Famiqo Privacy Policy
Effective date: 25 August 2026 Last updated: 24 August 2026 Version: 2026-08-24 Operated by: Fold and Flock LLC (“Famiqo,” “we,” “us”) Contact: privacy@famiqo.com
The short version
Famiqo is a private, parent-governed “family brain” — chat, a family wiki, schedules, and an always-available AI steward named Iqo. We built it privacy-first:
- Your family’s data is yours. We don’t sell it, rent it, or use it to target ads. There are no ads.
- We pseudonymize before AI sees it. Before any of your content is sent to a third-party AI model (for reasoning or for search indexing), we replace your family’s names and personal identifiers with stable stand-ins. The AI models we use receive the pseudonymized text, not your real identities.
- Your voice never leaves your control. Speech-to-text and Iqo’s spoken replies run on your own device where it supports it (the Famiqo desktop app and modern browsers), and otherwise on our own servers. Your voice audio is never sent to a third-party AI provider — in every mode, including the optional real-time conversation mode, what leaves your device is pseudonymized text, never audio. Raw audio is not retained after it is transcribed.
- Parents are in control. A family administrator governs the account, members, children’s visibility, and what Iqo is allowed to do. High-impact actions are proposed for approval, never applied silently.
The sections below give the full detail.
1. Who this policy covers
Famiqo is a family account product. A parent or guardian creates the family, becomes its administrator (admin), and adds household members — including children — and any external contacts. This policy applies to everyone who uses a Famiqo family account and to the information the family puts into Famiqo.
If you are a child, please use Famiqo only with your parent’s or guardian’s permission and supervision. See Section 8 — Children’s privacy.
2. Information we collect
a. Account information. When an admin creates a family, we collect the admin’s email address and password (managed by our authentication provider), the family name, and member profiles the admin enters (name, role, color, and optionally birthdate, email, or phone for contacts and members).
b. Family content you create. Chat messages, wiki pages and notes, tasks and events (“Steps”), people and place records, focus-window summaries, uploaded files and images, and content you forward by email (see (d)).
c. Voice interactions. When you talk to Iqo, your microphone audio is transcribed to text. The text becomes part of the conversation (treated like a chat message). Raw audio is not stored after transcription.
d. Email you forward to Famiqo. Each family can receive email at an address on our domain. Forwarded messages and their attachments are ingested into your family’s wiki. We store the processed (pseudonymized) content and may retain the original message in cold storage subject to your family’s retention settings.
e. Connected accounts you choose to link. If you connect an outside calendar (Google, Microsoft, Apple), we receive the events from the calendars you select, along with the access credential or private calendar address needed to keep reading them, which we store encrypted. See Section 6a.
f. Usage and operational data. We record limited operational telemetry — e.g. counts and token/character usage of AI calls (to enforce family budgets and estimate cost), error logs, and standard server logs (IP address, timestamps, user agent) needed to run and secure the service.
g. Location data. If you add addresses (e.g. for a place or a scheduled event), we may send that address to a mapping provider to compute travel times or coordinates. See the subprocessor table in Section 6.
We do not collect device contacts, browsing history outside the app, or advertising identifiers, and we do not use tracking cookies for advertising.
3. How Famiqo’s privacy pipeline works (what makes us different)
This is the core of how we protect your family, so we describe it plainly:
- Pseudonymization before storage, indexing, or AI. Before your content is embedded for search or sent to an AI model, a privacy step replaces personal identifiers (family members’ names and nicknames, and similar personal details) with stable, fake stand-ins. The mapping between a real value and its stand-in is stored encrypted (AES-256-GCM, with a separate key per family). Reasoning AI models and the search-indexing model receive the pseudonymized text.
- Admin transparency. A family admin can review the family’s stand-in map at any time in Settings — what is masked, the fake used for each value — and can edit or forget any stand-in. A best-effort activity log records when new values are masked and when real values are shown back to a member.
- Voice stays on your device. Speech-to-text and Iqo’s spoken replies run on your own device — in the Famiqo desktop app, and in browsers that can run the models locally. Where a device cannot, they run on servers we operate. Either way your voice audio is never handed to a third-party voice or AI service; what leaves your device is pseudonymized text.
