Apliom Family Privacy Policy
Apliom Family (formerly Famio) is a family organizer: calendar, tasks, helper schedules, chat and shopping. We build it privacy-by-default: we collect as little data as possible, never sell it and show no ads. The family's helpers see only what you have explicitly shared.
This policy explains in plain words what data we collect, why, where we store it and how you can delete it.
If anything is unclear, write to us at support@apliom.com.
1. Who we are
Data controller: Ardent Interactive FZCO, a company registered in the United Arab Emirates. Apliom is the brand under which we release our apps; Apliom Family is our product for families.
EU representative (Art. 27 GDPR): ApenGames OÜ (Estonia, EU). EU/EEA residents can contact our representative about the processing of their data via privacy@apliom.com.
Privacy contact: privacy@apliom.com. Legal requests: legal@apliom.com.
2. What data we collect
2.1. Adult accounts (parents and helpers)
When you register:
- Email — to sign in, recover your password and receive invitations.
- Name — whatever you enter yourself. Initials or a nickname are fine.
- Password — stored only as a bcrypt hash; not even we can see it in plain text.
- Interface language — so the app speaks your language.
As you use the app — the content you create within your family:
- Calendar events, tasks and their comments, the shift schedule, announcements.
- Photos you attach to tasks and send in chat.
- Chat messages, shopping lists, the house manual, family contacts.
- Vault entries — visible only to the family, never to helpers. Financial records — visible to parents and to the admin helpers they appoint.
- Device push token — a technical identifier from Firebase Cloud Messaging (Google) needed to deliver notifications. It contains no personal information about you.
2.2. Children's profiles
Children in Apliom Family do not have their own accounts or logins. A child's profile is an entry within the family, managed by a parent:
- The name the parent entered.
- Information the parent added themselves (schedule, notes for helpers).
No email, phone number, location or biometrics of children. The app is meant for parents and adult members of the household — it is a tool for running a family, not a product for children.
2.3. Concierge requests
If you (a parent or family administrator) send a request to Apliom Concierge, we store your name, how to reach you, what the request is about and any notes you added. More in section 6.
2.4. Usage statistics and ad measurement — only with your consent
After you sign in, the app asks once whether it may collect usage statistics and measure which of our ads or links brought you to the app. It is one question with two buttons, “Accept” and “Decline”; until you tap “Accept”, nothing is collected. You can change your decision at any time: Settings → “Usage analytics & ad measurement”.
If you allow it, the app sends the following to Google Analytics for Firebase:
- which screens you open and which features you use — for example “task created”, “message sent”, “invitation sent”. Only the fact of the action: no task titles, message texts, names or photos;
- your role in the family (parent, administrator or helper) and how you signed up (email, Google or Apple);
- subscription purchases: plan, price, currency and transaction number;
- pseudonymous identifiers: a random ID of your account (not your name or email) and an app installation identifier;
- technical data: device model, system and app versions, language, and approximate location (country, city), which Google derives from your IP address;
- on Android, the device's advertising ID (Advertising ID), which Google Analytics can read automatically. We use it only to measure our own ad campaigns (see below) and never to show you ads; you can reset or delete it in your Android settings.
On iOS, if you tapped “Accept”, the app then shows Apple's own request to allow tracking (App Tracking Transparency). Only if you allow it there as well is the advertising identifier (IDFA) read — by AppsFlyer, for ad measurement. If you refuse either request, the IDFA is never used. You can change the Apple setting at any time: iPhone Settings → Privacy & Security → Tracking.
Ad measurement (AppsFlyer). If you tapped “Accept”, the app also uses AppsFlyer, a mobile measurement service, to find out which of our ads or links brought you to the app and whether our ad campaigns work. For this, AppsFlyer receives:
- the advertising ID (on Android; on iOS the IDFA only if you allowed tracking in Apple's request) and technical app and device identifiers;
- technical data: device model, system and app versions, and your IP address, from which the country is determined;
- the dates the app was installed and opened, and a random ID of your account (not your name or email);
- if you subscribe: the plan, price and currency, the start of a free trial, and later renewals or cancellations — on Android, Google Play reports these to AppsFlyer itself;
- whether the app has been removed from the device (using a technical push token).
AppsFlyer shares the results with our marketing partner that runs our ad campaigns and with the ad network that showed you our ad, so that the campaign can be measured. Names, messages, photos, files and your family's content are never sent. There are no ads in the app, and we never sell your data.
We use the statistics to understand which features are useful to families and where the app is awkward, and ad measurement to know which of our campaigns bring families to the app. Nothing of this is used to show you ads, and nothing is sold.
2.5. Crash reports
To find and fix bugs, the app sends technical crash reports to Firebase Crashlytics (Google) and Sentry (data stored in the EU, Germany). A report contains a description of the error and where in the code it happened, the device model, system and app versions, and a technical installation identifier. We don't attach your name, email or account ID to reports; they are meant for technical details of the error, not your family's content. Reports are kept for up to 90 days.
