Privacy Policy
Protecting your personal data is a central concern for us. This Privacy Policy informs you about which data we collect when you use JH FamilySync, for what purpose we process it, and what rights you have. We process your data in accordance with the EU General Data Protection Regulation (GDPR) as well as the Swiss FADP (revDSG).
Last updated: 9 October 2026
This English version is a translation provided for your convenience. The legally binding version is the German original.
1. Data Controller
The controller responsible for data processing within the meaning of the GDPR and the Swiss FADP (revDSG) is:
JH Virtuell KollektivgesellschaftChlini Schanz 31, 8260 Stein am Rhein, Switzerland
Commercial register no.: CH-290.2.021.387-3 · UID: CHE-378.337.964
Represented by: Jermain Huber, Eugenia Ebel
Email for data protection requests: datenschutz@jh-familysync.app
For further details, see the Legal Notice.
1.1 Representative in the EU (Art. 27 GDPR)
We have appointed the following as our representative in the European Union pursuant to Art. 27 GDPR:
Thomas Beirer-HipplerReutestrasse 7, 78467 Konstanz, Germany
Email: eu-vertreter@jh-familysync.app
Data subjects and supervisory authorities in the EU can contact him with any questions about the processing of personal data in JH FamilySync, in addition to us or instead of us. JH Virtuell remains the controller.
2. Data We Collect
We collect and process only the data required to provide the app's functions:
2.1 Account Data
- Email address
- Display name, i.e. your first name (freely chosen), and optionally your last name
- Password, stored only as a hash (managed by Firebase Authentication)
- Optional: profile picture
- When signing in with Google or Apple: the email address and name transmitted by the provider, and for Google additionally the URL of your profile picture (section 4.10)
- Preferred app language (for notifications and emails in your language)
- Date of birth — mandatory, used to check the minimum age (section 9): when registering with an email address, and when signing in with Google or Apple right after the first sign-in — as well as the time of your age confirmation
- List of your signed-in devices, so that you can see them in the app and sign them out, and so that we can point you to an update in a targeted way if you are using an outdated version of the app (service message without a separate switch, section 8): device type, platform, browser or user agent, operating system version, app version, in the browser the screen size, whether the web app is installed, time of first and last use, and any name of your own for the device
The members of your family can see your display name, email address and profile picture (section 2.2). The app does not show them other information in your account record, such as a last name you may have entered, your language and notification settings, when you last used the app or the customer identifier of a web subscription, but it is technically readable for them. Your date of birth, on the other hand, is kept in a protected area of your account that only you can read; the members of your family cannot see it – unless you switch on “Show my birthday in the family’s occasions” in your profile. The app then creates your birthday with day, month and year as an occasion (section 2.2) that all members of your family can see and are reminded of, as with any occasion. This only happens if you want it; if you switch it off, we remove the occasion again. The exception is a few accounts from the early days that were created without an age confirmation: for them, the date of birth may still be stored in the account record, where the app does not display it either, but where it is technically readable for the members. On request, we move it to the protected area (section 11).
2.2 Family Data
Content that you and the members of your family actively create in the app:
- Appointments and calendar entries, including in your own calendar spaces (name, colour, icon, owner and whether the space is visible to the whole family or only to you)
- Occasions such as birthdays, anniversaries or memorial days (name of the person, relationship, date, gift ideas and notes), including for people who do not use the app, together with the members they are assigned to
- Polls with options and members' votes (including appointments created automatically upon a majority)
- To-dos and lists, the shopping list with “Often bought” (section 2.12), packing lists and your own packing templates
- Chores (tasks with assignment, due date and stars) together with the star balances of the members and of people without their own device, rewards and redeemed rewards
- Wishlists (wish, note, link and who has reserved a wish), including for people without their own device, as well as the meal plan (dishes, ingredients, meal, who is cooking and any photo)
- The family’s name and family photo, and the family members (name, role, colour, profile picture and email address); all members of the family can see this information
- People without their own device, such as children or grandparents without a phone, whom a member of your family adds (name, colour, a photo if you like, who added them and when); they have no account, cannot sign in and receive no notifications; all members of the family can see this information
- Attachments (files, images) together with the identifier of the member who uploaded them
- Emergency contacts (label, phone number, optional note) — either visible to the whole family or only to you
- Subscribed calendars (section 2.7), linked families and shared events (section 2.8) and invitations (section 2.9)
Private appointments: Appointments that are visible only to you (marked "Private": for example when "Only me (private)" is chosen under "Who can see this event?", in older app versions when only one person is selected under "For whom?", or in a calendar space visible only to you, as long as "Show in family calendar" is off) are shown by the app only to you. Like all appointments, they are stored with your family and are not technically shielded from access by other family members; we are working on changing this. If you switch families, we take your private events with you to the new family. If you leave your family without joining a new one, or a managing person removes you, we keep them for your account without anyone else being able to read them and take them with you when you next join a family. When you delete your account, we delete them in all families, including former ones (section 5).
"Selected people only" appointments: If you choose "Family" under "Who can see this event?" and do not keep everyone selected under "For whom?", but more than just yourself (if only you remain selected, the appointment is private; in older app versions: several but not all people under "For whom?"), the appointment is marked "Selected people only" (in older app versions "Invitees only"). The app shows it only to you and the people selected under "For whom?". It, too, is stored with your family and is not technically shielded from access by other family members.
"About": For an appointment, you can select people without their own device under "About" so that it is clear whom the appointment concerns. They do not appear under "For whom?", and this does not change who can see the event; the app shows the selected people to everyone who can see the appointment.
This data is stored in Cloud Firestore (region europe-west1, Belgium) or Firebase Storage (region europe-west1, Belgium).
2.3 Push Notifications
- FCM token (Firebase Cloud Messaging) for the delivery of push notifications
2.4 Technical Data
When you access the website and the web app, our hosting provider Firebase Hosting (Google, section 4.1) processes technical data in server logs (IP address, user agent, timestamp). This serves the delivery of the pages and the security and stability of the service. How long these logs are kept is governed by Google's terms; according to Google, Firebase Hosting retains IP addresses for a few months.
Independently of the consent in section 7.2, our server counts how often the steps of the initial setup are reached (signed in, profile created, setup assistant shown, family created or joined, invitation step shown, invitation link shared, second person in a family, person without their own device added). Only one number per day and step is stored — without an account identifier, without an IP address and without a time per person. To protect against abuse, the IP address is used only as a hash for rate limiting.
Protection against misuse (App Check): To ensure that only our genuine apps and our website access our service, we use Firebase App Check from Google. On the web, the app loads Google reCAPTCHA Enterprise for this purpose; it assesses characteristics of your browser and device and issues a short-lived token. On Android, Google Play Integrity checks, and on the iPhone Apple App Attest or DeviceCheck checks, whether the app is unmodified. The token is valid for one hour, serves only to protect against automated misuse, is not used for advertising and is not linked to your account. Because the token serves to protect the service, we load reCAPTCHA without prior consent (Section 25(2) no. 2 TDDDG); it is not used for any other purpose. The legal basis is our legitimate interest in secure operation (Art. 6 para. 1 lit. f GDPR). Google acts as a processor (section 4.1).
2.5 Payment and Billing Data
Web subscription (Stripe): If you take out a subscription in the web app, we store for your account the Stripe customer ID and the subscription identifier, the plan (monthly or yearly), the subscription status (for example active, cancelled at the end of the period, or ended), whether a trial is currently running and whether you have already used it, and the time you took it out and the end of the current period. Invoices, proofs of payment and payment method data (such as card number, security code and expiry date) are processed and retained exclusively by Stripe (PCI-DSS Level 1 certified, section 4.6); we do not hold them.
Purchase in the App Store or on Google Play: For a purchase in the iOS or Android app we receive no payment method data. Via RevenueCat (section 4.7) we receive and store for your account: product and plan, store (Apple or Google), subscription status and expiry date, the times of purchase and first payment, in the event of a cancellation or expiry the reason reported by the store, type of period (trial, introductory offer or regular), price and currency, the store's original transaction identifier, the environment (production or sandbox) and the identifier of the purchase event. In addition, we keep every purchase event that RevenueCat reports to us unchanged as a raw record, so that no purchase is lost if its processing fails; it contains the complete event as RevenueCat reports it, including the country that RevenueCat assigns to your account (section 4.7). We delete these raw records together with your account (section 5). The seller and payment processor is Apple or Google (section 4.9).
Notification to us: For subscription events (such as the start of a trial, a purchase, the first payment, a cancellation, the end or a failed payment) we receive an internal email. It states the plan and details of your account: for a web subscription your email address or account identifier; for a purchase in the App Store or on Google Play your name, your email address, the name of your family, the store and, where applicable, the reported reason for cancellation or expiry. Like our other emails it is sent via Infomaniak (section 4.2); it arrives in our business mailbox info@jh-virtuell.ch at Microsoft (section 4.12) and is deleted from our sending queue within the periods in section 5.
2.6 Family Tree Data (optional)
If you use the optional family tree tool, you store information about persons in your family — including persons who do not use the app themselves (e.g. children or deceased relatives): names, gender, dates of birth and, where applicable, dates of death, family relationships including the type of a partnership (such as married or separated), nationality/nationalities, notes and photos. Information about nationality does not, in itself, constitute special categories of personal data; only where, in an individual case, it reveals ethnic origin may Art. 9 GDPR or Art. 5 lit. c Swiss FADP (revDSG) be affected. This data is stored in Cloud Firestore or Firebase Storage (region europe-west1, Belgium) within your family. You are yourself responsible for entering data about third parties and warrant that you have the necessary authorisation to do so. Use is voluntary; the data can be deleted in the app at any time.
2.7 Subscribed Calendars (ICS)
You can subscribe to external calendars by entering the address of a publicly accessible ICS file (e.g. a school, club or Google calendar). Within your family we store the address, the name you assign, the colour and the target calendar space of the subscription, together with the identifier of the member who created it, the time of the last fetch, an error text of the last fetch if any and, on deletion, who deleted it. Only the member who created the subscription can read the address itself in the app; other members see the name, colour and sync status. If you delete your account, every subscription you created ends, including one in the family calendar; its events then disappear from the family's calendar. Our server (Cloud Functions, region europe-west1, Belgium) fetches the address when the subscription is created, whenever you request an update in the app and automatically at regular intervals (currently every six hours); the calendar provider sees the request of our server, not your device. From the file we take, for each event, the title, date, start and end time, description (up to 1000 characters) and location as calendar entries of your family; they are visible to the members who may see the chosen calendar space. Events that are no longer contained in the source are deleted from your family at the next synchronisation. The fetched files themselves are not stored, only the events derived from them.
If you delete the subscription, the subscription and all events taken over from it are moved to the family's recycle bin, where you can restore them for 30 days; after that they are permanently deleted. While the subscription is in the recycle bin, the address is no longer fetched. For a one-time import of an ICS file via an address, our server fetches the file once and hands it to the app; no subscription is created. You are responsible for being permitted to use the calendar address and to make its events accessible to your family. Legal basis: Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG).
2.8 Linked Families and Shared Events
Admins can link their family with another family. To do so, one family generates a six-character link code (valid for 48 hours, single use) which the other family enters. The link stores the identifiers and names of both families, the account that created it, the status and optional nicknames each family assigns to the other. If your family has a family photo, it is also stored in the link and is visible to the other family: from the request if your family enters the code, otherwise from acceptance. Each family can also give the other family a photo of its own choosing; the app shows it only to the family that chose it, but it is stored in the same link, which both families can read. The admins of the requested family receive a push and in-app notification with the name of the requesting family; the admins of the requesting family are likewise notified when the request is accepted or declined.
With an active link, admins can share an event with the other family. The following is transmitted to the other family: title, date (for multi-day events also the end date), start and end time, location, notes, links, any recurrence and attachments, the name and identifier of your family, the identifier of the creating account and the name of the member who created the event. Both families can edit the shared event; a change history that both families can see records who created or changed it and when (name and account identifier of the member, name of their family). All members of the other family receive a push and in-app notification; the push notification has the title “Event suggestion from [family name]” and the text “[title] · [date] · [location] — respond now”. If the event is changed, the members of the other family receive a notification with the name of the person who changed it, the title and the date. Like any push notification, these may appear on the lock screen of their devices (section 8). The other family can accept or decline; its reply is communicated to the admins of your family. Which members of your family take part in a shared event is stored only within your family and is not visible to the other family. Do not share events whose content the other family should not see. Legal basis: Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG).
If the link is removed, events already shared remain stored with both families and both can continue to edit them; new events are then no longer sent to the other family. Only the admins of the family that created a shared event can delete it. If a family is deleted, the link and the events it shared remain stored with the other family. A declined request also remains stored with the names of both families and any family photo of the requesting family. We delete such entries on request (section 11).
2.9 Invitations and Join Codes
If you invite a person to your family by email, we store an invitation record with the email address of the invited person, the name of your family, your display name, your account identifier, the status of the invitation and timestamps. The identifier of the record is derived from the family and the email address (truncated SHA-1 hash) so that the same person receives only one record per family; the email address itself is stored in readable form in the record. We send the invitation email via the SMTP service of Infomaniak (Switzerland, section 4.2); it names your family and your name and contains a join link with a join code that is valid for 7 days and can be redeemed once. In addition, the app shows a join card with a code; after one hour it shows a new one, but a code that was already shown or shared remains valid for 7 days and can be redeemed once. If you share an invitation link in the app (for example via a messenger, by text message or email), it contains its own join code, which is likewise valid for 7 days and can be redeemed once; you send the message yourself through the app you choose. Names you type in for this or take from your contacts stay on your device and are not sent to us (unlike the name of a person without their own device whom you add to the family, section 2.2). For each code we store the code, the family, the creating account, the expiry time and redemptions.
Connecting a person without their own device: If a person added without their own device later gets their own account, the member who added them and the managing people can share an invitation link for them. For the code of this link we additionally store which person it is for; only our server can read this assignment. If the person joins the family with this link and their own account, our server connects the entry with their account: their account takes over the name, colour and any photo, and the appointments where they are listed under "About", their chores, stars, rewards and their wishlist are transferred to their account; the entry without a device is removed. The age limits in section 9 apply to their own account.
An invitation can only be viewed by an account whose email address matches the invited address; it can only be accepted once that address has been verified. Invitation records and codes remain stored as long as the family exists and are deleted together with it. If you have been invited and do not wish to open an account, you can ask us at any time to delete your address (section 11). Legal basis: Art. 6 para. 1 lit. b GDPR (towards the inviting person) and lit. f GDPR (legitimate interest in delivering the invitation), Art. 31 para. 1 Swiss FADP (revDSG).
