Privacy Policy
Last updated: August 17, 2026
1. Responsible Party
The responsible party under the Data Protection Regulation (Art. 4 No. 7 GDPR) for data processing on this website and in the Famora.EE app is:
MATTALNET GRUPP OÜ
Tuukri tn 19-315
10120 Tallinn
Estonia
Represented by: Andreas A. Gleim
Registration code: 14744075
E-Mail: mail@famora.one
Contact: Contact form
2. Data Collected
In the course of using Famora.EE, we collect and process the following personal data:
- Account data: Phone number, name, email address (during registration)
- Location data: GPS coordinates of family members (only when actively shared)
- Calendar data: Events, recurrences, participants
- Chat data: Messages in family chat (encrypted transmission and encrypted storage; access is restricted to your family)
- Voice input: Audio recordings for event creation (deleted immediately after processing). To improve recognition quality, the speech recognition system receives the first names of family members, the names of your safe places, and frequently used addresses as recognition aids (details in section 7).
- Poster scan / Multi-scan: Photos of posters, notices, or flyers are first processed on your device using text recognition (OCR); the recognized text is transmitted to our servers for event recognition. If the text is insufficient for a reliable result — or if you select precise photo recognition — an additional reduced copy of the photo is transmitted for one-time evaluation and not permanently stored (details in section 7).
- Email→Event (optional): Text from emails that family members forward to your family's personal Famora inbox address. Emails from unknown senders are not accepted; the original email is deleted immediately after evaluation (details in section 7).
- Medication plan (optional): Medication plans you voluntarily create for family members — medication name, dosage, intake times, duration, notes, reminders recipients you select, and intake confirmations ("taken", "later", "missed") with timestamp. These are health-related data (details in section 7a).
- Dietary preferences (optional): Selectable dietary attributes per family member (e.g., gluten-free, vegan) for meal planning suggestions and — only when additionally activated — for location-based suggestions (details in section 7b).
- Place suggestions: Information about public places your family suggests for the place directory — name, address, contact details, website, category, and dietary offerings (details in section 7c).
- Device information: Device type, operating system, app version (for technical support)
- Waitlist: Email address and optionally name (when signing up for the waitlist)
3. Legal basis
The processing of your personal data is based on the following legal bases under the GDPR:
- Art. 6 Abs. 1 lit. a GDPR — Consent (e.g., location sharing, waitlist)
- Art. 6 Abs. 1 lit. b GDPR — Contract performance (provision of app features)
- Art. 6 Abs. 1 lit. f GDPR — Legitimate interests (security, technical operation)
- Art. 9 Abs. 2 lit. a GDPR — Explicit consent for special categories of personal data (health data in the voluntary medication plan and potentially health-related dietary information, sections 7a and 7b)
4. Storage duration
- Location data: Deleted automatically and irrevocably after 30 days.
- Account data: Stored as long as your account is active. After account deletion, all data is removed within 30 days.
- Chat messages: Stored until deleted by the user or when the account is deleted. Additionally, automatic deletion can be enabled in each chat group (e.g., after 30 days); when enabled, older messages and attachments are automatically and irrevocably removed. This setting is optional and managed by your family.
- Chat attachments: Photo and voice attachments in family chat are automatically deleted 30 days after sending.
- Voice input: Audio recordings are deleted immediately after processing. Only the extracted event is stored.
- Read-aloud audio files (TTS): Generated voice output is stored on our own servers to provide repeated playback without additional external processing. Files with personal content (e.g., names of your family members) are exclusively associated with your family and are automatically deleted after 90 days of non-use.
- Forwarded emails (Email→Event): The original email is deleted immediately after evaluation. Only the evaluation result (recognized event suggestions) is stored.
- Medication plan: Entries and intake confirmations are stored until the plan is deleted. Upon account deletion, they — like all account data — are removed within 30 days (details in section 7a).
- Waitlist: Email data is stored until launch or until you request deletion.
