1UpFam — Privacy Policy
Last updated: September 26, 2026
1UpFam (formerly Family Locator; "the app," "we," "us") is a private location-sharing app for members of a
family group to see each other on a map and message one another. This policy explains what
information the app collects, how it is used, and the choices you have. By using the app you
agree to this policy.
Current release status: New paid-plan signup is disabled. Existing
subscription status can still be checked with RevenueCat and the app stores for restoration,
account management, and accurate access records. Turning off new purchases does not cancel
an existing store subscription. Firebase App Check token collection and enforcement remain
disabled.
Who the app is for
1UpFam is designed to be set up and managed by a parent or guardian for use within a
single family group. If the app is used to share the location of a minor, the parent or
guardian is responsible for that child and consents on their behalf. Do not add a person to a
family group or share their location without their (or their guardian's) knowledge and
consent.
Information we collect
-
Account information — when you sign in with Google or Apple, we receive
your name and email address to identify your account and show your name to your family
group. If you use Apple's Hide My Email option, we receive Apple's private relay address
instead of your personal email address. Provisioned app-review accounts can use a
separate email and app-only password handled by Firebase Authentication. We do not
save that password in family profiles, chat, or app logs.
-
Location — your device's precise location, including in the background when
you grant "Always"/"Allow all the time" permission, so your family group can see where you
are. We also derive speed and heading from location. The one current point carries the
phone's reported uncertainty radius and how old the fix was when the server received it;
those values keep a delayed or coarse reading from replacing a newer, better point while
looking fresh. Travelling with them are a counter and a random identifier for the app
installation that sent the update. That identifier is generated on your device the first
time it reports, is not derived from any hardware or advertising ID, and is not shared with
anyone outside your family group; its only job is to let the server tell two phones apart,
so that if you carry a second device an older reading cannot overwrite a newer position.
Like the point itself, both are replaced by every update. Each accepted update overwrites
the prior point and metadata — the app does not keep a location trail. Location sharing can
be turned off at any time in the app's Settings.
-
Battery level and power state — your device's battery percentage, published
alongside your location and shown to your family group, so a pin that has stopped moving can
be told apart from a phone that is about to die. Two further facts about that same moment
travel with it: whether your device was connected to power, and whether battery saver was
switched on. Each is a single current value, overwritten by every update — no history of
when your phone was charging is kept, and none of these carry a location. When the level
falls to 15%, your device also writes a short
notice — your percentage and the time, nothing else — so the people in your household
(not the whole family group) get one notification that you are about to run out. It is sent
once per charge, is deleted automatically after 24 hours, and carries no location.
-
Saved places — locations you add (such as home, school, or work) so the app
can notify your household when a member arrives or leaves.
-
Meeting points — when you set a meeting point, the app stores the
coordinates you picked on the map, the short label you optionally type, your name, and the
time you set it. It is shown to everyone in your family group. There is only ever one at a
time — setting a new one replaces the old — and it is deleted automatically when its time
runs out, at most six hours later. It is never kept as a list of places your family has met.
-
Arrival and departure records — when you arrive at or leave a saved place,
the app stores the name of that place, whether you arrived or left, and the time it
happened. These are shown to your household in the Activity tab and are deleted
automatically after 90 days.
Older saved places that were created before household privacy scopes remain visible so
the Family Owner can remove them, but they do not register or send arrival/departure
alerts until they are removed and added again for a specific household.
-
Who looked you up — when a family member opens your profile or your pin,
the app records that they did and shows it to you. Deleted automatically after 30 days.
-
Legacy location requests — an older version of the app let a family
member ask your phone for a current location. While older installed versions remain in use,
the app stores who asked and when so your phone can answer and tell you who requested it.
There is only one pending request per person, and it is deleted automatically within six
hours. Current versions no longer offer a button for creating these requests.
-
Profile photo — an optional photo you choose or take, shown to your family
group. Your phone re-saves it before uploading, which removes the location, date and
camera details that cameras normally store inside an image file — so your profile photo
does not tell anyone where it was taken.
-
Messages — the text you send in Everyone chat to the family group, the
text you send in Household chat to your current household, legacy family-wide announcements,
and any emoji reaction you attach to a message (one of four, stored with your name,
removable by tapping it again). New app-wide announcements may be sent only by the app
administrator, shown as “Admin”, and are visible to every signed-in user,
including users without a family. Older family-only posts are not made app-wide.
Announcements expire after seven days and are deleted automatically
afterward; database cleanup typically completes within 24 hours of expiry.
-
Photos you send in chat — a photo you take or choose is shown to the
people in that conversation: your whole family group in Everyone chat, or only your
current household in Household chat. Your phone re-saves the photo before sending it,
which removes the location, date and camera details that cameras normally store inside
an image file — so a photo you send does not tell anyone where it was taken. Chat photos
opened through current versions require a current conversation-membership check. Older
photos created before this protection may remain accessible to someone who already has
their download link until those links are retired after compatible phones are verified. They are
deleted with the message they belong to, after 60 days.
-
Events — the title, date, and any note for events you add to the family's
Upcoming list (birthdays, weddings, graduations, and so on), shown to your family group
along with your name as the person who added it.
-
Weekly activity counts — running totals your own device keeps about
itself for the current week: distance travelled, top speed, how many times you arrived at
or left a saved place, a count per place, and the earliest time of day your device
detected you starting to move. That last one is a time only — minutes past
midnight, with no date and no place attached to it — and it is not recorded before 4am.
These are counts, not a history: no route or trail of where you travelled
is stored, and they reset each week. They are shown to your family group in the weekly
summary on the Activity tab. (The arrival and departure records described above are
separate from these, and are the only timestamped record the app keeps of where you have
been.)
-
Notification token — a push-notification identifier for each device signed
into your account so the app can send you chat and arrival/departure notifications. Tokens
are stored in an account-private record and are not visible to your family group.
To avoid duplicate alerts during retries, private notification delivery records also
store hashed account and device-token identifiers and delivery outcomes. These records
contain no message text or location and are deleted automatically after 90 days.
Delivery and recovery bookkeeping also keeps one private scan position
using a record identifier and its last-update time, so checks can reach every family.
That position is replaced as the check advances; it contains no coordinates and is not
a history of where anyone has been.
-
Your settings, and your device's time zone offset — your quiet hours, chat
notification preference, whether sharing is on or paused, and which household you belong
to. The time zone offset is stored so the notification service applies quiet hours in
your local time.
-
What your device is able to do — whether it has background location
permission and whether sharing is switched on, so the app can tell your family "only
updates while their app is open" rather than leaving them to guess from a frozen pin.
-
Who has asked to be told when you drive — if a family member turns on
trip alerts for you, a record is stored linking the two of you, and they get a notification
when your device detects you have set off or stopped driving. This is off unless
someone deliberately turns it on, and you can see everyone who has
on the Members list. The alerts say only that a journey started or ended: no route, no
speed, and no destination. The departure and arrival notices themselves are deleted
automatically after 24 hours.
-
When you ask for directions home — tapping "Directions Home" quietly
tells the people in your household that you asked, along with roughly how far
from home you were (a distance only — your household can already see your pin on the
map). At most one notice per hour, deleted automatically after 24 hours, and it ignores
quiet hours on purpose: it exists for the moment someone is lost.
-
Why your device last failed to report — a short reason such as "no
connection" or "no location from their phone", and the time it happened. Your family
group sees this so a gap in your updates has an explanation instead of being guessed at.
It is a single most-recent value, not a log: each one replaces the last,
it stops being shown after six hours, and it never includes where you were. Your own
device keeps a fuller version of this record for troubleshooting on your Settings screen;
only the reason and the time are shared.
Information kept on your phone
Unsent chat text is saved locally for up to seven days, separately for Everyone and your
current Household conversation. Drafts are not uploaded or sent automatically. Signing out,
deleting your account, or a confirmed loss of access clears the affected drafts on that
phone. You can also erase a draft by clearing its text. Your phone's own backup settings
may govern copies of its local app data.
Settings can prepare an app diagnostics report containing this phone's app, build and update
versions, permission and notification status, and recent classified errors. You see the exact
report before choosing to share it. It excludes names, coordinates, chat content, sign-in
details and other family members' records. Reports are not sent automatically; if you share
one, the recipient and service you choose control that copy.
Optional crash reports
Builds that include Firebase Crashlytics offer an optional crash-report setting. Sending is
off by default. If you turn it on, the next full app launch can send technical reports
already saved on this phone, and later launches can send newly saved reports. The native
crash library can keep reports on the phone even while sending is off. An app launch with
sending off requests deletion of saved reports instead of sending them.
Reports help us find crashes and recoverable app errors. They include stack traces, app,
build and update versions, technical device information, relevant app state, and random
installation identifiers generated by Firebase. We do not attach account names, email
addresses, family or household identifiers, coordinates, messages, photos, or activity
breadcrumbs. Reports captured through the app's JavaScript handlers replace free-text
errors and file paths with restricted technical fields. Errors before those handlers start
and native crashes use the native crash-library path.