2.6. Subscriptions and purchases
You buy and pay for a subscription through the Apple App Store or Google Play. They handle the payment details (card number and so on) — we never receive or see them. From the store we receive: which plan was bought, the start, renewal or end dates, the subscription status (active, cancelled, refunded), whether a free trial is running, the transaction number, and a random technical key that links the purchase to your account. We need this to unlock paid features and to restore your purchase on a new device.
2.7. What we do NOT collect
- ❌ Location.
- ❌ Contacts from your phone's address book.
- ❌ Voice, biometrics, face recognition.
- ❌ Ads: the app shows no ads and has no ad SDK that would show them.
- ❌ Advertising identifiers without your consent — and on iOS, not without Apple's tracking permission either.
3. Why we use data
Only to run and improve the app:
- To show you and your family the shared calendar, tasks, chat and lists.
- To show helpers exactly the slice of data you have shared.
- To send invitations and sign-in/password-reset emails.
- To deliver push notifications (reminders, messages).
- To handle your concierge request, if you sent one.
- To translate chat messages, task titles and notes, and announcements into the reader's language — only if you turned on auto-translation for the family (off by default; see section 8).
- To process and restore your subscription, if you bought one.
- To find and fix crashes (crash reports).
- To understand how the app is used so we can improve it, and to measure which of our ads and links bring families to the app — only if you accepted usage statistics and ad measurement.
Legal bases for processing (Art. 6 GDPR): performance of our contract with you — running your account, the app's features and your subscription; your consent — usage statistics and ad measurement, sign-in with Google or Apple, Google Calendar import and push notifications (you can withdraw consent in settings at any time); our legitimate interest — crash reports, the security of the service and preventing abuse; legal obligation — responding to lawful requests from authorities.
We do not use your data for: showing you ads, selling to third parties or training AI models. Ad measurement (section 2.4) only tells us which of our own campaigns brought you to the app.
4. Helper privacy — how access works
This is the core of the product. A nanny, driver, tutor or housekeeper sees only what you have explicitly opened to them:
- Only the children you chose, and only shared events and the tasks assigned to them.
- The Vault and private events/tasks are not visible to any helper; financial records are visible only to parents and the admin helpers they appoint. These restrictions work at the database level (Row-Level Security), not just in the interface.
- Helpers don't see each other or private conversations they are not part of.
- The “What this helper sees” screen shows the access you have granted transparently; access can be revoked instantly.
5. Sign-in with Google or Apple, and calendars (your choice)
- Sign in with Google — optional. We receive only your email and name from Google to create the account.
- Sign in with Apple — optional. Apple gives us an account identifier and, if you agree, your email and name. Instead of your real address, Apple may give us an anonymous address that forwards emails to you.
- Google Calendar import — optional and read-only: events from your calendar are shown next to family events. Access tokens are kept in secure server-side storage; we never change or delete events in your Google Calendar.
- Phone calendar (Android) — optional. If you allow access, the app shows events from the phone calendars you choose next to family events. They are read only on your device: we don't write anything to your calendar and don't send these events to our servers. You can revoke access in your Android settings.
Data received from Google APIs is used only to show your events to you and is not shared with third parties, in accordance with the Google API Services User Data Policy, including the Limited Use requirements. You can turn the integration off in settings at any time — the tokens are deleted when you do.
6. Concierge service
- Only a parent or family administrator can send a request, on their own initiative.
- We process the request to contact you and help with coordination (for example, pointing you to a licensed service provider in your country).
- Request data may be passed to a partner only at your explicit request, and only to the extent needed to fulfil it. We never pass your family's in-app data to partners.
- Requests are kept for up to 12 months and then deleted. You can ask for earlier deletion via privacy@apliom.com; when a family is deleted, its requests are deleted within 30 days.
7. Where we store data
- Database and files — Supabase (PostgreSQL, EU-Frankfurt region, Germany). Row-Level Security at the database level: family A's data is inaccessible to family B.
- Encryption in transit — TLS (HTTPS) everywhere.
- Encryption at rest — AES-256.
- Backups — automatic, kept for 7 days.
