We do not sell your data
Familiplan uses information to provide and secure the service. It does not sell personal data or use it for behavioural advertising.
Familiplan privacy
This policy explains which data Familiplan processes, why it is used, how artificial intelligence is involved and the controls available to each person.
Familiplan uses information to provide and secure the service. It does not sell personal data or use it for behavioural advertising.
Nia and other Familiplan features use third-party artificial intelligence models. They can be wrong, and you should review their suggestions.
Images sent only for scanning, recipe generation or use with Nia are temporary. Audio is deleted after processing; its transcript may remain in Nia chat for up to 30 days.
You can delete the Nia conversation at any time and request access, correction, deletion, objection, restriction or portability of your data.
The data controller and owner of Familiplan is Jose Maria Cruz Iglesias, Spanish tax ID 70903610S, Calle Sol Oriente 11, 1.º C, 37002 Salamanca, Spain. Email: contacto@familiplan.app. Phone and WhatsApp: +34 668 551 613.
You can use these channels for any privacy matter. No data protection officer has been appointed because our current assessment does not identify a statutory appointment requirement. We will review this if the scale or nature of processing changes.
This policy applies to the Familiplan website, mobile apps and services. It covers the account holder's data and information that authorised members add about their household.
Anyone adding another person's data confirms that they have a lawful basis, have informed that person where required and will respect household permissions. Household administrators do not own other members' privacy rights.
Data comes from you, authorised household members, your device and, when used, sign-in providers and app stores.
Name, surname, email, birth year, hashed password, verification status, language, social sign-in identifiers and session data.
Household name, members, roles, relationships and permissions; tasks, comments and attachments; events; shopping lists; meals, recipes and preferences; expenses, budgets, reminders and notifications.
Only if you choose to provide it: allergies, intolerances, pregnancy, medical restrictions or similar information used to personalise meals. These data are optional and receive enhanced protection.
Messages, transcripts, temporary files, the household context needed to answer, suggestions, outputs and usage metadata. Nia may receive member names and roles and relevant tasks, calendar, shopping, expense or meal data that are visible to the requesting user.
Product, store, purchase identifiers, status, renewal and entitlement. Apple or Google processes payment; Familiplan does not receive or store full card details.
Push token, operating system, app version, language, IP address, access dates, technical logs, incidents and support communications. This includes AI-safety signals such as flagged content, attempts to bypass safeguards, anomalous usage patterns and measures applied.
Reading this policy is not treated as blanket consent. Where consent is required, Familiplan asks separately and specifically. Core service is not conditional on marketing consent.
Create the account and household, sync information, enforce roles, carry out requested actions, provide support and manage subscriptions. Basis: contract or pre-contractual steps (GDPR Art. 6(1)(b)).
Interpret text, voice, images or documents, generate suggestions and personalise meals when you activate these features. Basis: contract; where health data is involved, separate explicit consent is also requested (Arts. 6(1)(b) and 9(2)(a)).
Authenticate access, limit fraud, detect and block dangerous content, attempts to bypass safeguards or quotas and other abusive use, investigate incidents and protect households, the service and third parties. Basis: legitimate interests in a secure service (Art. 6(1)(f)) and legal obligations where applicable.
Accounting, tax, rights requests, valid legal demands and legal claims. Basis: legal obligation (Art. 6(1)(c)) and legitimate interests in legal defence.
Send news or offers only where authorised or otherwise legally permitted. Basis: consent (Art. 6(1)(a)), withdrawable at any time.
Specific providers and models may change for quality, security or availability. This policy identifies relevant categories, locations and safeguards without making a particular brand a permanent contractual term.
Do not submit third-party documents, images or audio without authority. Avoid including more sensitive information than necessary.
Held temporarily while processing or retries complete and then deleted. Nia attachments expire after 24 hours and a daily purge removes anything not already cleaned up, so fallback deletion may take about 48 hours. A provider with abuse-monitoring logs may retain them for up to 30 days where zero retention is unavailable.