These reports are visible to the app operator and Firebase, not your family group.
Turning sending off stops new app error captures and new send requests; an upload already
requested may finish. Fully close and reopen the app after it confirms the setting was
saved; if saving fails, retry before closing. Turning
it off does not erase reports already sent. Firebase keeps crash traces and associated
identifiers for 90 days before starting removal from its live and backup systems. This is
separate from the seven-day database recovery backups. We do not use crash information for
advertising or combine it with your family records to identify you. See
Firebase's privacy information.
How we use information
Information is used only to provide the app's features: showing family members on a map,
routing "directions home," sending arrival/departure and chat notifications, and displaying
names and photos within your family group, and diagnosing technical problems when you choose
to send a report. We do not sell your data, use it
for advertising, or track you across other apps or websites.
Who can see your information
Your location, name, photo, events, weekly activity counts, Everyone chat including any
photos sent there, and family-wide announcements are visible to other members of your
family group — the people who have your family's invite code and whom you have joined a
group with.
Household chat, its photos, its reactions, and its read receipts are
visible only to your current household. When you look up another
member, they are told that you did. Arrival and departure alerts for a saved place are sent
only to members of that place's household. Your information is not shared with other users
of the app outside your family group.
Service providers
The app relies on the following services to function. Optional services process information
only for the features described below; app integrity verification remains staged.
-
Google Firebase (Authentication, Firestore, Storage, Cloud Messaging) —
stores your account, location, profile photo, chat photos, and messages, and delivers
notifications. Optional Firebase Crashlytics reports are described above. See Google's Privacy Policy.
-
App administration records — Firebase stores the app administrator's
account identifier, the family identifier protected by a permanent complimentary grant,
and who changed the app-wide payment requirement and when. These records restrict
administrative controls and document changes; ordinary family members cannot change them.
-
Subscription information — when purchase status is checked, the plan's
product, store, status, and paid-through date are linked to the purchaser's app account
so one plan can cover the family group. Existing status can be synchronized even while
new purchases are disabled. We do not receive or store a card number or bank information.
Private synchronization records also keep the account's current family binding and
technical request counters so an older response cannot replace newer status or bind a
plan after the account has changed families.
Enhanced-radar access is recorded separately from base-plan access. If the store reports
a scheduled plan change, we retain the replacement product and effective date so the app
can explain when access and the renewal price will change.
-
Future app and device integrity signals (currently disabled) — the
current release does not collect or enforce Firebase App Check tokens. If a future release
enables App Check, it may verify that a request came from the authentic 1UpFam app
on a genuine device. The resulting short-lived security token would be used only to
prevent fraud, automated abuse, and unexpected service charges.
-
Apple (Sign in with Apple) — verifies the identity of iPhone users who
choose Apple sign-in. Apple's privacy choices, including Hide My Email, apply.
-
Expo push notification service — relays alerts for arrivals, chat, and
other family updates to your device. A lock-screen notification says only what
kind of update arrived — for example “New message”, “New
announcement” or “Someone arrived or left” — and carries no names, no
message text, no place, no battery level, and no event category;
the signed-in app fetches the current content after it opens.
-
Google Maps (Android) / Apple Maps (iOS) — renders the
map and processes location to display it.
-
Weather radar (optional) — when you turn on the weather radar layer on
the map, the app loads radar images from the National Weather Service's public map
service (NOAA), and on some devices from the Iowa Environmental Mesonet at Iowa State
University, which serves the same NOAA radar data. Near some radar sites the images
come instead from our own radar server, which we run on Amazon Web Services and which
draws the same public NOAA radar data. Like the map provider, whichever server is used
receives the map areas being requested,
which indicate the general area you are looking at, and your device's network address.
NOAA requests contain no family account identifiers. To authorize enhanced radar, our
Firebase service checks your signed-in account, current family membership, and plan access.
It issues a short-lived signed permission that the AWS radar server validates; this
permission contains no names, family identifiers, or member locations. We keep technical
request counters to limit abuse, not a history of the areas each family views.
Our radar server counts, per
radar site, how often the map is viewed near it: a total, with nothing about who asked.
The layer stays off unless you turn it on.
-
Subscription providers — RevenueCat, Apple App Store, and Google Play
process and validate subscription status. Apple or Google handles payment information;
RevenueCat tells the app whether a purchased plan is active. New paid-plan signup is
currently disabled, but restoration, store updates, and account cleanup can still use
these services for existing purchase records.
