Privacy & cookies
A family's records are sensitive. This page explains, in plain language, what Famvaro stores, why, who else touches it, and what control you have.
Last updated 24 September 2026 · applies to the invite-only beta
Famvaro is in an invite-only beta. This policy describes how it works today and will be reviewed, and updated where needed, before the service opens to the public.
1. Who we are
Famvaro is operated by Edward Ljunggren, a private individual based in Sweden, who is the “controller” of the personal data described here. You can reach us at hello@ljunggren.org or via the contact page.
Within a family, the family’s admin decides what is put on the family’s site and who can see it. We process that content on the family’s behalf to run the service.
2. What data we handle
Your account
- Your name, email address and profile picture, as provided by Google when you sign in.
- Your role in your family (admin, full or restricted) and the time you last signed in.
What your family adds
- Member profiles: birthdays, clothing sizes, health notes, passport and ID details, and scanned documents.
- Calendar events, chores, meal plans, travel plans and bookings, stories, photos and birthdays.
- Finances: accounts and balances, investments, pensions, property and vehicles, bank-statement transactions, budgets, subscriptions and saved logins.
- Files you upload (PDFs, images) and the notes attached to them.
Some of this is sensitive — for example health notes and identity documents. Only add what you and the people concerned are comfortable storing here; by adding it you ask us to process it for your family.
If you request an invite
- Your name, email, the family name you give and an optional note.
Technical data
- Session cookies (see below) and standard server logs, which can include your IP address and the pages requested.
- Your IP address is also used briefly, in memory, to limit repeated requests and prevent abuse.
AI features
- When you use the assistant or an AI import, your question, the relevant parts of your family’s data, and any file you attach are sent to our AI provider to produce the answer.
3. Why we use it
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service you signed up for: sign-in, storing and showing your family’s content, sending invitations | Performance of a contract (Art. 6(1)(b)) |
| Keeping the service secure, preventing abuse, fixing faults | Legitimate interests (Art. 6(1)(f)) |
| Optional features you switch on, such as calendar sync or connecting a photo server; sensitive information you choose to add | Your consent (Art. 6(1)(a) and 9(2)(a)), which you can withdraw |
| Answering rights requests and meeting legal obligations | Legal obligation (Art. 6(1)(c)) |
We don’t use your data for advertising, we don’t sell it, and we don’t profile you.
4. Who we share it with
We use a small number of service providers (“processors”) to make features work. They receive only what each feature needs.
| Provider | What for | Data involved | Location |
|---|---|---|---|
| Supabase | Database and file storage | All family content and files | EU (Stockholm) |
| Sign-in; optional Calendar sync | Name, email, picture; calendar entries you choose to sync | US / global | |
| Anthropic (Claude API) | The AI assistant and AI imports | Your question, relevant family data, attached files | US |
| SendGrid (Twilio) | Sending invitation and request emails | Email address, name, family name | US |
| Flight-schedule providers (AeroDataBox, AviationStack) | Flight lookup on a travel plan | Flight number and date, only when you use lookup | Various |
| OpenStreetMap (Nominatim) | Turning photo locations into place names | Approximate coordinates | UK / EU |
| Swedish Transport Agency | Vehicle details lookup | The registration number you enter | Sweden |
| Our application server | Running the site | Everything the site handles while you use it | Sweden |
If your family connects its own services (a Synology or Immich photo server), those connections are configured and controlled by your family. We may also disclose data if the law requires it. Inside a family, other members can see what the family’s admin allows.
5. Transfers outside the EU/EEA
Some providers above are based in, or process data in, the United States. Where personal data leaves the EU/EEA we rely on the safeguards in those providers’ data-processing terms, such as the European Commission’s standard contractual clauses or an adequacy decision. Your family’s stored data is held in the EU.
6. Cookies
Famvaro uses only the cookies it needs to work. There are no analytics, advertising or tracking cookies, so there is no cookie banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
| Session cookie | Keeps you signed in | Up to 30 days, or until you sign out |
| Sign-in security cookies (CSRF and callback) | Protect the sign-in step and return you to the right page | Session / a few minutes |
| Preference cookie | Remembers your display currency | Up to 5 years |
| Calendar-connect cookie | Protects the Google Calendar connection step, if you use it | 10 minutes |
7. How long we keep it
- Family content is kept while the family has an account. If a family is closed, or you ask us to delete your data, we delete it.
- Deleted data can remain in our database provider’s backups for a limited time until they are overwritten.
- Invite requests are kept so we can manage approvals; ask us and we will delete yours.
8. How we protect it
- Connections to the site are encrypted (HTTPS).
- Each family’s data and files are kept separate, and every request is checked against the family you belong to.
- Vault passwords and connected-account tokens are encrypted, each family under its own key.
- Access inside a family is controlled by roles set by the family’s admin.
No system is perfectly secure. If you find a problem, please tell us — see the contact page.
9. Your rights
Under the GDPR you can ask us to:
- give you a copy of your personal data and details about how it is used;
- correct data that is wrong or incomplete;
- delete your data, or restrict how it is used;
- give you your data in a portable format;
- stop processing that is based on legitimate interests, and withdraw any consent you gave.
Email hello@ljunggren.org and we will reply within one month. If you are a member of a family, some content is managed by your family’s admin, and we may need to involve them. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY, imy.se) or your local data-protection authority.
10. Children
Famvaro is for families, and families include children. Adults set up and manage the family, decide what is stored about children, and are responsible for it. We don’t market to children, and children join only through a family invitation.
11. Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and tell family admins by email or in the site. The latest version is always on this page.