in the app, returns everything your account may see as JSON.
- Original media: the media export lists downloadable photo, document and posted-message originals separately from the JSON. Download the JSON once, then download each ZIP part from the list; each part contains at most 100 originals and 50 MiB of raw data. Files larger than that, missing originals and unavailable storage are listed instead of silently skipped. A ZIP is returned only when every original in that part has been read and verified. If a part reports that the list changed or a read failed, refresh the list and retry that part. Original downloads are never cached by the app.
- Media export validation: ZIP parts are generated on demand and are not retained by the service. S3 storage and native iOS/Android download-and-share flows still require validation with real storage and devices.
- Deletion: deleting your account removes it and its sessions and access tokens. If you created a family that others still use, transfer or close it first.
- Access tokens: tokens for your own integrations are stored only as hashes. See Access tokens.
- Your own AI key: stays on your phone. See Assistant.
For the implemented export, deletion and retention behavior of every persisted collection, see the data lifecycle inventory. It also lists the remaining policy decisions and provider/backup verification.