{"version":"1.23.9","lastUpdated":"2026-09-17","sections":[{"title":"Introduction","content":"FamilyCamp — also marketed as \"FamilyCamp Calendar\" (collectively, \"FamilyCamp\" or \"the App\") — is a family planner application developed by Togetherlee, LLC. \"FamilyCamp\" and \"FamilyCamp Calendar\" refer to the same application and are used interchangeably throughout this Privacy Policy. This Privacy Policy explains how we collect, use, and protect your personal information, including location data. We are committed to complying with applicable privacy laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), Children's Online Privacy Protection Act (COPPA), and other regional privacy regulations.\n\nFamilyCamp is a general-purpose family organization app and is NOT a co-parenting, custody-management, or legal record-keeping tool; it should not be relied upon for custody, divorce, or other legal proceedings."},{"title":"Information We Collect","content":"Account Information: Email address, name, date of birth, and password (hashed). We collect this at registration to create and manage your account. Your date of birth is stored in our database for as long as your account is active. It is used to determine whether you are a minor (under 18) and to enforce age-gating (users under 13 are not permitted to create accounts). We also record the date, time, and version number of your acceptance of our Terms of Service.\n\nEmail Verification: To confirm that you own the email address associated with your account, we generate a temporary one-time verification code, send it to your email address, and store that code together with a short expiry time and a flag indicating whether your email has been verified. The code is used solely to verify ownership of your email address for account security; it is deleted as soon as your email is verified or the code expires, whichever comes first.\n\nParental Consent Information: For users aged 13–17, we collect a parent or guardian's email address. We use this email to send a verifiable parental consent request. We also generate and store a one-time consent token to process the parent's approval or rejection. Upon consent approval, we create a parent-child relationship linking the accounts. When a parent or guardian approves consent, they provide their date of birth on the consent page for age verification only — this date of birth is processed in real time and is not stored in any database (unless the parent has their own FamilyCamp account, in which case their DOB was already collected during their own registration).\n\nFamily Information: Family name, member names, display names, avatar selections, assigned colors, roles, and invite codes for shared family planning. Members are added only through a controlled invite-and-approval process: every member holds their own account, an invite code is used to submit a join request, and a family admin (owner) or parent must explicitly approve that request before the person becomes a member. When you join a family, your name, display name, avatar, assigned color, and role, along with the events, lists, tasks, routines, milestones, and messages you create or share within that family, become visible to the other members of that family in accordance with each item's visibility settings. We do not create accounts or profiles on your behalf, and there are no unmanaged child profiles.\n\nCalendar Events: Event titles, dates, times, notes, location/address, GPS coordinates (with consent), recurrence rules (hourly, daily, weekly, monthly, yearly, and custom repeat intervals such as every N hours, days, weeks, or months), an optional recurrence end date, priority levels, reminder settings (one or more reminders, each from the time of the event up to four weeks before it), visibility preferences, and member assignments. This data is collected when you create or edit calendar events.\n\nShared Lists & Tasks: List names, task titles, due dates, completion status, member assignments, sort order, visibility settings, help-request indicators, and optional location/GPS coordinates on individual tasks. This data is collected when you create or manage shared lists.\n\nRoutines & Checklists (Premium): Routine names, icons, colors, schedule settings (daily, weekdays, weekends, custom, or recurring), step/item titles, time windows, member assignments, and completion tracking — including who completed each step and when. This data is collected when you create and use routines.\n\nBirthday & Anniversary Tracker (Premium): Person names, dates (birthdays, anniversaries, or custom milestones), milestone types, emoji labels, and notification preferences — including whether reminders are enabled and the reminder lead times you choose (for example, on the day, one day before, or one week before). Milestone reminders are delivered at 9:00 AM in the recipient's local time zone. This data is collected when you add milestones to your family's tracker.\n\nFamily Chat Messages (Premium): Message text content, timestamps, private-message recipient selections, read receipts (who read each message and when), emoji reactions, and — for messages posted in an event discussion — the identifier of the calendar event the message is associated with. Family chat is organized into threads: a shared \"General\" thread and a separate discussion thread for each calendar event. The event association determines which thread a message appears in; it does not change who can see the message. Chat messages are stored in our database for as long as your account is active. Private messages are only visible to the sender and selected recipients. When a calendar event is deleted, the messages in that event's discussion thread are permanently deleted along with it.\n\nLocation Data (Optional): When you explicitly grant permission, we collect GPS coordinates and address information to attach to calendar events and list tasks. This data is never collected without your express opt-in consent. You can revoke location access at any time. When you grant location consent, we also record your IP address along with the consent timestamp for compliance record-keeping purposes.\n\nPrecise location vs. IP-derived location — an important distinction: Opting out of, or never granting, location access completely stops all precise GPS/location collection; we cannot and do not capture your device’s GPS location without your opt-in, and this is true for every account with no exceptions. It does NOT, however, stop the separate, automatic recording of the IP address associated with content you upload. That IP address is ordinary network/technical metadata captured on every upload regardless of your location setting. If content you upload is later detected as suspected child sexual abuse material (CSAM) or other content that sexually exploits or endangers a minor, that IP address may be coarsely geolocated to an approximate city, region, and country and included in the report we are legally required to file with NCMEC (see “How We Use Location Data,” “Data Security,” and “Third-Party Services”). This coarse, IP-derived approximate location is legally distinct from the opt-in GPS location feature and cannot be disabled, because it is required for mandatory CSAM reporting under U.S. law (18 U.S.C. §2258A).