1UpFam — Privacy Policy

Last updated: September 26, 2026

1UpFam (formerly Family Locator; "the app," "we," "us") is a private location-sharing app for members of a family group to see each other on a map and message one another. This policy explains what information the app collects, how it is used, and the choices you have. By using the app you agree to this policy.

Current release status: New paid-plan signup is disabled. Existing subscription status can still be checked with RevenueCat and the app stores for restoration, account management, and accurate access records. Turning off new purchases does not cancel an existing store subscription. Firebase App Check token collection and enforcement remain disabled.

Who the app is for

1UpFam is designed to be set up and managed by a parent or guardian for use within a single family group. If the app is used to share the location of a minor, the parent or guardian is responsible for that child and consents on their behalf. Do not add a person to a family group or share their location without their (or their guardian's) knowledge and consent.

Information we collect

Information kept on your phone

Unsent chat text is saved locally for up to seven days, separately for Everyone and your current Household conversation. Drafts are not uploaded or sent automatically. Signing out, deleting your account, or a confirmed loss of access clears the affected drafts on that phone. You can also erase a draft by clearing its text. Your phone's own backup settings may govern copies of its local app data.

Settings can prepare an app diagnostics report containing this phone's app, build and update versions, permission and notification status, and recent classified errors. You see the exact report before choosing to share it. It excludes names, coordinates, chat content, sign-in details and other family members' records. Reports are not sent automatically; if you share one, the recipient and service you choose control that copy.

Optional crash reports

Builds that include Firebase Crashlytics offer an optional crash-report setting. Sending is off by default. If you turn it on, the next full app launch can send technical reports already saved on this phone, and later launches can send newly saved reports. The native crash library can keep reports on the phone even while sending is off. An app launch with sending off requests deletion of saved reports instead of sending them.

Reports help us find crashes and recoverable app errors. They include stack traces, app, build and update versions, technical device information, relevant app state, and random installation identifiers generated by Firebase. We do not attach account names, email addresses, family or household identifiers, coordinates, messages, photos, or activity breadcrumbs. Reports captured through the app's JavaScript handlers replace free-text errors and file paths with restricted technical fields. Errors before those handlers start and native crashes use the native crash-library path. These reports are visible to the app operator and Firebase, not your family group.

Turning sending off stops new app error captures and new send requests; an upload already requested may finish. Fully close and reopen the app after it confirms the setting was saved; if saving fails, retry before closing. Turning it off does not erase reports already sent. Firebase keeps crash traces and associated identifiers for 90 days before starting removal from its live and backup systems. This is separate from the seven-day database recovery backups. We do not use crash information for advertising or combine it with your family records to identify you. See Firebase's privacy information.

How we use information

Information is used only to provide the app's features: showing family members on a map, routing "directions home," sending arrival/departure and chat notifications, and displaying names and photos within your family group, and diagnosing technical problems when you choose to send a report. We do not sell your data, use it for advertising, or track you across other apps or websites.

Who can see your information

Your location, name, photo, events, weekly activity counts, Everyone chat including any photos sent there, and family-wide announcements are visible to other members of your family group — the people who have your family's invite code and whom you have joined a group with. Household chat, its photos, its reactions, and its read receipts are visible only to your current household. When you look up another member, they are told that you did. Arrival and departure alerts for a saved place are sent only to members of that place's household. Your information is not shared with other users of the app outside your family group.

Service providers

The app relies on the following services to function. Optional services process information only for the features described below; app integrity verification remains staged.

Data retention and deletion

We keep daily recovery backups of the database for up to seven days. These private copies can contain the then-current location, account information and messages, including data deleted from the live app after a backup was made. They are used only to recover from data loss, are not available to family members, and never provide a location-history feature. Before restoring data to active use, we must reconcile later account deletions and sharing choices. Deleted photo objects also have a separate seven-day provider soft-delete window. Database backups do not include photo files or sign-in accounts.

Your information is kept while you are a member of a family group. You can:

Security

Data is transmitted over encrypted connections and stored using Google Firebase's security infrastructure. Access is restricted by security rules so that only members of your family group can read your family's data. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.

Children's privacy

The app may be used to share a minor's location within a family group at the direction of a parent or guardian, who is responsible for obtaining any necessary consent. We do not knowingly collect information from children outside of this family-managed context. A parent or guardian may review or request deletion of a child's information using the contact below.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.

Contact

Questions or deletion requests: mbwallace1390@gmail.com