Family FreelySign in
Back to FamilyFreely

Trust centre

Privacy Notice

FamilyFreely is designed for families to collaborate without advertising trackers, shared passwords, or unnecessary surveillance. This notice explains what the hosted service processes and the choices available to your household.

Effective 21 July 2026

Who operates FamilyFreely

The hosted FamilyFreely service is operated by MaPeL-LAB. Questions, access requests, or deletion questions can be sent to privacy@mapellab.app.

Information the service processes

  • Account identity, such as email address, display name, household membership, role, and permissions.
  • Household content you choose to enter, including accounts, budgets, categories, transactions, goals, recurring items, imports, and messages.
  • Points & Rewards records, including parent-managed profile names, age bands, behaviours, balances, rewards, questions, and guardian acknowledgements.
  • Authentication and device records, such as sessions, passkey public credentials, authenticator settings, notification subscriptions, and security events.
  • Operational metadata needed for reliability, audit history, abuse prevention, and troubleshooting.

FamilyFreely does not ask for bank passwords, advertising identifiers, contacts, precise location, biometric templates, or children's dates of birth. Face ID, Touch ID, Windows Hello, or Android device authentication stays with the operating system; the service receives a public-key result.

Why it is used

Data is used to provide the household workspace, apply role-based visibility, authenticate members, deliver requested email or device notifications, keep writes consistent, prevent abuse, support exports and deletion, and maintain an owner-visible audit trail. FamilyFreely does not sell personal information, show behavioural advertising, or use third-party advertising trackers.

Optional OpenAI assistance

FamilyFreely Assist is optional and may be disabled by the operator. When enabled, it sends only the minimum context needed for a positive points-plan draft or product workflow answer. It excludes transaction rows, account details, emails, household messages, point history, and child names. Requests use store: false and a hashed safety identifier. AI output is advisory and cannot change money, points, permissions, rewards, or account state.

Service providers

The hosted service uses Cloudflare for application delivery, Workers, transactional email, and notification infrastructure; Neon for hosted PostgreSQL; and OpenAI only when the optional Assist feature is enabled. Browser push delivery also passes through the notification service used by the member's browser or operating system. These providers process data only to operate the requested service under their applicable terms.

Household visibility and children

Household owners control invitations, roles, and visibility. Restricted members do not receive full financial data or other members' email addresses. Child and teen profiles are parent-managed, use broad age bands rather than birth dates, and do not support public profiles, leaderboards, or under-13 self-registration. A guardian acknowledgement is required before the optional response-cost feature can affect a child profile.

Storage and retention

Account and household records are retained while needed to provide the service. Access tokens are short-lived; refresh sessions expire or can be revoked. Account deletion revokes authentication and anonymizes the departing user. Financial and audit records that belong to a shared household may remain so another member's records stay coherent and corrections remain visible. Backup retention and any legally required preservation are controlled by the operator's reviewed production schedule.

Your choices

  • Export household transaction history from Settings.
  • Correct household records through the relevant workflow or remove mistaken transactions with an owner-visible audit entry.
  • Disable notifications on each device and remove passkeys or authenticator access from Security settings.
  • Request account deletion; owners must first hand the household to another adult or remove the household.
  • Contact the operator to ask about access, correction, deletion, objection, restriction, or applicable privacy rights.

Changes to this notice

Material changes will be dated here and should be communicated in the application before they take effect. This notice describes the current FamilyFreely application; a self-hosted operator is responsible for its own deployment, providers, retention schedule, and legal obligations.