2.10 Time Clock (working time tracking)
The time clock under "Everyday" is a personal working time tracker (Premium). If you use it, we store the working hours, breaks, absences (such as vacation, illness, compensation) and notes you enter yourself, as well as your related settings (workload, target hours and planned times per weekday, vacation entitlement, opening balance, region for public holidays). If you provide them, we also store your employer and your shift plan (name, start, end, break and colour of your shifts, the rotation and the shift of individual days). This data is stored in Cloud Firestore (region europe-west1, Belgium) exclusively in your account; other family members cannot see it unless you add your planned times to the family calendar (see below). It serves only your own overview and your export (CSV, PDF); we do not analyse it and do not pass it on. You can delete individual entries or whole days in the app at any time; when you delete your account, the data in your account is removed completely.
Family calendar (optional): If you turn on "Add to the family calendar", your planned working hours for the next eight weeks are stored as events in your family's family calendar. Such an event contains the date, start and end, "Work" with your employer and, where applicable, the name of the shift, as well as your name and your member colour. These events are visible to all members of your family; they do not trigger push notifications. Recorded working hours, breaks, notes, balance and vacation account are not transferred; on days with a full-day absence or a public holiday, no event is created. If you turn the switch off, the events are deleted from today onwards; events on past days remain in the family calendar like other events. If your Premium access ends, you leave the family or you delete your account, events already entered may remain in the family calendar; on request (section 11) we delete them. Legal basis for the time clock: Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG).
2.11 Household finances (budget)
The "Finances" area under "Everyday" is an overview of a household's recurring income and expenses (Premium). If you use it, we store the entries you create yourself — name, amount, whether it is income or an expense, frequency, category, start and, where applicable, end date, any due day and, for monthly income, any 13th salary — and, for individual months, whether and when payment was made and for what amount. This information may allow conclusions to be drawn about your financial circumstances, such as income, rent or insurance.
The data is stored in Cloud Firestore (region europe-west1, Belgium) with your family, but is accessible only to the family's admins — both for reading and for editing. Other family members do not see this area. Anyone made an admin also gains access; this is pointed out before the appointment. Anyone who becomes an admin automatically, because the last admin left the family, does not gain access until another admin confirms them. The data serves only your own overview; we do not analyse it and do not pass it on. Entries can be deleted at any time, together with the amounts and receipts recorded for them. If Premium access ends, the area is no longer accessible; the information stays stored, is back unchanged with a new Premium access, and can be downloaded at any time via the data export (section 6). The finance data belongs to the family: if you delete your account, it remains available to the other admins; deleting the family removes it, including receipts. Legal basis: Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG).
Invoices and receipts (optional): If you upload an invoice or receipt for an entry — as a photo or PDF — we store the file in Firebase Storage (region europe-west1, Belgium) together with its file name, type, size and the month it belongs to. Photos are downsized first. These files, too, are accessible only to the family's admins. If you delete a receipt or the entry, the file is deleted with it.
Payment reminders (optional): If you set a due day and a reminder for an entry, our server checks every day whether the entry is due soon, today or has been due for a few days and has not yet been marked as paid, and then sends a notification — at most one per day, only to the family's admins: as a push notification to their devices and as an entry in the app's bell. The notification names the entry but never an amount, because it may appear on the lock screen.
Currencies: Entries in a currency other than the household's are converted using the daily reference rates of the European Central Bank. Our server fetches the rates from the central bank once a day; no data about you or your family is transmitted in the process.
2.12 Shopping list, “Often bought” and your own prices
On the shopping list we store, for each item, its name and quantity, who added it and who ticked it off (the member’s name) and when. In addition, the app keeps the list “Often bought” for each family: how often an item was put on the list and bought (ticked off), when it was last bought, the usual interval between two purchases and in which of your family’s shops it was last bought. The counting takes place on our server when an item is ticked off (Cloud Functions, region europe-west1, Belgium). Optionally, your family records staples, favourite shops (name, the chain where applicable, currency and order of the aisles) and its own prices per shop or for any shop. The list, the shops and the prices belong to the family, not to an individual person; for a price, we do not store who entered it. Prices in another currency are converted using the reference rates of the European Central Bank (section 2.11).
Only the members of your family can see this information. It is used for suggestions while typing, for staples, for sorting by the aisles of a shop and for estimating and comparing costs. Shops are only names that your family enters; we do not obtain any price or offer data from retailers, do not analyse your family’s purchases and do not pass them on. The information is deleted when an item is forgotten in “Often bought” or a shop is deleted, via “Reset all data” → “Shopping list” and when the family is deleted. It is included in the data export (section 6). Legal basis: Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG).
2.13 Location sharing (premium, only with your consent)
With “Location” under “Everyday” you can show the members of your family where you are. The feature is part of premium; without premium you can only view it with sample data, which stays on your device and is not stored anywhere. You only ever share your own location: it can only be saved by someone signed in with your account, and only after your consent — our server checks this on every save. The app does not allow anyone to retrieve another person’s location unless that person shares it themselves.
Consent: Before your location is collected for the first time, the app explains how sharing works, who sees your location and how long it is stored, and asks for your consent; only then does your device or browser ask for permission to access your location. For each family, we store when you gave your consent and which version of this explanation you saw (proof under Art. 7 para. 1 GDPR). If something material is added, you confirm the new version before it applies: since October 2026, once before the first live sharing that also continues in the background. The members of your family can see whether you have set up location sharing.
When your location is collected: only when you tap to share it — once (“I’m here” or in reply to “Where are you?”), in which case it is visible for one hour, or live for a period you choose (one hour, until this evening or until you stop it). When sharing live, the app updates your location every few minutes. In the app for iOS and Android this also happens while the app is in the background (for example with the screen off or while another app is open), until the end you chose or until you stop it; during this time your device shows it, on iPhone with the blue location indicator at the top, on Android with the ongoing notification “You’re sharing your location live”. On Android the app uses a so-called foreground service for this; it does not ask for background location permission (“Always”) on Android or on iPhone, only for permission while using the app. If you close the app completely (swipe it away) or your device restarts, updates stop; in the web app, updates only happen while the page is open in your browser. If no update arrives for more than 30 minutes, your family no longer sees you. “I’m here” and replies to “Where are you?” collect your location only while the app is open. When you open the app again, live sharing continues by itself until the end you chose or until you stop it; the app tells you so and offers “Stop”. For this, only the device or browser on which you share live remembers your choice: the end you chose, when you started and until when your last update is visible, plus the identifiers of the family and the account, but no location. The app removes this entry as soon as live sharing ends or you sign out; if it ends while the app is closed, the next time you open it. If you stop live sharing on another device, it may still continue the next time you open the app on the device on which you share live, again with the notice and “Stop”. Your location is determined by your device or browser (for example via GPS, Wi-Fi or the mobile network); depending on the device and settings, the maker of the operating system or browser (such as Apple or Google) uses its own location services for this, under its own privacy policy.
What we store: only the latest position for each person — the coordinates (rounded to about one metre), the accuracy reported by the device, the time, whether it is shared once or live, until when it is visible, any end time you chose and a place name (see below). Each new update overwrites the previous one; we do not keep a history of your locations. If you have turned off precise location on your device, the others only see approximately where you are. This information is stored in Cloud Firestore (region europe-west1, Belgium) with your family and is included in the data export (section 6).
Battery level: if “Share battery level” is on (the default; the switch is in “Location” under “You”), we also store your device’s battery level in percent with each position, and whether it is currently plugged in. This lets your family see, for example, if your phone is about to run out. The app only reads the value at the moment it stores your position; like the position, it is overwritten and there is no history. If you turn the switch off, the app immediately removes the battery level from your latest position, and later updates no longer contain one. In the browser, the battery level is only available where the browser provides it (such as Chrome), not in Safari or Firefox. We store the setting in your profile.
Who sees your location: the members of your family, as long as your family has premium; the app shows who they are under “Visible to”. Anyone who leaves the family or is removed from it loses access immediately. Linked families (section 2.8) do not see your location. Like other data, the members’ apps keep the most recently received position cached on the device for use without a connection. We do not analyse locations, do not create profiles from them and do not pass them on.
“Where are you?”: Members who have set up location sharing themselves can ask each other for their location. For this we store who asked whom and when, until when the request is valid (15 minutes) and whether it was answered. There is only one request between any two people; a new one replaces the old one, at the earliest two minutes later. The person asked receives a push notification with the name of the person asking (“[Name] would like to know where you are.”); if they share their location, the person asking receives a notification (“[Name] shared their location”, or “[Name] is at [place]” if the position is within a saved place). Declining does not trigger a notification; the person asking only sees in the app that you are not sharing right now. The notifications contain no coordinates and no address; at most they name a saved place (see below).
Notifications to your family: When you share with “I’m here”, the members of your family who have set up location sharing themselves receive a push notification (“[Name] is at [place]” if your position is within a saved place, otherwise “[Name] shared their location”). When sharing live, your app recognises when you arrive at or leave a saved place (in the app for iOS and Android also in the background, in the browser only while the page is open) and reports this in the same way (“[Name] arrived at [place]”, “[Name] left [place]”), at most once every five minutes per place. For this we store one event per occasion: who, whether it is “I’m here”, an arrival or a departure, which saved place including its name, and the time — no coordinates. Our server only reads the event to send the notification; the other members cannot retrieve it. The database deletes events automatically after one day (usually within a further 24 hours). Anyone who does not want such notifications can turn them off for themselves in the app under “Notifications” (“Location: arriving and leaving”, “Location: I’m here”); only those who have them switched on there receive them. Arriving and leaving can also be switched off for the whole family for each saved place (see “Saved places”). The notification may appear on the lock screen.
Saved places: Your family can save places such as “Home” or “School” (name, symbol, coordinates and radius, up to 20). If your location is within such a radius, the name of the place is shown instead of an address; your device works this out. With the switches “On arrival” and “On leaving”, you decide for each place whether the family receives a notification when someone arrives there or leaves it; both are on at first, and for each place we only store which switch is off. The switches apply to the whole family and can only restrict notifications, never send anyone additional ones: if one is off, our server sends no notification for it (current versions of the app do not store an event for it either); if it is on, the notification still only reaches those who have switched it on under “Notifications”. They do not apply to “I’m here”. Saved places belong to the family, not to an individual person: all members see them, every member can change and delete them, and we do not store who created them. They are deleted with the family. When you add or edit a place, you can search for an address. Your input then goes to Photon (section 4.8), together with the centre of the map view, rounded to one decimal place (about 10 km), so that results nearby come first. If the map is currently showing your surroundings (which is how a new place starts), this roughly reveals the area you are in, but not your exact location. If Photon finds nothing or does not respond, the app asks swisstopo (section 4.4) instead when the map view is in Switzerland, with your input only. Neither service receives details of your account or your shared location.
Place name: If you are not at a saved place, the iOS or Android app looks up a place name (such as “Hauptstrasse, Stein am Rhein”) using the built-in service of your operating system. To do so, your device sends the coordinates to Apple or to the provider of this service on your Android device (usually Google), which processes them as an independent controller under its own privacy policy; no information about your account with us is sent. When sharing live, this happens at most every five minutes and only after you have moved a noticeable distance. Only the name found (up to 80 characters) is stored in your position. This lookup does not exist in the web app.
Map: We load the map from our own storage at Google Cloud (Google Cloud Storage, section 4.1), not from a map service; we do not use Google Maps or other third-party map or geocoding services for it. To display it, your device loads the map sections it needs from there and keeps them cached; in doing so, Google technically sees your IP address and which section your device loads. We do not analyse these requests. The map data comes from OpenStreetMap (© OpenStreetMap contributors, Open Database License); we list the sources on the attributions page.
Aerial view: Our server fetches the aerial view for Switzerland, Liechtenstein and Austria from swisstopo or basemap.at and stores it in our storage at Google Cloud; like the map, your device loads it only from there (Google technically sees your IP address and the section loaded), and neither swisstopo nor basemap.at receives your IP address or any information about you. If an image section is still missing, the app asks our server, using your sign-in; we do not store who requested which section.
Directions: If you tap “Directions” for a member whose location you can see or for a saved place, a maps app opens with that location, such as Apple Maps, Google Maps or Waze; if more than one is available, you choose. In a browser, and on devices without a maps app, Google Maps opens in the browser, with Apple Maps as an alternative on Apple devices. Only the coordinates are passed on, and only when you tap, never a name. What happens to the data there is governed by the respective provider under its own privacy policy.
Deletion: If you stop or remove sharing, we delete your position immediately; the same applies when you sign out. A position shared once is visible for one hour, a live position until the end you chose, at the latest until 30 minutes after the last update. After that the app no longer shows it, and the database deletes expired positions and requests automatically, usually within 24 hours. If you turn off location sharing, we delete your position, your consent, your events and the requests from you and to you. Our server does the same if you leave the family, are removed from it or delete your account. If premium ends, sharing ends too and your position is deleted; your consent remains stored until you withdraw it. Like all data in our database, this information is contained in our technical backups (daily backup and point-in-time recovery of the database); earlier positions may also be contained there for up to 7 days. We only use the backups to restore data after a technical fault and do not analyse them; after 7 days the information is deleted there as well.
Legal basis and withdrawal: The legal basis is your consent (Art. 6 para. 1 lit. a GDPR, Art. 31 para. 1 Swiss FADP (revDSG)). It is voluntary; you can use all other functions of the app without it. You can withdraw it at any time with effect for the future, without asking anyone: in the app under “Location” → menu → “Turn off location sharing”, by email to datenschutz@jh-familysync.app or, for further collection, by revoking the location permission in the settings of your device or browser. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Young people: Young people also decide for themselves whether to share their location; it can only be turned on with their own account, not from the account of their parents or other members (section 9).
3. Purpose of Processing
We process your data for the following purposes:
- Provision and operation of the app's functions (account, family calendar, polls, lists)
- Synchronisation of data between family members and devices
- Sending push notifications (e.g. appointment reminders, new polls, a notice about an update if your version of the app is outdated)
- Fetching subscribed calendars, sharing events with linked families and sending invitations (sections 2.7 to 2.9)
- Location sharing within the family when you turn it on yourself (only with your consent, section 2.13)
- Sending emails about your account and subscription, e.g. to confirm your email address, set a new password, delete your account, or about a trial, purchase or cancellation (section 8.2)
- Email notifications that you switch on and off in the app: new and changed events, polls and the weekly summary (section 8.2)
- Occasional emails with news about JH FamilySync, such as new features, unless you object (section 8.2)
- Reach measurement and improvement of the app (only where consent has been given)
- Ensuring technical operation and protection against misuse
- Handling of subscriptions, payments and invoicing — legal basis Art. 6 para. 1 lit. b GDPR
Legal bases: Art. 6 para. 1 lit. b GDPR (performance of a contract or pre-contractual measures), Art. 6 para. 1 lit. f GDPR (legitimate interest in secure operation and in occasionally informing you about JH FamilySync), Art. 6 para. 1 lit. a GDPR (consent) for usage statistics (section 7.2), location sharing (section 2.13) and, from version 1.38 of the app, photo recognition with AI (section 4.5) as well as the corresponding provisions of the Swiss FADP (revDSG) (Art. 31). We process information about people without their own device whom members add to the family (section 2.2) on the basis of Art. 6 para. 1 lit. f GDPR (legitimate interest of the family in planning its everyday life together) and Art. 31 para. 1 Swiss FADP (revDSG).
4. Processors and Other Recipients
We do not sell or rent out your personal data and do not pass it on to advertising networks or data brokers. We use carefully selected service providers. With the service providers that process data on our behalf (processors), we have concluded the legally required data processing agreements (DPA). The public interfaces of swisstopo (4.4), Photon (4.8) and OpenHolidays (4.11) are not processors, nor are Apple and Google where they act as independent controllers as a store (4.9), for sign-in (4.10) or with the location and place-name services of their operating systems (2.13), nor is Apple for the ads on the App Store (4.13).
4.1 Google Firebase
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase handles authentication, database (Cloud Firestore), file storage (Firebase Storage), push notifications (Firebase Cloud Messaging), server-side functions (Cloud Functions, europe-west1 Belgium and europe-west3 Frankfurt) as well as — where consent has been given — reach measurement (Firebase Analytics / Google Analytics 4) and the delivery of the web app and the website (Firebase Hosting, CDN edge worldwide; for the server logs see section 2.4). The app also loads the map and the aerial view (Switzerland, Liechtenstein, Austria) for location sharing from Google Cloud Storage (section 2.13). Storage location of the family data: EU (europe-west1, Belgium). Firebase also includes App Check (section 2.4), on the web with Google reCAPTCHA Enterprise.
Transfer to third countries: Google LLC (Mountain View, USA) acts as an intra-group sub-processor of Google Ireland Limited. Although data processing physically takes place in the EU (europe-west1/west3), technical access by Google LLC in the context of support and security incidents is possible. Safeguarded by EU Standard Contractual Clauses (SCC) as well as the EU-U.S. Data Privacy Framework (DPF certification of Google LLC).
Privacy policy: firebase.google.com/support/privacy
4.2 Infomaniak Network SA
Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland. The domain jh-familysync.app and its name servers (DNS) are held with Infomaniak. In addition, we use the Infomaniak SMTP delivery for all emails we send to you and to invited persons (DKIM-signed via the domain jh-familysync.app): emails about your account and subscription, invitations, email notifications and news about JH FamilySync (section 8.2). The website and the web app themselves are delivered by Firebase Hosting (section 4.1), not by Infomaniak.
The mailboxes of our @jh-familysync.app addresses that you write to are also
held with Infomaniak: support@jh-familysync.app for questions about the app
and your subscription, cancellations, withdrawal from a subscription and feedback,
datenschutz@jh-familysync.app for data protection requests and requests
concerning your rights, and eu-vertreter@jh-familysync.app, which reaches our
representative in the EU (section 1.1). Replies to emails from the app go to
support@jh-familysync.app. We process the content of the emails together with
the sender and recipient address and the time in order to handle your request
(Art. 6 para. 1 lit. b and f GDPR, Art. 31 para. 1 Swiss FADP (revDSG)). We keep these emails for as long as we
need them for their purpose (for example until your request has been dealt with, or
for managing your subscription); statutory retention obligations remain
unaffected.
Privacy policy:
infomaniak.com (privacy policy)
4.3 Sentry (crash and error telemetry)
Operator: Functional Software, Inc. (Sentry.io),
45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
We use Sentry to automatically capture crashes and unexpected errors in the app
so that we can fix them quickly.
Data categories: error stack traces, browser user agent,
app version, environment identifier (dev/prod), technical information about the
device (such as manufacturer and model, operating system and version, language, time
zone, screen size and memory), the area of the app that was open when the error
occurred, with the view, the window size rounded to 10 pixels and the layout, a
technical log of the last steps before the error (such as moving to the background or
network requests with address and status; the app’s console output is not included) as
well as, in the iOS and Android app, an installation identifier generated at random by
Sentry; it is not an account identifier and is not linked to your account.
The web app does not transmit any such identifier.
The app does not transmit an account identifier, the email address from your
profile or cookies (sendDefaultPii = false). An additional
beforeSend filter in the app discards the request object and removes
email addresses from error texts. Errors that the browser reports directly in the
web app bypass this filter; they do not contain cookies either, but an email
address in the text of such an error message is not removed. Under our project
settings, Sentry does not store IP addresses, and it discards the approximate
location derived from them on receipt.
Legal basis: Art. 6 para. 1 lit. f GDPR
(legitimate interest in stable, secure operation of the app)
or Art. 31 para. 1 Swiss FADP (revDSG).
Retention period: 90 days; thereafter automatic deletion
by Sentry.
Transfer to third countries: The events are transmitted to
Sentry's EU location (Germany, ingest.de.sentry.io) and stored
there. As Functional Software, Inc. is based in the USA, access from the
USA (e.g. for support) cannot be excluded; it is safeguarded by the EU-US
Data Privacy Framework as well as by EU Standard Contractual Clauses (SCC).
Automatic session tracking is disabled. For part of the usage (currently around
10%), Sentry also measures how long processes take, such as the app start or network
requests.
Privacy policy:
sentry.io/privacy
4.4 Swisstopo / GeoAdmin API (address autocomplete)
Operator: Federal Office of Topography swisstopo,
Seftigenstrasse 264, 3084 Wabern, Switzerland.
When you enter a location for appointments, we offer you a
live suggestion service that accesses the official
GeoAdmin Search API of the Swiss Confederation. For saved places (location
sharing, section 2.13), the app only asks swisstopo as a fallback, if Photon (section 4.8)
finds nothing or does not respond and the map view is in Switzerland.
Data categories: the search string currently
entered in the input field (e.g. street name, place name) as well as,
for technical reasons, your IP address, because the app queries the
service directly from your device. No account data, no appointment
content and no calendar IDs are transmitted. According to swisstopo, the
requests are not stored in a personally identifiable manner.
Legal basis: Art. 6 para. 1 lit. f GDPR
(legitimate interest in convenient address entry)
or Art. 31 para. 1 Swiss FADP (revDSG).
Transfer to third countries: None — swisstopo operates
the service in Switzerland.
Terms of use:
geo.admin.ch (terms of use)
4.5 Vertex AI Gemini (image recognition, only with active premium AI auto-fill)
Operator: Google Ireland Limited,
Gordon House, Barrow Street, Dublin 4, Ireland.
For the optional premium feature "Camera + AI auto-fill"
we use Vertex AI Gemini (currently the Gemini 3.5 Flash model) to automatically
extract event details such as title, date, time and
location from a photo you actively upload (e.g. flyer, invitation,
timetable).
Purpose: automatic pre-filling of the appointment form
from an image — exclusively upon your explicit action.
Data categories: only photos that you
select or take for analysis via the camera button. No
images are transmitted to Vertex AI without your active
involvement.
Legal basis: Art. 6 para. 1 lit. b GDPR
(performance of the contract within the premium subscription) or
Art. 31 para. 1 Swiss FADP (revDSG); from version 1.38 of the app, additionally your
consent (Art. 6 para. 1 lit. a GDPR, Art. 31 para. 1 Swiss FADP (revDSG)).
Consent (from version 1.38): Before the first analysis, the app tells you
which photo goes to whom (Google, Vertex AI, processing in the EU, currently Frankfurt),
what it is for and what does not happen, and asks whether you agree. Without your consent
it does not send any photo for analysis. We store in your account whether and when you
consented or withdrew your consent and which version of the notice you saw (proof under
Art. 7 para. 1 GDPR). Only you can read this information, not the other members of your
family; it remains stored until you delete your account.
Withdrawal: You can withdraw your consent at any time with effect for the
future: in the app under Settings → App info → Photo recognition (AI) or by email
to datenschutz@jh-familysync.app. After that, we no longer transmit photos from your
account to Vertex AI until you consent again; the app asks you again before the next
analysis. The lawfulness of the processing carried out until the withdrawal remains
unaffected.
