What this is
FamilyHub SG is a household finance and household tracker. This policy explains what information we collect when you use it, how it's stored, who can see it, and how to reach us with questions or requests.
Information we collect
We collect information you choose to enter into the app, which may include:
- Your email address, used solely to send you a secure sign-in link
- Household and family member details you add (names, relationships)
- Financial information you enter — properties, loans, insurance policies, investments, savings and CPF balances, and other assets
- Health-related notes you choose to add for yourself or family members
- Inventory items and any photos or documents you upload
- Notes, reminders, and history you add against any record
We do not ask for or store payment card numbers, passwords (sign-in is passwordless via emailed link), or government ID numbers.
How your data is stored and protected
Your data is stored with Supabase (database, authentication, and file storage) and the app itself is served via Cloudflare. Connections to FamilyHub SG are encrypted in transit (HTTPS).
FamilyHub SG is built around households. Each household's data is kept separate from every other household by database-level access rules — your data isn't visible to other households using the app. If you invite someone to join your household, they gain the level of access you grant them to that household's data.
Photos and documents you upload are stored privately — not on the open internet. Viewing or downloading a file always requires being signed in as a member of your household first; nobody can access your files without that. When you view a file in the app, or when a link is generated for you, that link is time-limited: links used inside the app expire after about an hour and are silently regenerated each time you need them, and links included in downloaded exports remain valid for up to 10 years, so exported files stay useful long after you've downloaded them. A link, once generated, isn't password-protected beyond that — treat it like you would a shared cloud storage link, and avoid forwarding it to anyone you wouldn't want to have that file. Uploads are also limited in size and file type to keep the service reliable.
Who can see your data
Only people you've explicitly invited into your household, plus FamilyHub SG's operator for the limited purpose of running and maintaining the service. We do not sell your data, and we do not share it with advertisers — FamilyHub SG does not run ads or third-party analytics or tracking scripts.
We use Supabase and Cloudflare as infrastructure providers to operate the service; they process data on our behalf under their own data protection commitments, and don't use your data for their own purposes.
Cookies and local storage
FamilyHub SG uses your browser's local storage to keep you signed in and to remember a small number of display preferences (such as light/dark mode and reminder thresholds). We don't use advertising or cross-site tracking cookies.
Exporting and deleting your data
You can export your household's data at any time from Settings → Data, in two ways: an Excel workbook covering every record in the app (with time-limited links to your photos and documents, valid for up to 10 years), or a full backup as a single .zip file that includes the same spreadsheet plus the actual photo and document files themselves — fully self-contained, with nothing that depends on FamilyHub SG continuing to run. If you'd like your account and data permanently deleted, contact us at the email below and we'll action it.
Children's information
FamilyHub SG is intended for use by adults managing household records. A parent or guardian may enter information about their children (for example, a child's health note) as part of managing the household — FamilyHub SG itself does not knowingly collect information directly from children.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date above and let existing users know within the app.
Data breach response
If we become aware of, or suspect, a data breach, our first step is to contain it — for example, by revoking exposed access or fixing the underlying issue. We then assess what data was affected, how many people, and how serious it is. If that assessment finds the breach is likely to cause significant harm to anyone, or affects a large number of people, Singapore's PDPA requires us to notify the Personal Data Protection Commission (PDPC) within 3 calendar days of completing that assessment, and to notify affected individuals directly where significant harm is likely. We keep a written record of any suspected breach and our response, whether or not it ends up meeting the reporting threshold.
Data Protection Officer
FamilyHub SG's founder acts as Data Protection Officer, responsible for this app's compliance with Singapore's PDPA. Reach the DPO at the contact email below for any data protection question, concern, or request.
Contact us
Questions, data requests, or concerns: support@familyhubsg.com
This policy is provided as general information about how FamilyHub SG handles data and is not a substitute for legal advice.
← Back to FamilyHub SG