Famipics

Privacy Policy

Last updated: 15 September 2026

Famipics is built so that your family's photos and videos can be seen by your family only. This policy explains what that means in practice: what we can never see, what we do process, why, and what you can do about it.

1. Who we are

Famipics is operated by JUJUTECH, a sole proprietorship registered in Japan (the "operator", "we"). For any question about this policy or your personal information, write to support@famipics.com. The operator's name, address and telephone number are disclosed without delay on request.

2. What we can never see

Everything you put into your family's album is locked on your phone before it leaves it, with keys that exist only on the phones of your family's members. Our servers store and pass along the locked form only. This covers:

We cannot read, view, search, recover or hand over any of it — not to you, not to a court, not to ourselves. Location data and the rest of the camera information a photo carries — the device that took it, the settings it was taken with — are not removed: they are locked together with the photo on your phone, and only the phones of your family's members can read them. The one exception is the date and time the photo was taken, which we also hold in readable form so that the album can be sorted by month (section 3.4). Notifications carry no content: the wording you see ("Grandma commented on a photo") is composed on your phone; what reaches our notification provider says only that something happened, to which family, and who did it.

3. Information we do process

Running the service needs some information in readable form. This is the complete list.

3.1 Your account

You sign in with Apple or Google. Through Firebase Authentication (a Google service) we receive an account identifier and the email address the provider shares with us — with Sign in with Apple you may choose to share a relay address instead of your own — together with sign-in times. We do not take your name or picture from the provider; the name your family sees is one you type in the app, and it is locked like the rest.

3.2 Your devices

For each phone you use: a public key that lets other members lock things for that phone, the platform (iOS or Android) and device model, and a notification token so we can deliver notifications to it.

3.3 Your family's structure

Which accounts belong to which family, each member's role, when they joined or left, pending invitations, the family's name, and the counts the plan's limits are measured against: how many photos the family holds and how many minutes of video.

3.4 Records about each photo and video

The date and time it was taken (so the album can be sorted by month), whether it is a photo or a video, a rough duration bracket for a video, the size of the locked file, when it was added and by which member. For comments and reactions: which photo they belong to, who wrote them and when — never what they say.

3.5 Subscriptions

Purchases are made through the App Store or Google Play. Through RevenueCat we receive the plan you bought, its renewal and cancellation events and a purchase identifier, tied to your account identifier. We never see your card or bank details.

3.6 Usage and crash data

The app sends usage and crash data to Firebase Analytics and Firebase Crashlytics (Google services): which screens are opened, which features are used (for example "a photo was added" — never the photo), the app version, the phone's model and operating system, per-installation identifiers, and crash reports. This data is tied to your account identifier, so it is not anonymous. Google derives a coarse region from the connection's address. There is no advertising identifier, no advertising and no tracking across other apps or websites. This collection cannot be turned off inside the app; it is a condition of using Famipics. What it can never contain is listed in section 2: no photo, no video, no comment, no name.

3.7 Server logs

Our servers keep, for seven days, one technical line per request: a request identifier, the kind of request, its outcome and how long it took. They do not record addresses of pages, content, or the identifiers of families, photos or devices.

3.8 Support

When you write to us, we keep the correspondence for as long as needed to help you and to keep a record of what was agreed.

4. What we use it for

We use nothing for advertising, and we sell nothing to anyone.

5. Who handles it for us

We rely on a small number of providers, each acting on our instructions for the purposes above:

Apple and Google also process your purchase and your sign-in under their own terms, as independent operators of their stores and sign-in services.

We may disclose information when the law requires it. What we can disclose is limited to what we hold: never the content of section 2.

6. Where it is processed

The providers above process information in the United States and in the other locations of their networks. Under Japan's Act on the Protection of Personal Information (Article 28), you are entitled to know that: each provider is bound to us by contractual terms requiring safeguards equivalent to those the Act asks of us, and each operates a published privacy programme. Information about the personal-data regime of the United States, and about the measures each provider takes, is available on request.

7. How long we keep it

8. Your choices and rights

Most of what you may want to do, you can do in the app itself:

You may also ask us, at support@famipics.com, to tell you what personal information we hold about you, to correct it, to stop using it or to delete it, as the Act on the Protection of Personal Information provides. We will ask you to confirm you are the account holder, and answer without undue delay. Two limits follow from how Famipics is built: we cannot give you a copy of, or act on, the content of section 2, because we cannot open it; and a photo added to a family's album is that family's, so its removal is a matter for the family's members.

9. Children

Famipics is used by adults, or by minors with the consent of a parent or guardian. Children who appear in photos are not users: their photos are added by family members, who are responsible for doing so appropriately, and the names and birth dates recorded for them are locked like everything else. We do not knowingly collect personal information directly from a child under 13.

10. Security

The locking described in section 2 is the core of our security, and it means the keys are yours: the recovery QR code shown when you create a family, and the recovery code it contains — the same key in two forms, either one of which is enough — are the only way back into an album if every phone of the family is lost, and we cannot replace them. Beyond that, every connection to our servers is encrypted in transit and every request is signed by the phone that makes it.

11. This website

famipics.com sets no cookies, runs no scripts and carries no analytics. It is served by Cloudflare, which may record connection data for security purposes under its own policy.

12. Changes

When this policy changes, the new version is published here with a new date, and the app tells you when a change matters to you.

13. Contact

JUJUTECH — support@famipics.com

This policy is written in English, which is the governing text. The Japanese and French versions are translations provided for convenience.