Skip to content
FAM360

Legal

Privacy Policy

How FAM360 handles personal data in its iPhone and Android apps, on fam360.app and in its e-mails. FAM360 is free and shows no ads.

Responsible for FAM360
NEOVIASAS, SIRET 990 188 724 00019
Postal address
9 rue de Condé 33000 Bordeaux France
Privacy contact
hello@fam360.app
Hosting
Hostinger, France

This policy explains how the company named under "Who is responsible" at the top of this page ("we", "us") processes personal data when you use the FAM360 apps for iPhone and Android, the website fam360.app and the e-mails we send. FAM360 is free. We do not sell personal data, we show no advertising and we do not track you across other companies' apps or websites.

Some features described below are not available yet: location history, places and arrival and departure alerts, SOS alarms, screen time and parental controls. Their sections say "when available". We describe them now so that this policy stays true on the day we switch one on. Until then the apps do not offer them and their data is not collected, except the sharing records described in 4.6.

1. Who is responsible

  • Controller: the company named under "Who is responsible" at the top of this page, at the postal address given there.
  • Privacy questions and requests: the privacy contact e-mail given there.
  • No data protection officer is currently appointed. Privacy requests can be sent to the privacy contact e-mail given there.

2. In short

  • You decide whether your location is shared, with whom, and how precisely. Joining a family or a group never switches sharing on.
  • Children have no account. A parent or guardian creates a child profile and connects the child's phone. The child's phone always shows that it is connected and what is shared.
  • We keep positions for hours, not months: raw positions 24 hours with the default settings, and never more than 7 days.
  • Our staff cannot see where anybody is. No screen of our administration console shows a location.
  • You can delete your account in the app or at fam360.app/account-deletion.

3. Whose data we process

  • People who create an account, who must be aged 18 or older.
  • Children for whom a parent or guardian creates a child profile. They have no account.
  • People invited by e-mail to a family or a group, before they answer.
  • People who share their location with you or with whom you share yours, within FAM360.
  • Visitors of fam360.app, and people who write to us.

4. What we collect and why

4.1 Your account

  • Your e-mail address, password, display name, first name (optional), avatar (a colour or one of FAM360's own pictures: you cannot upload a photo), language and time zone.
  • Your password is stored only as an Argon2id hash. Nobody at FAM360 can read it.
  • When you accept the terms and this policy, we record the date, the version, a keyed hash of your IP address and the user agent of your app or browser.
  • If our support team created your account for you, we used the e-mail address and name provided to us to send you an activation link. You choose your own password.
  • Links we e-mail you (address confirmation, password reset, activation, account deletion) are single-use and stored only as a hash until they expire.

Why: to create and run your account, sign you in and write to you about it. Children use FAM360 only through a child profile (section 5).

4.2 Sign-ins

Each sign-in creates a session that records the platform (iPhone, Android or web), the device name and app version sent by the app, when it was last used, the user agent and a keyed hash of your IP address. You can see your sessions in the app and end them.

Why: to keep you signed in, let you sign out other phones and detect misuse.

4.3 Families, groups and invitations

  • The families you create or join: the family name, its members, their roles and when they joined, and the permissions each guardian holds for each child. If you leave a family, the record that you were a member stays while your account and the family exist.
  • Groups of people close to you outside your family: the group name, its members and their roles.
  • Your sharing choice in each family and group: on, paused or off, and exact or approximate.
  • Invitations: the e-mail address of the person invited (typed by the adult who invites them), the role offered, the status and the dates. The invited person receives an e-mail with the inviter's name and the name of the family or group. An invitation expires after 7 days with the default settings.

Why: to provide the family and group features you use.

4.4 Your phones

  • A random installation identifier created by the app. It is not a hardware identifier and not an advertising identifier.
  • The device name, the manufacturer (Android), the model, the operating system version, and the app version and build.
  • Which permissions are granted (for example location or notifications) and which features the phone supports: the state only, never what a permission gives access to.
  • When the phone last checked in, its battery level and whether it is charging (the current value only, no history), and whether its last location report was accepted.
  • A push notification token, stored encrypted.
  • We do not collect advertising identifiers, IMEI or serial numbers, MAC addresses, your contacts, your photos, the microphone, your messages or your browsing history.