Place of processing: EU region
europe-west3 (Frankfurt am Main, Germany). Photo data
does not leave the EU.
Retention period: The images uploaded for analysis
are stored briefly in the tempAnalysis path of your family's
Firebase Storage (region europe-west1) and are deleted by the app
immediately after the analysis is complete. If you keep the image as an
attachment of the event, it is stored there instead. Files left behind that
are older than 24 hours are removed by a daily clean-up job on our server.
No training-data sharing: Vertex AI is a Google Cloud
enterprise service; under the Google Cloud terms, the transmitted images
are not used to train Google models.
No automated decision-making: The result of the
image recognition merely pre-fills form fields as a suggestion. No
automated decision in an individual case producing legal effects
within the meaning of Art. 22 GDPR takes place; you review and
confirm every entry yourself.
Privacy policy:
cloud.google.com (Vertex AI Data Governance)
4.6 Stripe (payment processing)
For the processing of paid subscriptions, we use Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland.
- Purpose: payment processing, fraud prevention, invoicing.
- Data categories: name, email, payment method data (the card number is not stored by us but transmitted directly to Stripe), IP address, Stripe customer ID, subscription status, transaction ID, billing history.
- Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract), Art. 31 para. 1 Swiss FADP (revDSG).
- Transfer to third countries: Stripe Inc. (USA) acts as a sub-processor. Safeguarded by EU Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Retention period: in accordance with the commercial-law retention period (10 years pursuant to Art. 958f CO), for payment data in accordance with Stripe's specifications. When you delete your account, we end a running web subscription immediately and delete your Stripe customer account (section 6); Stripe retains invoices and payment records for us pursuant to Art. 958f CO.
- Stripe privacy policy: stripe.com/privacy
4.7 RevenueCat (management of in-app subscriptions, iOS/Android)
For the verification of purchase receipts and the management of in-app subscriptions in the native apps (Apple App Store, Google Play), we use RevenueCat, Inc., San Francisco, California, USA.
- Purpose: server-side verification of purchase receipts and management of subscription status (purchase, renewal, cancellation, expiry) via the app stores.
- Data categories: your Firebase account identifier (as app user ID, passed to RevenueCat at sign-in), the purchase receipts transmitted by the store with transaction and original transaction identifiers, product, store, price and currency, type of period (trial, introductory offer, regular), purchase timestamps and expiry date, the country that RevenueCat assigns to your account (according to RevenueCat, derived from the last known location) and, for technical reasons, your device's IP address when the app contacts RevenueCat. RevenueCat reports these purchase events to us; what we store from them is set out in section 2.5. No payment method data (this remains with Apple or Google).
- Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract), Art. 31 para. 1 Swiss FADP (revDSG).
- Transfer to third countries: USA — safeguarded by EU Standard Contractual Clauses (SCC).
- Retention period: for the duration of the subscription or as long as necessary for billing and verification purposes.
- RevenueCat privacy policy: revenuecat.com/privacy
4.8 Photon / Komoot (address and location search)
For address and location search for appointments, we use the open geocoding service Photon, operated by komoot GmbH, Berlin, Germany (EU), in addition to the swisstopo API (section 4.4). Photon mainly provides addresses outside Switzerland as well as places such as shops or restaurants. For appointments, every search goes to both services at the same time; the app queries them directly from your device. For saved places (location sharing, section 2.13), the app first asks only Photon and also sends the centre of the map view, rounded to one decimal place (about 10 km), so that results nearby come first.
- Purpose: conversion of an entered address/location search into suggestions with coordinates.
- Data transmitted: the search string you enter as well as, for technical reasons, your IP address; for saved places, also the rounded centre of the map view.
- Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in location search), Art. 31 para. 1 Swiss FADP (revDSG) — only upon your active input.
- Transfer to third countries: None — servers operated in the EU (Germany).
- Komoot privacy policy: komoot.com/privacy
4.9 Apple App Store and Google Play (purchase in the native apps)
If you take out the subscription in the iOS app, Apple (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, or the Apple entity responsible for your country) is the seller and payment processor; in the Android app it is Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, or the Google entity responsible for your country).
- Role: Apple or Google processes your payment and billing data as an independent controller under its own privacy policy; there is no processing relationship with us.
- What we receive: no payment method and no billing address data, but via RevenueCat (section 4.7) only the purchase data listed in section 2.5.
- Withdrawal and refunds: exclusively through the procedure of the respective store (see Terms §5).
- Privacy policies: apple.com/legal/privacy · policies.google.com/privacy
4.10 Sign-in with Google and with Apple
Instead of an email address and password, you can sign in with your Google or Apple account. Sign-in runs through Firebase Authentication (section 4.1); Google or Apple processes the sign-in as an independent controller.
- Google (Google Ireland Limited, Dublin, or Google LLC, USA): We request the "email" and "profile" permissions and receive your email address, your name and the URL of your Google profile picture, which we adopt as your profile picture in the app.
- Apple (Apple Inc., Cupertino, USA): We request your email address and name. If you choose "Hide My Email" with Apple, Apple transmits a relay address; we then receive and store only that address.
- No further access: We receive no access to contacts, calendars, photos or other content of your Google or Apple account.
- Purpose and legal basis: sign-in without a separate password; Art. 6 para. 1 lit. b GDPR, Art. 31 para. 1 Swiss FADP (revDSG). Use is voluntary; sign-in with email address and password is always available.
- Privacy policies: policies.google.com/privacy · apple.com/legal/privacy
4.11 OpenHolidays API (public holiday and school holiday data)
We obtain public holidays and school holidays for Switzerland, Germany and Austria from the open interface openholidaysapi.org. Our server fetches this data once a month and stores it in our database; the app reads it only from there. No data about you is transmitted to the provider in the process. Where school holidays for a region are missing there, we add them from the official information published by the cantons or states; we compile this supplement ourselves and keep it on our server, and no data about you is transmitted in this case either. We store with your family which region and, where there are several holiday calendars, which school your family has chosen for the school holidays.
4.12 Microsoft 365 (our business mailbox)
Our business mailbox info@jh-virtuell.ch is operated for us by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft 365 / Exchange Online).
- Purpose: receiving the internal notifications about subscription events (section 2.5), and receiving and handling emails that you write to this address. It was our contact address until September 2026 and still appears in older app versions; today you can reach us at the addresses in section 4.2.
- Data categories: content of the emails including sender and recipient address and time; for the internal notifications, the information listed in section 2.5.
- Legal basis: Art. 6 para. 1 lit. b GDPR (contract and pre-contractual enquiries) and lit. f GDPR (legitimate interest in handling enquiries and looking after subscriptions), Art. 31 para. 1 Swiss FADP (revDSG).
- Transfer to third countries: Microsoft Corporation (USA) may have access as a group company, for example for support; safeguarded by EU Standard Contractual Clauses (SCC) and the EU-U.S. Data Privacy Framework (DPF).
- Retention period: as long as we need the emails for their purpose (for example until your request has been dealt with, or to look after your subscription); statutory retention obligations remain reserved.
- Microsoft privacy statement: privacy.microsoft.com
4.13 Ads for the app on the App Store (Apple Ads)
We promote the iOS app with ads on Apple's App Store (Apple Ads), for example in the search results. We decide for which search terms (or whether Apple chooses matching search terms itself), in which countries and on which devices an ad may appear, whether it is shown only to people who have not yet downloaded the app, and how much it may cost. Who is shown an ad is decided by Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) as an independent controller under its own privacy policy; there is no processing relationship with us.
- What we receive from Apple: only aggregated reports without personal reference, such as how often an ad was shown and tapped, how many installs followed and what it cost, per campaign, search term and country. We cannot attribute these figures to a person or an account.
- What the app does for this: It does not ask for permission to track (App Tracking Transparency). Only if you have agreed to the usage statistics in the iOS app (section 7.2) does the Firebase Analytics library it contains ask Apple, via Apple's AdServices interface, whether the install came from an ad on the App Store. If so, the usage statistics record details of the ad under a pseudonym (such as campaign and search term, as ID numbers), without your name or email address. Without your consent, this query does not take place. Beyond this, the app does not pass any data to advertising networks.
- Your choice: You decide whether Apple shows you personalised ads, on iPhone and iPad under Settings > Privacy & Security > Apple Advertising.
- Apple's privacy information: apple.com/legal/privacy/data/en/apple-advertising
5. Retention Period
We store your personal data for as long as your account exists or as long as it is required to perform the contract. After confirmation of your account deletion (see the section "Your Rights"), all data associated with your account (sign-in account, profile including profile picture, your memberships, personal calendar spaces and emergency contacts, time clock, device list, notifications, FCM tokens, your position, your consent, your events and your requests for location sharing, section 2.13, the stored purchase events from the App Store and Google Play, section 2.5, and the emails to your address) is irrevocably removed from the production systems without delay, but no later than within 30 days. If you were the last member of your family, the family is deleted along with all its content, except for the events it shared with linked families and the link itself: these remain stored with the other family (section 2.8). We delete events that were visible only to you with your account in all families, including former ones, together with their attachments. Calendar subscriptions you created end with your account, including in the family calendar: we delete the subscription, its address and the events taken over from it (section 2.7). If you leave or switch a family, the calendar subscriptions you created there stay with it; delete them beforehand if you do not want that. If your family continues to exist, the other content you created in it remains stored with the family (for example appointments with their attachments, tasks, lists, polls, family tree entries and working hours entered by the time clock, section 2.10; the household finances remain available to the other admins, section 2.11); on request (section 11) we delete it. Statutory retention obligations remain reserved.
Emails: The emails we send remain in our sending queue (Cloud Firestore) after sending, so that we can investigate delivery problems. We delete delivered emails 30 days after delivery and undelivered ones 90 days after they were created. The emails to your address are deleted immediately together with your account. The confirmation of the deletion is only created afterwards and is deleted within the same periods, as is the copy of the internal notifications to us about subscription events in the sending queue (section 2.5). If the receiving server permanently rejects an email to your address (for example because the address or its domain does not exist), we note this with the date on your account so that the app can point out the wrong address to you. We remove the note as soon as an email to you is delivered again, at the latest together with your account. Emails in our mailboxes are covered by sections 4.2 and 4.12.
Location sharing: We delete your position as soon as you stop or remove sharing, otherwise after it expires: the database deletes expired positions and requests automatically, usually within 24 hours. Events (“I’m here”, arriving, leaving) are deleted after one day, likewise usually within a further 24 hours. We delete your consent, events and requests when you turn off location sharing, leave the family or delete your account. This information remains in the technical backups of the database for up to 7 days (section 2.13).
Recycle bin: Deleted appointments, tasks, occasions, polls, calendar subscriptions and removed members are first kept for 30 days in the family's recycle bin, where they can be restored; after that a daily job deletes them permanently together with their attachments. Invitation records and join codes are deleted together with the family (section 2.9).
People without their own device: People added without their own device (section 2.2) belong to the family, not to the account that added them. If that account leaves the family or is deleted, they remain stored; managing people can then edit or remove them. If the member who added a person or a managing person removes the entry, we delete it permanently (it is not moved to the recycle bin), together with the photo, star balance, redeemed rewards and wishlist, and remove the person from appointments, chores and rewards. When the family is deleted, its people without their own device are deleted with it.
Commercial-law retention obligation: Invoices, proofs of payment and business records are retained for 10 years pursuant to Art. 958f of the Swiss Code of Obligations (CO). This period exceeds the regular 30-day deletion following account deletion; only the payment-relevant records are affected (Stripe customer ID, invoice date + amount, subscription period), not the calendar content. Stripe retains these records for us; your customer account with Stripe is deleted with your account.
6. Your Rights
You have the following rights vis-à-vis us:
- Access to the data stored about you (Art. 15 GDPR / Art. 25 Swiss FADP (revDSG))
- Rectification of inaccurate data (Art. 16 GDPR / Art. 32 Swiss FADP (revDSG))
- Erasure of your data (Art. 17 GDPR / Art. 32 Swiss FADP (revDSG))
- Restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR / Art. 28 Swiss FADP (revDSG)) — you can download your complete data yourself at any time as a machine-readable JSON file under Settings → App info → Export my data
- Objection to the processing (Art. 21 GDPR); to news about JH FamilySync by email at any time also via the unsubscribe link in every such email (section 8.2)
- Withdrawal of consent given (for usage statistics, section 7.4, for location sharing, section 2.13, and for photo recognition with AI, section 4.5) at any time with effect for the future
- Complaint to a supervisory authority (in Switzerland: the FDPIC; in the EU: the competent data protection authority of your country of residence)
Note on account deletion: A complete account deletion is possible directly in the app under Profile → Delete account permanently. For security reasons, you sign in once more (with your password, Google or Apple); after that, your account and your data are immediately and irrevocably deleted, and we confirm the deletion to you by email. If the renewed sign-in cannot be completed in the browser, we instead send you a confirmation email with a link valid for 7 days; the deletion then only takes place after you click this link. If you were the last member of your family, the entire family — including all appointments, polls, lists, occasions and attachments — is deleted along with it as part of a cascade delete, except for the events it shared with linked families and the link itself (section 2.8); if it continues to exist, section 5 applies. Premium that your family has through your subscription ends with the deletion. We end a web subscription (Stripe) immediately; time already paid for is not refunded. Your Stripe customer account is deleted; Stripe retains invoices and payment records for us pursuant to Art. 958f CO. A subscription via the App Store or Google Play is not cancelled by the deletion; cancel it yourself in your App Store or Google Play account, otherwise it keeps running. Alternatively, you can submit an informal deletion request by email to datenschutz@jh-familysync.app; we will process it within 30 days.
7. Cookies and Analytics
JH FamilySync uses cookies as well as local storage technologies (localStorage, IndexedDB) of your browser. We clearly distinguish between technically necessary storage and optional analytics services, which are activated only with your consent.
7.1 Technically Necessary Cookies and Storage
The following storage is strictly required for the operation of the app and is set without consent (Art. 6 para. 1 lit. f GDPR / legitimate interest in secure operation):
- Firebase Authentication — sign-in and maintenance of the session
- App settings — e.g. theme (light/dark), language, selected view
- Service Worker — offline capability, PWA functionality, push registration
- Cookie consent — storage of your decision under the localStorage key
jhfs_cookie_consent - Device and sign-in markers — the identifier of this device for your device list (section 2.1), the identifier of the family your account last belonged to on this device (so that the app also starts correctly without a connection) and, in the web app while you are signed in, the localStorage key
jhfs_angemeldetso that the home page takes you straight to the app; it is removed when you sign out - Purchase in the web app — after payment, the identifier of the Stripe payment session and your account identifier (
jhfs_kauf_offen) until Premium is activated; if activation is still pending after 24 hours, the app removes the entry the next time the web app is opened in this browser with a signed-in account - Location sharing — while you share live, your choice for continuing after a break (
jhfs_standort_live): the end you chose, when you started and until when your last update is visible, plus the identifiers of the family and the account, but no location; the app removes the entry as soon as live sharing ends (if the app is closed at that time, the next time it is opened) or you sign out (section 2.13) - Protection against misuse (App Check) — in the web app, the Firebase App Check token (valid for one hour), which the Firebase SDK caches in the browser, the entries that Google reCAPTCHA Enterprise stores in the browser for this purpose, for the current session the selected check type together with the public key of our website (sessionStorage), and the localStorage keys
appCheckGestoertBis(if the check is disrupted, the app starts without it until this time, for up to 24 hours) andappCheckGemeldetAm(the day on which the app last reported such a disruption, so that it does so at most once a day). They serve only to protect the service and are therefore stored without consent (section 2.4).
