Family Assistant
Family Assistant Privacy Policy
Effective date: July 31, 2026
Family Assistant is a household organization app operated by 2xWD. It helps household members coordinate groceries, stores, tasks, events, reminders, notes, memories, member information, and household activity.
This Privacy Policy explains what information Family Assistant processes, why it is processed, when it is shared, and the choices available to you.
1. Operator and Contact
Family Assistant is operated by 2xWD.
For privacy, support, or account-deletion questions, contact familyassistant.app@gmail.com.
2. Account and Sign-In Information
Family Assistant uses Firebase Authentication for signed-in accounts. Sign in with Apple is used on iOS, and Google Sign-In is used on Android.
When you sign in, Family Assistant receives or processes account information from the applicable sign-in provider and Firebase, including:
- a Firebase user ID;
- an Apple or Google provider identifier;
- your email address, including an Apple private relay address when you choose that option;
- your display name, when provided;
- a profile photo URL, when provided by the sign-in service; and
- authentication tokens and session information needed to sign you in securely.
Family Assistant uses this information to authenticate you, connect your account to the correct household and household member, maintain your session, recover household access, and protect sensitive actions such as account deletion. Sign-in credentials and provider tokens are not shared with other household members.
3. Household Profile and Membership Information
Family Assistant stores information needed to create, join, and manage shared households, including:
- household name and household identifier;
- household owner user ID;
- household plan and entitlement status;
- household members and member names;
- owner or member roles;
- member colors;
- account-to-member links;
- household invite and invite-reservation information;
- membership records used to find households connected to an account; and
- household-access and recovery notices.
Household owners and members can see shared membership information needed to use the household. Some household-management actions are restricted to the owner.
4. Shared Household Content
Family Assistant stores shared household content created, edited, completed, or deleted by household members, including:
- groceries, quantities, categories, and stores;
- tasks, assignments, and completion information;
- Family Assistant events and event details;
- reminders;
- notes and memories;
- member information; and
- household activity.
This content can include names, titles, descriptions, facts, dates, times, locations, quantities, categories, recurrence information, completion or cancellation status, assignment information, creator information, and other details entered by household members.
Shared household content is available to the members of that household. Do not add information to a shared household unless you are comfortable with the other household members seeing it.
5. Notes, Memories, and Sensitive Information
Notes and memories can contain household facts, preferences, routines, important dates, relationship details, school or work information, pet information, travel information, and other facts entered by household members. A user can also voluntarily enter sensitive information, including health or medical information.
Family Assistant does not require users to enter health, medical, or other sensitive information. If you enter such information, it is treated as household content and can be visible to the other members of the household. It can also be included in relevant Smart AI context when that processing is necessary for your request and you have given the separate OpenAI text-and-context permission described below.
6. Calendar Information
Family Assistant events are stored as shared household content in Cloud Firestore.
Calendar integration differs by platform:
- On iOS, Family Assistant can request Apple Calendar permission and read calendar sources and events from the device so they can be displayed in the app. Native Apple Calendar events remain private to the user and device by default. They become shared household content only when the user takes an action that creates or imports a Family Assistant event. If calendar mirroring is enabled, Family Assistant can create, update, or delete a corresponding event in Apple Calendar. Apple Calendar connection and mirror metadata are stored locally on the device, while per-user sync status for a shared Family Assistant event can be stored with that event.
- On Android, Family Assistant can request Google Calendar read-only access to list selected calendars and events. If the user separately enables write access, Family Assistant can create, update, or delete events in a writable Google Calendar. Google Calendar connection settings, granted-scope information, selected calendar identifiers, and write-status metadata are stored locally on the device. Per-user sync status for a shared Family Assistant event can be stored with that event.
Private native calendar events are not included in Smart AI household context. Smart AI calendar context is limited to relevant Family Assistant events stored for the household.
7. Voice Recordings and Transcription
Voice transcription is available to signed-in cloud households. Before recording begins, Family Assistant asks for separate permission to send recorded audio to OpenAI for transcription. Operating-system microphone permission is also required, but microphone permission does not replace the OpenAI voice permission.
When you choose to use voice transcription:
- the app creates a temporary audio recording on your device;
- the app sends the audio, duration, language, MIME type, household identifier, and Firebase authentication information to a Firebase Cloud Function;
- the Firebase Cloud Function verifies your identity, household access, permission, and available usage allowance;
- the Firebase Cloud Function sends the audio file, language, transcription model, and a transcription instruction to OpenAI; and
- OpenAI returns transcript text to Family Assistant.
The Firebase authentication token, Firebase user ID, household ID, plan, device identifier, and purchase information are not included in the OpenAI transcription request body.
Family Assistant does not intentionally store the original voice audio in Cloud Firestore. The temporary local recording is deleted after successful processing, failure, cancellation, or an abandoned recording session. The Firebase Cloud Function does not save the original audio or transcript as an AI conversation. A failed OpenAI request can be retried by the OpenAI service client and can retransmit the same audio.
The returned transcript is placed into the assistant input. It is not submitted automatically. If you submit it, it is handled like typed text. It can become ordinary shared household content if you use it to create or update a grocery, task, event, reminder, note, or memory.
If you decline or withdraw the OpenAI voice permission, Family Assistant will not start future voice recordings for transcription or send future audio to OpenAI. You can continue typing and using deterministic features.
8. Smart AI, Parser-First Processing, and OpenAI Permission
Family Assistant uses its parser, local knowledge, and deterministic business rules before using Smart AI. Clear supported requests are handled without OpenAI whenever the parser and built-in rules can resolve them reliably. Declining OpenAI permission does not disable parser-based or deterministic groceries, tasks, reminders, events, memories, or other core household functionality.
Smart AI is used only for supported requests that need AI-assisted interpretation, answers, briefings, suggestions, contextual help, or clarification. Before Family Assistant sends a Smart AI request to OpenAI, it asks for explicit permission to send text and relevant household context. This permission is separate from the permission for voice transcription.
For a permitted Smart AI request, Family Assistant sends the request to a Firebase Cloud Function. The server uses account and household identifiers to authenticate the request, verify household membership and allowance, and select relevant context. OpenAI can receive:
- the typed request or a transcript you choose to submit;
- at most one recent clarification exchange consisting of the original request, Family Assistant's question, and your answer;
- language, time zone, and the date or time needed to understand the request;
- relevant household member names;
- relevant grocery names and quantities;
- relevant task titles and assignee names;
- relevant Family Assistant event titles, dates, and times; and
- relevant memory or note text, subject names, and categories.
Information entered by or about another household member can be included when it is relevant to the household request. Family Assistant limits context by request type, field allowlists, item limits, and a context-size limit. Authentication tokens, provider OAuth tokens, purchase data, device identifiers, account email addresses, Firebase user IDs, household IDs, raw database paths, and raw database document IDs are not intended to be included in the OpenAI text-and-context payload.
Family Assistant does not keep an AI chat-history database. An immediate clarification can be held temporarily so you can answer it. If an AI-assisted action is accepted, the resulting grocery, task, event, reminder, note, or memory is stored as ordinary household content rather than as a separate AI conversation.
Family Assistant requests that OpenAI not store response state for Smart AI text requests. OpenAI processes text, context, and audio under its applicable API terms and the data controls configured for the OpenAI project used by 2xWD.
You can review or withdraw each OpenAI permission separately in the app at Household β AI data sharing. Under AI assistance or Voice audio, select Withdraw. Withdrawal stops future transmissions for that permission after the update is received. It does not undo processing already completed, remove ordinary household content created through an accepted action, or delete other household data. If the disclosure version changes, Family Assistant requires you to review and accept the updated disclosure before OpenAI processing resumes.
9. Usage Analytics and Operational Data
Family Assistant maintains household usage information needed to apply plan allowances, including the monthly period, voice-transcription count and seconds, Smart AI request count, reset times, and remaining boost credits.
Family Assistant also records linked daily product-interaction counts for features such as Smart AI, voice transcription, store actions, task actions, calendar actions, reminders, memories, assistant actions, and upgrade-screen interactions. These daily records can include the local date, time zone and offset, platform, app version, app build, visible plan, and feature-access status. They are used to understand feature use and improve app reliability and functionality.
Firebase Cloud Functions and related services can record limited operational metadata for reliability, security, abuse prevention, billing validation, and troubleshooting. This can include request IDs, user or household identifiers, plan, feature outcome, consent or quota outcome, model name, timing, error codes, notification-delivery status, and purchase-validation status. Family Assistant does not intentionally include original voice audio or full household context in its standard operational log entries.
Family Assistant does not include a third-party advertising SDK, cross-app tracking SDK, or a crash-reporting SDK.
