Last updated 12 September 2026. This policy applies to the FamPlan applications for iPhone, iPad, Android and the web, and to the FamPlan services operated by Spydaz Holdings LLC.
Not to advertisers, not to data brokers, not to analytics companies, not to anybody. We do not rent it, trade it, or hand it over in exchange for anything, and we do not use it for advertising or profiling.
FamPlan is operated by Spydaz Holdings LLC, a company registered in the United States. We are the controller of the information described in this policy. It covers the FamPlan applications and the services behind them. It does not cover a third-party service you choose to connect to FamPlan, which is governed by that service’s own policy.
FamPlan is a shared record. Information you enter is visible to the other members of your family, according to the permissions the family’s owner and parents set. That is what the product is for, and it is the main way your information is seen by anybody other than you.
All of it is information you or another member of your family enters, or that the service generates in the course of running. We do not buy information about you and we do not collect it from other sources.
For an account holder: an email address, a password stored only as a hash, and any multi-factor authentication you enroll. If you sign in with Apple instead, we store the identifier Apple gives us for you rather than a password. For a member who signs in without an email address — typically a child — a name within the family and a PIN, also stored only as a hash. We also keep the sessions and devices signed in to an account, and a record of sign-in attempts, in order to keep the account secure.
The family name and handle, and for each member a display name, a color, an optional avatar, a role and the permissions attached to it, a birthdate if one is entered, and any private nickname another member gives them.
A push notification token and a device identifier for each signed-in device, your notification preferences and quiet hours, and which devices are currently allowed to act for a member.
Which optional modules a family has switched on and the settings it chose for them.
Where a module connects to an outside source, we store the information required to authenticate to that source, together with whatever that source returns for your family.
A module operates under the policies of the service it connects to. You accept those policies when you enable the module, and they govern that service’s handling of what passes between it and FamPlan.
Calendar feeds you subscribe to, and guest links you create to share a single event with somebody outside the family, including which link was opened and when.
When you report a problem: your description, any screenshot you attach, the screen you were on, the application version, and your device model. Before a report is sent, the app shows you exactly what will go with it, and anything optional can be switched off.
FamPlan can turn a sentence into an event. If you switch on Help improve recognition in the assistant’s settings, we keep the words you gave the app and the correction you made, in order to improve that recognition. It is off unless you turn it on, it covers only your own words, and turning it off deletes what was already collected. This setting is not available to children and the server refuses it for a child’s account.
Which plan a family is on, when it started and renews, and the receipt or subscription identifier from the store or payment processor. We do not receive or store card numbers.
Server logs, error reports, and an audit record of administrative actions taken by our own staff. These exist to run and secure the service, and to show who did what.
Counts and timings describing how the applications are used — how many events a family creates, which screens are opened, how often the app reads a sentence incorrectly. These are numbers about behavior, not the content of it. They are not published, sold or shared. There are no third-party analytics, tracking or advertising components in FamPlan.
We use the information in section 3 to:
We do not supply client data outside our own applications, except for the reasons stated in this section or where we are compelled to do so by law.
We use the service providers below. Each receives only what its function requires, may use it only to provide that function to us, and is not permitted to use it for its own purposes.
In most cases a provider will know that the request came from FamPlan and from Spydaz Holdings LLC, because that is how we are identified to them as their customer. Being a FamPlan user is therefore not something we can hide from a provider we send a request to on your behalf.
| Provider | What it receives |
|---|---|
| Amazon Web Services | Hosts the database and application servers, in the United States, and holds the encrypted automated backups of the database. |
| Cloudflare | Hosts our website and carries traffic between the applications and our servers. |
| Microsoft | Carries the transactional email the service sends to you — password resets, security notices, and replies to a support request — through our own business mail tenant. |
| Apple | Delivers notifications on Apple devices and operates the App Store and its subscriptions. A notification passes through Apple and may contain an event title. |
| Delivers notifications on Android devices and operates the Play Store and its subscriptions. | |
| Stripe | Processes subscription payments made on our website, and receives the email address and payment details you give it. Card numbers go to Stripe directly and do not reach us. |
| Anthropic | Provides the cloud AI behind four optional features: reading an event from an image or a sentence; cloud recipes and meal plans; importing a recipe from a photograph; and suggesting a likely cause for a problem report. What is sent is set out below. |
| TheMealDB | Receives the words you search for when looking for a recipe, and returns matching recipes. Nothing about you or your family is sent. |
Our helpdesk software runs on our own infrastructure. A problem report is not handed to another company to hold.
A module that connects to an outside source is separate from this list. What it sends, and the policies it operates under, are stated by the module and accepted by you when you enable it, as described in 3.5.
