GDPR / EU & UK Notice

Legal
GDPR / EU & UK Notice
Effective: April 24, 2026
In plain language
If you live in the EU, UK, EEA, or Switzerland, the GDPR (or UK GDPR) governs how we handle your data. We are the data controller. You have eight specific rights you can exercise free of charge from inside the app or by emailing us.
1. Who is the controller
FamCove, Inc. is the data controller for the personal data described in this notice. Our address and contact email are at the bottom of this page. We have not appointed a Data Protection Officer because we do not meet the GDPR Article 37 thresholds, but you can reach our privacy contact directly.
Update this section once you have a registered EU/UK representative, if and when you ship to the EU directly. Article 27 requires one if you offer the service to EU residents from outside the EU.
2. Lawful basis (Article 6)
Performance of contract
Account, family workspace, calendar, vault, subscription state. We can't run the service without these.
Consent
Location sharing, AI processing of your content, anonymous analytics, marketing emails. Withdrawable any time in Settings.
Legitimate interest
Security audit logs, abuse prevention, infrastructure monitoring. Balanced against your interests, with safeguards.
Legal obligation
Tax records of paid subscriptions, lawful enforcement requests after counsel review.
3. Special-category data (Article 9)
You may upload medical documents, vaccination records, or other health information to your Family Vault. This is special-category data under Article 9.
We process it under Article 9(2)(a) — your explicit consent, provided when you upload the document.
We do not analyze, scan, or share that content. It is encrypted at rest and served only to you via 10-minute signed URLs.
You can delete any vault item at any time. Deletion removes the file from storage and the metadata row from the database immediately.
4. Your rights (Articles 12–22)
Article 13/14 information — provided by this notice and the Privacy Policy.
Article 15 — right of access. Settings → Privacy → Export my data hands you a JSON file with every row. Free of charge.
Article 16 — rectification. Edit any field directly in the app.
Article 17 — erasure ("right to be forgotten").Settings → Privacy → Delete my account. 14-day grace, then irreversible cascade.
Article 18 — restriction of processing. Email us; we flag your account read-only pending resolution.
Article 20 — data portability. The export is structured JSON. We'll provide additional formats on request.
Article 21 — right to object to legitimate-interest processing. Email privacy@famcove.com.
Article 22 — automated decision-making. We do not make automated decisions with legal or similarly significant effect about you. AI-generated content (tone scores, retros, recipe ideas) is purely advisory.
5. International data transfers
Our infrastructure is in the United States. When you sign up from the EU/UK, your data is transferred to the US. These transfers are covered by:
Standard Contractual Clauses (the EU Commission's 2021 SCCs) signed with each US processor (Supabase, OpenAI, RevenueCat, Expo).
EU–US Data Privacy Framework certification, where the processor participates.
UK International Data Transfer Addendum for UK residents.
Email us if you need a copy of the SCCs or our Transfer Impact Assessment summary.
6. Retention
Same as the Privacy Policy section 9. Concrete numbers, not "until no longer necessary".
7. How to exercise your rights
In-app: Settings → Privacy. Fastest, no waiting.
Email privacy@famcove.com with the rights request and the email on the account.
We respond within 30 calendar days as required by Article 12(3), extendable by two months for complex requests with notice.
8. Right to lodge a complaint
If you think we've mishandled your data, we'd rather you tell us first — but you also have the right to complain to your local supervisory authority:
UK — Information Commissioner's Office (ICO), ico.org.uk.
EU — your national data protection authority. The European Data Protection Board has the full list at edpb.europa.eu/about-edpb/about-edpb/members_en.
Switzerland — Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
9. Contact
FamCove, Inc. Privacy contact: privacy@famcove.com EU/UK representative: appoint and update before EU launch.
Questions?
Email privacy@famcove.com — we respond within 30 days as required by GDPR. Replace with your real contact before public launch.