Why: to deliver notifications, show whether a phone is set up and reachable (for example when its battery is low or a permission was removed), and help you when something does not work. Who sees it: you and, for a child's phone, the child's guardians. Our support staff see device information, never a location.

4.5 Location

Your phone sends your location only when three things are true: location sharing is available in FAM360, at least one person may see you (because you chose to share with them, or, for a child's phone, because a guardian may see the child), and the phone's location permission is granted. When nobody may see you, your phone is told to stop and anything it still sends is discarded.

  • What the phone sends: latitude, longitude, accuracy and the time of the fix, and, when the phone provides them, altitude, speed and direction of travel. We store speed, altitude and direction with the raw position but never show them to anyone. FAM360 has no driving detection, speed monitoring or journey scoring.
  • With your permission, the app also sends positions while it is closed (background location). With the default settings, the phone notes a new position only after you have moved and sends what it noted in small batches, normally every 15 minutes or so; during live mode it sends about every 10 seconds.
  • Live mode is requested by someone who may already see you and lasts 15 minutes at most. You receive a notification and your screen shows it while it runs.
  • Who sees your location: the members of the families and groups you share with, at the precision you chose. Approximate means an area (about 1 km across with the default settings) computed on our servers: the phone of someone who sees you approximately never receives your exact position. You can pause or stop sharing at any time, and it takes effect immediately.
  • Your current position is kept only while someone may see it. Raw positions are kept 24 hours with the default settings and never more than 7 days.
  • While offline, the app keeps a small number of recent positions (50 with the default settings) in memory, never on disk, and sends them when the connection returns.
  • Your position is determined by your phone's own location services (Apple, or Google Play services on Android), under your device settings and those companies' terms.
  • The map is provided by MapTiler (section 7): your phone asks MapTiler for the map area shown on your screen.

Why: to show your position to the people you chose and, when they are available, to provide history, places, alerts and SOS.

4.6 Location history (when available)

When location history is available, your positions are condensed into a short route and the places where you stayed. They are kept 7 days with the default settings and never more than 30. Someone can see your past only for the periods when you shared with them, and only as precisely as you shared then: with the default settings, approximate history is shown as areas of about 2 km, in 15-minute steps. You can see your own history. A guardian needs a separate permission to see a child's history.

To apply this rule we record when each person could see you and how precisely, never the position itself. These records are kept already, before history is available, while they describe the present; once they have ended they are deleted after the history retention period (7 days with the default settings).

4.7 Places and arrival and departure alerts (when available)

  • A place has a name, a type (such as home, school or work), a centre point and a radius between 100 m and 5 km. Places belong to a family and are created by the family owner or a guardian with the places permission.
  • A child can be added to a place by a guardian. An adult can only add themselves.
  • Our servers decide arrivals and departures from the positions described above. Each event (the place name at that time, the person, the time) is kept 30 days with the default settings and never more than 90.
  • An alert that names a place is sent only to someone who may see that person's exact position. Each person chooses the alerts they receive.
  • On iPhone, the place and history screens show Apple Maps: your phone asks Apple for the map area shown.

4.8 SOS alarms (when available)

  • When you raise an SOS, we record the alarm: when it started and ended, its state, whether it went to your family or your groups, who was notified and how it ended. No position is stored in the alarm.
  • While the alarm runs (60 minutes at most with the default settings), the people notified can see your exact position, even if you normally share approximately with them, have paused, or have not switched sharing on in that family or group. Your phone sends positions during your own alarm even if you share with nobody. When the alarm ends, your usual settings apply again: an alarm never changes them.
  • FAM360 does not contact emergency services. In an emergency, call your local emergency number.
  • Alarm records are kept 90 days after the alarm ends with the default settings, and never more than 365.

4.9 Notifications

  • Your notification choices and your quiet hours (start, end and time zone). SOS alerts cannot be muted.
  • The words of a notification are written on your phone from templates in the app, but the message we send carries short values such as a first name, a place name, a group name, a device name, a number of minutes or a battery level, never a position. These values pass through Apple (iPhone) or Google (Android) to reach your phone, and may appear on your lock screen.
  • We keep no inbox of the notifications sent to you. Our delivery queue keeps its most recent deliveries (the type of notification and those short values) for troubleshooting, until newer deliveries replace them.