8. Third parties (processors)
We use as few services as possible:
| Service | What it processes | Why |
|---|---|---|
| Supabase (EU, Germany) | Database, authentication, files | Storing family data and photos |
| Firebase Cloud Messaging (Google) | Device push token | Delivering notifications |
| Firebase Analytics (Google) (only if you accepted) | Usage statistics, pseudonymous identifiers, device data; on Android, the advertising ID | Understanding how the app is used and improving it |
| AppsFlyer (AppsFlyer Ltd., Israel) (only if you accepted) | Advertising ID (on iOS only with tracking permission), app and device identifiers, IP address, install and app-open dates, account ID, subscription purchases and renewals, app removal | Measuring which of our ads and links bring users to the app |
| Our marketing partner and the ad network that showed you our ad (only if you accepted) | Measurement results from AppsFlyer about installations and purchases that came from their campaigns | Measuring and improving our ad campaigns |
| Firebase Crashlytics (Google) | Technical crash reports | Finding and fixing crashes |
| Sentry (Functional Software, Inc.; storage in the EU, Germany) | Technical error reports | Finding and fixing errors |
| Google (only if you turned it on) | Email/name at sign-in; calendar events on import | Sign-in with Google, calendar import |
| Apple (only if you use it) | Identifier, email/name at sign-in | Sign in with Apple |
| Microsoft Azure Translator (EU) (only when auto-translation is on) | Text of chat messages, task titles and notes, and announcements | Translating this text into the reader's language |
| Transactional email service (Resend — Plus Five Five, Inc., USA) | Email address; in a report notice to our support team: the reason, whether a comment was added, the chat type, a short family reference and the report number (never the text of the message, the comment itself or anyone's name) | Confirmation, password-reset and invitation emails; telling our support team about a new report |
| Email forwarding and our mailbox (Cloudflare, Inc., USA, and our email provider) | Emails you send us; report notices | Receiving and answering email |
| Google Play / Apple App Store | Installation data under their own rules; subscription payment (your card details stay with them, not us) | Distributing the app and paying for subscriptions |
Each service receives only the minimum it needs for its function. Vault contents and financial records are stored only in our database (Supabase, EU-Frankfurt region) and are never passed to other services: they don't appear in push notifications, emails, concierge requests, usage statistics or ad measurement.
Auto-translation (your choice, off by default). If a parent turns on auto-translation for the family, the text of chat messages, task titles and notes, and announcements is sent to Microsoft Azure Translator to be translated into each reader's language. Processing takes place on Microsoft servers in the EU; Azure does not store the text or use it to train models. Only these kinds of text are translated — financial records, the Vault and private entries never go to translation. Translations are stored in our database (Supabase, EU) and are deleted together with the original. The feature can be turned off at any time, for the whole family or just for yourself; when it is off, no text is sent to Azure.
Reports about messages. If you report a message in a chat, we receive your report: the reason you chose, your comment if you wrote one, and which message it concerns. We look at that message to decide what to do, for example to remove it. Our support team is told about each new report by email and gets regular reminders about reports that are still open; these emails contain only the reason, whether you added a comment, the type of chat, a short family reference and a report number — never the text of the message, your comment or anyone's name. A report is kept until the family or the account of the message's author is deleted, or until 30 days after the chat is deleted; deleting only your own account does not erase it. Legal basis: our legitimate interest in keeping the service safe and preventing abuse.
9. Your rights (GDPR)
- Access — everything is visible in the app. Need an export? Write to privacy@apliom.com and we'll send a machine-readable copy of your data within 30 days.
- Rectification — edit any field right in the app.
- Erasure — deleting your account and family is available in the app settings; also on request to privacy@apliom.com.
- Withdrawing consent — you can turn usage statistics and ad measurement off at any time: Settings → “Usage analytics & ad measurement”; on iOS you can also withdraw tracking permission in iPhone Settings → Privacy & Security → Tracking. Withdrawal does not affect processing that took place before it. To have data already collected by AppsFlyer deleted, write to privacy@apliom.com.
- Restriction of processing and objection — write to us and we'll sort it out.
- Complaint — if you are in the EU/EEA, you have the right to lodge a complaint with the data protection supervisory authority in the country where you live or work (list at edpb.europa.eu). In the UK — the Information Commissioner's Office (ICO).
10. International data transfers
Primary data storage stays in the EU (Frankfurt, Germany). The operator (Ardent Interactive FZCO) is registered in the UAE and accesses data to run the service; for this access, and for individual services that process data outside the EU (Firebase Cloud Messaging, Firebase Analytics and Crashlytics — Google, USA; the transactional email service — Resend, USA; email forwarding — Cloudflare, USA; ad measurement — AppsFlyer, Israel and USA), appropriate GDPR safeguards apply: standard contractual clauses (SCCs), the EU–US Data Privacy Framework where applicable, the European Commission's adequacy decision for Israel, and equivalent mechanisms. Sentry is a US company, but our report data is stored in the EU (Germany). EU/EEA residents can contact our EU representative (see section 1).
11. Retention
- Active family data — for as long as you use the app.
- Inactive accounts (no sign-in for 12 months) — we may delete them after warning you by email 30 days in advance.
- Deleted families — data is irreversibly destroyed; backups stop containing it within 7 days.
- Concierge requests — up to 12 months (section 6).
- Usage statistics linked to identifiers — no longer than 14 months; after that only anonymous aggregate reports remain.
- Ad measurement data — as long as it is needed to measure the campaign that brought you, after which it is deleted or anonymised; earlier on request (section 9).
- Crash reports — up to 90 days.
- Subscription data — while your account exists; after it is deleted, only where the law requires it.
12. Security
- Passwords — bcrypt hashes only, never in plain text.
- HTTPS is mandatory everywhere.
- Row-Level Security is enforced at the database level; writes to sensitive tables go only through verified server functions.
- Role separation (parent / administrator / helper) is checked on the server, not in the interface.
13. Changes to this policy
We will notify you of material changes by email or in the app 30 days before they take effect.
14. Contact
- General questions: support@apliom.com
- Privacy and data deletion: privacy@apliom.com
- Legal requests: legal@apliom.com