A cloud AI feature sends what that feature needs in order to answer, and each one states what it sends at the point you use it. Whatever is in what you give it is part of what is sent. None of them runs unless somebody asks for it and the family’s plan and permissions allow it. Cloud AI can be switched off for a member by a parent, and for the whole family by its owner. The in-app help assistant is separate: it runs on your device and nothing it reads leaves the device.
You may connect an outside AI assistant. It is optional and off until you turn it on. If you connect one, we store what it sends us. What it does with the information you give it is beyond our knowledge and is governed by its own policy and terms. You can revoke the connection at any time in Settings.
The service providers named above operate under their own terms and privacy policies. Using FamPlan, and in particular using a feature that depends on one of them, subjects you to those terms in respect of that provider.
We will disclose information where we are legally compelled to do so. We will tell you unless we are prohibited from telling you, and we will disclose no more than is demanded.
FamPlan is used by households and children’s information is in it. “Parent” and “child” here mean the roles a family assigns within FamPlan, which the Terms of Use define. We collect nothing with which to verify anybody’s actual relationship to anybody else.
A member in the child role is added only by the family’s owner or by a member in the parent role, either by enrolling a device with an invitation code and PIN or by giving them a sign-in of their own. Adding them is that person’s consent to our collection of that member’s information, and they accept this policy on that member’s behalf.
For a child we collect the same limited information as for anybody else: a display name, what they are going to, who is taking them, and any chores, homework or balances recorded for them. We do not knowingly allow children to create their own accounts, we do not ask a child for information beyond what the family’s plan requires, and we do not use a child’s information for advertising or profiling. The assistant samples described in 3.8 are never collected from a child.
A parent withdraws consent by removing the child from the family, which takes them off the roster and signs out every device and sign-in they had. A parent may also remove a single device or a single sign-in. Removing a member does not delete the record of what the family did; it is no longer attached to that person, and it is removed when the family itself is deleted.
If you believe a child’s information is in FamPlan without a parent’s involvement, write to support@spydaz.com and we will delete it.
Your data is encrypted in transit and encrypted at rest on our servers.
Your data is isolated from other customers’ data in our database, and the isolation is enforced by the database itself rather than only by the application. One family cannot see another family’s information. Where a person belongs to more than one household they see each family they are a member of and nothing else, and an individual event reaches somebody outside the family only through a guest link that a member creates for that one event.
Account holders authenticate with an email address and a password, with optional multi-factor authentication. Members who sign in without an email address authenticate with an identifier unique to their family and a PIN, and a device enrolled by a parent authenticates with a credential issued to that device, which a parent can revoke. Passwords and PINs are stored only as hashes. Access to production systems is restricted to staff who require it, and administrative actions are recorded.
If we become aware of a breach affecting your information, we will notify you and the relevant authorities as the law requires.
We keep your family’s information for as long as the family exists.
Canceling an event, declining a request or removing an item from the calendar marks it as canceled and keeps the record. Canceled items can be shown in the app. This is deliberate: FamPlan is a record of what a family agreed.
A photograph submitted as proof of a chore is deleted once the chore is approved or declined, and in any case within 15 days. A photograph attached to an event is deleted once the event has passed, and in any case within 180 days.
The person who created a family can delete it in the app, which deletes the family’s records and the accounts belonging only to that family. Instructions are in the help pages within the app.
Deleted data is removed from the live database within 24 hours, and remains in our backup systems until those backups expire in accordance with our retention schedule. Backups are encrypted and are not used for any purpose other than restoring the service.
Two things outlive the deletion. Records we are required to keep for tax and accounting purposes, such as proof that a subscription was sold, are retained for as long as the law requires. And our internal audit record of administrative actions taken by our own staff is retained, including the identity of the member of staff, because an audit record that can be erased is not one.
A problem report, and any screenshot attached to it, is kept while the issue is open and after it is resolved, as the record of what was reported and what was done about it. It is held in our helpdesk and is retained there when the family it came from is deleted, because it is our record of a request made to us and of how we answered it. Any photograph or screenshot attached to a report persists with the ticket for the same reason. A screenshot uploaded but never attached to a report is deleted automatically.
Nothing is deleted because a payment stopped. A family’s information remains available for one year after its subscription ends, or for one year from the day the family was created if it never had one, after which it is deleted by the same process described in 9.3.
We do not collect locality information about our users, so we have no knowledge of where any individual is and cannot apply the law of a place we do not know. Any dispute, request or claim arising out of this policy or your use of FamPlan shall be brought in the jurisdiction of Spydaz Holdings LLC, currently Hartford County, Connecticut, and governed by the laws applicable there.
We may change this policy at any time. We will give 30 days’ notice of a change by email and in the application when you sign in. During that 30 day period you may decline the change, which will result in the closure of your account. If you continue to use FamPlan after the change takes effect, the amended policy governs all of your data, both existing and new.
Every version is dated, and previous versions remain available.
Spydaz Holdings LLC
support@spydaz.com
(860) 292-0859