4.10 E-mails

  • Service e-mails (address confirmation, password reset, invitations, deletion confirmations, security notices) go to the address concerned. Information about the service itself, for example a change to these documents or to the service, may be sent to all verified adult accounts. You cannot opt out of these while you have an account.
  • Newsletters go only to verified adult account holders who have expressly chosen to receive them. Nobody is signed up on their behalf. Each newsletter has an unsubscribe link that works without signing in, and you can withdraw your choice at any time.
  • Our e-mails contain no tracking: we do not measure whether you open them or click their links.
  • For each e-mail we keep a delivery record for 90 days: a masked and hashed form of the address, the subject, the type of message and its delivery status. We never keep the text of the message.
  • When an address bounces, reports spam or unsubscribes, we keep a hashed and masked record of it so that we do not write to it again.

4.11 Security records and technical logs

  • We keep a security log of important actions, for example sign-ins, changes to a family, a phone connected or removed, or a deletion request. It uses internal identifiers and a keyed hash of the IP address, never a position.
  • Our servers log each request to our service (IP address, time, path without its parameters, result) for security and troubleshooting. Passwords, tokens and positions are removed from these logs.
  • To stop abuse, we count requests per account, IP address and phone over short periods (from minutes to a day), using hashed identifiers.

4.12 The website

fam360.app has no analytics, advertising or social-media trackers. The servers that deliver it may record technical data about each request (IP address, time, page requested) for security, as in 4.11. The only cookie is described in section 14.

4.13 Writing to us

When you write to our support or privacy address, we use your message and your address only to answer you and follow up, and we keep them no longer than that needs. Never send us your password: we never ask for it.

5. Children

  • Children have no account, no e-mail address and no password. An adult with the owner or guardian role in a family creates a child profile (a first name or nickname, an optional birth date and an avatar) and becomes the child's first guardian, with every permission. We record that this adult authorised the processing of the child's data. Other adults become guardians only with the permissions the family owner gives them.
  • By creating a child profile, you confirm that you are the child's parent or legal guardian, or that you act with their authority.
  • A child's phone is connected only by a guardian, with a single-use code or QR code valid for a few minutes (15 at most). The phone then has its own credential. It never shows where anyone else is, and it cannot disconnect itself; a guardian can.
  • The child's phone always shows that it is connected and to which family, whether its location is shared and with whom, and when someone asks for live location. FAM360 never hides on a child's phone.
  • A child's phone sends its location once a guardian may see the child and location is allowed on the phone, and while FAM360 is closed only if background location is allowed there too. On Android, a connected child's phone shows a permanent "FAM360 is connected" notification whenever the app runs, and it sends nothing while FAM360 is closed if that notification cannot be shown.
  • By default, the guardian who created the profile can see the exact location of the child's connected phone. Other guardians need the location permission. Other family members see a child's location only if a guardian switches it on, exactly or approximately. A guardian needs separate permissions to see a child's history and screen time.
  • What we collect about a child: the profile; the phone information in 4.4; the location in 4.5; and, when available, the history, places and alarms in 4.6 to 4.8 and the parental controls below.
  • Parental controls (when available): the rules guardians set (daily allowance, limits per app, bedtime, school timetable) with the history of who changed them and when; temporary extra time; and extra-time requests (the minutes asked for and, when the phone knows it, the app the child was using).
  • Screen time on Android (when available): when screen-time reporting is switched on and Usage access is allowed on the child's phone, the phone sends, for each day, the total minutes and the minutes per app, with the app's identifier and name. We never collect the order in which apps were opened. Kept 30 days with the default settings and never more than 90.
  • Screen time on iPhone: Apple does not let these figures leave the phone, so we receive none. FAM360 on iPhone does not choose or read the child's apps; when parental controls are available, it may ask for Apple's Screen Time permission, and we only record whether it was granted.
  • Retention: rules and their history while the profile exists; temporary extra time 7 days after it ends; extra-time requests 60 days after they were answered or expired with the default settings, and never more than 365; screen time as above. Deleting a child profile deletes it with everything attached to it; stored positions are erased by the next hourly clean-up at the latest.

