Privacy Policy
Privacy Policy
Version 2026-08-11. Effective 11 August 2026. Replaces version 2026-08-10.
Contents
1. Who we are
FamOwl ("FamOwl", "we", "us") is a New Zealand-based service. FamOwl is the agency responsible under the New Zealand Privacy Act 2020 and, where applicable, the controller under other privacy laws.
General contact: hello@famowl.app. The FamOwl Data Protection Officer and privacy/data-rights contact can be reached at compliance@famowl.app.
2. Scope and country availability
This policy covers the native FamOwl iOS app, its account and subscription services, and famowl.app. FamOwl does not currently operate an Android app. Third-party sites and services we link to have their own policies.
Child-privacy requirements differ by country. During fresh family setup, a parent must declare the family's country before FamOwl accepts any child-profile information. The server permits collection only for countries that have a current, documented launch clearance. A country appearing in an App Store does not by itself mean child-profile onboarding has been cleared there.
United States: new child-profile onboarding is not currently available. In particular, we will not collect personal information about a child under 13 until a suitable verifiable-parental-consent method has been implemented and reviewed. We do not treat an App Store login, an ordinary email check, or an in-app checkbox as sufficient by itself.
The first intended Family Reset availability wave is New Zealand, Australia and Singapore. Each country remains disabled until its privacy, consumer, provider and store controls have been evidence-bound and activated on the server. Other countries may be added after the same review. If a country is not enabled, FamOwl stops before collecting child information.
3. What we collect
3.1 Parent account and household
- Email address and authentication records used to sign in and recover the account. Passwords are handled by Firebase Authentication; FamOwl does not store a readable copy.
- The parent's display name, household name, role and household membership.
- The country declared during setup and records showing which Terms, Privacy Policy, child-collection notice and optional consents were accepted, including their versions and timestamps.
- Subscription entitlement and product information. Apple processes payment details; FamOwl does not receive the payment card or bank-account number.
3.2 Child profile and paired device
A parent or guardian provides a child's profile information. Depending on the features used, this may include:
- a display name or nickname, avatar colour and optional avatar image;
- an optional birth year used for age-appropriate safety controls;
- the parent or guardian's child-collection declaration and consent record; and
- a paired-device record and generation used to give one device a revocable, child-scoped identity.
A paired child device is not an independent public account. It cannot access other households, and its authority ends when the pairing is revoked or replaced. We do not ask a child for an email address, phone number, home address, school, legal name or full date of birth.
3.3 Family Reset records
- Nest: family responsibilities, schedules, checklists, progress and verification. Nest earns no XP or money.
- Wings: child-specific agreements, Comfy/Stretch/Brave targets, the child's challenge choice for each run, checklists, progress, proof, verified facts, deterministic outcomes, XP transactions and levels.
- Flight: parent-approved economic work records, locked deal terms, evidence and settlements. Flight is the only money lane.
- Form and rewards: weekly Form records, reward proposals, parent approvals, earned entitlements, holds, requests, scheduling and fulfilment.
- Family record: activity and audit records showing important actions, corrections and authority changes.
Recorded family facts are kept separate from Hoot's interpretations. “Helpful preferences” fields are for ordinary day-to-day preferences only. The app tells families not to enter medical or health information, diagnoses, or details the child has asked to keep private. A child may challenge a recorded fact and a parent may correct or remove a fact. Settled history is not silently rewritten.
3.4 Optional content and technical information
- Proof photos and other files a family chooses to upload.
- Hoot conversations, family briefings, recommendations and integrity findings, only when the relevant AI feature and consent are active.
- Push-notification tokens if notifications are enabled.
- Security and operational records such as request identifiers, device/app version, timestamps, error logs and administrator-access audit entries.
- Product analytics and crash diagnostics only where the parent has given the required choice in the app. Analytics is disabled while a paired child identity is active and must not include family-entered names, mission text, photos or Hoot prompts.
3.5 Information we do not collect for our business model
FamOwl does not sell personal information, use third-party advertising networks, use advertising identifiers, or build advertising profiles about children. We do not request location, contacts, microphone recordings, medical or health information, diagnoses, or payment-card details through the app. If a family unexpectedly enters medical, health or other sensitive information in a free-text field, FamOwl treats it as personal information, lets the family correct or delete it, and does not treat that entry as permission for a new use. We do not use personal family data to train our own or a provider's general AI model.
