Who We Are
FamilyBrain is a UK-based family assistant product that helps households organise their calendar events, store important documents, capture memories, and manage daily life — all through WhatsApp. FamilyBrain is operated as a private product and is not currently a registered company; the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 is the FamilyBrain service operator.
For any privacy-related enquiries, please contact us at privacy@familybrain.co.uk.
FamilyBrain is for adults aged 18 and over only.
Children are not users of this service and do not have accounts. By using FamilyBrain you confirm that you are 18 years of age or older. If you are under 18, please do not use this service. See Section 9 for how we handle information about children stored on behalf of adult users.
This policy applies to all users of the FamilyBrain WhatsApp bot, the FamilyBrain web calendar, and any associated web pages at familybrain.co.uk.
Data We Collect
We collect only the data necessary to provide the FamilyBrain service. The table below describes each category of data we process.
| Category | What it includes | Source |
|---|---|---|
| WhatsApp messages | Text messages, voice notes (transcribed), and any captions you send to the FamilyBrain bot number. | You, via Meta WhatsApp Cloud API |
| Images & photos | Photos you send to the bot (e.g. photos of documents, receipts, letters). Text is extracted via OCR, and both the extracted text and the original image file are securely stored. | You, via Meta WhatsApp Cloud API |
| PDF documents | PDF files you send to the bot (e.g. insurance documents, school letters). Both the extracted text content and the original raw PDF file are securely stored. | You, via Meta WhatsApp Cloud API |
| Calendar events | Event name, date, time, location, and the family member the event relates to. Captured from messages or synced from Google Calendar if you connect it. | You, or Google Calendar (if connected) |
| Family member details | Names and WhatsApp phone numbers of family members you register with FamilyBrain. | You, during onboarding |
| Memories & notes | Structured summaries of information you share with the bot (e.g. medical details, vehicle information, financial references). Stored as text with AI-generated metadata tags. | You, via WhatsApp messages |
| Google Calendar tokens | OAuth refresh tokens that allow FamilyBrain to read and write to your Google Calendar on your behalf, if you choose to connect it. | Google, via OAuth 2.0 consent |
| Session data | Temporary in-memory conversation history used to maintain context within a single session. This is not persisted to the database. | Automatically, during your session |
| Usage logs | Server-side application logs (e.g. message received, command processed). These contain phone numbers and timestamps but no message content. | Automatically, by the server |
We do not collect: payment card details, government ID numbers (unless you explicitly send them), biometric data, or browsing history. We do not use tracking pixels, advertising cookies, or any third-party analytics on our web pages.
How We Use Your Data
We use your data solely to provide and improve the FamilyBrain service. We do not sell your data, share it with advertisers, or use it for any purpose unrelated to the service you have requested.
AI Processing (OpenAI)
When you send a message to FamilyBrain, the text content is sent to OpenAI's API to extract structured information (such as event details, document type, and action items), generate a semantic embedding for search, and compose a helpful reply. OpenAI processes this data as a data processor acting on our instructions. Your messages are not used to train OpenAI's models under our API agreement.
Calendar Synchronisation (Google Calendar API)
If you choose to connect your Google Calendar, FamilyBrain will read your upcoming events to provide reminders and context, and will write new events when you ask the bot to add something to your calendar. This connection is entirely optional and can be revoked at any time from your Google Account settings at myaccount.google.com/permissions.
Document Storage (Supabase / PostgreSQL)
Extracted text from your messages, documents, and photos is stored in a PostgreSQL database hosted by Supabase. This allows FamilyBrain to answer questions about information you have previously shared. All data is stored in the European Union (Ireland region) and is encrypted at rest and in transit.
WhatsApp Messaging (Meta Platforms, Inc.)
All WhatsApp messages are sent and received via the Meta WhatsApp Cloud API. Meta Platforms, Inc. processes your phone number and message content in order to route messages to and from the FamilyBrain bot. Meta's data processing is governed by their Data Processing Addendum.
Morning Briefings & Alerts
FamilyBrain may send you proactive WhatsApp messages, such as a morning summary of the day's events or an alert about an upcoming document expiry. These are generated from data you have already stored and are sent only to registered family members.
Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases for processing your personal data:
| Processing activity | Legal basis |
|---|---|
| Storing and retrieving your messages, memories, and documents | Contract — necessary to provide the service you have signed up for (Article 6(1)(b) UK GDPR) |
| Sending proactive alerts and briefings | Legitimate interests — to provide the core value of the service (Article 6(1)(f) UK GDPR). You can opt out at any time. |
| Google Calendar synchronisation | Consent — you explicitly authorise this connection via Google's OAuth consent screen (Article 6(1)(a) UK GDPR) |
| Server logs and security monitoring | Legitimate interests — to maintain the security and integrity of the service (Article 6(1)(f) UK GDPR) |
Data Processors We Use
We use a small number of carefully selected third-party data processors. Each processor is bound by a Data Processing Agreement (DPA) and processes your data only on our instructions.