\n\nAttachments: Photo (image) attachments sent in family messages and photos added to the family Photo Journal (including the file name, type, and MIME type) are stored in secure cloud storage (Amazon Web Services S3). For safety, only images (photos) may be uploaded — PDFs and other document types cannot be attached or shared. Attachment metadata is stored in our database.\n\nDevice Information: Push notification tokens for delivering reminders and chat notifications, device type for service optimization, and your device's time zone (for example, \"America/New_York\"). Your device's time zone is detected automatically from your device's system settings and is stored on your account so that reminders and scheduled notifications are delivered at the correct local time for you; at the family level it is used only as a fallback when an individual member's time zone is not yet known. Because you may travel or change your device's settings, we automatically re-check and update your stored time zone when you reopen the app, so your reminders stay accurate. A time zone is a coarse regional identifier (such as \"America/New_York\") — it is NOT precise GPS location, and we do not derive, infer, or store your precise location from it. You can also update your family's time zone at any time from Settings. Push notifications are delivered only to devices where you are actively logged in; if you log out, your device stops receiving push notifications until you log in again, and the associated push notification token is removed. You may log out of your account at any time. You may be logged in on more than one device, and each such device receives your notifications. If a device is shared, only the account currently logged in on that device receives push notifications — when a different account logs in on the same device, notifications are delivered to the newly logged-in account and no longer to the previous one. Tapping a notification opens the relevant screen in the app (for example, the family, calendar, list, or chat screen the notification relates to).\n\nPayment Information: All purchases are processed securely by the Apple App Store or Google Play. We use RevenueCat to verify purchases and manage your subscription entitlement. We never collect or store your credit card numbers or payment details."},{"title":"How We Use Location Data","content":"Location data is used solely to:\n• Attach a location/address to calendar events and list tasks you create\n• Show map previews for events with locations\n• Provide address search/autocomplete via OpenStreetMap\n\nLocation data is:\n• Only collected when you explicitly tap \"Use my location\" or search for an address\n• Never collected in the background\n• Never used for advertising or tracking\n• Never sold to third parties\n• Stored only as event/task metadata (latitude/longitude coordinates)\n• Deletable at any time through Settings → Privacy → Delete Location Data\n\nPrecise GPS location vs. IP-derived location: Everything above concerns precise GPS location, which we collect ONLY with your explicit opt-in and which you can turn off or delete at any time. It is entirely separate from the IP address we automatically record when you upload content — a standard network identifier captured regardless of your location setting. If uploaded content is detected as suspected CSAM or other minor-exploitation material, that IP address may be coarsely geolocated (to an approximate city, region, and country) solely for the mandatory report to NCMEC. Turning off, revoking, or never granting location access does NOT suppress this coarse, IP-derived approximate location, because it is required for legally mandated child-safety reporting and is not part of the optional GPS location feature."},{"title":"Legal Basis for Processing (GDPR)","content":"We process your data based on:\n• Consent: Location data is collected only after you provide explicit opt-in consent, which you can withdraw at any time.\n• Contract Performance: Account and family data is necessary to provide the planning service you signed up for.\n• Legitimate Interest: Device tokens for push notification reminders you configure."},{"title":"Your Rights","content":"Depending on your jurisdiction, you have the right to:\n\n• Access: View your account information in Settings, or export all your data via Settings → Privacy & Data → Export My Data. The export includes all personal information we have collected: account data, events, lists, messages, routines, milestones, location consent, and subscription details.\n• Rectification / Right to Correct: Update your name directly in Settings → Account. For other corrections, contact admin@togetherlee.com.\n• Erasure (\"Right to be Forgotten\"): Delete your location data (Settings → Privacy) or delete your entire account (Settings → Danger Zone). Account deletion immediately and permanently removes all your data including events, lists, tasks, chat messages, read receipts, chat reactions, routines, milestones (birthdays/anniversaries), push tokens, location consent, and any files stored in our cloud. Because subscriptions are billed by the Apple App Store or Google Play, deleting your account does not automatically cancel an active subscription — you must cancel it separately in your store subscription settings to stop future charges. Parents and legal guardians may also delete their minor child's account and all associated data directly from the Parental Controls screen in Settings.\n• Data Portability: Export your data in JSON format at any time via Settings → Privacy & Data → Export My Data.\n• Withdraw Consent: Revoke location consent at any time (Settings → Privacy) without affecting prior lawful processing.\n• Object: Object to processing based on legitimate interests by contacting us.\n• Non-Discrimination (CCPA): You will not receive different service for exercising your privacy rights.\n\nTo exercise these rights, use the privacy controls in Settings or contact us at admin@togetherlee.com. We respond to verifiable consumer requests within 45 days."},{"title":"Age Requirement & Children's Privacy (COPPA & California Compliance)","content":"FamilyCamp is strictly for users aged 13 and older. This App is off-limits for children under 13. During account registration, all users must provide their date of birth. Users under 13 are prohibited from creating an account, accessing the App, or using any of its features under any circumstances. The App will block registration and no personal information is retained. If we learn that a user under 13 has circumvented age verification, we will promptly delete their account and all associated data.