The audio file is deleted once transcribed and processed. The transcript becomes part of the conversation and is kept for no more than 30 days unless you delete it earlier.
Photos or audio notes you choose to keep as attachments form part of the task and remain while it exists or until deletion is requested. They are not temporary scanning files.
AI-created recipe or meal images may be stored as household content. They will be labelled as AI-generated or manipulated where the law requires.
Familiplan does not sell, rent or disclose data for third-party advertising. Processors receive only what is necessary, act on instructions and must provide appropriate confidentiality and security safeguards.
Familiplan aims to host and process ordinary service data in the European Economic Area. Some technology and AI providers may process data in the EEA, the United States and, depending on the configured text model, China. The precise location depends on the feature and current production configuration.
Before allowing a transfer outside the EEA, Familiplan must sign an Article 28 processor agreement and use a valid Chapter V mechanism: an adequacy decision where available or European Commission Standard Contractual Clauses, together with a country assessment and supplementary measures. If equivalent safeguards cannot be demonstrated, that provider will not be used for personal data.
You may request the current processor list, countries and applicable safeguards at contacto@familiplan.app. Publishing this policy does not replace those safeguards or make a transfer lawful on its own.
At the end of a period, data is erased or anonymised. Data required for a legal duty or claim is restricted and not used for ordinary features.
Content and transcripts: up to 30 days from each message. You can delete the entire conversation earlier. Minimal security, usage and audit metadata may be kept separately for as long as needed to prevent abuse and resolve incidents.
Until processing and retries finish. Nia attachments expire after 24 hours and are purged daily, so fallback cleanup may complete in about 48 hours. A provider may retain abuse logs for up to 30 days where the contracted service does not offer zero retention.
While the account or household is active, and afterwards only as needed to complete deletion, rotate backups and meet legal or claims requirements.
For applicable tax, accounting and limitation periods. As a reference, accounting documents may be held for 6 years and tax records for at least 4 years.
Ordinary application logs are limited to 14 days. Evidence for an incident, review or appeal may be kept as long as needed to investigate, prevent recurrence and defend claims. Following a confirmed closure, minimal blocking identifiers may be retained while necessary and proportionate to prevent evasion, subject to periodic review; this does not justify retaining all household content.
Exercise these rights at contacto@familiplan.app or by post to the controller's address, stating the right and affected account. We request extra information only where needed to verify identity. We normally respond within one month, extendable for complex requests under the GDPR.
You may also complain to the Spanish Data Protection Agency at www.aepd.es, particularly if you believe your request was not handled correctly.
Familiplan accounts are intended for people aged 18 or over. Adults may add information about children in their care where needed for household organisation and where they have parental responsibility, guardianship or other sufficient authority.
A child must not be invited to create an independent account or have health data entered without a legal representative's involvement and authority. If we detect an unauthorised child account, we may restrict it and request verification or delete it.
Familiplan uses risk-appropriate technical and organisational measures: household separation, role controls, encrypted communications, hashed passwords, private file storage, access limits, backups and security logs. We review providers and access and maintain an incident-response process.
No internet-connected system is infallible. If a breach creates risk, we will notify the authority and, for high risk, affected people within statutory deadlines.
The public website currently uses no advertising or optional analytics cookies. It may use storage or cookies strictly necessary for security, load balancing, language or technical continuity; these do not require consent.
If we introduce non-essential analytics, personalisation or advertising, controls to accept or refuse will be shown before activation and this policy will be updated.
We update this policy when the service, providers or law changes. Material changes will be notified in the app or through an appropriate channel, and new consent requested where legally required.
Questions or requests: Jose Maria Cruz Iglesias, Spanish tax ID 70903610S, Calle Sol Oriente 11, 1.º C, 37002 Salamanca, Spain. Email: contacto@familiplan.app. Phone and WhatsApp: +34 668 551 613.