FamilyFlow
Privacy Policy
Last updated: August 12, 2026
FamilyFlow (“the app”) is a family wall calendar that helps households view and manage Google Calendar events, chores, lists, weather, and related settings in a browser-based wall display.
Information we access
- Google account basics — name, email address, and profile image used to sign you in.
- Google Calendar — calendar lists and events you choose to connect, so the app can display, create, edit, and delete events on your behalf. FamilyFlow requests the Google Calendar scope (not read-only) because wall users create, update, and remove events from the app.
- Household content you enter — people, chores, lists, RSS feeds, weather location preferences, and display settings.
- Optional device notifications — if you enable push notifications, a browser push subscription endpoint is stored so we can send chore and reminder alerts to that device.
How we use Google user data
Google user data is used only to provide FamilyFlow features you request: signing in, showing your calendars on the wall, and syncing event changes you make in the app. We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train AI/ML models. We do not transfer Google user data to third parties except as needed to run the service (hosting/database providers that process data under our instruction).
Data protection
We protect account, household, and Google-connected data with these measures:
- Encryption in transit — the app is served over HTTPS; requests between your browser, FamilyFlow servers, and Google APIs use TLS.
- Access controls — Google Calendar access is available only after you sign in with Google and grant consent. Household data is limited to members of that household. Server APIs check session membership before reading or changing data.
- Credential handling — Google OAuth access and refresh tokens are stored in our application database so Calendar sync can continue until you disconnect or revoke access. Tokens are not embedded in client-side code or public pages.
- Least use of Google data — Calendar data is fetched to render the wall and to perform the create/edit/delete actions you initiate. We do not scrape unrelated Google products or retain Calendar payloads beyond what the service needs to operate.
- Infrastructure safeguards — application hosting and database providers keep data in secured cloud environments; access to production configuration and secrets is limited to operators of the FamilyFlow project.
- Incident response — if we become aware of unauthorized access to Google user data we store, we will investigate, take steps to contain the issue, and notify affected users where required.
Storage
Account and household data are stored in our application database. Google access tokens are stored so the app can keep Calendar sync working until you disconnect or revoke access. Weather requests use Open-Meteo and do not require a Google account.
Data retention and deletion
We retain account, household, and token data while your household remains active. When you revoke FamilyFlow in Google Account permissions, Calendar API access stops. You may also email us to request deletion of household data associated with your account; we will delete or de-identify that data from our systems within a reasonable period, except where we must retain limited records for security or legal reasons.
Sharing within a household
If you invite someone to your household with an invite code, members of that household can see shared household content (such as chores and lists) and calendars you connect for that household wall.
Your choices
- Revoke FamilyFlow access anytime in your Google Account permissions.
- Contact us to request deletion of your household data associated with your account.
Contact
Questions about this policy: rosenauproductions@gmail.com.