\n\nThis section describes how we comply with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA, Cal. Civ. Code §§ 1798.100–1798.199.100), and the California Age-Appropriate Design Code Act (CAADCA, Cal. Civ. Code §§ 1798.99.28–1798.99.40).\n\nChildren Under 13:\n• We do not collect, store, or process any personal information from or about children under 13.\n• There are no child profiles, managed accounts, or any other mechanism within the App for storing data about children under 13.\n• This complies with COPPA's prohibition on collecting personal information from children under 13 without verifiable parental consent (16 C.F.R. Part 312). Because we store zero data about children under 13, no parental consent mechanism is required.\n\nTeen Accounts (Ages 13–17):\n• Users aged 13–17 may create an account but must provide a parent or guardian's email address during signup. The teen does not need to know the parent's age, account status, or any other personal information about the parent.\n• A verifiable parental consent email is sent to the parent containing Approve and Reject action links. The parent's identity is verified through access to the provided email address.\n• Before approval is processed, the consenting parent or guardian must verify their age by providing their date of birth on the consent page. Only adults aged 18 or older may approve a minor's account. If the parent already has a FamilyCamp account, the provided date of birth is cross-referenced against the one on file for additional identity verification. The parent's date of birth is used solely for age verification and is not stored beyond this purpose (unless the parent has their own account).\n• The minor's account is placed in a \"pending consent\" state until the parent responds. While pending, the minor cannot access any app features.\n• Consent tokens expire after 7 days. The minor may request a new consent email from within the App.\n• In compliance with CAADCA, we provide a high level of privacy by default for users under 18 and restrict data collection to what is necessary for the service.\n\nParental Controls:\n• Upon approval, a parent-child link is established between the parent's FamilyCamp account and the minor's account.\n• Parents can view their children's activity summary from the Parental Controls screen in Settings.\n• Parents can manage individual permissions for each child: location access, Smart Add (AI) — the AI-powered Quick Add feature, uploading photos to the shared Photo Journal, saving/downloading photos from the journal to the device, data export, and account deletion. In-app purchases are ALWAYS disabled for minors and cannot be enabled by a parent.\n• Parents may revoke consent at any time, which fully restricts the minor's account until consent is re-granted.\n• Parents may delete their child's account and all associated data at any time, directly from the Parental Controls screen in Settings. This permanently erases the minor's account and all data associated with it.\n• A minor can never be made the owner of a family. Family ownership and billing responsibility are reserved for adult members; a minor is never assigned or promoted to ownership.\n\nDefault Permissions for Approved Minor Accounts:\n• Location Access: Disabled (parent can enable)\n• In-App Purchases: Disabled (always disabled for minors; cannot be enabled)\n• Data Export: Enabled (parent can disable)\n• Account Deletion: Disabled (parent can enable)\n• Smart Add (AI): Enabled (parent can disable)\n• Upload Photos to Journal: Enabled (parent can disable)\n• Save/Download Photos from Journal: Enabled (parent can disable)\n\nMinors whose consent is pending or rejected cannot access any app features.\n\nIf we learn that a user under 13 has circumvented age verification, we will promptly delete their account and all associated data. If you believe a child under 13 has created an account, please contact us at admin@togetherlee.com."},{"title":"Data Retention","content":"We retain your data for as long as your account is active. Specifically:\n\n• Account data (email, name, date of birth, password hash, ToS acceptance record, email-consent record, and email-verified status): Retained for the lifetime of your account.\n• Email verification codes: The temporary one-time email-verification code and its expiry are retained only until your email address is verified or the code expires (whichever comes first), and are then deleted. Your email-verified status (a yes/no flag) is retained for the lifetime of your account.\n• Calendar events, shared lists, and task data: Retained until you delete individual items or delete your account.\n• Routines and completion logs: Retained until you delete individual routines or delete your account.\n• Birthday/anniversary milestones: Retained until you delete individual milestones or delete your account.\n• Chat messages, read receipts, and reactions: Retained for the lifetime of your account. Private messages remain accessible only to the sender and selected recipients. Messages posted in a calendar event's discussion thread are automatically and permanently deleted when that event is deleted.\n• Location data attached to events and tasks: Retained until you delete individual items, use \"Delete All Location Data\" in Settings → Privacy, or delete your account.\n• Location consent records (including IP address): Retained until you delete your account.\n• Message attachments in cloud storage: Retained until you delete the individual item or delete your account.\n• Operational & diagnostic logs (including AI Quick Add usage metadata — token counts, input character length, family identifier, AI model, and timestamps — and security/error logs): These logs never contain the content of your messages, events, tasks, or Quick Add input. They are retained for up to 90 days for billing/usage accounting, cost control, security, and abuse prevention, after which they are automatically rotated and deleted.\n\nWhen you delete your account, all personal data — including events, lists, tasks, routines, milestones (birthdays/anniversaries), chat messages, read receipts, chat reactions, family memberships, push tokens, message attachments (from cloud storage), location consent records, and IP addresses — is permanently and immediately removed. Because subscriptions are billed by the Apple App Store or Google Play, deleting your account does not automatically cancel an active subscription; you must cancel it separately in your store subscription settings to stop future charges.\n\nContent Preserved for Legal Reporting (CSAM & Safety Holds): If our automated moderation or a human reviewer preserves content as suspected child sexual abuse material (CSAM) or other content that sexually exploits or endangers a minor, that content and the associated account and technical information are placed on a legal hold. Under U.S. law (18 U.S.C. §2258A(h), as amended by the REPORT Act of 2024) we preserve it for at least one year, and we retain it thereafter for as long as required by law or as requested by NCMEC or law enforcement. Content on a legal hold is excluded from account deletion and from all automated cleanup (including the Dormant Lapsed-Premium Content cleanup described below), and it is never returned to you in a data export. When the applicable preservation and reporting obligations have ended, we may delete the preserved content.