6. Legal bases

  • Performance of our contract with you: your account, families, groups, the features you use, service e-mails and support.
  • Your consent: sharing your location, the phone permissions you grant (location, notifications, Usage access), and the newsletters you chose to receive. You withdraw it by switching sharing off, pausing it, removing the permission or unsubscribing.
  • Our legitimate interests: security, preventing abuse and fraud, security records and server logs, and, for children, the interest of parents and guardians in their child's safety as they decide it.
  • Vital interests: an SOS alarm, where it is needed to protect someone.
  • Legal obligations: answering lawful requests from authorities and keeping records the law requires.

An e-mail address, a password and a name are needed to have an account. Everything else is optional. We make no decision with legal or similarly significant effects about you by automated means, and we do not profile you for advertising.

7. Who receives your data

We never sell personal data and never share it with advertisers or data brokers. Your data goes:

  • to the people you choose, as described above;
  • to our service providers, who process it on our instructions and only to provide the service;
  • to authorities, when the law requires it.

Our service providers:

  • The hosting provider named under "Who is responsible" at the top of this page hosts our servers, database and website.
  • Backups of our database are kept by our hosting provider or by a storage provider acting on our instructions.
  • MapTiler (MapTiler AG, Switzerland) provides the map. Your phone contacts MapTiler directly. MapTiler receives your IP address, technical information about the app and the map tiles requested, which reveal the area shown on your screen. We never send MapTiler your name, your account or anyone's position.
  • Apple provides the maps of the place and history screens on iPhone (Apple Maps), when those screens are available. Your phone asks Apple directly for the map area shown; we send Apple no name, account or position.
  • Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging) deliver notifications. They receive the push token and the notification content described in 4.9. On Android, Google's Firebase software also sends Google an installation identifier and technical information about the app in order to deliver messages.
  • Mailjet, a company of the Sinch group, sends our e-mails. It receives the address, the message (including single-use links) and reports delivery events to us.
  • Google, on a child's Android phone only: when the phone scans a pairing QR code, it uses Google's code scanner, provided by Google Play services. According to Google, the scanner sends Google device information, the app version, performance measurements and an identifier used for diagnostics.

Our staff: support staff can see account details (e-mail address, name, status), family and group membership, children's first names, whether sharing is on in a group, and device information, only as needed to help. Their access requires two-factor authentication, depends on their role and is logged. No console screen shows a position, a location history or a place.

8. International transfers

Our servers are located in the country named with the hosting provider at the top of this page. Mailjet keeps e-mail data in data centres in the European Union, in Germany and Belgium. Some of our providers are established, or process data, outside the European Economic Area:

  • MapTiler AG is established in Switzerland, a country the European Commission recognises as ensuring an adequate level of protection.
  • Apple states that its transfers of personal data from the European Economic Area are governed by the European Commission's standard contractual clauses.
  • Google LLC is certified under the EU-U.S. Data Privacy Framework, which the European Commission recognised on 10 July 2023 as ensuring an adequate level of protection for certified companies, and relies on the European Commission's standard contractual clauses where needed.

You can ask us for more information about these safeguards at the privacy contact e-mail given at the top of this page.

9. How long we keep data

Periods said to apply "with the default settings" are settings we can change, never beyond the maximum shown.

  • Account: until you delete it, then 30 days before permanent deletion (section 12).
  • Sessions: until they expire (180 days with the default settings) or you sign out, then 7 days.
  • Links we e-mail you: until they expire, then 7 days.
  • Current position: only while someone may see you.
  • Raw positions: 24 hours with the default settings, 7 days at most.
  • Location history, when available: 7 days with the default settings, 30 days at most.
  • Arrivals and departures, when available: 30 days with the default settings, 90 days at most.
  • Live-mode requests: 7 days after they end.
  • SOS alarms, when available: 90 days after they end with the default settings, 365 days at most.
  • Android screen time, when available: 30 days with the default settings, 90 days at most. Extra-time requests: 60 days with the default settings, 365 days at most. Temporary extra time: 7 days after it ends.
  • A child's rules: while the child profile exists.
  • Phones: while your account, or the child profile, exists. A removed phone stays listed as removed; its credentials and push token are deleted 30 days after removal.
  • Places, when available: while the family exists. A place you delete stops being used and shown at once; its record is erased when the family is deleted.
  • Families: while they have members. A family deleted together with an account is erased 30 days later.
  • Invitations: group invitations 30 days after they close; family invitations while the family exists. Invitations sent to an address are erased when the account using that address is deleted.
  • Groups: a deleted group is erased 30 days later; ended group memberships 90 days after they end.
  • E-mail delivery records: 90 days, or until the account concerned is deleted. Records of addresses that bounced, complained or unsubscribed: until removed on request.
  • Security log: 400 days.
  • Server logs: they stay on our hosting server and are not sent to any other service. We have not set a fixed period for them: each part of the service keeps its log until that part is replaced by newer versions and removed from the server.
  • Backups: a backup holds the data that existed when it was made. Information you delete therefore remains in the backups made before its deletion until those backups are deleted in turn. Backups are used only to restore the service after an incident.

