How Family Ready handles information

Privacy Policy

This policy describes information processed by the Family Ready app, website and related support services.

Effective date: July 17, 2026

1. Who operates Family Ready

Family Ready is operated by an independent app developer (“the developer”, “we”). You can reach the developer at ran.gray.james@gmail.com for privacy questions about the app or this website.

2. Scope

This policy applies to Family Ready: Emergency Plan on iPhone and iPad, its collaboration backend, this website and direct support communications. Apple, RevenueCat, authentication, hosting, file-storage and email providers process information under their own terms and policies.

3. Information you provide

Depending on the features you use, you may enter:

  • Names, email addresses, phone numbers, physical addresses and relationships.
  • Emergency contacts, healthcare contacts, household members, dependants, pets and trusted-person information.
  • Health-related details such as medical conditions, medications, allergies, accessibility or care information.
  • Plan notes, important locations, document references, insurance or institution information, instructions and personal wishes.
  • Invitation permissions, access confirmations and proposed plan changes.
  • Information you choose to include in a support email.

You decide what to enter. Avoid entering complete passwords, access codes, payment-card numbers, government identifiers, recovery phrases or other secrets that are not needed for the plan.

4. Information processed automatically

When the relevant feature is used, Family Ready or its processors may handle:

  • Account identifiers, account name and email from sign-in.
  • App version, locale, onboarding route, acquisition route and limited completion-state or product-interaction attributes.
  • Subscription product identifiers, purchase and entitlement status, expiration state and Apple transaction information processed by Apple and RevenueCat.
  • Household, invitation, role, permission, confirmation, proposal and plan-version records.
  • IP addresses, request metadata and security logs ordinarily processed by authentication, backend and hosting providers.

The audited app does not register push-notification tokens, include a third-party crash-reporting SDK, use third-party advertising or perform cross-app tracking. Local lifecycle events remain on the device; limited allowlisted attributes are sent to RevenueCat.

5. Information stored on your device

The complete local plan and offline Emergency Card are stored on the device using Apple data-protection features. The main local plan is encrypted with a key stored in the device Keychain. A limited widget cache contains the plan owner’s first name, readiness status, family-access status and last-review date. If you enable the contact option, it also contains the first contact’s first name and relationship. The widget does not include phone numbers or medical, address, document or financial details.

6. Cloud synchronization and collaboration

Core local use does not require uploading the full plan. If you sign in and use household collaboration, Family Ready transmits account information and the plan content needed for synchronization and permissioned sharing to the Family Ready backend over HTTPS. Shared cloud content is stored as structured data protected by authenticated access controls; it is not end-to-end encrypted with a key known only to household members.

The owner selects people and section permissions. A permitted member may receive current and historical shared plan versions, invitation information, confirmations or proposals associated with that household.

7. Device permissions

Notifications
Used for local review, important-date and print-placement reminders that you choose to schedule. The audited app does not register for remote push notifications.
Camera
Used when you choose to scan a Family Ready Recovery Card QR code. Camera images are processed for scanning and are not added to your plan as photographs.
Contacts
Used through Apple’s individual contact picker. Only the contact you select is copied into the plan; the app does not upload your full address book.
Face ID
The audited release does not request Face ID permission or present a biometric lock feature.
Other permissions
No location, microphone, photo-library, HealthKit, tracking or local-network permission was found in the audited release.

8. Third-party processors

  • Apple — Sign in with Apple, App Store purchases, device services, Contacts picker, local notifications, printing, share sheets and any Files or iCloud Drive location you choose.
  • RevenueCat — subscription products, purchase validation, entitlement status, account association and limited product-interaction attributes.
  • Rork Auth — account authentication and session processing.
  • Supabase — authenticated backend functions and storage for cloud collaboration records.
  • Rork (Cloudflare-backed hosting) — website delivery and ordinary hosting request logs.
  • Google (Gmail) — support and privacy email communications.

9. Why information is processed

Information is processed to provide local planning, offline access, authentication, household sharing, synchronization, invitations, confirmations, proposals, subscription access, backup/export tools, support, security, fraud prevention and legal or operational recordkeeping.

10. Sharing with trusted household members

Information is shared only when a user uses collaboration features and assigns access. Owners are responsible for choosing appropriate recipients, having permission to share another person’s information and reviewing section-level permissions. Revoking access blocks future authenticated retrieval, but cannot erase copies another person already printed, exported, photographed or downloaded.

11. Retention

Local information remains until you edit it, delete device information, delete the app, restore or replace a profile, or otherwise remove it. Cloud collaboration records are intended to remain while needed to operate the account and household and to be removed through the in-app account-deletion process, subject to verified database behavior. Apple, RevenueCat, authentication, backend, hosting and support providers may retain purchase, security, backup, fraud-prevention, legal or operational records under their own schedules.

Manual verification required: exact database cascades, backup/log windows, authentication-record deletion, RevenueCat retention, expired-invitation retention and support-email retention have not been conclusively verified.

12. Account and device deletion

Signed-in users can request deletion from Family Ready Settings. The app requests deletion of the Family Ready cloud profile, any household the user owns and memberships in other households, then removes Family Ready data from the device and signs out. Apple and RevenueCat purchase records are not deleted. The audited source does not prove deletion of the separate underlying authentication-provider identity.

You may separately delete all information on the current device without deleting cloud data. See Delete Your Account for the precise steps and known limits.

13. Leaving a household

Leaving or losing access to someone else’s household is different from deleting your own account. The other household keeps information controlled by its owner. Account deletion is intended to remove your memberships while leaving other owners’ household information intact.

14. Backups, PDFs and exported files

Encrypted backup files, recovery cards, PDFs, printed pages and shared exports are controlled by you after export. Keep recovery codes separate from encrypted backup files. Family Ready cannot remotely erase files, printouts or copies held by other people or third-party storage providers.

15. Security

Implemented safeguards include Apple data protection, local encryption, Keychain storage, HTTPS, authenticated backend requests, permission filtering, hashed invitation tokens and limited widget content. These measures reduce risk but do not guarantee absolute security, confidentiality, availability or recovery.

16. Children

Family Ready is a household planning tool and may contain information about dependants. The audited app does not include a verified age-gating or parental-consent system. An adult responsible for a household should decide whether and how to enter a child’s information and obtain any permission required by applicable law.

17. International processing

Processors may handle information in countries other than your own. The final operator and processor locations, contractual safeguards and cross-border notices must be confirmed before this policy is finalized.

18. Privacy rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict or object to certain processing, or withdraw consent where consent applies. These rights can have exceptions. Family Ready does not claim universal compliance with every privacy law. Use in-app editing and deletion where available, or contact the privacy address after it becomes operational.

19. Policy changes

This policy may be updated when features, processors or legal requirements change. A revised effective date will be shown. Material changes should be communicated through an appropriate channel when required.

20. Contact

Privacy contact: ran.gray.james@gmail.com