\n\nLeaving or Removal from a Family: When you leave a family, or a family admin or parent removes you, your family-membership record is deleted and you lose access to that family's shared information. To preserve the shared plans the other members rely on, content you created within that family (events, lists, tasks, routines, and milestones) is reassigned to the family owner or another remaining member and is retained by the family rather than deleted. Leaving or being removed does not delete your FamilyCamp account or your other personal data; to erase your personal data entirely, delete your account.\n\nDormant Lapsed-Premium Content: FamilyCamp+ premium content (Photo Journal photos, family chat messages and their photo attachments, routines, and birthday/anniversary milestones) is retained but locked when a subscription lapses. If the subscription remains lapsed AND no family member uses the family for an extended period of at least 9 months, we may permanently delete that locked premium-only content, including the associated files in cloud storage, to minimize the data we retain. Your account and free-tier data (calendar events and shared lists) are preserved, and any content under a legal-hold or preservation obligation is excluded and retained as required by law. This practice supports the data-minimization and storage-limitation principles of the GDPR, is disclosed in our Terms of Service, and is accepted by you when you create your account. We do not send a separate warning email before this cleanup; you can avoid it by keeping an active subscription or by exporting your data beforehand.\n\nFamily Ownership on Deletion: If you are the owner of a family and delete your account, ownership is automatically reassigned to another adult member of the family so the shared family data is preserved for the remaining members. A minor is never assigned or promoted to family ownership. If no adult member remains, the entire family and all of its shared data are permanently deleted at the time of your account deletion.\n\nParental Consent Data: Consent tokens are deleted upon use (approval or rejection) or upon expiry (7 days). The parent's date of birth entered on the consent page is never stored — it is used only for real-time age verification. Parent-child account links and permission settings are retained for as long as the minor's account is active and can be modified by the parent at any time. If parental consent is revoked, the minor's permissions revert to fully restricted defaults."},{"title":"Email Communications","content":"Togetherlee, LLC sends transactional emails for account verification, password resets, subscription changes, payment failures, and parental consent requests. These are essential service communications, not marketing emails. You acknowledge and agree to receive these essential emails during account registration (via the email-acknowledgment checkbox on the sign-up screen); our lawful basis is performance of our contract with you, not marketing consent, and we record the date, time, and version of your acknowledgment.\n\nService & Product Update Communications: In addition to the transactional emails above, we may from time to time send you service-related emails about material changes to the App or the services we offer — for example, notices of new, changed, or discontinued features, scheduled maintenance or service-availability notices, important security or privacy notices, and changes to our Terms of Service or this Privacy Policy. These are operational, service-related communications about a product you actively use, not marketing or promotional email; our lawful basis is our legitimate interest in keeping you informed about the service and, where applicable, performance of our contract with you. You cannot opt out of essential legal-change and security notices while you maintain an account. Genuine marketing or promotional emails are separate and are never sent without your distinct, opt-in consent, which you may withdraw at any time without affecting these essential service and update communications. We never send marketing or promotional emails to any user under 18.\n\nMinor Accounts (Ages 13–17): Because a minor cannot independently provide legally binding consent, essential service emails to a minor's own email address (such as email verification and password resets) are authorized by the verifiable parental consent we obtain during the parental approval process. By approving the minor's account, the parent or legal guardian consents on the minor's behalf to these essential communications. The parental consent request email is sent to the parent or guardian, not to the minor. We never send marketing or promotional emails to any user under 18, and a parent or guardian may revoke consent at any time (which restricts the minor's account) by contacting admin@togetherlee.com.\n\nIf you are not receiving emails from Togetherlee, LLC:\n• Check your Spam, Junk, or Promotions folder\n• Mark emails from Togetherlee, LLC as \"Not Spam\"\n• Add admin@togetherlee.com to your contacts or safe-sender list\n\nAll Togetherlee, LLC emails include a reminder to check spam/junk folders and instructions for adding our sender address to your safe-sender list. We do not send marketing or promotional emails without explicit opt-in consent."},{"title":"Payment & Financial Information","content":"Payment Processing:\n• All purchases are processed by the Apple App Store or Google Play, depending on your device. We never store, process, or have access to your credit card numbers, CVV, or bank account details.\n• We use RevenueCat, a subscription-management service, to securely verify your purchases and manage your premium entitlement. RevenueCat receives a store-provided purchase token and your app-level family identifier — never your card details.\n• Payment receipts and billing history are available directly through your Apple App Store or Google Play account.\n\nWhat the App Stores Process:\n• Credit/debit card details, billing address, and transaction history are collected and managed solely by Apple or Google in accordance with their own policies and PCI-DSS standards.\n• You can review Apple's privacy policy at https://www.apple.com/legal/privacy/ and Google's at https://policies.google.com/privacy. RevenueCat's privacy policy is available at https://www.revenuecat.com/privacy.