10. Monthly Allowances and Persistent Boosts
Allowances apply to the household:
- Free supports 2 connected devices, 10 voice transcriptions per month, and 5 Smart AI requests per month.
- Premium supports 4 connected devices, 250 voice transcriptions per month, and 125 Smart AI requests per month.
- Family Pro supports 8 connected devices, 1,000 voice transcriptions per month, and 500 Smart AI requests per month.
Monthly allowances reset for the new monthly period and do not roll over.
One-time boosts add persistent household credits:
- Small Boost grants 50 voice credits and 20 Smart AI credits.
- Large Boost grants 110 voice credits and 45 Smart AI credits.
Boost credits remain until used. The included monthly allowance is consumed before boost credits. Boosts belong to the household selected for the verified purchase and cannot be redirected to another household. They do not unlock Premium or Family Pro features and do not increase the household device limit.
11. Connected Devices and Push Notifications
A connected device is one Family Assistant app installation registered to a household. Each installation creates a random installation secret that is kept in secure local storage on the device. The server stores a one-way representation of that secret so the original secret cannot be recovered from the server record.
A connected-device record can include:
- the one-way installation identifier;
- household and linked member identifiers;
- the user ID that registered the installation;
- platform;
- device label or model name;
- app version;
- Expo push token;
- notification-enabled status;
- creation, last-active, and update times; and
- record and migration information needed to maintain device access.
The household owner can view and remove all installations connected to that household. A member can view the device list and remove installations registered by that member's account, but cannot remove another member's installation. Removing an installation ends its household access but does not delete its account or household membership. Device management is available from the Manage connected devices control in the Household area.
If notifications are enabled, Family Assistant uses Expo Notifications, Expo Push Service, and Firebase Cloud Functions to deliver household and reminder notifications. Notification content can include household activity such as task assignments, events, memories, grocery or store changes, and reminders. Expo and the platform notification services receive the push token and notification content needed for delivery.
Notification handling combines operating-system permission, a local app preference, and the server device record. Turning notifications off in the app or operating-system settings stops delivery as applicable. The Expo push token can remain in the device record with notifications marked disabled so notifications can be enabled again. Invalid or stale tokens can be disabled after delivery errors.
12. Subscriptions, Purchases, and Recovery
Apple processes App Store payments on iOS, and Google processes Google Play payments on Android. 2xWD does not receive your full payment-card details.
Family Assistant receives and stores the minimum purchase and entitlement information needed to verify a purchase, apply household access or credits, prevent duplicate grants, process renewals, refunds or revocations, recover interrupted transactions, and reconcile store status. Depending on the platform and transaction, this can include:
- store and environment;
- product and plan identifiers;
- transaction or subscription identifiers and one-way hashes;
- purchase token and package or app identifiers needed for Google validation;
- purchaser user and household binding;
- subscription status, renewal state, billing period, expiration, grace-period, retry, hold, cancellation, refund, and revocation information;
- validation, synchronization, and entitlement timestamps; and
- boost credit-grant and recovery records.
Family Assistant uses server-side validation and idempotency controls so the same verified transaction does not grant an entitlement or boost more than once.
Subscription restoration or synchronization sends an App Store or Google Play purchase for server verification. An existing verified subscription remains bound to its applicable household and is not silently granted to a different household. Small Boost and Large Boost are consumable purchases, not subscriptions, and are not restored as subscriptions. If a consumable purchase is interrupted, Family Assistant can keep limited local recovery information and retry completion for the original household without granting the boost twice.
Deleting a Family Assistant account does not automatically cancel an App Store or Google Play subscription. You must separately manage or cancel the subscription through the store that processed it.
13. Local Device Data
Family Assistant stores information locally when needed to run the app. Depending on the features you use, this can include:
- authentication session state;
- a local or guest household and workspace identifiers;
- the secure installation secret;
- notification preferences and prompt state;
- Apple Calendar or Google Calendar connection and sync metadata;
- pending account-deletion recovery state;
- pending consumable-purchase recovery state;
- assistant guide and product-interaction counts awaiting synchronization;
- app language and interface state; and
- temporary voice audio and transcript input state.
Local-only or guest household data stays on the device unless you choose to save it to a cloud household or use a feature that sends it to a service described in this policy. Local data generally remains until you clear app data, delete the app, replace it through normal app operation, or complete an account-deletion cleanup. Some secure operating-system storage can follow the operating system's own backup or keychain behavior.