5. Subscription, blocking, and deletion for non-payment
Use of Famora.EE requires an active subscription after the 14-day trial period expires. If your family's subscription ends — such as through cancellation or non-renewal — access to the family account is blocked.
30 days after the subscription ends, the family's data is deleted. Before this deadline, we notify you by email and push notification so you can renew your subscription or export your data beforehand. Statutory retention obligations (e.g., for billing data) remain unaffected.
We inform you about changes to features and your subscription — such as the end of the trial period, an upcoming block, or deletion — within the app and via email or push notification. The legal basis is Art. 6 Abs. 1 lit. b GDPR (contract performance).
6. Recipients of data
Your data is not shared with third parties for advertising or analysis purposes. There are no advertising partners, no third-party analytics tools, and no data sales. Famora.EE is funded through a fair subscription model, not by user data.
For technical operations, we use selected processors under Art. 28 GDPR: our hosting providers in Germany, our email service provider one.com (for sending and receiving emails, e.g., notifications and the Email→Event function), and — exclusively for the AI functions described in section 7 — specialized AI service providers. We have data processing agreements (DPA) with all processors; they process data only on our instructions.
Payment processing. Subscriptions and add-on packages purchased through the Apple App Store or Google Play are processed by Apple or Google respectively; we only receive a purchase confirmation to verify entitlement (purchase token or transaction ID, product and status), not payment data such as card numbers. The individually agreed Enterprise plan is billed via the web with our payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland); Stripe processes the resulting payment and billing data as an independent controller or processor. The legal basis in each case is Art. 6 Abs. 1 lit. b GDPR (contract performance).
7. AI-powered features and processors used
Famora.EE offers optional assistant features that use external AI services. Three principles apply:
- No autonomous decisions: AI never acts independently. Every suggestion (e.g., a recognized event, conflict resolution, or pickup request) is presented to you for review and only adopted after your explicit confirmation.
- Data minimization: GPS coordinates, raw location data, complete chat histories, or email addresses of third parties are never transmitted to AI services — only the text content absolutely required in each case.
- Transparency: Proactive suggestions (e.g., daily brief or pickup reminders) include a traceable explanation of why you're receiving them. All AI functions can be disabled in settings.
Data flows for individual features:
- Voice event capture: Your audio recording is sent to OpenAI (Whisper) for conversion to text. Recognition aids such as the first names of your family members, the names of your safe places, and frequently used addresses are provided so these terms are recognized correctly. The recognized text is then sent to one of the AI processors listed below for event recognition. The audio recording is deleted immediately after processing.
- Poster/Multi-scan: Text recognition (OCR) is initially performed on your device; the recognized text is sent to one of the AI processors listed below for event recognition. If the recognized text is insufficient for a reliable result — or if you explicitly select precise photo recognition — an additionally reduced copy of the photo is transmitted so the model can read the layout of the document. The photo is used exclusively for this single evaluation and is not permanently stored by us or the processor.
- Daily brief (Smart Brief): Family facts already summarized on our server (e.g., today's events, pending confirmations, birthdays, tasks) are sent to one of the AI processors listed below to compose a brief summary text. The weather forecast is retrieved via Open-Meteo; only a rough regional coordinate is transmitted, no personal data.
- Conflict resolver: For event conflicts, the affected event titles and times are sent to one of the AI processors listed below to formulate solutions.
- Pickup assistant: No cloud AI is used. Distance calculation is performed exclusively on our own servers; location data does not leave our servers. Notifications contain only pre-composed text.
- Email→Event: The text of emails that a family member forwards to your family's Famora inbox address is sent to one of the AI processors listed below for event recognition. Only emails from verified family member addresses are accepted; the original email is deleted immediately after evaluation.
- Read aloud (text-to-speech): The text to be read aloud is sent to OpenAI or ElevenLabs for voice synthesis. The generated audio files are stored on our own servers (storage duration see section 4).
AI processors used: For redundancy, we operate multiple equivalent providers for event recognition; each request is processed by exactly one of them. For all: only the content mentioned above for each function is transmitted, and the data transmitted via the API is not used by each provider to train AI models.
- Anthropic (USA): Language model for event recognition (from text, photos, and emails) and text composition. Data is retained only for the duration of processing according to API retention conditions. Legal basis: Art. 6 Abs. 1 lit. b GDPR (provision of the function you use). Transfer to the USA is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
- OpenAI (USA): Speech recognition (Whisper) for converting your audio recordings to text including the mentioned recognition aids; voice synthesis for the read-aloud function; optionally, event recognition from text and photos. Legal basis: Art. 6 Abs. 1 lit. b GDPR. Transfer to the USA is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
- Google (USA): Optionally, event recognition from text and photos (Gemini), if the primary providers are not available. Legal basis: Art. 6 Abs. 1 lit. b GDPR. Transfer to the USA is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
- Mistral AI (France, EU): Optionally, event recognition from text, if the primary providers are not available. Processing occurs within the EU. Legal basis: Art. 6 Abs. 1 lit. b GDPR.
- ElevenLabs (USA): Voice synthesis (text-to-speech) for the read-aloud function. Only the text to be read aloud is transmitted. Legal basis: Art. 6 Abs. 1 lit. b GDPR. Transfer to the USA is based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
- Open-Meteo: Retrieval of weather forecast for the daily brief. Only a rough regional coordinate is transmitted — no personal data. Legal basis: Art. 6 Abs. 1 lit. f GDPR (legitimate interest in functional weather display).
- one.com: Email service provider for sending notification emails and receiving Email→Event messages. Legal basis: Art. 6 Abs. 1 lit. b GDPR.
Voice recordings of children are only sent to speech recognition if parents/guardians have enabled the voice function for the family (see section 11).
7.5 Transparency according to Art. 50 EU AI Regulation
Famora.EE uses AI exclusively in a supportive capacity. We explicitly inform you when you're using an AI function:
- Product labeling: Content generated by AI — such as suggested recipes or the daily brief — is visibly marked as AI-generated in the app.
- Read-aloud text: The "read aloud" function produces a synthetic voice. Generated audio files contain machine-readable marking identifying them as artificially created. No real person's voice is imitated; a standard catalog voice from our service provider is used.
- No automatic decisions: AI never independently creates events or other entries. Every suggestion must be confirmed by you.
- No emotion or biometric recognition: Famora does not analyze emotions or biometric characteristics.
- Disableable: All AI functions can be disabled in settings; the remaining functions remain fully usable.
7a. Medication plan (health data)
With the medication plan, you can voluntarily create medication plans for family members. Processed data includes: medication name, dosage, intake times, duration, notes, reminder recipients you select, and intake confirmations ("taken", "later", "missed") with timestamp.
This information constitutes health data within the meaning of Art. 9 Abs. 1 GDPR. Processing is based exclusively on your explicit consent (Art. 9 Abs. 2 lit. a GDPR), which you grant by actively creating a medication plan. You can withdraw consent at any time for the future by deleting the plan; associated data will be removed in the process.
Data is visible exclusively within your family. Reminders and escalation notifications are sent only to family members the plan creator selected. Intake events are additionally entered in the family activity chat; these chat entries are — like all chat messages — stored encrypted. The medication plan entries themselves are stored on our servers in Germany like other app data (e.g., calendar data).
Medication data is not transmitted to AI services or other third parties and is not used for advertising or analysis purposes. Account deletion follows the 30-day deletion period (section 4).
7b. Dietary preferences and location-based suggestions
For each family member, dietary attributes (e.g., gluten-free, vegan) can optionally be stored. They are used for suggestions in your family's meal planning. The legal basis is your consent (Art. 6 Abs. 1 lit. a GDPR); to the extent that health circumstances can be inferred from an entry (e.g., an intolerance), processing is based on your explicit consent (Art. 9 Abs. 2 lit. a GDPR), which you grant by voluntarily storing the entry.
Location-based suggestions (only when activated): Only when a family member has enabled the corresponding toggle and simultaneously has location sharing enabled will the location reports already processed as part of location sharing be compared on our servers with the published places in the place directory within the self-selected radius (1–50 km). When there is a match, the member receives a push notification and an entry is created in a family activity feed. To limit the frequency of suggestions, a notification log (member, place, time) is stored.
No additional movement tracking occurs. When the toggle or location sharing is disabled, the comparison ends. The legal basis is your consent (Art. 6 Abs. 1 lit. a GDPR).
7c. Place directory (user suggestions)
Families can suggest public places for the place directory. Captured data includes the place's name, address, contact details, website, category, and dietary offerings. Suggestions are reviewed by us before publication; only after approval are the submitted (business) contact details published in the app.
If a website is provided, our server automatically retrieves this publicly accessible website once to verify the name and address for review purposes. The legal basis is Art. 6 Abs. 1 lit. f GDPR (legitimate interest in an accurate and abuse-free directory); for providing the suggestion function otherwise Art. 6 Abs. 1 lit. b GDPR.
8. Data subject rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): You can request information about your data stored with us at any time.
- Right to rectification (Art. 16 GDPR): You can request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You can request deletion of your data. In the app, you can delete your account and all associated data yourself.
- Right to data portability (Art. 20 GDPR): You can export your data in a common format.
- Right to object (Art. 21 GDPR): You can object to processing of your data at any time.
- Right to lodge a complaint: You have the right to lodge a complaint with a data protection authority.
9. Cookies and analytics
Necessary cookies. Technically necessary cookies required for website function are used (e.g., session cookies). Your consent decision for analytics is stored locally in your browser (localStorage), not as a cookie.
Cookie-free analytics (always active). For anonymous traffic measurement, we use the self-hosted, open-source tool "Umami", which runs on our own servers in Germany. Umami sets no cookies, creates no cross-device profiles, and transmits no data to third parties. Only aggregated, anonymous metrics are captured (e.g., pages visited, country, device type). The legal basis is our legitimate interest in privacy-respecting traffic measurement (Art. 6 Abs. 1 lit. f GDPR). Consent is not required because no cookies are set and no personal profiles are created.
Google Analytics (only with your consent). Additionally, we use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) — but only if you actively consented in the cookie banner. Without your consent, Google Analytics is not loaded and no data is transmitted to Google. After your consent, Google Analytics sets cookies and processes, among other things, your (shortened) IP address, browser and device information, and your website usage behavior; IP anonymization is enabled. This may result in data transmission to Google servers, including in the USA (third-country transfer). The legal basis is your consent (Art. 6 Abs. 1 lit. a GDPR and § 25 Abs. 1 TTDSG). You can withdraw your consent at any time for the future — via the "Cookie settings" link in the footer.
10. Hosting
This website and the Famora.EE app are hosted on servers in Germany. Your stored data (account, calendar, chat, locations) remains on these servers. Data transfer to third countries outside the EU occurs only in the context of the AI functions described in section 7 — based on Standard Contractual Clauses or the EU-US Data Privacy Framework.
For map display in the Famora.EE app, we use OpenStreetMap. Map tiles are loaded from OpenStreetMap Foundation (OSMF) servers. Due to technical reasons, your IP address is transmitted to OpenStreetMap to display the map. The legal basis is Art. 6 Abs. 1 lit. f GDPR (legitimate interest in functional map display). For more information, see OpenStreetMap's privacy policy: wiki.osmfoundation.org/wiki/Privacy_Policy .
11. Children and minors
Pursuant to Art. 8 GDPR, processing personal data of children under 16 years of age is only permitted with parental consent. In Famora.EE, child accounts can only be created and managed by parents or guardians. All privacy settings for children are controlled by parents.
The same applies to AI functions: voice recordings of children are only sent to speech recognition if parents/guardians have enabled the voice function for the family. Parents/guardians can disable this function at any time.
12. Contact
For privacy questions, you can reach us by email at mail@famora.one or via our contact form .