\n\nSubscription Data We Store:\n• Plan type (monthly/annual), subscription status, start date, renewal date\n• Number of family members\n• A store transaction/subscription identifier and your family identifier (used to manage your entitlement)\n\nWe do not:\n• Store credit card numbers, CVV codes, or bank details\n• Sell or share financial information for advertising\n• Use payment data for purposes other than managing your subscription"},{"title":"Data Security","content":"We protect your data using:\n• Encrypted data transmission (TLS/HTTPS)\n• Hashed passwords (bcrypt)\n• Secure token-based authentication (JWT)\n• Email verification via one-time codes to confirm ownership of your email address\n• Payment processing handled entirely by the Apple App Store and Google Play (we never receive card data)\n• Secure cloud storage (Amazon Web Services S3) for file attachments\n• Access controls and role-based permissions\n\nHuman moderation for safety: To keep the service safe and to comply with app-store requirements and applicable law, authorized Togetherlee, LLC personnel may access and review User Content (chat messages and attachments) when reasonably necessary to investigate a report of objectionable content or abuse, to enforce our Terms of Service, or to comply with a legal obligation. Where warranted, we may permanently delete offending content, suspend or terminate any user's account — temporarily locking that user out of the App until the suspension is lifted — and remove any member, including a family owner, from a family (with ownership automatically reassigned to an eligible adult member, as described in our Terms). This access is limited to what is necessary for these safety and compliance purposes; we do not access your content for advertising, profiling, or any unrelated purpose. When a member reports content, our reviewer sees who filed the report and the account identifiers (name, email address, and account-creation date) of the member who created the reported item. We also keep a record of the reports each member files and whether they were upheld or dismissed, and show our reviewers a reliability indicator derived from that history, so we can identify and act on misuse of the reporting feature (such as repeated false or spam reports).\n\nWhat our staff can and cannot see: Your content is private. Unless an item is flagged for review — either reported by a human family member, or preserved as suspected child-exploitation material — no member of our staff reads your messages or opens your photos. Absent such a flag, your everyday content is not accessible to our staff at all. Our moderation tools are deliberately limited when it comes to your CONTENT, so we cannot browse your family's messages, photos, or other everyday content at will — the actual text and images of your calendar events, shared lists, milestones, and ordinary chat messages and photos are not visible to our staff. What our staff CAN see, without any report, is account- and family-level information rather than your content: a directory of families searchable by family name or family ID, in which each family is listed with its name, its number of members, a count of how many chat messages it contains (a number only — never their text), whether it is on a free or premium plan, and its creation date; and, for any family, its member roster — each member's display name, email address, role (owner, parent, member, or child), join date, and whether their account is suspended. We also maintain an internal cost-and-usage overview showing per-family counts (such as how many items were automatically screened, storage used, and plan). This account-level visibility lets us find the right account to act on a report or a safety issue; it does not let us read your messages or open your photos. A staff reviewer can read the text of a specific chat message only when a human family member has reported that message for review. Content flagged only by our automated AI scanner, and never reported by a person, is not shown to staff — for those items we retain only metadata (such as cryptographic hashes and the AI's reason), not the text or the image. Where a photo (or its accompanying text) is suspected to be CSAM or other child-exploitation material, it is withheld from our own staff by design and delivered to NCMEC automatically and server-to-server. The preserved IMAGE can NEVER be viewed, opened, downloaded, exported, emailed, or screenshotted by our staff under any circumstances. The preserved TEXT is likewise withheld by default, subject to one narrow exception: if the automatic report to NCMEC does not complete — for example it fails, or automated reporting is unavailable — an authorized operator may use an audited \"break-glass\" control to reveal the preserved text solely in order to file the legally mandated CyberTipline report by hand. Every such access is recorded in an audit log identifying who accessed it, when, and the stated reason, and it triggers an alert to the business owner, so no access is ever silent; the revealed text is used only to complete that report and is never used for any other purpose. Aside from this narrow, logged manual-filing path, there is no way for us to transmit the preserved content to anyone from our console. If law enforcement needs the content, we refer them to NCMEC, which holds it and coordinates disclosure.\n\nAutomated content moderation: To keep families safe, all content you create is automatically screened by an AI content-safety agent at the moment it is created, before it is saved or shown to other members. This screening applies across the whole app and to every family on every plan, including free-tier families. The text of calendar events (titles and notes), shared list names, task/to-do items, milestone names, routine names and their checklist steps, member display names, family names, chat messages, and photo captions is analyzed as text, and uploaded photos are analyzed as images (including any text, links, or QR codes visible within them). This screening looks for objectionable content such as harassment, hate, sexual content, child sexual abuse material (CSAM) and other child-exploitation content, self-harm, violence, illegal activity, illegal drugs, and unsafe links. Screening is performed by third-party and/or in-house AI providers acting as our data processors (see \"Third-Party Services\") and is used solely for safety and Terms-of-Service enforcement — never for advertising, profiling, or training models on your content. Depending on the result, content may be allowed, allowed but flagged for human review, blocked from being posted, or (where content is suspected to sexually exploit a minor) preserved and reported to the authorities with the responsible account suspended. From time to time we may also re-screen content that is already stored in the App using our current automated systems — for example after our detection rules are updated — so that content posted before a change is also checked against the latest safeguards. This periodic auditing is performed by automated systems.