- Real-world lookups keep the two halves apart. When you ask Iqo something that needs the outside world — “what’s open near the school”, “look up the clinic’s number” — the stand-in would be useless to a search engine. So the question is put together using stand-ins, the real name is substituted back in only at the moment we call the search or maps provider, and the results are put back into stand-in form before the AI model reads them. The AI provider never receives the real place; the search provider receives the lookup and not your family’s conversation. Lookups happen when a member asks Iqo for one, or when an automation your family wrote runs on the schedule you gave it. Our own background jobs — digests, summaries, search indexing — cannot make them at all. If we cannot put a result back into stand-in form, we discard the whole result rather than show it to the model.
- Encryption. Data is encrypted in transit (TLS) and at rest (by our database and storage providers); the real-value mappings are additionally encrypted by us as described above.
Honest limits. Pseudonymization reduces, but cannot perfectly guarantee the removal of, every identifying detail in free-form content you write. It replaces the names of the people and places your family has told us about, and certain structured values (such as phone numbers and postal codes); it does not change the substance of what you write, and it cannot substitute a name we have never been told. Address data sent for travel-time/geocoding is sent as entered, and a real-world lookup you ask for is sent to the search or maps provider as described above. AI models can make mistakes. We describe AI limitations in Section 6 and in our Terms.
4. How we use information
We use your information to:
- provide the service — store and display your family’s content, run chat and Iqo, schedule Steps, deliver digests, and power family-private search;
- let Iqo assist your family (with pseudonymized content as described above);
- enforce per-family usage budgets and estimate operating cost;
- secure the service, prevent abuse, debug, and maintain reliability;
- communicate with you about the service (e.g. the daily digest you enable, or important account/security notices).
We do not sell your personal information, and we do not use your family’s content to train third-party AI models (we use AI provider APIs under terms that do not train on submitted data). There is no advertising in Famiqo.
5. The propose-approve-apply model
Iqo proposes high-impact changes (calendar changes, wiki edits, adding a contact, running a skill) to your family’s inbox with a rationale; a member with permission must approve before anything is applied, and an audit record is kept. Iqo’s outputs are suggestions, not professional advice. See the Terms.
6. AI processing and service providers (subprocessors)
To run Famiqo we use the third-party providers below. Where a provider receives family content for AI processing, it receives pseudonymized text as described in Section 3 (or, for self-hosted components, the data is processed on our own servers and not shared with the provider as a data consumer).
Two providers are deliberately different, and Section 3’s real-world-lookup bullet explains why: search and maps providers receive real names, because a lookup for a stand-in would find nothing. They receive the lookup a member asked for and nothing else — no conversation, no roster, no history.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | Account data and family content (stored; encrypted at rest); auth credentials |
| Vercel | Web application hosting | Standard request/server logs |
| Fly.io | Hosts our self-operated services (real-time collaboration, document conversion, and speech services used as a fallback when your device cannot run them) | Family content/audio processed on our own containers; not used by Fly as a data consumer |
| Cloudflare | DNS, inbound email routing, cold object storage (R2) | Inbound family email; archived raw email/attachments |
| Resend | Sending digest and notification emails | Recipient email + the email content we send |
| OpenAI | Our current AI provider for Iqo’s reasoning and conversation, and for the text embeddings that power family-private search | Pseudonymized conversation, context and content text. Never audio. |
| Google Cloud / Vertex AI (Gemini) | Alternative AI provider, selectable by us per workload | Pseudonymized content text (only when selected) |
| xAI (Grok) | Alternative AI provider, selectable by us per workload | Pseudonymized content text (only when selected) |
| Google Maps Platform | Travel-time / geocoding for places & events; place lookups a member asks Iqo for | Addresses you enter (as entered); the lookup a member asked for, with real place names — never your conversation |
| Firecrawl | Web search and page retrieval a member asks Iqo for | The search query or page address for that lookup, with real names — never your conversation |
Which AI provider we use. Iqo’s work is routed through a small number of governed tiers, and the model behind each tier is a setting we control centrally. Today all three tiers use OpenAI. We may switch a tier to Google (Vertex AI) or xAI without changing anything about what those providers receive: in every case it is pseudonymized text, subject to Section 3.
Not in use (we will update this policy before enabling): payment processing (Stripe) for any future paid plans. Group voice runs on our own real-time infrastructure, not a third-party voice platform.
We sign data-processing terms with providers where applicable, and we choose providers whose API terms do not train on submitted data.
