Family Command Central (“the app”, “we”, “us”) is a shared organizer for households. This policy explains what we collect, why, who we share it with, and the choices you have. We built the app to hold a family’s day-to-day plans, so we keep data collection to what the product needs and never sell it.
1. Who we are
Family Command Central is operated by lumingon DWC-LLC, a company based in Dubai, United Arab Emirates (“the Provider”). If you have any question about this policy or your data, contact us at familycommandcentralapp@lumingon.com.
2. Information we collect
Account & sign-in
You sign in with Google or Apple. We receive a stable account identifier and, depending on what you approve, your name and email address. We do not receive or store your Google or Apple password. Every family member who signs in — parents and children alike — has their own account of this kind.
Family content you create
The information you and your family add to the app: member profiles (display name, role, optional short bio), calendar events, tasks, shopping and other lists, family projects, chat messages (in the family chat, custom chats and project chats — stored on our servers so every member sees the same conversation, and never scanned for advertising), and saved places (a name, an address and map coordinates you type or pick — we do not read your device's location to create them). This content belongs to your family and is visible only within your family; a parent can remove members and content.
Vault documents & document scanning
Parents on a paid plan can save photos and PDFs of household paperwork — warranties, receipts, school letters and similar — to a private Vault. Vault documents are visible only to the parents of your family, never to children or other families, and are stored encrypted in a private Google Cloud Storage bucket in Europe. When you take a photo for the Vault we remove its camera metadata (including any location data) before saving it. Using the camera or photo library is optional and only happens when you choose to add a document.
If a parent chooses Scan on a document and confirms, we send that document to Google’s Gemini API to extract facts such as the title, merchant, amount, purchase date and warranty expiry. The extracted values are shown back to the parent as suggestions to review and edit; nothing is created for the family unless a parent explicitly saves it. We do not use scanned documents to train models. Google processes them under its paid Gemini API terms as a service provider acting for us: it does not use them to train its models and keeps them only as long as its API terms allow for abuse monitoring. We send only the document a parent chose to scan — never chats, calendars, lists or other family content — and the extracted suggestions are stored with that document under your family's control. Scanning is limited per month by your plan, and you can add document details by hand instead of scanning.
Usage & device analytics
If the app crashes, a crash report (the technical stack trace, device model, operating-system version, app version and an internal member identifier — never message or document contents) is sent to Firebase Crashlytics so we can fix the problem. Crash reports are not sent from development builds.
Device identifiers & notifications
To deliver push notifications we store a push token and an app-installation identifier issued by Firebase for each device you sign in on; they are tied to your member record and removed when you sign out of that device or delete your account. Our sign-in and crash-reporting components use similar installation identifiers to work. We never use the advertising identifier and we do not track you across other companies' apps or websites.
To understand how families use the app and which features are useful, we collect product-analytics events (for example: screens viewed, features opened, and in-app actions such as adding a member or sharing an invite), together with basic device and app information (device type, operating-system version, app version, and a random analytics identifier). Analytics events are keyed to internal identifiers, not to your message content, and we do not put the text you type into analytics.
Subscriptions
When subscriptions are available, purchases are processed by Apple, Google, or our web payment processor. We receive subscription status (which plan, trial or active, renewal and cancellation) but not your full payment card details.
3. How we use information
- To provide the app and keep your family’s data in sync across devices.
- To operate secure sign-in and keep each family’s data scoped to that family.
- To understand product usage and improve features, flows, and performance.
- To manage subscriptions, trials, and renewals, and to prevent abuse.
- To communicate with you about the service and respond to support requests.
4. Children & families
Family Command Central is a family app used by adults and children together. A family can only be created by an adult (a parent or guardian), and new members can only join through that adult's invite code — the invite is the parent's authorisation for that child to take part. Members who join with an invite are added as children; only a parent can change a member's role. An adult who adds a child is responsible for that child’s use of the app and for any consent required where they live, and can review, edit or remove what the child has added, or remove the child from the family, at any time.
From a child's account we collect the same limited information as from any member: the name and email address provided by Google or Apple sign-in, the content they add, push and installation identifiers, crash reports and product-analytics events. Children never see the Vault or document scanning, which are parent-only features. We do not show advertising to anyone, and we do not use children’s personal information for advertising, profiling or sale. If you believe a child has provided us information without appropriate consent, contact us and we will remove it.
5. Who we share information with
We do not sell your personal information. We share it only with service providers who help us run the app, under contracts that limit them to that purpose:
| Provider | Purpose |
|---|---|
| Google (Firebase Authentication) & Apple | Secure sign-in |
| Google Cloud Platform | Hosting, database, and storage of your family’s data, including Vault documents (private storage bucket, Europe) |
| Google Gemini API | Extracting details from a Vault document — only when a parent chooses Scan and confirms |
| PostHog | Product analytics |
| Google (Firebase Crashlytics) | Crash reports |
| Apple, Google Play, and our web payment processor (Stripe) | Subscription billing |
We may also disclose information if required by law, to protect the rights and safety of users, or as part of a business transfer, in which case we will tell you.
6. Where your data is processed
Our servers, database and Vault storage are hosted in Google Cloud Platform in Europe. Some providers (sign-in, push notifications, crash reporting, analytics and the Gemini API used for document scanning) may process data in other countries. Where we transfer data internationally, we rely on appropriate safeguards for that transfer.
7. How long we keep it
We keep your family’s content for as long as your family account is active. Note that the app is forward-looking by design: past calendar events are not shown in the app. You can delete individual items at any time, and you can ask us to delete your account and its data (see below). Vault documents you delete move to a Trash for seven days so they can be restored, then they and their stored files are permanently removed; deleting your family removes its Vault documents and files as well. Scan results are kept with the document they belong to and are deleted with it.
8. Your choices & rights
- Access and correction: most of your data is visible and editable in the app.
- Deletion: you can remove members, items, and content in the app, and delete your whole account from the app or by email — see Delete your account.
- Analytics in the app: you can turn usage analytics off any time under Account → Share usage analytics. Nothing further is sent from that device while it's off.
- Analytics on this website: we ask before counting anything. Until you choose “Allow”, no analytics are loaded and nothing is stored in your browser. If you change your mind, clear this site's data in your browser and the question is asked again.
- Depending on where you live (for example under GDPR or similar laws), you may have rights to access, correct, delete, or port your data, and to object to certain processing. Contact us to exercise them.
9. Security
We use industry-standard measures including encryption in transit, authenticated APIs, app attestation, and strict per-family access controls. No system is perfectly secure, but we work to protect your family’s data and to respond quickly if something goes wrong.
10. Changes to this policy
We may update this policy as the app evolves. We will post the new version here with an updated date and, for material changes, notify you in the app.