14. How Family Assistant Uses Information
Family Assistant uses information to:
- authenticate users and maintain account security;
- create, join, recover, and manage households;
- connect accounts, members, households, and installations;
- synchronize household content across signed-in devices;
- display and manage groceries, stores, tasks, events, reminders, notes, memories, members, and activity;
- provide calendar integrations requested by the user;
- process deterministic assistant requests;
- provide voice transcription and Smart AI after the applicable OpenAI permission is given;
- enforce monthly allowances, persistent boost balances, feature access, and device limits;
- validate purchases, maintain entitlements, prevent duplicate grants, and support transaction recovery;
- send requested push notifications;
- measure linked product interactions and improve functionality;
- diagnose errors and maintain reliability;
- prevent fraud, abuse, and unauthorized access;
- complete account deletion; and
- respond to privacy, support, and account-deletion messages.
15. What Is Shared With Household Members
Members of the same household can access the household name, member names and roles, shared groceries and stores, tasks and assignments, Family Assistant events, reminders, notes, memories, activity, and creator, assignee, completion, or cancellation details stored with shared items.
Private sign-in credentials, authentication tokens, purchase tokens, the local installation secret, and private native calendar events are not shared with other household members through Family Assistant. Device-management information is shown only as needed to manage household installations, and removal authority depends on whether the user is the household owner or the user who registered the installation.
16. Service Providers and Other Recipients
Family Assistant uses the following providers as applicable:
- Firebase Authentication for account authentication;
- Cloud Firestore for cloud household, account, entitlement, device, consent, and usage data;
- Firebase Cloud Functions for server-side processing, account deletion, device registration, notifications, billing verification, Smart AI, and voice transcription;
- Expo Notifications and Expo Push Service for push notification delivery;
- Apple for Sign in with Apple, Apple Calendar APIs, App Store payments, and Apple platform notification delivery;
- Google for Google Sign-In, Google Calendar APIs, Google Play payments, Firebase services, and Android platform notification delivery; and
- OpenAI for permitted Smart AI text-and-context processing and permitted voice transcription.
These providers receive only the information needed for the applicable service. They process information under their own terms, contractual obligations, security controls, and retention rules.
2xWD requires service providers that process personal information on its behalf to protect that information consistently with their applicable contractual obligations, applicable law, and the protections described in this Privacy Policy.
If you contact familyassistant.app@gmail.com, 2xWD receives your email address, message, and any information you choose to include so it can respond to your request.
17. Selling, Advertising, and Cross-App Tracking
Family Assistant does not sell personal information. Family Assistant does not use household content for advertising. Family Assistant does not conduct cross-app tracking.
Information is used for app functionality, household sharing, requested integrations, subscriptions and boosts, notifications, analytics, reliability, security, support, and the other purposes described in this policy.
18. Retention by Data Category
Family Assistant retains information according to its purpose and category:
- Account and authentication information is retained while the account exists and is removed from Family Assistant account storage when account deletion completes, subject to the minimized billing and short-lived deletion records described below. Apple or Google can retain provider-side records under their own terms.
- Household membership records are retained while the account remains a member. When a member deletes an account, that account's memberships, linked member profiles, and registered device records are removed from households owned by others.
- Shared household content is retained until it is deleted through Family Assistant or the owning household is deleted. Shared content can remain after an ordinary member deletes an account because the content belongs to the shared household.
- A household owned by a deleting account and its household-scoped groceries, stores, tasks, events, reminders, notes, memories, members, activity, invites, devices, usage balances, and entitlement projection are permanently deleted during successful owner-account deletion.
- OpenAI consent records are retained with the user account, including grant or withdrawal timestamps and disclosure version, and are deleted with the user account.
- Temporary voice audio is deleted locally after processing, failure, cancellation, or abandonment and is not intentionally stored in Cloud Firestore. The Firebase Cloud Function does not keep a voice-audio or AI-conversation archive. OpenAI applies its API terms and configured data controls to information it processes.
- Calendar connection metadata remains locally until it is cleared through disconnect, account-deletion cleanup, app-data clearing, or app deletion. Family Assistant events follow the shared-household retention rule.
- Connected-device and push-token records remain while the installation is connected or until the installation, linked member, account, or household is removed. A push token can remain in a disabled device record to support later re-enablement.
