Privacy Policy
In one line: we collect only what the app needs, store it encrypted, never sell it or show ads, and you can export or delete everything yourself at any time. FF Family LTD is the data controller. We process your data to provide the service you signed up for, on the basis of your informed consent, and for no other purpose.
What we collect
Only what the app needs to do its job for you:
- Your account info: email, the name you choose, your country and currency.
- Your financial data: the accounts, transactions, balances, budgets, goals, and other entries you create.
- Your calendar data: events, reminders, habits, tasks you add.
- Your connections: when you connect to a family member, friend, client, or supplier who also uses FF Family, we record that the connection exists, plus the data you both agree to share.
- Light technical and usage data: events like sign-ins and sessions, plus basic first-party measures of how the app is used (which features, how often, roughly how long). Used only for security/abuse-prevention and improving the product. Never sold, never shared with advertisers, never used to profile your finances or market to you.
We don't ask you for, and please don't enter, bank credentials, login passwords, or account-access details. We never connect to your bank, never move money, never need access to your accounts. By design, there's no place in the app to enter such credentials.
We also don't collect: photos, scanned documents, PDF statements, or other file uploads (deliberately unsupported); third-party trackers, advertising or marketing analytics, fingerprinting, or tracking pixels. There are no ads, ever, and nothing is sold to anyone.
Where it's stored
- Google Cloud / Firebase: our database (Firestore) is hosted in Google's European Union multi-region; some processing (Cloud Functions) runs on Google servers in the United States. Data is encrypted at rest and in transit.
- SendGrid: delivers outbound emails (invites, password resets, verification). Email subject and recipient address pass through SendGrid; bodies aren't stored on their side beyond delivery.
That's it. We do not copy your data to any other service.
Who can see your data
- You. Always. Export everything via Settings > Export; delete everything via Settings > Delete account.
- People you explicitly share with. If you create a pool, share a goal or budget, or connect with someone, the data inside that shared surface is visible to those people. Nothing else is.
- Google and SendGrid, as infrastructure providers, bound by their own terms; they don't get to use your data for their products.
- If the law requires it. We may disclose information under a court order or a lawful demand by a competent authority, and we will tell you about it, unless we are legally barred from doing so.
Administrators do not read your data. Our admin tools manage account-level operations only (waitlist approvals, invite quotas, deletion requests, abuse reports); they are not designed to and are not used to browse your financial or personal content. Every administrative action writes to an audit log.
Children
FF Grows is designed for children and works only through an account created and supervised by a parent or legal guardian. The guardian consents on the child's behalf, controls the connection, and can review and delete the child's data at any time. We collect no more data about a child than the app needs, and children's data is never used for marketing of any kind.
Your rights and how long we keep data
You can access, export, correct, and delete your data yourself, at any time, from inside the app (Settings > Export / Delete account). Under Israeli privacy law (the Protection of Privacy Law, 5741-1981, as amended) you also have rights to review and correct information we hold about you. Write to us and we'll act within the timeframes the law sets.
Retention: we keep your data only while your account exists. Deleting your account removes your data from the live systems immediately. Residual copies in encrypted backups expire on the backup rotation schedule (daily backups after 7 days, weekly backups after 14 weeks), after which no copy remains. Logs of administrative actions are kept for 90 days.
Cookies and local storage
We use no third-party cookies and no advertising cookies. The apps use your browser's local storage for functional needs only: your session, your preferences, and your consent record.
International transfers
As described above, your data is stored in the EU and some processing runs in the US (Google) with email delivery via SendGrid (US). For these transfers we rely on our providers' contractual data-protection commitments, in line with the Israeli Privacy Protection (Transfer of Data Abroad) Regulations.
Security
- Google-managed authentication with mandatory email verification; invite-only registration.
- Per-document database security rules: data is returned only to its owner or people it's explicitly shared with.
- Sensitive operations run server-side (Cloud Functions), with rate limiting on abuse-prone endpoints.
- HTTPS everywhere; secrets kept in a managed secret store, not in code; IP addresses hashed with a secret salt when logged for security (raw IPs aren't stored).
- Audit logging for administrative actions; daily backups with deletion protection.
- Planned: two-factor authentication (public beta), a formal third-party security audit (before public launch).
Languages
This policy is published in English and Hebrew (fffam.app/privacy-he). For users in Israel the Hebrew version prevails in case of conflict; for all other users the English version prevails.
Changes to this policy
If this policy materially changes, we will notify you and ask you to re-accept it inside the app before you continue. The version and effective date above are updated with every change.
Contact
Questions or requests: support@fffam.app. FF Family LTD, Buki Ben Yagli 11, Tel Aviv, Israel, Company No. 517355863.