Privacy policy

1. At a glance

Personal data is any information that can identify you. This policy covers this website and the FamilyManager app (iOS, iPadOS and web app). It explains what we collect, why we use it and what rights you have.

2. Controller

Controller within the meaning of Art. 4(7) GDPR:
Ben Kohler
Auf dem Kreuz 32/1
89073 Ulm
Germany
Contact: mail@benkohler.de

3. Data we process and why

Registration and account

When you register we process your email address, your chosen display name and, if provided, a profile picture and date of birth. You may alternatively sign in with Google or Apple, in which case we receive your email address and name from those providers. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Household content

In the app you create content: events, tasks, shopping lists, messages and other entries. This content is visible to the members of your household. Legal basis: Art. 6(1)(b) GDPR.

Managed children's accounts

Parents can create accounts for their children without a separate email address. We process the display name chosen by the parent, an identifier and a sign-in code. The account is set up by the holder of parental responsibility, who thereby also provides consent under Art. 8 GDPR. Legal basis: Art. 6(1)(b) GDPR in conjunction with Art. 8 GDPR.

Payment data

Premium subscriptions are processed through Stripe (web app) or Apple in-app purchase and RevenueCat (iOS). From these providers we receive a user identifier, the product identifier, transaction and receipt data and the purchase status including renewal and cancellation. We neither receive nor store full payment details such as card numbers. Legal basis: Art. 6(1)(b) GDPR.

Server logs

When you open the website, the hosting provider automatically records the IP address, date and time, the address requested, the referrer, browser type and operating system. Legal basis: Art. 6(1)(f) GDPR (operation and security of the service).

4. Processors and third-party services

We use the following providers. Data processing agreements under Art. 28 GDPR are in place with all of them.

ServicePurposeLocation
SupabaseDatabase, authentication and backendUnited States, processing in the EU (Ireland)
Vercel Inc.Hosting of the website and web appUnited States
StripePayment processing in the web appUnited States and Ireland
AppleIn-app purchases and push delivery on iOSUnited States and Ireland
RevenueCat Inc.Subscription management on iOSUnited States
ResendTransactional email deliveryUnited States
GoogleOptional sign-in with a Google accountUnited States and Ireland
GiphyGIF search in the family chat, only when usedUnited States

The database and stored content are located in the Europe (Ireland) region. Some of the providers listed are established in the United States. Where personal data is transferred to a third country in the process, the transfer is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

5. Web analytics

This website and the app do not use any third-party analytics or tracking services. No usage statistics are shared with third parties and no analytics cookies are set. Within the app we record individual technical events about the setup process in order to detect errors.

6. Cookies and local storage

We do not use advertising or analytics cookies. For technical purposes we store on your device a sign-in token for the current session, your language preference and the key material required for encryption. The web app may additionally cache content for offline use. This data does not leave your device and is deleted when you sign out. Legal basis: Art. 6(1)(b) GDPR and Section 25(2) TDDDG.

7. Encryption and security

All traffic is transmitted over TLS. Access to data is further restricted by row-level security rules in the database, so that each household can only read its own content.

Key content is additionally encrypted on your device before it is stored (AES-256-GCM). This covers in particular task and event titles, message content, shopping items, notes, expense titles and notes together with budget and expense categories, the password area, children's profiles and the files in the document vault.

Not encrypted in this way is information that has to be evaluated for the service to work. This includes email addresses and names, times and due dates, assignments to people, amounts, currency and dates of expenses, the names of event and task categories, names of lists and folders, the entries of the custody schedule, and images attached in the family chat or as proof on a task. This data is protected by access control and transport encryption, but is technically accessible to us as the operator.

8. Retention

We store your content for as long as your account exists. After you delete your account, your personal data is removed; content you created in a shared household remains available to the other members and is detached from your person.

In addition we delete automatically:

9. Your rights

You have the right at any time to:

You can start an export and delete your account directly in the app. The export contains your profile, memberships, tasks, messages, checklists and care log entries. For anything beyond that, a message to mail@benkohler.de is enough.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Wuerttemberg, Germany.

10. Automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.

11. External links

This website may contain links to external sites. We accept no responsibility for their content or privacy practices.

12. Changes to this policy

We update this policy when our processing changes. The current version is always available on this page and in the app.

Status: September 2026