4. Why we use information
We use personal information to:
- authenticate parents and operate a private household across authorised devices;
- provide Nest, Wings, Flight, Form and reward features;
- calculate deterministic outcomes, XP, levels and locked Flight settlements;
- provide Hoot features that a parent has separately enabled;
- process and restore subscription entitlements through Apple and RevenueCat;
- send requested notifications, provide support and respond to privacy requests;
- protect households and FamOwl from unauthorised access, abuse and duplicate operations; and
- meet legal obligations and maintain accountable access records.
Where consent is the applicable basis, it can be withdrawn in the app or by contacting us. Withdrawal does not make earlier lawful processing invalid, but it stops the associated optional feature going forward. Where a law such as the EU or UK GDPR applies, core account and service processing is generally necessary to perform the FamOwl contract; optional Hoot, proof-photo and analytics processing is based on the consent shown for that feature; security and access auditing relies on legal obligations or legitimate interests where permitted.
5. Children and indirect collection
FamOwl is bought and administered by a parent or legal guardian aged 18 or older, but children are intended users of the family experience. We design the child device as a narrow, revocable identity rather than a public child account.
Notice before a parent gives us child information
Before FamOwl accepts a child payload, the parent is shown a versioned notice and must acknowledge it. The notice explains:
- Source: information may come from the parent, the child, other authorised family members and the family's use of FamOwl.
- Purpose: to run the private family experience, including missions, choices, progress, verification, XP, Form, rewards, Flight and the family record.
- Recipients of child information: authorised members of the household; Google services that host and process the service; and, only after separate Hoot consent, approved AI-routing and model providers. Apple and RevenueCat process the parent's subscription information, not the child profile.
- Choice and consequence: providing child information is voluntary, but FamOwl cannot create a child profile or provide its family journey without the required information and clearance.
- Control: the child and parent can inspect and correct family facts and Hoot insights in the app, and can ask for access, correction, export or deletion through compliance@famowl.app.
Notice for the child
In New Zealand, children have their own access and correction rights. A parent or caregiver is not automatically entitled to every child record merely because they are an adult in the household. For a formal request, we may need to verify identity, the authority to act for the child, the child's interests, and any lawful reason to withhold another person's information.
6. Hoot and AI
Hoot is optional software, not a person, counsellor, doctor, lawyer, emergency service or substitute for a parent's judgement. Hoot can be wrong. Do not rely on it for medical, psychological, legal, financial, safety or emergency advice.
Hoot is separated from the core family service and requires the applicable parent consent. When active, selected text and structured context may be sent through OpenRouter to an approved model provider. FamOwl does not automatically send proof photos to Hoot. A parent can withdraw Hoot consent, and disabling it stops new AI processing.
Hoot may:
- propose starter Wings agreements or recommend changes for future agreements, subject to parent approval;
- provide a parent briefing or advice that clearly separates recorded facts from interpretation;
- respond to a genuinely ambiguous Brave curveball using only the frozen agreement and verified facts; and
- create reviewable suggestions or findings that cannot directly change family records.
Hoot does not choose Comfy, Stretch or Brave for a child, change a choice after a run starts, decide ordinary outcomes, invent facts, calculate XP, silently change a mission or reward, or move money. Ordinary outcomes are determined by fixed server rules. A documented ambiguous Brave miss may remain pending if Hoot cannot safely resolve it.
An integrity auditor uses deterministic checks and, where model review is used, a separately configured model family or provider. It may produce a reviewable finding, but cannot silently modify Hoot or active family state.
7. Providers and disclosures
We use a small number of providers to operate FamOwl. They receive only the information needed for the stated service.
| Provider | Purpose | When information is sent |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, server functions, notifications, security, and consented analytics/crash reporting. | For the core service and optional diagnostics selected in the app. |
| Apple | App distribution, subscriptions and payment processing. | When the app or a subscription is obtained through Apple. |
| RevenueCat | Subscription entitlement management. | When checking, buying or restoring Premium. |
| OpenRouter and an approved downstream model provider | Route and generate Hoot responses. | Only while the relevant Hoot feature and parent consent are active. |
| Cloudflare | Host famowl.app and provide DNS/TLS. | When this website is visited. |
The current approved provider list, routing controls, retention settings and transfer safeguards are release-controlled. FamOwl will not activate a country or Hoot route unless the evidence required for that release is current.
We may disclose information where required by law, to protect a person from a serious threat where the law permits it, or as part of a business transfer with notice and protections appropriate to children's data. We do not sell, rent or trade personal information.
