Privacy Policy
Effective September 20, 2026
This is how Famile handles personal data — yours, and that of the relatives, including children and people who have passed away, whose photos and details your family keeps here. We wrote it to be read, not skimmed.
The short version
A summary to make it easy. The full text below is what counts.
-
Your memories are yours
You own them. We store them, make smaller copies so they open quickly and show them to your family, and that's all we do with them.
-
Paid for by families
Families pay for Famile, so there are no ads. We never sell your data, track you or use analytics cookies.
-
Never used to train AI, and faces stay on your device
Nothing you share is ever used to train AI. If you choose "Group by face" when you bring in photos, the matching happens in your own browser: nothing about a face is sent to us or stored, and it's forgotten when you leave the page. We don't profile anyone or make automated decisions about them.
-
Only your family sees your family
Your family is never public, and only the people you add can see inside. Our moderators see something only when it's reported to us, and nobody browses a family's photos.
-
Export or delete, any time
Download everything you added, or delete your account. You have 30 days to change your mind, and you choose what stays with your family.
-
Encrypted, in transit and at rest
Everything is encrypted on its way to us and where it's stored, and phone numbers, emails and birthdays are encrypted again in the database. It isn't end-to-end encrypted, because our systems work with your files to make thumbnails and play videos.
1. Who is responsible
The data controller is Validera (validera.co), the company behind Famile. Reach us at [email protected].
Within a family, the member who uploads a photo or adds a profile decides what is shared; we provide the means. This policy covers what we, the provider, do with the data.
2. What we collect
- Account: your phone number and/or email address, your date of birth (to check you are at least 13), language and appearance preferences, when you accepted the terms. If you are under 16, also who gave parent or guardian consent and when.
- Your profile in each family: name, nickname, photo, date of birth, gender, phone number, city and country if you add them, and whether you've stepped out of the family.
- Content: photos, videos and voice notes with the dates and (if the file carries it) the place they were taken, captions, titles, comments, reactions, tags of who is in a photo, mentions, wall posts, albums, events and check-ins.
- Profiles of relatives added by family members: name, nickname, dates of birth and death, gender, relationships, phone number if known, photos they appear in.
- Technical: the devices and browsers you sign in from, session tokens, IP addresses and times in our server logs, push notification tokens if you turn notifications on, and error reports if the app crashes.
- How you found us, when you sign up: the page you first opened on that visit, the name of the site or app that sent you (if your browser says), any campaign tag in the link, and your answer, if you give one, to "How did you hear about Famile?".
- Payments: plan and billing history. Card details are handled by our payment provider and never reach us.
- Support and reports: what you write to us, and reports you make or that are made about your content.
3. Why, and on what legal basis
- To run Famile for you — storing and showing your family's content, sign-in, notifications you've chosen, plans and billing: performance of our contract with you (GDPR Art. 6(1)(b)).
- To store and show photos, details and profiles of your relatives who are not account holders, including children and people who have passed away: the legitimate interest (Art. 6(1)(f)) of your family in keeping and sharing its own memories privately, weighed against those relatives' interests — which is why Famile is invite-only, never public, never advertising-funded, and lets anyone in a photo untag themselves or ask for it to be removed.
- To keep Famile safe — the word filter, reports, blocks, suspensions, rate limits, security logs: our legitimate interest in a safe service, and legal obligations where they apply.
- Crash reports: our legitimate interest in a working app; they contain no photos and we scrub personal details where we can.
- To learn which links, partners and campaigns bring families to Famile, and to pay partners correctly: our legitimate interest. It is counted in totals and never used to target anyone.
- To keep billing records: legal obligation (tax law).
- Anything optional — marketing email, for instance — only with your consent, which you can withdraw as easily as you gave it. Today there is none.
We do not profile you, do not use automated decision-making, and do not use your content to train AI. We do not run facial recognition on our servers. When you bring in a batch of photos you can choose "Group by face": your own browser then finds the faces in that batch and groups the ones that look alike so you can say who they are. That matching happens entirely on your device, is never sent to us, is never stored anywhere, and is forgotten when you leave the page; the only thing we receive is the tag you choose to save ("this photo shows Rania"), exactly as if you had tagged it by hand. We never match faces against other photos, profiles or anything else.
4. If you appear in Famile but don't have an account
A relative may have added a profile for you, or photos you're in, so that your family can keep them together. That is their decision inside a private family, made under the legitimate interest above. You can ask that relative, or us at [email protected], to correct or remove anything about you; if you are in a photo you would rather not be in, tell us and we'll ask the uploader and the family's admin to remove it, and remove it ourselves if they don't. If you later create an account, the profile becomes yours to control.
