Last updated: September 10, 2026
AltoTech operates Famalio, a shared family calendar. For privacy questions and requests, contact support@altotech.com.
We process the account identifier and confirmed email address supplied by Apple or Google to sign in and restore your family. Apple may provide a private relay email address. Family information includes names, roles, optional profile images, calendar titles, dates, times, entered locations, notes, shifts, assignments, and attachments you choose to add. Provide only information needed for your family's planning.
Famalio stores a local copy on your device and synchronizes shared family content through Supabase. The current database project is hosted in West EU (Ireland). Shared synchronization in this version does not use your personal iCloud account. Server-side access rules restrict content to authorized family members; viewers cannot retrieve parent-only event contents. Authorized operators and the hosting provider can technically access server contents. This is not end-to-end encryption.
An invitation contains a random token, is bound to the intended confirmed account email, expires after seven days, and can be revoked by the organizer. The server stores a hash of the token. The token is in the invitation URL fragment and is not sent to the navigation endpoint. Family administrators manage membership and access roles. Information already copied or exported by a member cannot be recalled.
Document recognition normally uses Apple's on-device Vision framework. You review extracted calendar entries before saving them. Saved shared entries are synchronized to Supabase. Images or documents that you explicitly attach to shared events are uploaded with those events.
If you configure an OpenRouter API key and explicitly enable cloud AI for a document import, recognized document text is sent to OpenRouter and the selected AI provider for analysis. The app displays this transfer before use. This optional processing is separate from on-device recognition and is subject to those providers' policies. Avoid sending sensitive documents unless you intend that processing.
Optional calendar permission allows Famalio to display your device-calendar events. Notification settings determine which local reminders your device schedules from its latest synchronized information. The 'Zeit für uns' feature only reads stored calendar entries to display gaps. It does not create or change events and cannot account for plans or travel times missing from the calendar.
Supabase provides authentication and shared storage. Apple provides Sign in with Apple, on-device recognition and App Store purchase processing. Google provides Google sign-in. Famalio offers Apple and Google sign-in; it does not offer email-code or password login or use an SMTP service for sign-in. OpenRouter and the selected model provider receive document text only when optional cloud AI is enabled as described above. We do not sell family content to advertisers or data brokers, and the app does not use advertising tracking.
Hosting and authentication services process technical request information needed to deliver and protect the service. Contact us for information about their operational logs and applicable retention.
To activate Family Pro for your Famalio family, our server verifies Apple's signed purchase information. We process your Famalio account identifier, Apple product and transaction identifiers, purchase environment, validity periods and revocation information. This associates a verified subscription with the purchaser's current Famalio family and supports renewals, restoration and refunds. Apple handles payment; Famalio does not receive or store your payment card details.
Authorized family members can see their family's Pro status and account count, but cannot retrieve the purchaser's transaction identifiers. Subscription records in active storage are removed when the associated Famalio account is deleted. The backup and log limitations below also apply. Account deletion does not cancel an Apple subscription.
Family content remains in the shared service until it is deleted through the app. Uninstalling Famalio does not delete your server account or family. Use 'Delete account' in the app to request account deletion; an organizer must first delete their family. If account deletion cannot be completed in the app, contact support@altotech.com.
Signing out removes the app's local family replica and associated local widget and reminder data, while keeping server data available for restoration with your account. Removing a member prevents further authorized server access; an offline device learns of removal when it reconnects. Manage or cancel subscriptions through Apple.
Deletion from active storage and deletion from operational logs or backup copies are separate processes. Contact us for information about retention and deletion of any backup copies. We do not claim immediate erasure of offline copies or exports held by other family members.
Parents and organizers can create and manage dependent family profiles. They should provide only the information needed for planning and review who can access their family. A dependent profile does not require a separate email account.
You can review and edit information where your role permits, change notification preferences, disable optional device permissions or cloud AI, leave a family, and request account deletion. Contact support@altotech.com for access, correction, deletion, or other privacy-rights requests. Applicable rights depend on your location and circumstances.
We update this page when our practices change and revise the date above. Contact: support@altotech.com.