8. Overseas processing
FamOwl is operated from New Zealand. Household database records are hosted by Google in the United States. Uploaded files and FamOwl's server functions use Google's Sydney, Australia region. Apple and RevenueCat may process subscription information outside New Zealand. If Hoot is enabled, selected content is processed by OpenRouter and approved downstream providers, generally in the United States.
For each activated country, FamOwl's release record must document whether an overseas recipient acts only as our processor/agent and, where information is disclosed overseas, the applicable contractual, legal or informed-authorisation basis. If that basis or the required safeguards have not been verified, the affected country or optional feature remains unavailable.
9. Proof photos
Proof photos are optional. The app asks for consent before the first upload, and the family can use non-photo verification where available. Photos are stored in Google Cloud Storage in Australia, are visible only to authorised household members and scoped service processes, and are not automatically sent to Hoot.
After verification, the server marks a proof photo for deletion 30 days later. A parent can request earlier deletion from the privacy controls, subject to preserving the minimum non-photo audit fact needed to protect settlement integrity.
10. Retention and deletion
| Record | Retention |
|---|---|
| Hoot conversation message text | Deleted after 90 days. |
| Family briefings and integrity findings | Deleted after 400 days. |
| Verified proof photos | Deleted 30 days after verification. |
| Private export artefacts | Deleted after seven days; each download link expires after 15 minutes. |
| Core family and settlement records | Kept while the household account is active because they provide the current service and accountable family history, then deleted through the account-deletion process unless a limited record must be retained by law. |
| Staff access and administrator audit records | Deleted after 400 days. They survive account deletion during that limited period because they are the evidence that access or deletion was authorised. |
Deleting an account removes live account and household data according to the in-app deletion flow. A cancelled subscription does not delete the account. Residual copies in provider backups may persist briefly until the provider's normal secure overwrite cycle completes. We may retain a narrowly limited record where required to meet a legal obligation, resolve a dispute or demonstrate authorised administrative access.
11. Security
FamOwl uses encrypted network connections, provider encryption at rest, server-enforced household boundaries, revocable child-device pairing, least-privilege service identities, append-only audit records for sensitive actions, rate limits, secret management and administrator-access logging. No internet service can promise perfect security. If a breach creates a risk of serious harm, we will investigate, contain it and notify affected people and regulators as required by law.
12. Access, correction and other rights
Depending on the law that applies, a parent, child or properly authorised representative may have rights to access, correct, export or delete personal information; withdraw consent; object to or restrict certain processing; and complain to a regulator.
- Inspect and correct: family-recorded facts and Hoot interpretations are shown separately in the app and have correction paths.
- Family account portability: a parent account holder can request a structured copy of the shared family-account record from Settings → Legal & privacy. This is an account feature, not a decision that the parent is the child's representative for a formal privacy request.
- Formal child request: a child can make their own request. A parent, guardian, caregiver or other representative may ask on the child's behalf, but we assess identity, the child's capacity and authorisation, best interests, possible coercion, third-party information and any lawful refusal ground before disclosure.
- Delete: a parent can start account deletion in the app. A child or representative can also contact us about the child's information.
- Withdraw optional consent: Hoot, proof-photo and analytics choices can be changed without cancelling the core account.
To start a formal request, email compliance@famowl.app with the request type, the child or profile concerned, your relationship to the child and a safe reply address. A parent account is not required. Please do not send identity documents in the first email; if evidence is necessary, we will explain the minimum needed and a safer way to provide it. Verification evidence is destroyed after the check and is not added to the family account, analytics or Hoot.
We do not assume that every parent-profile or household member is automatically entitled to every record. We double-check the recipient and delivery address, review information belonging to other people, record the decision and reasons, and use secure delivery for personal information. We respond within the time required by the applicable law—for example, generally 20 working days under the New Zealand Privacy Act, subject to any lawful extension notified to the requester.
13. Changes to this policy
Each policy revision has a version at the top of this page. If a change is material, the app requires the parent to review and accept the new version before continuing. A new country, material collection purpose, provider category or broader Hoot use will not be introduced merely through silent wording changes.
14. Contact and complaints
- General support: hello@famowl.app
- Data Protection Officer, privacy and data rights: compliance@famowl.app
- Postal address: available on a verified request to the privacy contact.
A child may contact the privacy address directly without using a parent account. Please use the subject “Privacy request” and do not attach identity documents unless we ask for the minimum evidence through an appropriate channel.
If you are not satisfied with our response, you may complain to the privacy regulator that applies where you live. In New Zealand, this is the Office of the Privacy Commissioner.