Privacy
We can’t sell what we can’t see
Privacy here isn’t a policy promise — it’s the architecture. There’s no account and no readable data on the server, so there’s nothing to mine, sell, or leak.
What the server never sees
- Your events or any content
- Names of people or spaces
- Who belongs to a space
- Your recovery phrase or any key
- An email address or password (there are none)
The two exceptions, named
A family calendar asks for two things a purely device-to-device app never does, and both are worth stating outright rather than leaving in a footnote.
- Reminders tell the server when to wake you. It holds a time and an opaque id — never what the reminder is for — and the wake-up it sends carries no content at all. Your device decrypts and writes the notification.
- Emailed invites leave the encryption. An email cannot be end-to-end encrypted to someone who holds no key, so an invite is plaintext and passes briefly through the server’s outbox. It is off until a family turns it on, and off for every person without an address saved.
Start using Family Manager
No sign-up, no email, no password. Open it and go — your data is encrypted before it leaves your device.