6a. Connecting an outside account (Google, Microsoft, Apple)
Famiqo is introducing the ability to connect a calendar you already keep elsewhere, so your family’s schedule appears in Famiqo without retyping it. Connecting is always optional, always initiated by you, and can be disconnected at any time. This section describes how we handle that data when you use it.
What we ask for. When you connect a Google account for calendar, we request only calendar permissions — enough to read the events you choose to bring in, and, if you enable it, to write back events you created in Famiqo. We do not request access to your Gmail messages, and we do not request broad access to your Google Drive. If we ever offer a file feature, it will use per-file access — you pick a specific file and we can see only that file.
What we do with it. Calendar events you connect are treated exactly like content you enter yourself: they pass through the pseudonymization pipeline in Section 3 before storage, search indexing, or any AI processing, they are visible only to the family members you allow, and they are deleted when you disconnect the calendar or delete your family.
What we never do. We do not sell this data. We do not use it for advertising. We do not use it — or anything derived from it, including search indexes built from it — to create, train, or improve any general-purpose or foundational AI model. Data derived from a connected account is used only to serve your own family, in features you can see in the product.
Limited Use. Famiqo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and — for Workspace data — the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
Revoking access. You can disconnect a calendar inside Famiqo at any time, and you can independently revoke Famiqo’s access from your Google account’s security settings. Disconnecting stops all future syncing; events already brought in are removed on request or when you delete your family.
Other providers. Microsoft and Apple calendars can also be connected, either by the same kind of account connection or by giving Famiqo a private calendar address that your provider publishes. A private calendar address is a secret — anyone holding it can read that calendar — so we store it encrypted and you can reset it with your provider at any time.
7. Data sharing and disclosure
We share information only: (a) with the subprocessors above, to run the service; (b) when you direct us to (e.g. inviting a member, or content you choose to share); © if required by law or to protect rights, safety, and the integrity of the service; or (d) in connection with a business transfer, with notice and continued protection under this policy. We never sell your personal information.
8. Children’s privacy (what a child can do, and what you decide)
Famiqo is built for households that include children, and a parent or guardian administrator operates the account on the family’s behalf. This section describes what we collect from a child, what a parent decides, and what a parent can do about it afterwards.
8a. What a child can do is set by you, and it starts closed
Every household member has a level of access that a parent sets, and it is not the same thing as whether they have a password. There are three:
| Level | What that person can do | What we collect from them |
|---|---|---|
| On the calendar only | Nothing themselves. They appear on the family calendar, in rotations, and on their own page — everything about them is entered by a parent. They cannot sign in. | Nothing from them. Only what a parent enters about them. |
| Can use their own tasks and rewards (the default for a child under 13) | Tick off tasks and habits, earn points, see their own day, and read the family content a parent has allowed them to see. They cannot talk to Iqo, use voice, upload photos or files, or use the shared browser. | Which tasks they completed and when, quick notes they capture, and the messages they write in family channels. |
| Can chat with Iqo and browse (the default for 13 and over) | Everything a member can do, including conversation with Iqo, voice, uploads, and browsing the web with the family. | Free text, transcribed speech, uploaded files and images, and pages opened in the shared browser. |
The level comes from age, and then it stays put. When a member is added we set the level from their birthdate. After that it never changes on its own — a child turning 13 changes nothing automatically. We tell you it happened and you decide. We do this because access that widens silently on a birthday is not something you agreed to.
Where a birthdate is missing, we assume a child. A household member with no birthdate on file is set to “on the calendar only” until you answer, because guessing in the other direction would open capabilities we were never told were appropriate.
These are enforced on our servers, not by hiding buttons. If a child at the “tasks and rewards” level tries to reach Iqo, voice, uploads, or the shared browser — through the app or by any other means — the request is refused, and the child is told plainly to ask a parent rather than being shown a feature that silently does nothing.
8b. Raising a child’s access is a decision we record
Moving a child under 13 up to “can chat with Iqo and browse” requires an explicit act by a parent, and we keep a record of it. Nothing is enabled by inaction, and skipping the question during setup leaves every child at the default for their age.
What you are told before you decide. At the moment of the decision — during setup and again in Family settings — we show, in plain language: what becomes collected; that Iqo’s answers come from an AI model run by another company, and that what reaches that company is pseudonymized text rather than your family’s real names and details; and that you can turn it back off at any time.
What we store. For each grant we record which child, which parent granted it, what was granted, the date, and the version of the notice that parent was shown — so the words you agreed to can be identified later, not merely the fact that you agreed. Revoking is recorded the same way, with its own date. We keep these records for as long as the account exists; a policy that deleted its own consent records could not show that consent was given.
Turning it back off closes the features again immediately, on the next request the child makes. There is no cached permission to wait out.
Shared devices. A profile with full access is protected by a PIN, so that switching to it on a shared family tablet is a deliberate act. Any parent’s PIN opens any of their children’s profiles, so nobody has to remember four of them. Profiles at the two lower levels are not PIN-protected, because marking a chore done on the family iPad should not need one. We record which PIN opened a profile, so the account history shows when a parent opened a child’s profile rather than the child doing so.
8c. What we do not do
- We do not show advertising to children, build advertising profiles, or sell children’s information. There is no advertising in Famiqo at all.
- We do not use your family’s content — or anything derived from it — to train any general-purpose AI model.
- There is no public profile, feed, or social discovery. Family content is private to the family by default, and a child’s content is additionally limited to the channels a parent has allowed.
- We collect only what is needed to provide the family service.
8d. How long we keep it
Children’s information is not kept indefinitely. Every category has a stated maximum period, a parent can shorten or lengthen it, and anything Iqo built from a child’s content is deleted with that content, never after it. The periods, the derived-record rule, and the two places where that rule stops are set out in full in Section 9a — Children’s data retention, which is the canonical statement.
8e. Seeing, downloading, and deleting what we hold
A parent can do all three, per child, at Settings → Children’s data:
- You can see everything we have collected from your child, download it, and delete it. The review shows every category, how much of it there is, and the period it covers; the download is the content itself.
- Deleting your child’s data does not remove them from your family, your calendar, or your points — and it does not delete what you wrote about them. A calendar event you created that mentions your child is your record, not theirs, and we show it to you separately and clearly labelled.
- Anything Iqo built only from your child’s content is deleted with it. Summaries that mix your child’s words with other family members’ are not, because deleting those would delete other people’s content; those age out on the retention schedule instead.
Two limits we would rather state than let you discover:
- A deletion does not remove everything about your child. It removes their own contributions and what was derived solely from them. The carve-outs in Section 9a — principally your family’s wiki pages — still apply, and any file already moved to long-term archive storage is reported on screen as skipped rather than silently left behind.
- A download withholds what you are not party to. If your child is old enough to have conversations in channels you are not part of, the export keeps the record that those messages exist and when, but not their contents, and tells you how many were withheld. A deletion, by contrast, does reach them — a deletion that quietly skipped them would be one we claimed and did not perform.
You can also request any of this by writing to privacy@famiqo.com. If you believe a child has given us information without the required parental consent, contact us and we will delete it.
9. Data retention and deletion
- We keep your family’s content while your account is active.
- Voice: raw audio is not retained after transcription.
- Email ingestion: processed content follows your family’s retention settings; archived originals follow your auto-delete rules.
- Operational records: transient processing queues and internal job logs are pruned on a rolling basis (e.g. processed queue items after ~7 days; internal run logs after ~90 days).
- Children’s information: every category has a stated maximum period, and anything Iqo derived from it is deleted with it. See Section 9a.
- Account deletion: an admin can request deletion of the family account and its content. On deletion we remove your content from active systems and schedule removal from backups within our providers’ backup-retention windows. Some records may be retained where required by law.
Request access, export, or deletion at privacy@famiqo.com.
9a. Children’s data retention
This section is the canonical statement of how long we keep information about the children in your family, and it is enforced by an automated job — not a policy we intend to apply by hand.
We do not keep children’s information indefinitely. Every category below has a maximum period. There is no “keep forever” setting, and a period cannot be removed — only shortened or lengthened within the stated bounds.
