Privacy policy
1. At a glance
Personal data is any information that can identify you. This policy covers this website and the FamilyManager app (iOS, iPadOS and web app). It explains what we collect, why we use it and what rights you have.
2. Controller
Controller within the meaning of Art. 4(7) GDPR:
Ben Kohler
Auf dem Kreuz 32/1
89073 Ulm
Germany
Contact: mail@benkohler.de
3. Data we process and why
Registration and account
When you register we process your email address, your chosen display name and, if provided, a profile picture and date of birth. You may alternatively sign in with Google or Apple, in which case we receive your email address and name from those providers. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Household content
In the app you create content: events, tasks, shopping lists, messages and other entries. This content is visible to the members of your household. Legal basis: Art. 6(1)(b) GDPR.
Managed children's accounts
Parents can create accounts for their children without a separate email address. We process the display name chosen by the parent, an identifier and a sign-in code. The account is set up by the holder of parental responsibility, who thereby also provides consent under Art. 8 GDPR. Legal basis: Art. 6(1)(b) GDPR in conjunction with Art. 8 GDPR.
Payment data
Premium subscriptions are processed through Stripe (web app) or Apple in-app purchase and RevenueCat (iOS). From these providers we receive a user identifier, the product identifier, transaction and receipt data and the purchase status including renewal and cancellation. We neither receive nor store full payment details such as card numbers. Legal basis: Art. 6(1)(b) GDPR.
Server logs
When you open the website, the hosting provider automatically records the IP address, date and time, the address requested, the referrer, browser type and operating system. Legal basis: Art. 6(1)(f) GDPR (operation and security of the service).
4. Processors and third-party services
We use the following providers. Data processing agreements under Art. 28 GDPR are in place with all of them.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and backend | United States, processing in the EU (Ireland) |
| Vercel Inc. | Hosting of the website and web app | United States |
| Stripe | Payment processing in the web app | United States and Ireland |
| Apple | In-app purchases and push delivery on iOS | United States and Ireland |
| RevenueCat Inc. | Subscription management on iOS | United States |
| Resend | Transactional email delivery | United States |
| Optional sign-in with a Google account | United States and Ireland | |
| Giphy | GIF search in the family chat, only when used | United States |
The database and stored content are located in the Europe (Ireland) region. Some of the providers listed are established in the United States. Where personal data is transferred to a third country in the process, the transfer is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR.
5. Web analytics
This website and the app do not use any third-party analytics or tracking services. No usage statistics are shared with third parties and no analytics cookies are set. Within the app we record individual technical events about the setup process in order to detect errors.
6. Cookies and local storage
We do not use advertising or analytics cookies. For technical purposes we store on your device a sign-in token for the current session, your language preference and the key material required for encryption. The web app may additionally cache content for offline use. This data does not leave your device and is deleted when you sign out. Legal basis: Art. 6(1)(b) GDPR and Section 25(2) TDDDG.
7. Encryption and security
All traffic is transmitted over TLS. Access to data is further restricted by row-level security rules in the database, so that each household can only read its own content.
Key content is additionally encrypted on your device before it is stored (AES-256-GCM). This covers in particular task and event titles, message content, shopping items, notes, expense titles and notes together with budget and expense categories, the password area, children's profiles and the files in the document vault.
Not encrypted in this way is information that has to be evaluated for the service to work. This includes email addresses and names, times and due dates, assignments to people, amounts, currency and dates of expenses, the names of event and task categories, names of lists and folders, the entries of the custody schedule, and images attached in the family chat or as proof on a task. This data is protected by access control and transport encryption, but is technically accessible to us as the operator.
8. Retention
We store your content for as long as your account exists. After you delete your account, your personal data is removed; content you created in a shared household remains available to the other members and is detached from your person.
In addition we delete automatically:
- activity feed entries after 90 days
- device tokens for push notifications after 60 days without use
- records limiting registration attempts after 30 days
- attachments on events after the event, if you enabled that option
- technical operating logs after 7 days
9. Your rights
You have the right at any time to:
- access your stored personal data (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- object to processing (Art. 21 GDPR)
- data portability (Art. 20 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR)
You can start an export and delete your account directly in the app. The export contains your profile, memberships, tasks, messages, checklists and care log entries. For anything beyond that, a message to mail@benkohler.de is enough.
You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Wuerttemberg, Germany.
10. Automated decision-making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place.
11. External links
This website may contain links to external sites. We accept no responsibility for their content or privacy practices.
12. Changes to this policy
We update this policy when our processing changes. The current version is always available on this page and in the app.
Status: September 2026