Processes message text to extract structured data and generate replies. Data is sent via the OpenAI API and is not used for model training under our API agreement.
OpenAI Privacy Policy ↗Routes WhatsApp messages between users and the FamilyBrain bot via the WhatsApp Cloud API. Processes phone numbers and message content for delivery purposes only.
Meta Data Policy ↗Hosts the PostgreSQL database where your memories, events, and documents are stored. Data is stored in the EU (Ireland). Supabase is SOC 2 Type II certified.
Supabase Privacy Policy ↗Used only if you choose to connect your Google Calendar. Allows FamilyBrain to read and write calendar events on your behalf. Connection is revocable at any time.
Google Privacy Policy ↗Hosts the FamilyBrain application server. Application logs may contain phone numbers and timestamps but not message content beyond what is needed for debugging.
Railway Privacy Policy ↗When you send a message to FamilyBrain, the text content passes through Meta's infrastructure (WhatsApp Cloud API) and OpenAI's API before being stored in Supabase. By using FamilyBrain, you acknowledge this processing chain. Please do not send highly sensitive information such as passwords, full bank account details, or National Insurance numbers unless you are comfortable with this processing.
Data Retention
We keep your data for as long as your FamilyBrain account is active. We do not automatically delete your data after a fixed period of time — your memories, calendar events, documents, and family information stay in FamilyBrain for as long as you want them there.
You are in control. You can delete your personal data at any time using the /delete-my-data command, or request a full family data wipe using the /delete-all-family-data command. See Section 8 for full details of our tiered deletion process.
No automatic deletions. FamilyBrain does not run scheduled jobs that delete your data based on age or time. Nothing is removed without your explicit instruction. Your data is yours, and it stays until you choose to remove it.
There is one narrow exception to this principle:
- Google Calendar tokens — if you disconnect your Google Calendar (either from within FamilyBrain or via your Google Account settings), the OAuth access token is deleted immediately and automatically, as it is no longer needed.
Note on files: Raw images, PDFs, and voice notes are stored securely alongside their extracted text or transcriptions. They are subject to the same retention rules as all other data and are not automatically deleted after processing.
If you close your account or ask us to delete your data by email, we will complete the deletion within 30 days and confirm once it is done.
Your Rights Under UK GDPR
As a data subject under the UK GDPR and the Data Protection Act 2018, you have the following rights. You can exercise any of these rights by contacting us at privacy@familybrain.co.uk or by using the in-bot commands described in Section 8.
You can request a copy of all personal data we hold about you and your family (Article 15 UK GDPR). We will respond within one calendar month.
You can request that we delete all your personal data ("the right to be forgotten") at any time (Article 17 UK GDPR). See Section 8 for how to do this instantly via WhatsApp.
If any stored information is inaccurate, you can ask us to correct it (Article 16 UK GDPR). You can also correct individual memories directly via the bot using the correct memory N: [new text] command.
You can request a machine-readable export of your data (Article 20 UK GDPR). Contact us at privacy@familybrain.co.uk and we will provide a JSON export within one month.
You can ask us to pause processing your data while a complaint or correction request is being resolved (Article 18 UK GDPR).
You can object to processing based on legitimate interests (Article 21 UK GDPR), such as proactive briefings and alerts. Contact us to opt out of any specific processing activity.
Where processing is based on consent (e.g. Google Calendar sync), you can withdraw consent at any time without affecting the lawfulness of prior processing.
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
We will respond to all rights requests within one calendar month. In complex cases we may extend this by a further two months, in which case we will notify you within the first month.
Requesting Data Deletion
Because FamilyBrain is a shared household tool, we use a tiered deletion system to ensure you can always delete your own data, while preventing one person from accidentally deleting the entire family's shared history without consensus. Deletion is permanent and cannot be undone.
Tier 1: Personal Deletion (Instant)
To delete only the data that you submitted, send the following command to the bot:
/delete-my-data
The bot will ask you to confirm by replying DELETE. Once confirmed, all memories, documents, and calendar events submitted from your phone number will be permanently deleted immediately. This does not require approval from other family members.
Tier 2: Full Family Wipe (Consensus Required)
To delete all data for the entire family (including data submitted by other members), send:
/delete-all-family-data
Because this affects everyone, it requires consensus. When you send this command, the bot will message all registered adult members of your family asking them to confirm. All members must reply YES within 48 hours. Once the final member confirms, the entire family's data is permanently deleted, including:
- All stored memories, notes, and document extracts
- All raw PDF, image, and audio files
- All calendar events
- All briefing and notification logs
- Any generated emergency PDF files
If 48 hours pass without full consensus, the request expires and no data is deleted.
Option 3: Email request
You can also send an email to privacy@familybrain.co.uk with the subject line "Data Deletion Request" and include the WhatsApp phone number(s) associated with your family. We will complete the deletion within 30 days and confirm by email.
Note on Google Calendar: Deleting your FamilyBrain data removes our copy of your calendar events. It does not delete events from your Google Calendar itself. To revoke FamilyBrain's access to your Google Calendar, visit myaccount.google.com/permissions and remove FamilyBrain from the connected apps list.
Children & the Adults-Only Policy
This service is for adults (18+) only. Children are not users of FamilyBrain.
Children do not have accounts, do not interact with the WhatsApp bot, and do not have access to any part of the FamilyBrain service. The UK Children's Code (Age Appropriate Design Code) does not apply to FamilyBrain because the service is not directed at children and takes no steps to attract child users.
Children as data subjects
Although children are not users of FamilyBrain, information about children may be stored as part of a family's data. For example, an adult user may store a child's name in a calendar event (such as a school sports day), a school letter, or a medical appointment. In these cases:
- The child is a data subject but not a user of the service.
- The adult account holder acts as the data controller in relation to their child's information, and FamilyBrain processes that information on the adult's behalf.
- Children's data stored in this way is subject to the same retention, deletion, and security rules as all other family data (see Section 6 and Section 8).
- Children's data is never shared with third parties beyond the data processors listed in Section 5, and is never used for advertising, profiling, or any purpose unrelated to providing the family assistant service.
Parental responsibility
By using FamilyBrain and storing information that relates to a child under the age of 18, the adult account holder confirms all of the following:
- They have parental responsibility for the child, or are otherwise legally authorised to store and process information about that child.
- They have considered whether it is appropriate to store the child's information in the service, and are satisfied that doing so is in the child's best interests.
- They understand that the child's information will be processed by the data processors listed in Section 5 (OpenAI, Meta Platforms, Inc., Supabase, Google Calendar API, Railway) as part of the normal operation of the service.
- They accept responsibility for ensuring that any information stored about a child is accurate and up to date.
No direct collection from children
FamilyBrain does not knowingly collect personal data directly from children. The service requires a WhatsApp account and active engagement with the bot; both of these require the user to be an adult. If we become aware that a child has accessed the service directly, we will take steps to remove their data and close their access.
Scope of the UK Children's Code
The UK Age Appropriate Design Code (Children's Code) applies to online services that are likely to be accessed by children. FamilyBrain is an adults-only service. We do not market to children, we do not design features to appeal to children, and we require users to confirm they are 18 or over at onboarding. Accordingly, the Children's Code does not apply to FamilyBrain. Should our service scope change in future, we will reassess this position and update this policy accordingly.
International Data Transfers
Some of our data processors are based outside the UK or process data in countries outside the UK. Where this occurs, we ensure that appropriate safeguards are in place as required by UK GDPR Chapter V.
| Processor | Location | Safeguard |
|---|---|---|
| OpenAI | United States | UK International Data Transfer Agreement (IDTA) / Standard Contractual Clauses (SCCs) |
| Meta Platforms, Inc. | United States (Meta Cloud infrastructure) | UK IDTA / SCCs; Meta Data Processing Addendum |
| Supabase | European Union (Ireland — AWS eu-west-1) | Adequacy decision (EU–UK adequacy); data does not leave the EU |
| Google (Calendar API) | United States / EU | UK IDTA / SCCs; Google Cloud DPA |
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the service, changes in applicable law, or feedback from users. When we make material changes, we will notify registered family members via WhatsApp at least 14 days before the changes take effect.
The "Last updated" date at the top of this page will always reflect the most recent revision. We encourage you to review this policy periodically. Continued use of FamilyBrain after the effective date of any changes constitutes your acceptance of the updated policy.
Previous versions of this policy are available on request by emailing privacy@familybrain.co.uk.
Contact & Complaints
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about how we handle your data, please contact us using the details below.
Privacy Contact
Email: privacy@familybrain.co.uk
We aim to respond to all privacy enquiries within 5 working days and to complete all rights requests within one calendar month.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
ico.org.uk/make-a-complaint | 0303 123 1113