5. Children
Nobody under 13 may hold an account; we check the date of birth at sign-in. From 13 to 15, an account needs a parent or guardian's consent, which we record (who gave it and when); that parent or guardian can withdraw it at any time by removing the number or the profile, or by writing to [email protected], and we then close the account. We hold no more about a teenager than about anyone else, show them nothing outside their family, and never advertise to or profile anyone. Younger children appear in Famile only as profiles and in photos added by adult family members, who are responsible for them. We treat requests to remove content about a child as urgent, and we apply our child safety standards (Terms, section 7) to every report.
6. Who sees your data
The members of your family, according to what you and they share: private circles limit content to their members, a private wall post to two people, and blocking hides two people from each other. Your family's admin can see and remove content in the family and receives reports.
Our moderators see reported content and what is needed to act on it. Nobody at Famile browses families' photos otherwise.
Companies that process data for us, under contracts that bind them to our instructions and to GDPR Article 28:
- Backblaze, Inc. (USA) — file storage for photos, videos and voice notes, kept in the EU (Netherlands).
- Heroku, part of Salesforce, Inc. (USA) — the servers and database, run in the EU (Ireland).
- Resend, Inc. (USA) — sending our email: sign-in codes, receipts, gift codes and replies to your messages.
- Twilio Inc. (USA) and SMS Misr (Egypt) — sending sign-in codes by SMS.
- Cloudflare, Inc. (USA) — the check that a person, not a program, is signing in or sending one of our forms (Turnstile), which reads technical signals from your browser.
- Rollbar, Inc. (USA) — error reports from the app and the website, with personal details scrubbed and IP addresses anonymised before they are sent.
- Paymob (Egypt) — payments on our website; card and wallet details go to Paymob, never to us, and Paymob is also an independent controller for the payment itself.
- Apple and Google — push notifications on their platforms, and the app stores themselves.
We share data with authorities only when the law requires it or a child's safety demands it. We never sell personal data.
7. Where your data goes
Some of the companies above are in the United States. Transfers there rest on the EU–US Data Privacy Framework where the company is certified, and otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum for the United Kingdom), with additional safeguards where needed. You can ask us for a copy of these safeguards.
8. How long we keep things
- Your content: as long as your family keeps it. What you delete is removed from our storage.
- Your account: until you delete it. Deletion is scheduled for 30 days, during which you can cancel by signing in; after that your details are erased and files you chose to remove are removed from our storage. Content you chose to leave with your family stays, attributed to "a former member".
- Sign-in codes: minutes. Sessions: until you end them or they expire.
- Server logs and security records: up to 12 months.
- Reports and moderation records: 12 months after they are closed, longer where the law requires.
- Billing records: as long as tax law requires, typically 6 to 10 years.
9. Your rights, and how to use them
You can access, correct, export and delete your data, restrict or object to how we use it, and withdraw any consent. In the app: edit your profile in Settings, download everything you've added from Settings › Download my data, delete your account from Settings › Delete account (on our website, an account with a phone number can start it at famile.org/delete-account with a code sent to the number; any other account signs in first), remove your own tag from any photo, and ask for a photo of you to be removed from its page. For anything else, or if you don't have an account, write to [email protected]; we answer within a month.
You also have the right to complain to a data protection authority — in the EU, the one where you live or work; in the UK, the Information Commissioner's Office.
10. Security
Everything travels encrypted. Phone numbers, emails and dates of birth are encrypted in our database. Photos are served only to signed-in members who are allowed to see them, through links that expire. Sign-in codes are short-lived and rate-limited, and you can end any session from Settings. If a breach ever puts you at risk we will tell you, and the authorities, without undue delay.
11. Signing in with Google, Apple or Facebook
If you sign in with Google, Apple or Facebook, we receive from that provider your name and email address (when it gives them; Apple gives your name only the first time, and may give a private relay address instead of your own), and an identifier that is yours alone at that provider. We receive nothing else, such as contacts, friends or posts. We keep the identifier and the email so that you can sign in again and so that Settings can show which account is connected.
From Apple we also keep a token. We use it only to tell Apple to end the connection when you disconnect Apple in Settings or delete your account.
To remove Famile from Facebook: in Facebook go to Settings & privacy, then Settings, then Apps and websites, choose Famile and select Remove. This ends the connection on Facebook's side; to remove it on ours, disconnect Facebook in Settings, Sign-in methods in Famile. Doing it on both sides is fine.
To delete your Famile data, including the link to the provider: open Settings, then Delete account, in Famile. On our website, an account with a phone number can start this at famile.org/delete-account with a code sent to that number; an account that signs in with Google, Apple, Facebook or an email signs in first and lands on Delete account. There is a 30-day period in which you can change your mind. You can also write to [email protected].
12. Cookies
Famile uses only the cookies it needs to work: your session, protection against forged requests, your language and, until you sign up, the page and site you arrived from. There are no advertising or third-party analytics cookies, so there is nothing to consent to and no banner.
13. Changes and contact
If we change this policy in a way that matters we will tell you in the app and ask you to read it again. Questions, requests and complaints: [email protected].