- Monthly allowance counters are retained with the household. Monthly usage resets for a new period and unused monthly allowance does not roll over. Persistent boost balances remain with the household until used or until the household is deleted.
- Linked daily product-interaction records remain with the account until account deletion. Pending local daily counts remain until synchronized or cleared through account-deletion cleanup or app-data clearing.
- Purchase, transaction, subscription, entitlement, credit-grant, and recovery information is retained as reasonably necessary to validate purchases, preserve entitlements, prevent duplicate grants, process refunds or revocations, recover purchases, reconcile store status, and meet security or legal obligations. When an account and owned household are deleted, Family Assistant minimizes retained billing records by removing or replacing direct user, household, and transaction identifiers where possible while preserving the verification and idempotency information still required.
- A completed account-deletion receipt can be retained for 7 days so the app can confirm a completed request. Account- and household-deletion tombstones can be retained for 30 days to prevent stale writes and support safe recovery. They expire after those periods.
- Operational service logs are retained according to the configured retention of Firebase, Google Cloud, Expo, Apple, Google, and OpenAI, as applicable.
- Support emails are retained as long as reasonably necessary to answer the request, maintain a support record, protect the service, and comply with legal obligations.
19. Account Deletion
You can delete your Family Assistant account in the app at Household β Danger zone β Delete account. The app shows the effect on memberships and any owned households and requires confirmation. You can request deletion help at https://www.1minutehabit.com/family-assistant/account-deletion-support or by emailing familyassistant.app@gmail.com if you cannot access the app. Identity verification can be required. Sending an email does not automatically delete the account.
When a household member who does not own the household deletes an account:
- the Firebase Authentication account and Family Assistant user profile are deleted;
- the account is removed from every joined household;
- linked household membership, member, and device records are deleted; and
- account-linked analytics, consent, calendar connection metadata, notification state, and other local account state are cleared as part of the deletion flow.
Shared content owned by another household can remain for its remaining members, including groceries, stores, tasks, events, reminders, notes, memories, member-related history, and activity.
When a household owner deletes an account:
- every household owned by that account is permanently deleted;
- all household-scoped information associated with those households is permanently deleted;
- all other members lose access to those households;
- the deleting account is also removed from households owned by other people; and
- ownership is not transferred during deletion.
For an account authenticated with Sign in with Apple, successful account deletion first revokes the applicable Sign in with Apple authorization. If revocation cannot be completed, deletion does not report success and can require retry or reauthentication.
Account deletion does not automatically cancel an App Store or Google Play subscription. Store subscriptions must be managed or canceled separately in App Store or Google Play.
Account deletion cannot be undone after it completes.
20. Your Choices and Controls
You can:
- decline OpenAI text-and-context permission and continue using parser-based and deterministic features;
- decline OpenAI voice permission and continue typing requests;
- withdraw either OpenAI permission separately at
Household β AI data sharing; - manage operating-system microphone, calendar, and notification permissions in device settings;
- enable or disable supported calendar connections and write access;
- manage connected installations according to your owner or member role;
- remove or edit shared household content when the app and your household role allow it;
- manage or cancel subscriptions in App Store or Google Play;
- delete your account through
Household β Danger zone β Delete account; and - contact familyassistant.app@gmail.com to ask about access, correction, deletion, or other privacy questions.
Available privacy rights can vary by where you live. 2xWD can request identity verification before acting on a request and can retain information where required for security, fraud prevention, legal compliance, or the rights of other household members.
21. Security
Family Assistant uses Firebase Authentication, Firestore Security Rules, Firebase Cloud Functions, server-side membership and ownership checks, secure local storage for the installation secret, one-way identifiers, transaction validation, and idempotency controls to help protect information. Firestore access is limited to authenticated household members, with owner-only controls for certain actions.
No app, network, or storage system can be guaranteed completely secure. Protect your device, Apple or Google account, email account, and household invite information. Do not share household access with people who should not see household content.
22. Accuracy and Availability
AI interpretation, voice transcription, reminders, notifications, calendar integrations, purchase recovery, and assistant actions can be delayed, unavailable, misunderstood, incomplete, or incorrect. Review important household information and do not rely on Family Assistant for emergencies or critical safety decisions.
23. Changes to This Policy
2xWD can update this Privacy Policy when Family Assistant features, providers, legal obligations, or data practices change. The effective date at the top identifies the policy version.
24. Contact
For privacy, support, or account-deletion questions, contact: