Privacy Policy
1. Who we are
FamilyFind is independently operated from Israel. This policy covers the Android app, the public website, Firebase/Google services used by FamilyFind, optional telemetry, feedback, and support.
2. Intended users and children
FamilyFind is for parents, guardians, and other authorized adult caregivers, not child-created accounts. Adults are responsible for lawful authority and for considering the privacy and dignity of people shown in photos.
3. Photos and face processing
Selected photos, face crops, facial representations, match results, scores, filenames, and album paths stay on the device. OpenCV components process them locally; temporary face representations are held in memory only and are discarded after processing. FamilyFind does not upload photos or face data, train models on them, sell them, or share them with the operator.
4. On-device storage
The app stores child nicknames, Android-granted photo references, album/date choices, settings, legal acceptance, and limited search history in private app storage. App data is excluded from Android cloud backup and device transfer. Search history is limited to 30 days. Exported copies are controlled by your photo library.
5. Cloud data
Firebase Authentication processes the Google sign-in identity. Firestore stores limited account access policy and shared scan-usage records: normalized email, access state, limit, count, period, app version, and timestamps. It does not receive photos, child names, face data, media references, match results, or scores. Google may process technical security and service data under its own terms.
6. Background scans and permissions
Automatic scanning is opt-in, can be disabled in Settings, and uses Android’s photo permission only for the album and recurring feature you choose. FamilyFind keeps a Photo Picker route for one-off reference-photo selection. Notifications avoid photo, child-name, face, and match-detail content.
7. Optional telemetry and crash reports
Telemetry and Crashlytics are off by default. If enabled, telemetry sends only allowlisted coarse actions, versions, Android SDK, language, a monthly rotating installation identifier, and timestamps. Crash reports may contain stack and device diagnostics. FamilyFind does not deliberately attach account identity, photos, child data, face data, URIs, results, or free text. Telemetry and feedback are configured for 30-day expiry; Crashlytics follows Google’s retention process.
8. Feedback and support
Match feedback may include a verdict, coarse count bands, optional text, and your email only if you explicitly allow contact. Support messages contain your signed-in email and message. Do not send photos, child names, face data, tokens, private diagnostics, or health information. Directly linked support and opted-in contactable feedback are deleted with the account; unlinked aggregate feedback expires after 30 days.
9. Why we use data
We use data to authenticate, provide requested local features, enforce access and scan limits, secure and troubleshoot the service, respond to requests, comply with law, and improve reliability only where you opt in.
10. Sharing and security
Google/Firebase is a service provider for authentication, database, App Check, and optional crash reporting. FamilyFind does not sell personal information or run targeted advertising. Controls include encrypted transport, no cleartext traffic, backup exclusion, restricted Firestore access, App Check configuration, and on-device processing. No system is perfectly secure.
11. Retention and deletion
You can remove local data, uninstall, or request deletion in the app or at /account-deletion. After recent-authentication confirmation, the trusted backend deletes Firebase Auth, account lifecycle, policy, usage, direct support messages, and contactable match feedback. A keyed opaque deletion tombstone is retained for 30 days to make retries truthful and prevent immediate account recreation; a keyed rate-limit record is retained for 24 hours. Pending technical request records expire within 7 days. These records contain no photos, names, face data, or raw email in their keys. Exported album copies remain in your photo library.
12. Your choices and contact
You can revoke Android permissions, disable automatic scans, telemetry, or crash reporting, delete local data, and request account deletion. For privacy questions contact FamilyFindApp@gmail.com. Identity verification may be needed before a request. This policy is version 2026-08-22-legal-v6 and takes effect 22 August 2026.