Privacy Policy

Last updated: September 16, 2026

1. Introduction

FAMMO ("Service"), available at fammo.app ("we", "us", "our"), is operated by a company registered in Latvia. We are the data controller for the purposes of the General Data Protection Regulation (GDPR). Full legal entity details are available in our Legal Notice.

This Privacy Policy explains how we collect, use, and protect your information and your child's information when you use our Service. Because FAMMO processes data about children, we take extra care to minimize data collection, protect children's privacy, and ensure transparency.

2. Children's Data — Our Approach

FAMMO is a parental monitoring tool. By design, it processes data about minors (your children) under your parental authority. We are committed to protecting children's privacy and follow these principles:

Legal Basis for Processing Children's Data

Under GDPR Article 8, processing personal data of a child below 16 years of age (or the lower age set by the child's Member State, but not below 13) in relation to information society services requires consent given or authorized by the holder of parental responsibility.

By creating a FAMMO account and linking your child's data, you, as the parent or legal guardian, provide this consent and authorize the processing of your child's data as described in this policy. You may withdraw this consent at any time by deleting the child's profile or contacting us (see Section 12).

3. Information We Collect

3.1 Parent Account Information

When you create an account, we collect your email address and password (stored as a bcrypt hash). If you subscribe to a premium plan, Stripe processes website payments and Google Play processes Android in-app payments. RevenueCat verifies store purchases and synchronizes subscription access. We do not store your card details. We keep provider customer identifiers, subscription status, billing periods and transaction references to manage your family's access. RevenueCat receives a pseudonymous family identifier, purchase and subscription data, and technical data from its SDK; we do not send it children's monitoring content.

For new website purchases, we keep a dated copy of the offered terms, price and trial details, checkout acknowledgement, and the acceptance confirmed by the payment provider. Contract confirmations include the terms and model withdrawal form. If you submit a withdrawal statement, we record your name, chosen confirmation email address, statement, contract or subscription reference, submission time, and related support correspondence. We also keep confirmation email content and sending status so failed messages can be retried. Family billing administrators can access these records; authorized Fammo support staff use them to handle the case.

3.2 Child Profile Information

When you add a child to your account, you provide their name (or nickname) and age. You may optionally add additional context to help the AI provide better insights.

3.3 Activity Data

Depending on how you configure the Service, FAMMO may process:

Sensitive categories such as location, call logs, SMS, social-media monitoring, chatbot conversation capture, and driving safety have dedicated controls and are disabled by default. Other baseline activity categories are controlled through the parent setup, feature availability, and device rules shown in the Service.

3.4 AI-Processed Data

Activity data is sent to our AI processing pipeline to generate:

Text and activity insights are processed on our behalf by OpenAI. We limit that data to what is needed and remove direct child identifiers where technically feasible. If screenshot analysis is enabled and available, OpenAI's Moderation API may process the screenshot image for safety classification. Screenshots can contain direct identifiers or sensitive visible content and cannot be described as pseudonymized in the same way as minimized text/activity fields.

3.5 Technical and Analytics Data

We collect standard technical data including:

We use PostHog Cloud's EU region for product analytics through our first-party t.fammo.app reverse proxy. Analytics configuration differs by surface and is minimized where practical.

3.6 Error and Performance Monitoring

We use Sentry to track application errors and performance. Sentry may receive technical data about errors including device information, browser state, and anonymized usage context. No child activity data is intentionally sent to Sentry.

3.7 Waiting List

If registration is not yet open and you join the Fammo waiting list, we collect your email address, language preference, signup time, confirmation status, beta-invite eligibility, launch-offer eligibility, and basic technical information used to prevent abuse. We use double opt-in email verification before sending launch announcements, beta invitations, or promotional offers.

4. How We Use Your Information

We do not:
  • Sell personal information — neither yours nor your child's — to third parties
  • Send marketing emails unless you explicitly opt in
  • Use children's data for advertising or commercial profiling

5. Data Sharing and Sub-Processors

We share data with the following service providers who act as data processors on our behalf (unless otherwise noted):

Sub-Processor Purpose Data Processed Location
OpenAI (text API) AI processing of activity data to generate insights Minimized activity data with direct child identifiers removed where technically feasible United States
OpenAI (Moderation API) Optional screenshot safety classification Child screenshot images, which may contain direct identifiers or sensitive visible content United States
Hetzner Online GmbH Server hosting and data storage All Service data Germany (EU)
Cloudflare, Inc. CDN, DDoS protection, object storage (R2) IP addresses, traffic data, stored files EU (with global edge network)
Stripe, Inc. Payment processing Parent's payment data (Stripe is an independent controller) EU/US
RevenueCat, Inc. Store purchase verification and subscription synchronization Pseudonymous family/customer identifiers, purchases, subscription status and SDK technical data United States and service-provider locations, subject to applicable transfer safeguards
Google Play Android in-app payment processing and subscription management Store account and payment data handled under Google's terms and privacy policy Google's global infrastructure
Amazon Web Services (AWS SES) Transactional email delivery Parent's email address, email content EU (Frankfurt region)
Sentry (Functional Software, Inc.) Error monitoring Technical error data, device info United States
PostHog Product analytics Usage and interaction analytics European Union (PostHog Cloud EU)

We may disclose information if required by law or to protect our rights and the safety of our users.

6. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (Germany).

Where data is transferred outside the EEA (including to OpenAI and Sentry in the United States), such transfers are protected by appropriate safeguards, including:

Regarding OpenAI text processing: Activity data used for summaries and insights is minimized before transmission, with direct child identifiers removed where technically feasible. Browser AI activity summaries use provider and evidence metadata; recognizing a service does not itself send browser conversation text for semantic analysis.

Regarding OpenAI Moderation: When screenshot analysis is enabled and available, a screenshot may be transferred for safety classification. Unlike minimized text/activity data, the image itself may contain faces, names, messages, or other direct identifiers. We apply feature, plan, and daily processing limits and use the result only to provide the requested Fammo safety-review feature.

You may request information about the specific safeguards in place by contacting us at [email protected].

7. Data Retention

Parent account data

Retained while your account is active and removed when your account is deleted. Submitted withdrawal cases and legally required payment records follow the separate retention periods below.

Child profile and activity data

Retained while the child's profile is active in your account. When you delete a child's profile or your account, this data is permanently deleted within 30 days (except for anonymized, aggregated data that cannot identify any individual).

AI-generated insights

Retained for up to 12 months to allow you to review historical summaries. Deleted when the child's profile is removed.

Technical logs

IP addresses and error logs retained for up to 90 days.

Payment records

Retained for up to 5 years as required by Latvian tax law.

Submitted withdrawal cases

If you delete your account after submitting a withdrawal statement, we retain the statement, confirmation contact, relevant subscription reference, acknowledgement and related support case separately from your family account. We retain this limited case for up to 90 days after account deletion, or 30 days after the case is closed if earlier, so deletion does not immediately erase an outstanding statement or its acknowledgement. Reopening a case does not extend the original 90-day limit. This exception does not retain children's monitoring data or your family account.

You may request earlier deletion of data by contacting us (see Section 12).

8. Data Security

We implement appropriate technical and organizational measures to protect your data and your child's data, including:

No system is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying affected users in the event of a data breach, as required by GDPR Articles 33–34.

9. Local Storage and Cookies

The Service uses local storage (browser-based storage similar to cookies) to maintain your session, preferences, and application state. This is strictly necessary for the Service to function.

We use essential cookies for authentication and session management. These do not require consent as they are strictly necessary.

We do not use advertising cookies or advertising pixels. PostHog analytics is delivered through our first-party reverse proxy to PostHog Cloud's EU region; the SDK may use first-party browser storage to maintain analytics state. We review consent requirements when analytics scope or storage behavior changes.

10. Automated Decision-Making

The Service uses AI to generate summaries and insights about your child's digital activities. These are informational outputs intended to assist you as a parent — they are not automated decisions with legal or similarly significant effects on your child.

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects any individual (GDPR Article 22).

If you believe an AI-generated insight is inaccurate, you can disregard it and contact us to report the issue.

11. Your Rights (GDPR)

As a parent/guardian and data subject in the European Economic Area, you have the right to:

Your child's rights: Children are data subjects with their own rights under GDPR. As the holder of parental responsibility, you exercise these rights on behalf of your child. As your child matures, they may exercise their own data protection rights.

The relevant supervisory authority is the data protection authority in Latvia.

12. Contact and Data Requests

For privacy-related questions, data access requests, or to exercise any of your rights, contact us at:

We will respond to data subject requests within 30 days. If a request is complex, we may extend this by an additional 60 days with notice to you.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes — especially those affecting how we process children's data — will be communicated via email to registered users with at least 30 days' notice before taking effect. Continued use of the Service after the effective date constitutes acceptance.

For significant changes to children's data processing, we may require you to re-confirm your consent.