Famio Care
Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how personal data is collected, used, and protected when you use the Famio Care mobile application and related services (the "App"). We process your data in accordance with the EU General Data Protection Regulation (GDPR).
Family care data. Famio Care lets you record care information about the people you look after (for example a child, baby, or elderly relative). Some of this information — such as medications, temperature, symptoms, or notes — may reveal health-related details. By entering this information you confirm that you are entitled to provide it, and that where it concerns another person (including a minor) you have the authority or consent to do so.
1. Who is responsible for your data
2. What data we collect
2.1 Account data
Authentication is handled by our identity provider, Auth0. We store in our own database:
- Email address
- First name, last name, display name (where provided)
- Profile picture URL (where provided by your login provider, e.g. Google)
- A pseudonymous account identifier from Auth0
- Account creation and update timestamps
We never receive or store your password. Credentials are managed entirely by Auth0.
2.2 Care profiles
- The name of the person being cared for
- Profile type (adult, baby, child, elderly)
- Date of birth (optional)
2.3 Care records (may include health-related data)
- Feeding (bottle volume, breastfeeding duration, solid food, water)
- Diaper changes
- Sleep periods
- Medication name and dose
- Temperature, pulse, blood pressure
- Symptoms and free-text notes
- Date and time of each entry, and which member recorded it
2.4 Sharing and access data
We store who has access to which care profile, their role (owner, caregiver, viewer) and permissions. Invitation codes are stored only as a secure hash, never in readable form.
3. Data we do not collect
- No analytics, advertising, or third-party tracking tools.
- No location, contacts, camera, microphone, or photo library access.
- No push notifications.
- We do not sell your data.
4. How we use your data
| Purpose | Legal basis (GDPR) |
| Providing the App and its care-tracking features | Performance of a contract (Art. 6(1)(b)) |
| Storing care records you enter, including health-related details | Your explicit consent (Art. 9(2)(a)) |
| Authenticating and securing your account | Legitimate interest / contract |
| Responding to your requests (deletion, export) | Legal obligation / contract |
5. Third parties and where your data is stored
| Provider | Role | Location |
| Auth0 (Okta) | Authentication / identity | EU region |
| Railway | Backend hosting & database | EU region |
| Cloudflare | DNS, domain, static pages | Global CDN |
The App communicates only with our own backend service. No other external service receives your data.
6. Data retention
We keep your data for as long as your account and care profiles exist. We do not run automatic time-based deletion. When you delete your account, data is removed or anonymized as described in Section 8.
7. Your rights
- Access the personal data we hold about you
- Export your data in a portable format (available in-app)
- Correct inaccurate data
- Delete your account and associated data
- Withdraw consent for health-related records at any time
- Lodge a complaint with a data protection supervisory authority, including the National Center for Personal Data Protection of the Republic of Moldova
8. Deleting your account
You can delete your account in the App, or via our Account Deletion page. When you do:
- Care profiles where you are the only member are permanently deleted, including all their records.
- For profiles shared with other caregivers, ownership is transferred to another member and the shared history is kept for them — but anonymized, so it is no longer linked to your identity.
- Your account is deleted from our database and from Auth0.
9. Children's data
Famio Care is intended to be used by adults. Care profiles may describe minors, but this information is entered by the responsible adult, not collected from the child directly. The App is not directed at children and does not knowingly allow children to create accounts.
10. Security
Authentication tokens are stored securely on your device (iOS Keychain / Android Keystore). API access and real-time connections require a valid authenticated session. Data in transit is protected with HTTPS.
11. Changes to this policy
We may update this Privacy Policy as the App evolves (for example, if we introduce payments or register a company). We will update the "Last updated" date and, for significant changes, notify you in the App or by email.
12. Contact
admin@nullrom.com