Privacy Policy

Effective Date: 7 February 2026

This Privacy Policy explains how Family Values (“we,” “our,” or “us”) collects, uses, and protects your information when you use our website, mobile application, and services (collectively, the “Service”). By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Information We Collect

We collect the following types of information:

  • Account Information: Email address, display name, and authentication credentials (including via third-party sign-in providers such as Google or Apple).
  • Recipe Content: Ingredients, instructions, tags, categories, and images you save or import.
  • Usage Data: Pages visited, features used, device type, browser type, IP address, and time spent (collected via analytics tools).
  • AI Input Data: Text, images, or audio content you submit to our AI tools for recipe import or processing.
  • Payment Data: Subscription status and billing information are processed by our payment providers (Stripe, Apple, Google). We do not store your full credit card number or payment credentials on our servers.
  • Communication Data: Messages or inquiries you send to us via our contact form or email.

We do not require personally identifiable information (PII) beyond an email address to use the platform, but providing additional information (e.g., display name) may enhance the user experience.

2. How We Use Your Information

We use your data to:

  • Provide, maintain, and improve our recipe storage, import, meal planning, and shopping list services
  • Process your subscription and manage billing
  • Respond to customer support requests and communications
  • Monitor platform performance, detect abuse, and improve security
  • Send service-related updates, reminders, or announcements
  • Enforce our Terms and Conditions
  • Comply with legal obligations

3. Lawful Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), we process your personal data on the following legal bases:

  • Contract: Processing necessary to provide the Service you have requested (e.g., storing your recipes, managing your subscription).
  • Consent: Where you have given explicit consent, such as for receiving marketing emails or for the use of non-essential cookies and analytics.
  • Legitimate Interests: Processing necessary for our legitimate interests, such as improving the Service, preventing fraud, and ensuring security, provided these interests are not overridden by your rights.
  • Legal Obligation: Processing necessary to comply with applicable laws (e.g., tax record-keeping for subscription payments).

You may withdraw consent at any time where consent is the basis for processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4. Data Sharing and Third-Party Processors

We do not sell, rent, or trade your personal data to third parties.

We use the following third-party service providers (data processors) to operate the platform:

  • Supabase – data storage and user authentication (servers in the United States)
  • Vercel – website hosting and content delivery (global edge network)
  • Stripe – subscription billing and payment processing (United States)
  • OpenAI – AI-powered recipe import, text extraction, and enhancements (United States)
  • AssemblyAI – voice-to-text transcription for audio recipe import (United States)
  • Google Analytics – anonymized usage tracking and analytics (United States)
  • Brevo (formerly Sendinblue) – transactional and service-related email communications (European Union)
  • RevenueCat – in-app purchase and subscription management for mobile apps (United States)

These providers process your data on our behalf and are contractually obligated to protect your data. Each provider operates under its own privacy policy and data protection commitments.

We may also disclose your data if required by law, in response to valid legal process, or to protect our rights, safety, or property.

5. International Data Transfers

Family Values is operated from the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States and potentially other countries where our service providers operate.

For users in the EEA/UK: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and other appropriate safeguards, to ensure that your personal data receives an adequate level of protection when transferred outside the EEA/UK.

By using the Service, you acknowledge that your data may be transferred internationally as described in this section.

6. Public vs. Private Recipes

You control the visibility of your recipes:

  • Private recipes are visible only to you.
  • Public recipes can be seen by anyone and may appear in search results or discovery features on the platform.

Please do not include sensitive personal data (e.g., medical information, addresses) in public recipes.

7. Cookies and Tracking Technologies

We use cookies and similar technologies for the following purposes:

  • Essential Cookies: Required for the Service to function (e.g., session management, authentication). These cannot be disabled.
  • Analytics Cookies: Used to understand how visitors interact with the Service (e.g., Google Analytics). These are loaded only with your consent where required by law.

When you first visit our website from a jurisdiction that requires cookie consent (e.g., the EEA), you will be presented with a cookie consent banner. You may accept or decline non-essential cookies at that time.

You may also manage cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service.

Google Analytics collects anonymized data including pages visited, session duration, device type, and approximate geographic location. We do not use Google Analytics to collect personally identifiable information.

8. AI Features and Data Processing

When you use our AI-powered features (e.g., recipe import from photos, text extraction, voice transcription), the content you submit is transmitted to third-party AI providers for processing:

  • Text and image data is sent to OpenAI for recipe extraction and formatting.
  • Audio data is sent to AssemblyAI for voice-to-text transcription.

Your AI input data is used solely to generate the requested output (e.g., a formatted recipe). We use API-based access to these services, which means your data is not used to train their AI models under their current API data usage policies.

OpenAI retains API input data for up to 30 days for abuse monitoring purposes, after which it is deleted. AssemblyAI deletes audio files after transcription is complete. Please refer to each provider’s privacy policy for their most current data handling practices.

We do not use your recipe content, images, or personal data to train any AI models.

9. Data Retention

We retain your data for the following periods:

  • Account and recipe data: Retained for as long as your account is active. Upon account deletion, your personal data and recipe content are deleted within 30 days, except as noted below.
  • Payment and billing records: Retained for up to 7 years after the transaction date as required by tax and accounting laws.
  • Usage and analytics data: Retained in anonymized/aggregated form for up to 26 months (Google Analytics default retention).
  • AI input data: Not retained by us after processing. Third-party retention periods are described in Section 8.
  • Support communications: Retained for up to 2 years after resolution.

You may request deletion of your data at any time by contacting us or using the account deletion feature in your account settings.

10. Data Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS/SSL), secure authentication, and access controls. Our database provider (Supabase) enforces Row Level Security (RLS) to isolate user data. However, no system is 100% secure, and we cannot guarantee absolute security. We encourage you to use a strong, unique password for your account.

11. Your Rights

Regardless of your location, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data and account
  • Withdraw consent where consent is the basis for processing

To exercise any of these rights, contact us via our contact form at https://familyvalu.es/contact or email help@familyvalu.es. We will respond to requests within 30 days.

12. Additional Rights for EEA and UK Residents

If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the General Data Protection Regulation (GDPR) and UK GDPR:

  • Right to Data Portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.
  • Right to Restrict Processing: You may request that we limit the processing of your personal data in certain circumstances.
  • Right to Object: You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on users.

13. Additional Rights for California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with the following rights:

  • Right to Know: You may request the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collection, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., legal compliance).
  • Right to Opt-Out of Sale: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

To exercise your rights, contact us at help@familyvalu.es. We will verify your identity before processing your request. You may also designate an authorized agent to make a request on your behalf.

14. Children’s Privacy

This Service is not directed to children under the age of 16 (or 13 in jurisdictions where 13 is the applicable age of consent). We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us immediately and we will take steps to delete that information.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via the platform, email, or a prominent notice on our website at least 30 days before the changes take effect. The “Effective Date” at the top of this policy indicates when it was last updated. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the updated terms.

16. Contact

For privacy questions, data-related requests, or to exercise any of your rights described above, contact us via our contact form at:
https://familyvalu.es/contact

You may also email us directly at help@familyvalu.es.

By using Family Values, you acknowledge that you have read and understood this Privacy Policy.