\n\nConversation context for child-safety screening: When we screen a chat message for child-safety risks, we may also consider a limited number of recent preceding messages in the same conversation thread as context. This context is used only at the moment of screening and only for child-safety detection, and it does not collect any new data about you.\n\nThis automated screening operates regardless of the language you write in: it is designed to detect objectionable content in many languages, not only English, and photos are screened for objectionable imagery as well as for any text visible within them in any language. Because our safety system can only clear content it is able to read, text written in a language our automated system cannot reliably recognize may be blocked or rejected at the moment you try to save it; if that happens, please rewrite your content in a widely used language (such as English) so it can be safely screened. Like all AI systems it is not perfect.\n\nWhere a single item contains both a photo and accompanying text (for example, a chat message with both a photo attachment and text, or a Photo Journal photo with a caption), both halves are screened together and treated as one item. If either the image or the accompanying text is suspected to sexually exploit a minor, the entire item is withheld and never posted or shown to anyone, is preserved on a legal hold, is reported to the authorities as a single combined report that includes every part of the item, and the responsible account is suspended. No part of such an item is published merely because only one half tripped the detection, and suspected material is never deleted before it has been screened and preserved. For safety, uploads are limited to images (photos); PDFs and other document types cannot be uploaded or shared. Automated moderation is not perfect: like all AI systems, it can make mistakes, and false positives (content wrongly flagged or blocked) as well as false negatives may occur; if you believe your content was wrongly flagged or blocked, you may contact us at admin@togetherlee.com to request human review.\n\nRight but not obligation to monitor; disclosure to authorities: We have the RIGHT, but NOT the OBLIGATION, to monitor, review, and screen User Content (chat messages and attachments). Any User Content that we reasonably suspect to be illegal — including, without limitation, child sexual abuse material (CSAM) or other content that sexually exploits or endangers a minor — may be preserved and disclosed, reported, or released to law enforcement, the National Center for Missing & Exploited Children (NCMEC), and other proper authorities, and to their agents and service providers, at any time, with or without notice to you, as we deem necessary or appropriate or as required or permitted by law. We may also preserve the associated account information for the same purpose. When our automated moderation detects apparent child sexual exploitation, FamilyCamp files a report with NCMEC's CyberTipline automatically through NCMEC's electronic reporting system (as an Electronic Service Provider), as soon as reasonably possible. Such a report may include the preserved content itself together with associated account and technical information — for example the uploader's email address, name or display name, account-creation date, the IP address linked to the content and an approximate location (city, region, and country) derived from that IP address using a third-party IP-geolocation service, the device/browser User-Agent, the account time zone, the names and email addresses of the other family members who could have received or viewed the content (its intended recipients), and the cryptographic hash values (SHA-256 and MD5) of the preserved file. These reports are filed automatically and retried automatically if a filing does not succeed on the first attempt; if automated filing still cannot be completed, we file the report manually so that a required report is never dropped. If law enforcement contacts us about a report, we refer them to NCMEC, which coordinates disclosure of the preserved content to the appropriate agency. This safety-and-legal disclosure is an exception to our general commitment not to share your content, and by using the App you consent to it."},{"title":"AI-Assisted Features","content":"FamilyCamp includes a \"Quick Add\" feature powered by artificial intelligence (AI). When you use Quick Add, the text you type (e.g., \"Soccer practice Tuesday at 4pm\") is sent to an AI language model to extract event or task details (title, date, time, etc.).\n\n• AI can make mistakes. AI language models can misinterpret input and generate results that are inaccurate, incomplete, or unexpected. FamilyCamp does not guarantee the accuracy or reliability of AI-generated events or tasks, and you should always review what the AI creates before relying on it. (Your legal rights and responsibilities regarding AI accuracy are described in the \"AI-Assisted Features\" section of our Terms of Service.)\n• The AI processes your input in real-time solely to create the calendar event or task you requested.\n• Your Quick Add input is NOT stored after processing, NOT used to train AI models, and NOT shared with third parties for advertising or profiling.\n• Operational metadata (non-content): to operate the feature responsibly we log limited metadata about each AI request — the token counts returned by the AI provider, the character length of your input, your family identifier, the AI model used, and a timestamp — solely for usage accounting/billing, cost control, and abuse prevention. This metadata does NOT include the text you typed or the resulting event/task, is never used for advertising, profiling, or model training, is treated as Internet or Network Activity (Category F) under the CCPA/CPRA, and is retained only in our operational logs for a limited period (see \"Data Retention\").\n• You can disable AI parsing for your entire family at any time in Settings → Smart Add (AI); when disabled, no text is sent to the AI provider and no such requests are made.\n• The AI does not have access to your account data, family information, or any other personal information beyond the text you submit in that single request.\n• No automated decisions are made about you based on AI processing — the AI only assists with data entry.\n• For minor accounts, Quick Add (Smart Add) is subject to parental controls and data minimization principles. In addition to the family-wide Smart Add (AI) setting, a parent can disable AI Quick Add for an individual minor from the Parental Controls screen using the dedicated Smart Add (AI) permission; when disabled for that minor, no text from the minor is sent to the AI provider."},{"title":"Third-Party Services","content":"We use the following third-party services:\n• OpenStreetMap/Nominatim: Address search and geocoding (your search queries are sent to OpenStreetMap servers)\n• Apple App Store & Google Play: Payment and subscription processing\n• RevenueCat: Subscription verification and entitlement management (receives store purchase tokens and your family identifier; never your card details)\n• SendGrid: Transactional email delivery (account verification, password resets, parental consent requests, subscription notifications)\n• Amazon Web Services (AWS S3): Secure cloud storage for user-uploaded message attachments\n• Expo Push Notifications: Delivery of reminder and chat notifications. Expo relays notifications through Apple Push Notification service (APNs) on iOS and Google Firebase Cloud Messaging (FCM, a Google service) on Android to reach your device; the notification payload and your device push token are transmitted through these services.\n• AI Language Model Provider: Processing of Quick Add text input for event/task creation (no personal data stored or used for training)\n• AI Content-Safety Moderation (OpenAI moderation and Abacus.AI): Automated screening of chat message text, photo captions, and uploaded photos for objectionable content, acting as our data processors. Content is analyzed only to determine a safety result and is not used for advertising or for training the providers' models. Unsafe-link checks use Google Web Risk / Safe Browsing.\n• IP Geolocation (ipwho.is): When we prepare a report of suspected child sexual abuse material (CSAM) or other content that sexually exploits a minor to NCMEC or other authorities, the IP address associated with the offending content is sent to a third-party IP-geolocation service (ipwho.is) to derive an approximate location (city, region, and country) for inclusion in that report. This lookup is used ONLY for law-enforcement/NCMEC reporting and is never used for advertising, analytics, tracking, or profiling.\n\nEach third-party service has its own privacy policy governing their data handling. We share the minimum data necessary with each service to provide the functionality described above. For minors, no data is shared with third-party advertising or analytics services."},{"title":"International Data Transfers","content":"Your data may be processed in servers located in the United States. If you are in the EU/EEA, we rely on Standard Contractual Clauses and your explicit consent for international data transfers."},{"title":"Categories of Personal Information Collected (CCPA/CPRA)","content":"The following table summarizes the categories of personal information we have collected in the preceding 12 months, as required by the California Consumer Privacy Act (Cal. Civ. Code § 1798.100):\n\nCategory A — Identifiers: Name, email address, date of birth, parent/guardian email (for minors). Collected to create and manage your account.\n\nCategory B — Customer Records (Cal. Civ. Code § 1798.80(e)): Name, email, payment information (processed by the Apple App Store or Google Play — we do not store card numbers). Collected to provide the service and process subscriptions.\n\nCategory C — Protected Classification Characteristics: Date of birth (used for age verification — minor/adult determination). Not used for any discriminatory purpose.\n\nCategory D — Commercial Information: Subscription plan, billing history (via the Apple App Store or Google Play), purchase records. Collected to manage your subscription.\n\nCategory E — User-Generated Content: Calendar event details (titles, notes, dates, times, recurrence, priorities, reminders), shared list/task data (titles, due dates, assignments, completion status, visibility, help requests), routine/checklist data (names, schedules, steps, completion logs), birthday/anniversary milestones (person names, dates, types), and family chat messages (text content, private-message selections, read receipts, emoji reactions, and the associated calendar event identifier for messages posted in an event discussion thread). All collected voluntarily by users to provide the family planning service.\n\nCategory F — Internet or Network Activity: Push notification tokens, device type, device time zone (automatically detected from your device settings and refreshed when you reopen the app), a temporary one-time email-verification code (used solely to confirm ownership of your email address, then deleted), IP address (recorded when you grant location consent, and also captured with content that our automated moderation preserves as suspected illegal content — such as child sexual abuse material — for reporting to the authorities, and that IP address may be coarsely geolocated to an approximate city, region, and country via a third-party service for inclusion in that report). Collected to deliver push notification reminders in your local time, verify your email address, and for safety and compliance record-keeping. The device time zone is a coarse regional identifier and is not precise geolocation. Push notification tokens are transmitted to Expo and, in turn, to Apple Push Notification service (APNs) on iOS or Google Firebase Cloud Messaging (FCM) on Android solely to deliver notifications to your device.\n\nCategory G — Geolocation Data: GPS coordinates (latitude/longitude) associated with calendar events and list tasks. Collected ONLY with your explicit opt-in consent.\n\nCategory H — Sensory Data: File and image attachments sent in family messages (including file name, type, and MIME type). Stored in secure cloud storage (AWS S3). Collected voluntarily by users.\n\nCategory I — Professional/Employment Information: Not collected.\n\nCategory J — Education Information: Not collected.\n\nWe do NOT collect: Social Security numbers, driver's license numbers, financial account numbers, biometric information, browsing history, or information from third-party advertising networks.\n\nDisclosure to Third Parties: We disclose Category A (identifiers — email) to SendGrid for transactional email delivery, Category D (commercial information) to RevenueCat and the Apple App Store or Google Play for payment and subscription processing, and Category H (file attachments) to Amazon Web Services for secure cloud storage. We do not sell or share any categories for cross-context behavioral advertising.\n\nRetention: We retain personal information only for as long as your account is active. Upon account deletion, all data is permanently removed."},{"title":"California Residents (CCPA/CPRA)","content":"California residents have additional rights under CCPA/CPRA (Cal. Civ. Code §§ 1798.100–1798.199.100):\n• Right to Know: What personal information we collect and how it is used. You can export all your data at any time via Settings → Privacy & Data → Export My Data.\n• Right to Delete: Request deletion of personal information via Settings → Danger Zone, or by contacting us.\n• Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is no need to opt out because no sale or sharing occurs.\n• Right to Correct: Update your name in Settings → Account, or contact us for other corrections.\n• Right to Limit Use of Sensitive Personal Information: We collect date of birth (stored for age verification for the lifetime of your account) and geolocation data (with consent, for event tagging). We also record your IP address when you grant location consent, for compliance purposes. We do not use sensitive personal information for purposes beyond providing the service. You may limit our use of your location data at any time via Settings → Privacy & Data → Location Access.\n• Right to Non-Discrimination: Exercising your privacy rights will never affect the quality or pricing of our service.\n\nVerifiable Consumer Requests: To exercise your rights, use the in-app privacy controls or email admin@togetherlee.com. We will verify your identity by confirming your account email address. We respond within 45 days (extendable by 45 days with notice).\n\nAuthorized Agents: You may designate an authorized agent to submit a request on your behalf. The agent must provide signed written authorization, and we may require you to verify your identity directly. Send authorized agent requests to admin@togetherlee.com.\n\nMetrics: In the preceding 12 months, we have not received any CCPA/CPRA requests for data access, deletion, or opt-out. This notice will be updated annually."},{"title":"Limit the Use of My Sensitive Personal Information","content":"Under the CPRA (Cal. Civ. Code § 1798.121), you have the right to limit the use and disclosure of your sensitive personal information to only what is necessary to perform the service.\n\nSensitive personal information we collect:\n• Date of birth — stored for the lifetime of your account, used solely for age verification (minor/adult determination)\n• Precise geolocation — collected only with your explicit opt-in consent, used solely to attach location to calendar events\n• IP address — recorded when you grant location consent, used solely for compliance record-keeping\n\nWe already limit all sensitive personal information to uses that are necessary to provide the service. We do not use it for profiling, advertising, or any secondary purpose.\n\nTo disable geolocation collection: Settings → Privacy & Data → Location Access (toggle off).\nTo request deletion of location data: Settings → Privacy & Data → Delete All Location Data.\n\nNote: Disabling geolocation turns off all precise GPS collection. It does not affect the IP address we record with uploaded content, which is separate network metadata; if such content is detected as suspected CSAM or other minor-exploitation material, that IP address may be coarsely geolocated (approximate city, region, and country) for the legally mandated report to NCMEC and cannot be disabled.\n\nBecause we already limit use to what is necessary, no additional opt-out action is required. If you have concerns, contact admin@togetherlee.com."},{"title":"Do Not Track Disclosure (CalOPPA)","content":"This disclosure is provided in compliance with the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §§ 22575–22579).\n\nTogetherlee, LLC does not track users across third-party websites or services and does not use cookies for advertising. Because we do not engage in cross-site tracking, our app does not change its behavior in response to \"Do Not Track\" (DNT) browser signals. No personal information is collected from third-party sites or services while you use FamilyCamp."},{"title":"Do Not Sell or Share My Personal Information","content":"Togetherlee, LLC does NOT sell your personal information. Togetherlee, LLC does NOT share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months. Because we do not sell or share personal information, there is no need to submit an opt-out request. This notice is provided in compliance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA, Cal. Civ. Code § 1798.120)."},{"title":"California \"Shine the Light\" Disclosure (Cal. Civ. Code § 1798.83)","content":"Under California's \"Shine the Light\" law (Cal. Civ. Code § 1798.83), California residents may request information about how we share personal information with third parties for their direct marketing purposes.\n\nWe do not share your personal information with third parties for their direct marketing purposes. We have not done so in the preceding 12 months.\n\nIf you have questions about this disclosure, contact admin@togetherlee.com."},{"title":"California Financial Information Privacy (Cal. Fin. Code § 4053)","content":"We comply with California financial information privacy requirements. All payment processing is handled by the Apple App Store and Google Play. We do not store, process, or access your credit card numbers, CVV codes, bank account details, or other financial account information. We store only a store-provided subscription identifier and your subscription status. We do not collect or share financial account information, as we never receive it."},{"title":"California Compliance Summary","content":"This Privacy Policy is designed to comply with the following California and federal regulations:\n\n• Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506): We do not collect, store, or process any personal information from or about children under 13.\n\n• California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA, Cal. Civ. Code §§ 1798.100–1798.199.100): See \"Categories of Personal Information,\" \"California Residents (CCPA/CPRA),\" \"Limit the Use of My Sensitive Personal Information,\" and \"Do Not Sell or Share\" above.\n\n• California Online Privacy Protection Act (CalOPPA, Cal. Bus. & Prof. Code §§ 22575–22579): See \"Do Not Track Disclosure\" above.\n\n• California Age-Appropriate Design Code Act (CAADCA, Cal. Civ. Code §§ 1798.99.28–1798.99.40): See \"Age Requirement & Children's Privacy\" above.\n\n• California \"Shine the Light\" (Cal. Civ. Code § 1798.83): See disclosure above.\n\n• California Automatic Renewal Law (Cal. Bus. & Prof. Code §§ 17600–17606): Auto-renewal terms are clearly disclosed before purchase, explicit consent is obtained, and confirmation with cancellation instructions is provided. See our Terms of Service.\n\n• California Financial Information Privacy Act (Cal. Fin. Code §§ 4050–4060): See \"California Financial Information Privacy\" above.\n\n• California Consumer Credit Reporting Agencies Act (Cal. Civ. Code § 1785.1 et seq.): Not applicable — we do not operate as a consumer credit reporting agency.\n\n• Song-Beverly Credit Card Act (Cal. Civ. Code § 1747.08): We do not collect personal identification information as a condition of accepting credit card payments.\n\nFor questions about California-specific compliance, contact admin@togetherlee.com."},{"title":"Updates to This Policy","content":"We may update this Privacy Policy periodically. Material changes will be communicated through the app and, where appropriate, by email to the address associated with your account. Continued use after changes constitutes acceptance."},{"title":"Contact Us","content":"For privacy inquiries or to exercise your rights:\nTogetherlee, LLC\nEmail: admin@togetherlee.com\n\nFor EU residents, you also have the right to lodge a complaint with your local data protection authority."}]}