Please read this short summary of how Family handles your data before continuing. Our lawyer is reviewing a full policy and will publish a finalized version before public beta — you'll be asked to re-accept then.
What we collect
- Account info — email, name, country, currency.
- Financial data you create — accounts, transactions, balances, budgets, goals.
- Calendar data — events, reminders, habits, tasks.
- Connections — who you connect to, and what you explicitly share inside pools / shared goals / shared budgets.
- Light technical events — sign-ins, invite-sends, etc., for security and abuse prevention. Not for marketing.
We don't ask you for bank credentials or login passwords — and you shouldn't enter them anywhere in the app. We never connect to your bank, never move money, never need access to your accounts. FF is a tracker: you tell it what your balances are, it does the math. By design, there's no place in the app to enter credentials.
We also don't collect: file uploads (photos, scanned statements, PDFs), behavioral analytics, fingerprinting, or third-party tracking pixels. No ads, ever.
Where it's stored
- Firebase (Google Cloud) — Firestore + Auth + Cloud Functions, in Google's
us-central1 region. Encrypted at rest.
- SendGrid — outbound email delivery only (invites, password resets, verification).
That's it. Your data isn't copied anywhere else.
Who can see your data
- You. Always. Export via Settings → Export; delete via Settings → Delete account.
- People you explicitly share with. Inside a pool, shared goal, shared budget, or connection — visible to those people only. Nothing else.
- Google and SendGrid as infrastructure providers. Bound by their own terms; they don't get to use your data for their products.
Administrators do NOT read your data. Our admin tools manage account-level operations only — approving waitlist signups, setting invite quotas, processing deletions, investigating abuse reports. They are not designed to and not used to browse your financial data or other content. Every administrative action writes to an audit log.
We don't sell your data, share it with advertisers, or provide it to anyone else.
Security measures in place
- Firebase Authentication (Google-managed).
- Email verification required.
- Invite-only registration — sign-up gated to allowlisted emails.
- Per-document Firestore security rules — even guessing an ID doesn't grant access.
- Server-side sensitive operations on Cloud Functions, not in the browser.
- Rate limiting on invite-create and signup endpoints.
- IP-address hashing — we don't store raw IPs.
- HTTPS everywhere; API keys in Firebase Secret Manager (not in source).
- Audit logging for administrative + connection-changing actions.
Ongoing security work + what we're still building toward:
- Continuous security review — automated security-audit routines run against the code before each release; separate AI review agents do quality + interaction QA passes on every meaningful change.
- Formal paid 3rd-party audit — planned before public launch. A bigger engagement than the informal review above; we'll commission one when we're ready to open the doors wide.
- Two-factor authentication — planned for the public-beta build.
- ISO / SOC2-style certifications — planned as we grow.
If you accept
By accepting, you confirm you've read this and agree to use the Family alpha on these terms. You can revoke acceptance any time by deleting your account. Re-acceptance will be required when our lawyer publishes the final version.
Questions? Email admin@finflowfamily.com before accepting.