GDPR-compliant · encrypted transmission

Privacy isn’t a feature. It’s the foundation.

This is a courtesy translation provided for convenience. The German version is legally binding.

This privacy policy describes what data we process when you visit this website and when you use the famagic app, what for — and what rights you can exercise at any time.

Last updated: August 2026 SSL/TLS-encrypted

01Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

famagic UG (haftungsbeschränkt) i. G.
represented by Yvonn Rau & Henning Rau
Kuckhoffstr 31
13156 Berlin
E-Mail

02General information on data processing

Protecting your personal data matters to us. This privacy policy informs you about which personal data we process and how. It covers visits to our website famagic.app (sections 03 to 09) and use of the famagic app (section 10).

03Hosting

Our website is hosted by an external service provider. The personal data collected on this website is stored on the host’s servers. This may include, in particular, IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data, and other data generated via a website.

We use the host for the purpose of fulfilling our contract with our potential and existing users (Art. 6(1)(b) GDPR) and in the interest of providing our online offering securely, quickly, and efficiently through a professional provider (Art. 6(1)(f) GDPR).

04SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the browser address bar switching from “http://” to “https://” and by the lock icon in your browser bar.

05Server log files

The provider of these pages automatically collects and stores information in so-called server log files, which your browser transmits to us automatically. These are: browser type and browser version, operating system used, referrer URL, hostname of the accessing computer, time of the server request, IP address.

This data is not merged with other data sources. It is collected on the basis of Art. 6(1)(f) GDPR.

06Contact form

If you send us inquiries via the contact form, the details you provide in the form, including the contact information you enter there, will be stored by us to process your inquiry and to handle any follow-up questions. We do not share this data without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR, provided your inquiry relates to the performance of a contract or is necessary for pre-contractual measures.

07Beta waiting list & feature requests

On this website you can sign up for the closed beta of the famagic app and send us feature requests. Both are voluntary.

Beta waiting list

We process the email address you provide, optionally a first name or a form of address of your choosing, and the platform you want (iOS or Android). You may also tell us voluntarily how you heard about us — with a short free-text note if you pick “Other”. This is optional; the sign-up works exactly the same without it. A random reference number and a form timestamp are also transmitted; both serve solely to protect against automated spam sign-ups.

The purpose is to manage the waiting list and to send you your invitation to the test phase. We use the voluntary information about how you found us solely to understand which routes lead people to famagic; it has no bearing on how your sign-up is handled. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give when submitting the form and can withdraw at any time with effect for the future.

Feature requests

In the feature-request form we process your message and, if you provide it, your email address so we can follow up. The email address is optional; without it, however, we cannot reply to you. The legal basis is likewise your consent (Art. 6(1)(a) GDPR).

Recipients and retention

Form submissions are transmitted to an automation instance we operate ourselves (n8n) at the domain n8n.prod.henningrau.com and processed there. We do not pass this data on to third parties for advertising purposes.

We delete waiting-list data once the beta phase has ended or once you withdraw your consent, whichever happens first. Feature requests are deleted once the request has been dealt with. An informal message to E-Mail is enough to withdraw your consent.

08Surveys with Google Forms

To conduct surveys, we use Google Forms, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).

If you take part in one of our surveys, the data you enter is stored on Google’s servers. Data may also be transferred to the USA. Google is certified under the EU-US Data Privacy Framework.

Google Forms is used on the basis of your consent pursuant to Art. 6(1)(a) GDPR. Participation in surveys is voluntary.

More information: policies.google.com/privacy

09Cookies

Our website only uses technically necessary cookies. These are small text files that your browser creates automatically and that are stored on your device when you visit our site.

Technically necessary cookies are required to enable certain functions of the website. They are not used to create user profiles.

These cookies are stored on the basis of Art. 6(1)(f) GDPR.

10Data processing in the famagic app

This section concerns use of the famagic app. It applies in addition to the sections above and matches the version available in the app under Help → Privacy.

What data do we process?

  • User data: name, email address, profile picture
  • Family members: details about the people you add to your family — see below
  • Usage data: recipes, shopping lists, events, tasks, meal planning, lending overview
  • Expense data (famCount): description, amount in euros, date, plus who paid and how an amount is split and settled within the group. We do not collect bank details or payment data — famCount only does the maths, it does not process payments.
  • Photos and documents: images you upload yourself (profile pictures, images attached to tasks, events or lent items, photographed notes for the inbox)
  • Location details: addresses and coordinates of meeting points you enter

All data is stored on servers in Germany (Supabase, AWS region Frankfurt am Main, eu-central-1), covered by a data processing agreement pursuant to Art. 28 GDPR. Transmission is SSL/TLS-encrypted, and access is restricted row by row to your own data and that of your family.

The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract); for details about children additionally your consent under Art. 6(1)(a) GDPR, and for error analysis our legitimate interest under Art. 6(1)(f) GDPR.

Details about children

Children are not users of the app. They have no accounts of their own and cannot sign in. Details about children are entered exclusively by you as a parent.

For a family member — including a child — the following details are possible: first name, last name, role in the family, gender, date of birth, phone number, address (street, postal code, city, country), profile picture, dietary details (allergies, diet type, dislikes), as well as clothing size, shoe size, school or nursery, and hobbies.

All of these details are optional. You decide which fields you fill in and in how much detail. Only a first name is required so the family member can be labelled in the app — a nickname or an initial is enough instead of the real name. Fields you leave empty stay empty; individual features simply work with less context.

You can change or clear individual details at any time and remove an entry entirely: in the app, open the family area and use the menu on the member in question (Remove from family). Removing the entry also removes the details belonging to it. For a withdrawal of consent beyond that, or for confirmation of deletion, write to us at E-Mail.

AI features

Some features analyse your input using language models. The data required for this is transmitted to our AI providers IONOS and OVHcloud. This affects:

  • Inbox (photo recognition): the document you photographed, or the text read from it. Such photos — invitation cards or school letters, for example — may contain children’s names, dates and addresses.
  • Family chat: your message plus the excerpt of your family data the answer requires
  • Meal plan suggestions: your family’s dietary details (allergies, diet type, dislikes) and recipe data. The request runs via an intermediary service we operate ourselves and from there to the AI provider.
  • Product alternatives while shopping: the item name and quantity you are looking for an alternative to, plus — where stored in the app — your family’s allergies and intolerances. These health-related details are included so that no products unsuitable for your family are suggested. If you start the search from a recipe, the title, description and ingredient list of that recipe are transmitted as well.
  • Recipe images: an image description for the recipe in question

Your content is not used to train AI models. The permitted transmission targets are hard-coded in our software so that data cannot flow to other providers. The legal basis is Art. 6(1)(b) GDPR; you decide yourself whether and when to use an AI feature.

Push notifications

If you allow push notifications, we store a device-side push identifier (token) together with the platform, device name and app version. Delivery goes through the push service operated by Expo and from there via Apple or Google to your device. You choose which kinds of notification you receive in the app; you can withdraw the permission itself at any time in your device settings. The legal basis is Art. 6(1)(b) GDPR.

Error and crash analysis

We use Sentry to keep the app stable. It records crash and error reports, technical details about the device and app version, the screen being viewed, and timings for queries. The legal basis is our legitimate interest in a functioning, secure app (Art. 6(1)(f) GDPR).

We have technically limited what is transmitted to the necessary minimum: automatic inclusion of user details is switched off, email addresses are stripped from error messages, identifiers of individual content (the ID of an event or a list, for example) are redacted in the technical details transmitted alongside a report, and pure connectivity errors are not transmitted at all. We do deliberately include a pseudonymous user identifier — a random character string without a name or an email address — so that error reports can be attributed to an account and fixed specifically. Content you create in the app — events, lists, notes, photos — is not sent to Sentry.

Location and maps

When creating a meeting point, you can choose to use your current location so you do not have to type the address. For this we ask once for location permission. Access happens only while you are actively using the app and only when you trigger the feature yourself — there is no background location tracking and no movement profile. You can withdraw the permission at any time and type the address instead.

To turn coordinates into an address and for address search we use Geoapify (map data from OpenStreetMap). For the map preview image of a meeting point, the map service provided by Apple is called. What is transmitted are the relevant coordinates or the search term — not your name or your account.

No sharing for advertising. We do not sell your data, do not use it for advertising and do not train AI models with it. We transmit data to the service providers named above only to the extent required for the respective feature.

11Retention & deletion

We store your data for as long as you use famagic — there is no automatic deletion after a set period.

  • Individual content (events, lists, tasks, expenses, images, family members) is deleted as soon as you delete it in the app
  • If you delete your account, the data attached to it is removed
  • AI-generated recipe suggestions that nobody adopted are cleaned up automatically
  • Data from the forms on this website is deleted after the beta phase ends or once the request has been dealt with (see section 07)
  • Server log files as well as error reports and technical logs are deleted after the retention period of the respective service

Content you have shared with others (a shared calendar or a shared expense group, for example) remains with the other participants insofar as it is attributed to them. Statutory retention obligations remain unaffected.

12Your rights as a data subject

With regard to your personal data, you have the following rights vis-à-vis us:

Access (Art. 15)

What data do we hold about you? You receive a machine-readable copy.

Rectification (Art. 16)

Have inaccurate data corrected.

Erasure (Art. 17)

Have your data deleted, unless retention obligations prevent it.

Restriction (Art. 18)

Temporarily restrict processing while you raise a complaint.

Data portability (Art. 20)

Receive your data in a common format and take it with you.

Objection (Art. 21)

Object to processing based on legitimate interest.

To exercise your rights, you can contact us at any time at E-Mail.

13Right to withdraw consent

If the processing of your personal data is based on consent, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of the processing carried out on the basis of the consent before its withdrawal. You can send your withdrawal by email to E-Mail.

14Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR.

15Validity of this privacy policy

This privacy policy is currently valid as of August 2026.

Questions? Email us anytime at E-Mail.