Who we are
Family Tracker is a family safety and location service operated by the account holder identified on this website. In this policy, "we", "us" and "our" refer to that operator, and "you" refers to the person using the service.
For any privacy question, or to exercise the rights described in section 9, contact us using the details in section 11.
The data we collect
We collect only what the service needs in order to function. Depending on which features a family enables, that can include:
- Account data — name, email address, password hash, chosen language, and two-factor authentication settings.
- Family data — the family you belong to, your role within it (parent, guardian or child), and invitations you send or accept.
- Location data — GPS coordinates, accuracy, speed and timestamps reported by a supervised device, plus the history of those points.
- Geofence data — the safe zones a parent defines and the entry and exit events they generate.
- Device data — device model, manufacturer, operating system, app version, battery level, charging state and push notification tokens.
- Screen time and app usage — which applications a supervised device opens and for how long.
- Captured message metadata and content — where a parent has enabled conversation monitoring on an Android device and the child device has recorded the required disclosure.
- Web and call activity — visited domains (aggregated per day, not full URLs) and call metadata, where the corresponding features are enabled.
- Billing data — subscription status, plan, and transaction identifiers. Card numbers are handled by our payment processors and never reach our servers.
How we use it
We process personal data to operate the service you asked for: showing family members on a map, alerting on geofence crossings and SOS events, enforcing the app and screen-time rules a parent sets, delivering notifications, providing customer support, preventing abuse, and taking payment for a subscription.
We do not sell personal data. We do not use the location, message or activity data of supervised children for advertising, and no advertising SDK is present in the child application.
Children's data
This service is designed to be used by a parent or legal guardian to supervise a minor in their own family. A child account is created and controlled by that parent or guardian, who is responsible for providing any consent required by law in their jurisdiction.
Consistent with the Children's Online Privacy Protection Act (COPPA) and equivalent rules elsewhere, we collect a child's data only under the direction of the supervising adult, we do not condition a child's participation on disclosing more than is reasonably necessary, and we do not serve advertising to children.
The child application is visible on the device and is not disguised. Where conversation monitoring is enabled, the supervised device records an on-device disclosure before any message content is captured.
A parent may review or delete their child's data at any time from the parent dashboard, or by contacting us.
Legal bases (GDPR)
Where the General Data Protection Regulation applies, we rely on the following bases:
- Contract — to provide the account, family, location and supervision features you have subscribed to.
- Consent — for optional features such as conversation monitoring, and for non-essential communications. Consent can be withdrawn at any time.
- Legitimate interests — to secure the service, prevent fraud and abuse, and improve reliability, balanced against your rights.
- Legal obligation — to retain billing records and to respond to lawful requests.
Transparency for the supervised person
Supervision should not be secret. The child application appears in the device app list, shows that it is active, and requires the device holder to grant the operating-system permissions that make monitoring possible. Neither Apple nor Google permits those permissions to be enabled silently from code, and we do not attempt to bypass that.
Every time a parent opens a captured conversation, that access is recorded in an audit log.
How long we keep it
Retention periods are configurable by the service operator and default to the following:
- Location history — 90 days
- Captured messages — 90 days
- Web history and call logs — 90 days
- Device telemetry — 30 days
- Notifications — 30 days
- Audit logs — 365 days
Account and billing records are kept for as long as the account exists and for the period afterwards required by tax and accounting law. When an account is deleted, associated personal data is removed or irreversibly anonymised.
Sharing and processors
We share personal data only with service providers that help us run the service, and only to the extent needed. These currently include payment processors (Stripe, Apple, Google), push notification providers (Apple Push Notification service and Firebase Cloud Messaging), our hosting provider, and, where enabled, an email or SMS delivery provider.
We may disclose data where we are legally required to, or where it is necessary to protect the vital interests of a person — for example, responding to an emergency services request following an SOS alert.
Where data is transferred outside your region, we rely on the transfer mechanisms permitted by applicable law.
Your rights
Subject to local law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.
Most of these can be exercised directly from your account settings. For anything else, contact us using the details below. We will respond within the period required by applicable law, normally within one month.
You also have the right to lodge a complaint with your local data protection authority.
Security
We protect data in transit with HTTPS, store passwords using a one-way hash, encrypt sensitive credentials at rest, and restrict administrative access. Two-factor authentication is available and is strongly recommended for parent accounts.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by law.
Changes and contact
We will update this policy when the service changes. The date shown at the top of this page reflects the most recent revision, and material changes will be communicated in the application.
To contact us about privacy, use the contact details published on this website.