How long each category is kept
The periods below are the defaults. A parent (family admin) can change them for their own family at Settings → Children’s data, to anywhere between 30 days and 10 years. They apply to every household member under 18 who has a birthdate on file, and keep applying for a period after their eighteenth birthday, so that nothing created while they were a minor is left behind.
| What it is | Kept for (default) |
|---|---|
| Messages a child wrote — in family channels, in their own conversation with Iqo, and anything said aloud in a voice session (voice is stored as text, never as audio) | 730 days (about 2 years) |
| Voice session records — that a call happened, who, when, how long | 730 days (about 2 years) |
| Files and photos a child uploaded | 1095 days (about 3 years) |
| Tasks and activity — tasks and habits ticked off, quick notes captured | 1095 days (about 3 years) |
| Browsing — pages opened in the shared browser, shared-browsing sessions hosted, navigations blocked by the family filters, and which Famiqo wiki pages were viewed | 90 days |
We chose periods measured in years rather than weeks deliberately: a retention period that expires before a parent would reasonably think to look back at something is not a privacy feature, it is data loss. The one category kept for months rather than years is browsing, which is the most sensitive and the least useful to retain.
What Iqo built from it goes with it
This is the part that is easy to get wrong, so we state it plainly.
When Iqo summarizes a conversation, builds a daily digest or records an activity entry, the result is also children’s information, and it is deleted with the content it was made from — never after it. These derived records have no retention period of their own:
- a daily digest and an activity entry are deleted on the schedule of the activity they describe;
- a conversation summary and the search embedding computed from it are deleted once the newest message they cover has reached the end of the messages period;
- a focus window your child opened, and Iqo’s summary of it, are deleted on the messages schedule;
- the pseudonymized text of a request sent to an AI provider is retained for at most 7 days regardless of the periods above.
Where a summary covers a shared channel, it necessarily blends several people’s contributions. Such a summary is still deleted on the schedule above — it is never kept longer than the messages inside it. But because it contains other family members’ content as well, it is not removed by a request to delete one child’s data; the surgical tool for that is the per-child deletion below.
Where this rule stops, stated plainly. Iqo also writes into your family’s wiki, and a wiki page can contain something learned from a child’s message. Wiki pages are not deleted on the schedule above. They are your family’s own knowledge — pages you read, edit and rely on — and deleting one because a child once contributed to it would destroy your work rather than protect theirs. Wiki pages are removed when you edit or delete them, when you delete a child’s data, or when you delete the family account.
What is kept for as long as the account exists
A short list, and the reason for each — none of it is left indefinitely by accident:
- XP, rewards and redemptions. These are running totals your family can see. Deleting an entry on a timer would silently change a number on a child’s page.
- The record of parental consent — who granted a child full access, when, and to which version of the notice. A retention policy that deletes its own consent records cannot show that consent was given.
- Your approval history and profile-switch log — the family’s own record of what was approved and who opened which profile.
- Bookmarks a child saved, and wiki pages, because they made them; they are removed by deletion, not by a timer.
All of the above is removed when a parent deletes a child’s data or deletes the family account.
What triggers deletion
- The schedule. An automated job runs nightly and removes content past its period, together with the derived records described above. It works through large backlogs over several nights rather than in one pass. Each run is logged, including any part of it that failed, so we can show what happened. The same job removes our own internal record of your family’s setup questionnaire 90 days after it finishes.
- A parent’s request. A parent can delete a child’s own contributions at any time; content a parent created about a child (a calendar event, for example) is that parent’s and is not removed by it.
- Account deletion. Deleting the family removes its content from active systems, with removal from provider backups following those providers’ backup-retention windows.
Uploaded files are removed in two steps, because the file itself lives in storage rather than in our database: the record is deleted immediately, which makes the file unreachable from anywhere in Famiqo, and a follow-up job deletes the stored file itself, normally within the hour.
Request deletion, export, or a copy of what we hold about a child at privacy@famiqo.com.
10. Security
We use TLS in transit and encryption at rest, per-family encryption of the real-value pseudonym map, row-level access controls so a family’s data is isolated to that family, and least-privilege access for operators. No system is perfectly secure; we cannot guarantee absolute security, but we work to protect your information and will notify you of a breach as required by law.
11. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Admins can exercise most of these directly in the app (member management, the pseudonym-map review, content editing/deletion, digest settings). For anything else, contact privacy@famiqo.com. We will not discriminate against you for exercising your rights.
12. Where your data is processed
Famiqo’s providers process and store data primarily in the United States. If you use Famiqo from outside that region, you consent to processing there.
13. Changes to this policy
We may update this policy. For material changes we will notify the family admin (e.g. by email or in-app) before they take effect. The “Effective date” above reflects the current version.
14. Contact
Questions or requests: privacy@famiqo.com · Fold and Flock LLC