Data retention and deletion
We keep daily recovery backups of the database for up to seven days. These private copies
can contain the then-current location, account information and messages, including data
deleted from the live app after a backup was made. They are used only to recover from data
loss, are not available to family members, and never provide a location-history feature.
Before restoring data to active use, we must reconcile later account deletions and sharing
choices. Deleted photo objects also have a separate seven-day provider soft-delete window.
Database backups do not include photo files or sign-in accounts.
Your information is kept while you are a member of a family group. You can:
- Turn off location sharing at any time in Settings (this removes your live location).
- Remove your profile photo in Settings.
- Leave your family group, which removes your live location from it.
-
Records of who looked you up are deleted automatically after 30 days. Announcements
expire after seven days and are then deleted automatically, typically within 24 hours.
Directions-home notices are deleted after 24 hours, chat messages and any photo attached
to them after 60 days, arrival
and departure records after 90 days, meeting points when their time runs out (at most
six hours), and one-off events a year after they were added. This happens on its own —
you do not have to ask. Messages sent before this policy took effect are not deleted
automatically; they stay until you delete your account.
-
Delete your account and your data from inside the app, at any time:
Profile → Settings → Delete My Account. After you confirm and verify your identity,
the app confirms when the server accepts your request. Your active family card and location
are removed, and cleanup continues in resumable steps even if you close the app.
If acceptance could not be confirmed, reopen the account screen to check or retry.
It removes your
profile, your live location, your photo, the record of who looked you
up, your arrival and departure history, your family and household read receipts, pending
legacy location requests involving you, your emoji reactions, notification tokens, and
your sign-in account. If a private subscription link or RevenueCat customer record
exists, deletion removes those records too.
The private cleanup record includes your account creation time, taken from our sign-in
provider, so deletion can find older content without searching unrelated families.
It also records the deletion request time and progress so accepted requests can be
retried safely without keeping the app open. Pending recovery records stay until cleanup finishes.
While this runs, a server-only recovery marker stops old devices and delayed background
work from recreating the data. A server-only list of family identifiers previously linked
to the account lets the cleanup find content after a family has been left; both are removed
with the account, with a short-lived deletion tombstone retained for up to seven days so
delayed uploads or notifications can still be rejected.
-
A family group has one Family Owner. If the Owner deletes their account
without first handing ownership to another current member, the family group is dissolved
and its shared family and household data is deleted for everyone. The app explains this
in the deletion confirmation. Transferring ownership first preserves the group. Any store
billing remains with the purchaser unless they separately cancel it through Apple or Google.
-
Store billing: deleting your 1UpFam account does not cancel an
Apple or Google recurring subscription, even while new purchases in the app are disabled.
Cancel it from the app's Manage Subscription button or your store's subscription settings
before deleting the account to prevent a later renewal. Store transaction records remain subject to
Apple or Google's own legal and retention duties.
-
For an ordinary member, what deleting your account does not remove, stated plainly:
the text of chat messages you sent and the shared events you added stay because removing them would
leave conversations incomplete or remove information the family still relies on. Your
name is taken off them and they are shown as from or added by “Deleted member”.
Photos you sent in chat are different: they are deleted from our servers,
because a photograph of a person identifies them whether or not a name is attached to it.
We cannot reach copies already saved or screenshotted on other people's phones, and we do
not claim to.
Announcements expire after seven days and are then removed by automatic cleanup. Records of you
looking someone else up sit on that person's list rather than yours, so they are not
yours to delete — they are removed automatically within 30 days. Very old orphaned
subcollections whose family parent had already been deleted before the family-history
ledger was introduced may not be discoverable by Firestore; their retained rows remain
inaccessible without that parent and continue to follow the automatic retention periods
above where a TTL applies.
-
You can also request deletion by emailing us at the address below, or via
our account deletion page, if you cannot access the
app. We will action it within 30 days.
Security
Data is transmitted over encrypted connections and stored using Google Firebase's security
infrastructure. Access is restricted by security rules so that only members of your family
group can read your family's data. No method of transmission or storage is 100% secure, but we
take reasonable measures to protect your information.
Children's privacy
The app may be used to share a minor's location within a family group at the direction of a
parent or guardian, who is responsible for obtaining any necessary consent. We do not
knowingly collect information from children outside of this family-managed context. A parent or
guardian may review or request deletion of a child's information using the contact below.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last
updated" date above.
Contact
Questions or deletion requests:
mbwallace1390@gmail.com