Privacy Policy
Last updated: 20 September 2026
About Famalio
Famalio is operated by Markus Fischnaller under the AltoTech name. Famalio is a shared family calendar. For privacy questions or requests, contact support@altotech.com.
Information we process
Famalio processes the account identifier and confirmed email address supplied by Apple or Google so that you can sign in, restore your account and share a family. Apple may supply a private relay email address.
Shared family information can include member names and roles, optional profile images, calendars, event titles, dates and times, entered locations, notes, assignments, shifts, comments, preparation checklists, lists and files or images that users choose to attach. Users can explicitly classify medical appointments and enter medication-related preparation items. This may reveal health information. Only add information that your family needs for planning and that you are authorized to share.
Shared storage and access
Famalio stores a local copy on the device and synchronizes shared family content through Supabase. The current database project is hosted in West EU (Ireland). Shared synchronization does not use a personal iCloud account. Server-side access rules restrict data to authorized family members and apply event and calendar permissions. Authorized operators and the hosting provider can technically access server contents. The service is not end-to-end encrypted.
Family members can add comments to shared events. These comments are visible to family members who can access the event and are stored with the event in Supabase.
Family invitations
An invitation contains a random token, is bound to the intended confirmed account email, expires after seven days and can be revoked by the organizer. The server stores a hash of the token. The token is placed in the invitation URL fragment and is not sent to the navigation endpoint. Family administrators manage membership and access roles. Information already copied or exported by another member cannot be recalled.
Document recognition and optional cloud AI
Document recognition normally uses Apple's on-device Vision framework. Users review extracted calendar entries before saving them. Saved shared entries synchronize to Supabase. Images or documents explicitly attached to shared events are uploaded with those events.
If a user configures an OpenRouter API key and explicitly enables cloud AI for a document import, recognized document text is sent to OpenRouter and the selected model provider for analysis. The app displays this transfer before use. This optional processing is separate from on-device recognition and is subject to the applicable providers' policies. Avoid sending sensitive documents unless you intend this processing.
Device calendars, reminders and free-time suggestions
Optional calendar permission allows Famalio to display device-calendar events. A device-calendar source stays local unless the user explicitly enables sharing for that source. Notification settings determine which reminders and family-change alerts are delivered. The “Zeit für uns” feature reads available calendar entries to display gaps. It does not create or change events and cannot account for missing plans or travel time.
Push notifications
When remote family-change notifications are enabled, Famalio stores the push token supplied by Apple or Google together with the signed-in account identifier, platform and environment, locale, time zone and notification-preview preference. These values are used only to route, localize and protect notification contents. They are not used for advertising or tracking. The token is removed for the account or device when notifications are unregistered or the user signs out; invalid tokens are also removed when the notification provider reports them.
Family Pro purchase verification
To activate Family Pro, the server verifies signed purchase information. Famalio processes the account identifier, store product and transaction identifiers, purchase environment, validity periods and revocation information. This associates a verified subscription with the purchaser's current family and supports renewals, restoration and refunds. Apple or Google handles payment-card information; Famalio does not receive or store payment-card details.
Authorized family members can see their family's plan status and account count but cannot retrieve the purchaser's transaction identifiers. Deleting a Famalio account does not automatically cancel an App Store or Google Play subscription.
Service providers and tracking
Supabase provides authentication and shared storage. Apple provides Sign in with Apple, on-device recognition, push delivery and App Store purchase processing. Google provides Google sign-in and, on Android, push delivery and Google Play purchase processing. OpenRouter and the selected model provider receive document text only when optional cloud AI is explicitly enabled.
Famalio does not sell family content to advertisers or data brokers and does not use advertising tracking. We require service providers that receive Famalio user data to protect it to the same or an equivalent level described in this policy and required by applicable law.
Retention, deletion and signing out
Family content remains in active shared storage until an authorized user deletes it or the family is deleted. Account, membership, push and active subscription-verification records remain while needed to operate the account and are removed from active storage when the associated account is deleted, subject to family-ownership safeguards. An organizer must delete or transfer responsibility for their family before deleting the organizer account.
Signing out removes the local family replica and associated local widget and reminder data while keeping server data available for later sign-in. Removing a member prevents future authorized server access; an offline device learns of the removal when it reconnects. Uninstalling the app does not delete the server account or family.
Deleted data may remain temporarily in managed backups and security or operational logs until those copies expire through normal provider rotation. Backup copies are used only for disaster recovery, not ordinary product use. Where Famalio controls the retention period, deleted data is removed from backups within 30 days and security or operational logs are removed or anonymized within 90 days, unless a longer period is required by law or is necessary to investigate security, fraud or abuse. Information already exported or copied by another family member cannot be remotely erased.
Use the in-app Delete account action to request deletion. If deletion cannot be completed in the app, contact support@altotech.com. Contact the same address for access, correction, deletion or other privacy-rights requests.
Children's profiles and user choices
Parents and organizers can create dependent profiles without separate sign-in accounts. They should provide only information needed for planning and review who can access the family. Users can review and edit information where their role permits, change notification preferences, disable optional permissions or cloud AI, leave a family and request account deletion. Applicable rights depend on location and circumstances.
Policy updates
We update this page when our practices change and revise the date at the top of the page.