Privacy Policy
Last updated: September 1, 2026
FamilyBox ("we", "us") is a task, calendar, and household management app for families, available at family.theideabox.app. This policy explains what information we collect, how we use it, and the choices you have. The short version: we collect only what the app needs to work, we never sell your data, and we never use it for advertising.
Information we collect
Account information. Your email address, used to sign you in and identify you within your family workspace.
Content you add. Tasks, projects, routines, journal entries, photos, shopping lists, recipes, meal plans, people and organization records, and anything else you or your family members create in the app.
Usage logs. Standard technical logs (timestamps, error details) used to keep the service running and diagnose problems.
Google user data
FamilyBox offers optional integrations with Google services. If you connect a Google account, we request the following permissions and use them only as described:
- Google Calendar (read —
calendar.readonly).We read events from the calendars you choose so they can appear alongside your family's tasks and agenda, and so the app can suggest routines, important dates, and birthdays from events you already have. - Google Calendar (events —
calendar.events). When a calendar event is mirrored as a task in FamilyBox and you edit or delete that task, we update or delete the corresponding event on your calendar so the two stay in sync. - Google Photos Picker (
photospicker.mediaitems.readonly).When you choose to add a photo from Google Photos, we access only the specific items you pick in Google's picker, to import them into your family journal or as covers for your content. We never browse your photo library.
Google user data is stored only to the extent needed for these features: calendar events you sync are cached in our database so the app is fast and works offline from Google, and photos you pick are copied into your workspace's private storage. We do not use Google user data for advertising, do not sell it, and do not share it with third parties except the infrastructure providers listed below, acting on our behalf. Google user data is never used to train AI or machine-learning models — neither generalized nor personalized — and is never transferred to AI model providers for that purpose.
FamilyBox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect your Google account at any time from the app's settings, which stops all access, or revoke FamilyBox's access from your Google Account permissions page.
How we use information
We use your information solely to provide FamilyBox: displaying your family's tasks and calendars, syncing with services you connect, and keeping your workspace secure. Some optional features (for example, suggested task fields or organization lookups) send the relevant text to Anthropic's Claude API to generate a suggestion; these requests are limited to the content needed for the feature, and Google user data is excluded from them.
Who can see your data
Your data belongs to your family workspace. Members of your workspace can see the content shared in it. We do not sell, rent, or share your personal information with third parties for their own purposes. We rely on a small set of infrastructure providers to run the service — Supabase (database, authentication, and file storage), Vercel (hosting), and Anthropic (optional AI features as described above) — each of which processes data only on our behalf.
Data retention and deletion
We keep your data for as long as your account is active. Disconnecting a Google account stops syncing and revokes our access tokens. To delete your account and its data, email us at the address below and we will remove your workspace content, including cached Google Calendar data and imported photos, within 30 days.
Security
Data is encrypted in transit (HTTPS) and at rest by our database provider. Access is protected by row-level security so each family's data is isolated, and Google access tokens are stored server-side and never exposed to the browser.
Children
FamilyBox accounts are created and managed by adults. Family workspaces may contain information about children that a parent or guardian chooses to add; we do not knowingly collect information directly from children under 13.
Changes to this policy
If we make material changes to this policy, we will update the date at the top of this page and, for significant changes, notify account holders by email.
Contact
Questions about this policy or your data? Email hq@hazelq.com.