10. Security

  • The apps and the website talk to our servers over HTTPS (TLS).
  • Passwords are hashed with Argon2id. Sign-in, verification, invitation and pairing tokens are stored only as hashes. Push tokens and our e-mail provider credentials are encrypted. IP addresses are stored in our database only as keyed hashes.
  • Staff access requires a password and two-factor authentication, is limited by role and is logged. No staff screen shows where anyone is.
  • On your phone, sign-in and pairing credentials are kept in the iOS Keychain or the Android Keystore. Android app backups are disabled.
  • Approximate positions are computed on our servers, never on the viewer's phone.
  • No system is perfectly secure. If a breach affects your data, we will inform you and the authorities as the law requires.

11. Your rights

You can:

  • access your data and receive a copy in a portable format;
  • correct it: you can change your name, first name and avatar in the app; to change your e-mail address, write to us;
  • delete it (section 12);
  • restrict or object to some processing;
  • withdraw your consent at any time (switch sharing off, pause it, remove a phone permission, unsubscribe), without affecting what was done before;
  • complain to the Commission nationale de l'informatique et des libertés (CNIL), 3 Place de Fontenoy, 75007 Paris, France, www.cnil.fr, or to the data protection authority of the country where you live.

Write to the privacy contact e-mail given at the top of this page. We answer within one month, or tell you why we need longer, as the law allows. We may ask you to confirm your identity, usually by writing from your account's e-mail address. Parents and guardians exercise their child's rights; a child can ask a parent or write to us.

12. Deleting your account

  • In the app: Settings, Account, then Delete my account. The app shows what will happen and asks for your password.
  • On the web, without the app: fam360.app/account-deletion. Enter your e-mail address; we send a link valid for 30 minutes that can be used once; the page shows what will happen before you confirm.
  • You cannot delete your account while you own a family that has other adults, or while you are the only guardian of a child in a family that has other adults. The app and the page tell you what to do first.
  • As soon as you confirm: your positions, location history, arrivals and departures and place settings are erased; the families where you are the only adult are deleted with their child profiles and places; you leave your other families and your groups; your pending invitations are cancelled; your phones are disconnected and you are signed out everywhere; an SOS you raised is ended. Your account can no longer be used.
  • 30 days later, everything that remains is permanently deleted: your account, your profile, your settings, the e-mail records and invitations linked to your address, and the families deleted with your account. A deletion cannot be cancelled. If you did not ask for it, someone may know your password or be able to read your e-mail: change those passwords.
  • What remains afterwards: security log entries that name you only by an internal identifier, for up to 400 days; a hashed and masked record if your address bounced, complained or unsubscribed; and, until they are deleted in turn, the backups made before your deletion, which are used only to restore the service.

13. What we do not do

  • We do not sell or rent personal data.
  • We show no advertising and use no advertising identifier.
  • The apps contain no analytics, crash-reporting or advertising software. The only third-party software in them that sends data to its maker is Google's, on Android, as described in section 7.
  • We do not track you across other companies' apps or websites.
  • We never record sound, pictures, messages or keystrokes. The camera is used only to scan a pairing code on a child's phone, and the image never leaves the phone. The app never hides itself.
  • Our staff cannot see where anybody is.

14. Cookies

fam360.app may set one cookie, NEXT_LOCALE, to remember the language of the pages you read. It is needed for the site to work in your language, contains nothing else and expires at the end of your browsing session. We use no analytics, advertising or tracking cookies, so we do not ask for your consent to them.

15. Changes to this policy

We publish every change on this page with its effective date. We tell account holders about a significant change by e-mail at least 30 days before it takes effect, unless a shorter period is required for legal or security reasons.

16. Contact

The name, postal address and privacy contact e-mail given under "Who is responsible" at the top of this page. For help with the app, see fam360.app/support.