7.2 Google Analytics 4 / Firebase Analytics (only with consent)
To improve the app and for pseudonymous reach measurement, we use Firebase Analytics (based on Google Analytics 4). Among other things, the screens accessed, usage duration, device type and a technically generated pseudonymous identifier are recorded, but not your name or your email address. In the iOS app, this also includes whether the install came from an ad on the App Store (section 4.13). The IP address is anonymised (IP anonymisation active), ad tracking and personalisation signals are disabled (allow_ad_personalization_signals = false, allow_google_signals = false). From the truncated IP address, Google derives an approximate location (such as country, region or city); usage statistics do not record your precise location. We only process your precise location for location sharing, when you share it yourself (section 2.13), and never for usage statistics.
Activation takes place exclusively after your explicit consent via our cookie banner (Art. 6 para. 1 lit. a GDPR, Art. 31 para. 1 Swiss FADP (revDSG)). The provider is Google Ireland Limited, Dublin. We load Google's analytics script (Google Tag Manager, googletagmanager.com) only after your consent. Before your consent and if you decline, neither the website nor the app sends data to Google Analytics: the script is not loaded, and there is no page view and no measurement.
7.3 Google Consent Mode v2
We use Google Consent Mode v2 in its basic variant: Google Analytics is loaded only after your consent; before that, no cookieless signals are sent to Google either. When you agree in the cookie banner, analytics_storage is set to granted. The advertising-related signals (ad_storage, ad_user_data, ad_personalization) remain permanently set to denied even after consent: the usage statistics set no advertising cookies, send Google no user data for advertising purposes and serve no personalised advertising (for the ads for the app on the App Store, see section 4.13). If you withdraw your consent, analytics_storage is set back to denied and measurement stops immediately; in the browser we also delete the analytics cookies (_ga).
7.4 Withdrawal of Your Consent
You can withdraw your consent at any time with effect for the future, or give it later:
- On the website: click Cookie settings in the footer — the cookie banner opens again and you can change your decision.
- In the web app and in the apps for iOS and Android from version 1.27.0: under Settings → App info → Cookie and statistics settings.
- At any time, you can also withdraw it by sending an informal email to datenschutz@jh-familysync.app.
Marketing or advertising tracking cookies are not used.
8. Push Notifications and Emails
8.1 Push notifications
Push notifications are sent exclusively if you have agreed to the browser- or device-side permission request. For delivery, we use Firebase Cloud Messaging (FCM); on iOS devices FCM forwards the message via the Apple Push Notification service (APNs) of Apple Inc. For this purpose, an FCM token is generated per device and associated with your account. A push notification contains the text you see (e.g. event title, date, location, name of an inviting or linked family or, for location sharing, the name of the person asking for your location or sharing theirs and, where applicable, the name of a saved place such as “Home”, section 2.13) and may appear on the device's lock screen. You choose in the app which types of notifications you receive. The exception is a notice about an update if one of your devices runs an outdated version of the app (section 2.1): you receive this service message as a push notification on the device concerned and as an entry among the notifications in the app; it has no separate switch.
You can withdraw the permission at any time in the settings of your browser or operating system. Upon logout, the associated FCM token is automatically deleted.
8.2 Emails
We send three kinds of email to the email address of your account:
- Emails about your account and subscription: confirmation of your email address, a new password, account deletion and messages about your subscription and Premium (e.g. trial, purchase, cancellation, expiry, a failed payment or Premium granted by us). They are part of using the service (Art. 6 para. 1 lit. b GDPR) and cannot be unsubscribed from.
- Email notifications: new and changed events, new and decided polls and the weekly summary with the events of the next seven days (Sundays at 6 pm Swiss time, if events are coming up). You switch them on and off in the app under Settings → Notifications. Initially, emails about polls are switched on and the others are switched off. Each such email contains a link that switches off this kind without signing in; you can switch it back on in the app.
- News about JH FamilySync: occasionally, e.g. about new features or changes to the service. We rely on our legitimate interest in informing you as a user about our own service (Art. 6 para. 1 lit. f GDPR, Art. 31 para. 1 Swiss FADP). You can object at any time free of charge (Art. 21 para. 2 GDPR): via the unsubscribe link contained in every such email, which works without signing in, or by email to datenschutz@jh-familysync.app. We store your unsubscription with its date so that you receive no further such emails until your account is deleted.
Invitations to an address entered by a member are described in section 2.9. All these emails are sent via Infomaniak (section 4.2); how long they are stored afterwards is set out in section 5.
9. Minor Users
JH FamilySync is a family app. Whoever creates the family or joins it through an invitation or a join code has their own account. People without their own device, such as younger children or grandparents without a phone, can be added to the family by a member with a name, a colour and, if you like, a photo (section 2.2); they get no account, cannot sign in and receive no notifications. You can enter further information about them in events, occasions, the family tree or emergency contacts (sections 2.2 and 2.6). You are responsible for these entries and confirm that you are entitled to make them, for example as a parent. The person concerned or their parents or guardians can ask us at any time to delete this information (section 11). Such an entry can only be connected with their own account (section 2.9) once the person meets the age limits below.
A minimum age of 13 years applies to the
independent registration of one's own account. Since the
age of consent relevant under Art. 8 GDPR is up to
16 years in the EU depending on the member state, persons under
16 years of age may create their own account only with the consent or
authorisation of their parents or guardians (in Switzerland, the Swiss FADP (revDSG) or
the capacity of judgement applies). When registering with an email address, we ask for
the date of birth as a mandatory field and store it in a protected area of your account that only you can
read (section 2.1, with the exception mentioned there); accounts for those under 13 years of age are not permitted, and we point out
to persons under 16 years of age that the consent of their parents or guardians is
required. In addition, you confirm that you are at least 13 years old; we store this
confirmation with a timestamp in the account record (ageConfirmed). When
signing in with Google or Apple, we ask for the date of birth right after the first
sign-in; the same age limits and the same confirmation apply. Accounts created before
that are asked once the next time the app starts. This applies in the web app and in
the apps for iOS and Android from version 1.27.0.
Location sharing: Each person gives consent (section 2.13) themselves, with their own account; sharing cannot be turned on from the account of their parents or other members. For persons under 16 years of age, the same applies as for their own account: depending on the country, the consent of their parents or guardians is also required.
If we become aware that an account has been created contrary to this age limit and without parental consent, we will block the account and delete the associated data. Please send reports of this to datenschutz@jh-familysync.app.
10. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy when the legal situation or our service changes. The version available at the time of your use applies in each case. In the event of material changes, we will additionally inform you in the app or by email.
11. Contact
For questions about data protection, the exercise of your rights or the deletion of your account, please contact:
JH Virtuell KollektivgesellschaftEmail: datenschutz@jh-familysync.app
From the EU, you can also contact our representative in the EU (section 1.1). For all other matters, such as questions about the app or your subscription, you can reach us at support@jh-familysync.app.