Privacy Policy
Version: 1.2 (Canonical English)
Last Updated: September 6, 2026
1. Introduction
Family Ping ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share information about you when you use the Family Ping mobile application and related services (the "Service").
Family Ping is designed as a consensual family-safety tool. It never runs hidden: nothing is shared unless the person set it up on their own phone, and they can stop it at any time.
2. Information We Collect
A. Location Information
- Precise Location: For users in the "Family member" role, we collect precise latitude and longitude data. This data may be collected in the background when the app is closed or not in use, so Family Ping can provide safety alerts and latest-location updates to your connected "Trusted helper."
- Safe Zone Data: We store the coordinates and radius of your designated "Safe Place" (e.g., your home).
B. Device and Usage Information
- Battery Status: We collect battery level and charging state to inform your trusted helper if your device is running out of power.
- Connection Status: We record whether the Service is active and whether your device is online.
- Event Data: We record safety-related events such as SOS triggers, manual check-ins ("I am okay"), and entries/exits from Safe Zones.
- Push Notification Token: We store the notification token your phone's operating system issues to this app, so an alert can be delivered to this device. A token identifies the app on one device. If it stops working we replace it, and we delete it when you unlink or delete your account.
- Language and Time Zone: We store your device language and its offset from UTC, so a notification arrives written in your language and can state a local time.
- Platform: We record whether the device is an Android phone or an iPhone, because the two behave differently in the background and we need to know which we are talking to.
- Crash Diagnostics: If the app crashes, Firebase Crashlytics sends us a diagnostic report so we can fix the fault. It includes the device model, the operating system version and the state of the app when it stopped. We do not join these reports to your account, and we do not attach your name, email or location to them.
C. Account Information
- Identifiers: We use Firebase Authentication IDs and pairing identifiers to connect your device with your trusted helper's device.
- Email Address: A Trusted helper signs in with an email address and a password, so their account can be recovered on a new phone. We hold that address in Firebase Authentication. It is not written into the shared records, and it is never shown to the Family member. A Family member signs in without an account and gives us no email address at all.
- Profile Data: Display names. A display name is sent to our servers so your trusted helper sees who an alert came from.
- Profile Picture: Optional, and it never leaves your phone. If you choose a profile picture it is stored only in your own device's app storage. It is not uploaded, not sent to your trusted helper, and not visible to us.
D. Camera and Photos
Family Ping asks for the camera only when you use it, and for one of two things:
- Pairing: scanning the pairing QR code shown on the other phone. The camera reads the code on the device. No image is stored and no image is sent anywhere.
- Profile picture: taking or choosing a photo for your own profile picture. As above, that picture stays on your phone.
Family Ping has no photo upload of any kind. There is no image or file storage in our backend.
3. How We Use Information
We use the collected information solely to:
- Share your latest known safety status with your connected trusted helper.
- Trigger notifications for your trusted helper (e.g., SOS or Safe Zone alerts).
- Improve the reliability of background location updates across different device manufacturers.
We do NOT sell your data.
We do NOT use your data for advertising.
4. Data Sharing and Disclosure
Your data is only shared with the specific "Trusted helper" user you have explicitly paired with using the unique Family Pairing Code. We do not sell your data and we do not share your precise location with any third party except as set out below or as required by law.
Service providers who process data on our behalf
We do not run our own servers. The Service is built on Google's Firebase platform, and Google processes your data on our instructions and under contract terms that require it to protect that data to the standard described in this policy. Specifically:
- Google LLC and Google Ireland Limited (Firebase) — Cloud Firestore stores your latest location, safe place, events and account records; Firebase Authentication holds your sign-in; Firebase Cloud Messaging delivers notifications to your phone; Cloud Functions runs the code that sends them; Firebase Crashlytics receives crash diagnostics.
- Apple and Google — the notification services built into iOS and Android carry the alert itself to your device. They receive the token for your device and the message.
- Google Maps — when you open a map to see a location, Google Maps serves that map.
These are processors, not recipients of data for their own purposes. We use no advertising network, no analytics broker and no data broker.
5. Data Retention and Deletion
These are the periods the Service actually enforces, not targets:
- Latest Location: replaced in place. Only the most recent position exists. We keep no history of your movements, so there is nothing to retain and nothing to hand over.
- Safety Events (SOS, "I am okay", leaving or returning to a safe place): deleted automatically 30 days after they are recorded.
- Pairing Codes: expire 10 minutes after they are created, and are deleted automatically. A code that has been used cannot be used again.
- Location Requests (a trusted helper asking "where are they now"): expire after 2 minutes and are deleted automatically.
- Account and Link Records: kept while your account exists, and deleted when you delete it.
The three automatic deletions above are enforced by the database itself, not by a routine we have to remember to run.
Deleting your account
You can delete your account from inside the app. Open Settings and choose to delete your account. The deletion happens straight away and cannot be undone: your account, your location, your safe place, your events and your link to your trusted helper are removed. You do not need to email us, wait for approval, or speak to anyone. If you can no longer open the app, write to contact@editerra.se and we will delete it for you.
6. Consent and Control
- Consent: Sharing is only active when you have selected the "Family member" role and paired with a Trusted helper.
- Visibility: The Service uses system-level indicators (such as persistent notifications or status bar icons) to ensure you are aware when background location sharing is active.
- Stop Sharing: You can stop sharing your location by unlinking devices or using any available sharing controls in the app.
Withdrawing your consent
You can withdraw consent at any time, and you do not have to delete your account to do it. Any one of these stops the sharing:
- Unlink in the app. The link between the two phones ends and nothing further is sent.
- Turn off the location permission in your phone's own settings, under the Family Ping entry. The app keeps working; it simply stops knowing where you are, and your trusted helper is shown that the location is unknown rather than a stale one.
- Turn off notifications in your phone's settings, if you want the link kept but the alerts stopped.
- Delete the app. Nothing further is collected. Records already stored are removed by deleting your account, as described above.
Withdrawing consent does not affect anything that was lawfully shared before you withdrew it.
7. Regional Privacy Disclosures
A. European Economic Area (EEA) and United Kingdom (GDPR)
If you are in the EEA or UK, your data is processed in accordance with the General Data Protection Regulation (GDPR). Our backend is powered by Google Firebase. You have the right to access, rectify, or erase your data, and the right to restrict or object to certain processing.
B. United States (CCPA/CPRA and other State Laws)
If you are a resident of California or other US states with comprehensive privacy laws, you have specific rights, including the Right to Know, Right to Delete, and Right to Opt-Out of sale/sharing.
C. Children’s Privacy (COPPA & GDPR Compliance)
Family Ping is intended for adults. You must be at least 18 years old to use the Service. It is not directed to, or intended for use by, children under 18, and we do not knowingly collect personal data from anyone under 18. The person whose location is shared (the Family member) consents to that sharing by pairing their own device with a Trusted helper. If we learn that we have collected personal data from a child under 18, we will delete it. If you believe a child has provided us with personal data, contact us at contact@editerra.se.