Summary & Key Principles
FamilyShield is built with a privacy-first engineering architecture designed to protect individuals and families from phone scams, fraud, and impersonation. We minimize data collection, process call risk indicators locally whenever possible, and give you full control over your family safety links and data.
- Zero raw call audio or voice conversation recordings are ever uploaded or stored.
- Contact numbers are matched using cryptographic hashes; address books are never uploaded in plaintext.
- On-device neural engines analyze threat indicators without sending private audio to the cloud.
- Data synchronized to the cloud is encrypted in transit and protected by strict Row-Level Security (RLS).
- We do not sell your personal information or monetize your data for advertising.
1. Introduction & Scope
FamilyShield Safety Technologies Inc. ("FamilyShield", "we", "us", or "our") operates the FamilyShield mobile application, backend safety APIs, and related website services. This Privacy Policy describes how we collect, process, store, disclose, and delete information when you download, install, or use FamilyShield.
By using FamilyShield, you acknowledge the data practices described in this policy. If you do not agree with this policy, please do not install or use our application.
Privacy Officer Contact
2. Information We Collect or Process
We collect and process only the information necessary to provide automated call risk detection, family safety notifications, and account synchronization. Data is categorized as follows:
2.1 Account & Identity Data
When you sign up or authenticate with FamilyShield, we collect:
- Primary email address and display name provided during authentication.
- Supabase Authentication User ID (UUID) and token metadata.
- Selected profile role (e.g., Parent/Protector or Protected Family Member).
- Account creation and last sign-in timestamps.
2.2 Family Linking & Pairing Data
To coordinate protection between family members, we process:
- Temporary 6-digit pairing codes and cryptographically signed QR link tokens.
- Pairing relationship state (Pending, Active, Unlinked).
- Linked family account identifiers (who is paired with whom).
- Shared safe-words or verification phrases configured for emergency confirmation.
2.3 Call Screening & Threat Detection Data
To detect potential phone scams and warn linked family members, the app processes:
- Incoming or outgoing phone numbers (normalized format).
- Call state, timestamp, and call duration.
- Computed risk classifications (Safe, Suspicious, High Risk, Impersonation Threat).
- Scam detection reasons (e.g., Spoofed Caller-ID pattern, unknown carrier anomaly).
- User-submitted call feedback (e.g., "Marked as Safe", "Marked as Scam").
Critical Privacy Guarantee
2.4 Contact Matching Data
When enabling caller verification against your address book, contact numbers are converted into cryptographic SHA-256 hashes locally on your device. Raw address book names and unhashed phone numbers are never transmitted to our servers.
2.5 Technical & Device Diagnostics
We collect technical metadata required for reliable app operation and push notifications:
- Firebase Cloud Messaging (FCM) push notification tokens.
- Device model, operating system version, and app version (1.2.0 (Build 142)).
- Network connection type (Wi-Fi, Cellular, Offline).
- Privacy-safe diagnostic logs (submitted voluntarily when requesting support).
3. How We Use Information
We use collected information strictly for defined safety and operation purposes:
- Authenticating your account and securing session access.
- Calculating call risk scores and warning you of incoming scam attempts.
- Sending real-time push notification alerts to linked family protectors when a high-risk call occurs.
- Synchronizing call history and risk logs across your authorized family devices.
- Verifying safe-words during family security checks.
- Processing and responding to your support requests, complaints, or feature suggestions.
- Maintaining system performance, security defenses, and preventing abuse.
4. Local Processing vs. Cloud Processing Architecture
FamilyShield employs a hybrid edge-cloud architecture designed to maximize privacy while enabling real-time family safety coordination:
| Data Type | Processing Location | Cloud Synchronization |
|---|---|---|
| Raw Call Audio & Speech | Local Hardware (On-Device) | NEVER uploaded or stored |
| Contact List Names | Local Hardware (On-Device) | NEVER uploaded |
| Contact Matching Hashes | Local Hardware (On-Device) | Temporary lookup only |
| Call Logs & Risk Classification | Local Storage & Supabase Backend | Encrypted cloud backup for user |
| Family Pairing & Link State | Supabase PostgreSQL Database | Synchronized for paired accounts |
| Push Notification Tokens | Firebase Cloud Messaging | Token stored for alert delivery |
Offline Resilience
6. Permissions & Device Access
To provide call screening and safety features on Android, FamilyShield requests the following system permissions:
READ_PHONE_STATE&CALL_SCREENING_SERVICE: Used to detect incoming phone numbers and display real-time scam risk overlays.POST_NOTIFICATIONS: Used to send urgent family scam alerts and threat warnings.READ_CONTACTS: Used locally to hash numbers and distinguish known family/friends from unknown callers.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS: Used to ensure background call screening operates reliably during incoming calls.
Revoking Permissions
7. Data Storage & Security Protections
We protect your information using enterprise-grade security standards:
- Row-Level Security (RLS): All PostgreSQL database tables in Supabase enforce strict RLS policies, ensuring users can only read or write their own data and authorized family records.
- Encryption in Transit: All API requests, authentication, and database streams use TLS 1.3 / HTTPS encryption.
- Encryption at Rest: Database volumes and backups are encrypted at rest using AES-256.
- Local Storage Security: Sensitive auth session tokens are stored securely in Android EncryptedSharedPreferences / KeyStore.
8. Data Retention Schedule
We retain data only as long as necessary to provide service functionality:
| Category | Retention Period | Deletion Trigger |
|---|---|---|
| Account Credentials | Active account lifetime | Account deletion request |
| Call History Logs | 90 days rolling | Manual row delete or account purge |
| Family Pairing Links | Active pairing duration | Unlink action or account deletion |
| Support Tickets | 1 year for resolution audit | Automated archival |
9. Account Deletion & Your Privacy Rights
You have full control over your data. Depending on your jurisdiction, you have the right to access, export, correct, or delete your personal information.
9.1 How to Delete Your Account
You can delete your account and all associated data directly within the app by navigating to Shield Settings -> Account Session -> Delete Account, or by submitting a Privacy Request in the Help Center. Upon deletion:
- Your user auth profile and database records are permanently deleted.
- All paired family links are automatically dissolved.
- Cloud call logs and risk history associated with your user ID are purged.
10. Children’s Privacy
FamilyShield is intended for parents, adult caregivers, seniors, and family members. It is not directed to children under 13 years of age. We do not knowingly collect personal information directly from children under 13 without verifiable parental consent.
11. International Data Transfers
FamilyShield is operated from the United States. If you access the application from outside the United States, please be aware that your information may be transferred to, stored, and processed in secure data centers in the United States.
12. Third-Party Service Providers
Our app integrates with selected third-party software development kits (SDKs) for core backend services:
- Supabase (Auth & Database): https://supabase.com/privacy
- Google Firebase (Push Notifications): https://policies.google.com/privacy
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When changes are published, we will update the "Last Updated" date at the top of this policy and notify active users via in-app banner or push notification.
14. Contact Us
If you have questions, privacy concerns, or data requests, please contact us at: