Privacy

Your family's plans aren't readable by us.

Ūna end-to-end encrypts sensitive household content before it syncs. We cannot read your event titles, notes, locations, birthdays, list items, or household text from our backend.

Last updated · 9 September 2026 v6
The short version

If you only read one paragraph.

Sensitive household content is encrypted on your device before it syncs. Our backend stores encrypted payloads and the minimum metadata needed to make the app work.

We do not sell your data, show ads, use third-party analytics SDKs in the iOS or Android app, or train AI models on your household content.

No. 02 · What we cannot see

We can't open the database and read your plans.

  • × What your events are called
  • × Event notes, locations, and links
  • × Birthdays and birthday names
  • × Household and family member names
  • × Shopping, to-do, chore and custom list names
  • × List item names and links
No. 03 · What we can see

The minimum metadata to sync correctly.

Account
Your chosen sign-in provider (Apple, Google, or Microsoft), its account identifier, and a hashed provider subject. Used to sign you in and link you to your household.
Household membership
Household and member ids, member roles (owner, adult, caregiver), and the profile each adult is linked to.
Invites
Invite status, expiration, acceptance and revocation timestamps.
Event metadata
Start/end times, all-day flag, recurrence rule, reminder timing, visibility (household / personal), assignment ids, and whether an event is private, busy-only, or agent-readable.
List metadata
List type (shopping, to-do, chores), item sort order, checked/completed state, due date, reminder timing, and assignee id.
Reminders
Reminder status — active, snoozed, completed, skipped, canceled.
Audit metadata
Action type, actor id, target id, timestamp, and result status. Used to debug sync issues and protect your household.
Profile photo storage
An encrypted-file storage id for an uploaded profile photo. The photo bytes themselves are encrypted on your device before upload.
Attachment metadata
Encrypted-file storage id, byte size, content-type group (image, document), the household item it's attached to, upload status, and quota usage. Filenames are encrypted before upload.
Diagnostic metadata
Feature name, error category, retry count, result counts, app version, build number, and platform. No household text, member names, event names, or household ids. Retained around 30 days.
Subscription metadata
From the App Store or Google Play: product id, transaction or order id, purchase token, dates, subscription status, store or environment, and opaque account identifiers where supplied. Apple or Google is the payment processor.
Android beta requests
The Google Play email address you submit, your consent timestamp, request status, and operational timestamps. Used only to review, grant, and administer Android beta access—not for unrelated marketing.
No. 01 · The household key

The key never leaves your devices.

When you create a household, Ūna generates a 256-bit household key on your device. It's kept in Apple Keychain on iOS or Keystore-backed secure storage on Android. Ūna uses AES-GCM on your device to encrypt content before it's sent to Convex, our sync backend. The backend only ever sees ciphertext and nonces.

  • Protected by your device. iCloud Keychain may restore it across your Apple devices; Android and cross-platform devices use trusted-device approval or a fresh invite.
  • Shared via invite. When another adult joins your household, the invite flow transfers the key to their device.
  • We can't recover it. That's the trade-off — see the runbooks on support.
Flow
Plaintext → Ciphertext
On device
"🍝 Spaghetti"
On-device
AES-GCM
In Convex
a8::3f1b…c4
Household key
Protected device storage
No. 04

No ads. No tracking. No selling.

More detail

The other questions people ask.

No. 05

Household keys & device access

The household key is created on your device and kept in protected operating-system storage: Apple Keychain on iOS and Keystore-backed secure storage on Android. iCloud Keychain may restore it across your own Apple devices; a new Android or cross-platform device regains access through approval from a trusted device or a fresh household invite. Our backend never stores the plaintext household key.

No. 06

Invites

Invite links should only be sent to people you trust. Joining a household gives that device access to the household's encrypted content. Invites have status and expiration metadata, and can be revoked at any time.

No. 07

Profile photos

Profile photos are optional. They're encrypted on your device before upload and stored as encrypted files — our backend holds the ciphertext and a storage id, never the photo bytes. Profile photos are not used for ads, tracking, analytics, or AI training.

No. 08

Files & attachments

When you attach a file, image, or document to a household item, the file bytes are encrypted on your device before upload and stored as encrypted files. The filename and display metadata are also encrypted. Our backend stores a storage id, byte size, content-type group (image, document), the household item the file is attached to, upload status, and quota usage. We never store the plaintext filename.

No. 09

Widgets

Widgets read decrypted household content from a small on-device snapshot managed by Ūna. They may display household names, events, list items, and people you choose to show on the device. Widgets do not connect directly to Ūna's sync backend. Widgets trade some of the in-app strict "decrypt-then-display" model for being readable at a glance — anyone with physical access to your unlocked device can read what a widget shows.

No. 10

Notifications

Ūna uses normal local notifications on iOS and Android. Reminder, birthday, and list-item notification text is composed on your device after local decryption. Ūna does not need to send plaintext reminder text through our backend to notify you.

No. 11

Maps & location

Event locations are encrypted before they reach our backend — we can't read them. When you use address suggestions while typing, or open a location in a maps app, the query may be sent to Apple Maps, Google Maps, or another map provider you choose. Those third-party requests are subject to the map provider's own privacy policies.

No. 12

Google Calendar import

Google Calendar import is optional. Ūna lets you connect Google Calendar so you can choose events to copy into your Ūna household calendar. In this section, "Google Calendar data" means Google user data obtained from Google Calendar APIs.

Data accessed

When you use Google Calendar import, Ūna requests read-only access to:

  • The list of Google calendars you are subscribed to.
  • Google Calendar events in the date range you choose.
  • Calendar IDs, calendar names, calendar colors, event IDs, event titles, descriptions, locations, event links, start and end times, all-day status, and related event metadata needed to display and de-duplicate import choices.

Data usage

Ūna uses Google Calendar data only to show calendars and events for import, let you select which events to copy, detect possible duplicates, and create the selected events in your Ūna household calendar.

Ūna does not create, edit, delete, invite guests to, or otherwise change events in your Google Calendar. Imported events become independent Ūna events. They are not continuously synced with Google Calendar. Changes made later in Google Calendar do not automatically update Ūna, and changes made in Ūna do not update Google Calendar.

Data storage

Ūna uses read-only Google Calendar OAuth access for the import flow. Ūna does not store a Google refresh token or keep long-term Google Calendar access.

Events you do not import are not saved by Ūna. For events you choose to import, event details such as title, notes, location, link, and import identifiers are encrypted on your device before syncing to Ūna's backend. Ūna's backend stores encrypted event content and limited operational metadata needed to run the calendar, such as event time, all-day status, household membership, assignments, visibility, recurrence, and reminder timing.

Data protection mechanisms

Ūna protects Google Calendar data using encrypted transport and on-device encryption. Connections to Google APIs and Ūna's backend use HTTPS/TLS. Imported event content is encrypted on your device before it is synced to Ūna's backend.

Ūna uses read-only OAuth access for the import flow, does not request permission to change your Google Calendar, and does not store a Google refresh token. Access to backend systems is limited to authorized operations needed to host, sync, secure, debug, and support Ūna. Ūna does not allow employees, contractors, or service providers to read Google Calendar event content except with your affirmative permission, when necessary for security or abuse investigation, or when required by law.

Data sharing, transfer, and disclosure

Ūna shares, transfers, or discloses Google Calendar data only in the limited cases described here.

  • Household members: selected imported events are shared with the members of your Ūna household because they become Ūna household calendar events.
  • Service providers: Ūna may process encrypted event data and limited operational metadata through service providers that host, sync, store, secure, debug, support, or operate Ūna, including Convex as Ūna's sync backend, only to provide and operate the app.
  • Legal and security needs: Ūna may disclose limited Google Calendar data if necessary to comply with applicable law, enforce our terms, or investigate security, abuse, or integrity issues.

Data not sold or used for unrelated purposes

Ūna does not sell Google Calendar data or disclose it to advertisers, data brokers, information resellers, analytics providers, or AI model providers. Ūna does not use Google Calendar data for advertising, tracking, analytics, AI model training, credit-worthiness, or lending purposes.

Ūna's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data retention and deletion

Ūna keeps imported Google Calendar events until they are deleted in Ūna or removed through account or household deletion.

You can delete imported events directly in Ūna. You can also delete your Ūna account from the app. If other adults remain in the household, shared household events may remain available to them until deleted by someone with access. If you are the last adult in the household, deleting your account also deletes the household and its content.

You can revoke Ūna's Google access at any time from your Google Account permissions page.

No. 13

Diagnostics

Ūna collects a small amount of first-party diagnostic metadata to help us find and fix bugs: feature name, error category, retry count, result counts, app version, build number, and platform. We do not include household text, member names, event names, or household ids in diagnostics. Rows are retained around 30 days.

No. 14

Operational alerting

The iOS and Android apps ship with no Sentry, Crashlytics, or similar diagnostics SDK. On our backend, if a routine ops task — such as data cleanup — fails, we may send the operational incident to Sentry so the team can fix it. Those alerts carry hashed ids and incident metadata. They never carry household content.

No. 15

Billing & app stores

Ūna subscriptions are purchased through the App Store on iOS or Google Play on Android. Apple or Google processes your payment; Ūna does not receive your full payment details. We receive the subscription metadata needed to verify access, such as product id, transaction or order id, purchase token, dates, subscription status, store or environment, and opaque account identifiers where supplied. Manage or cancel your subscription in the store where you purchased it.

No. 16

Retention windows

Cleanup runs asynchronously. Some operational rows are retained briefly so we can recover from cleanup failures without losing audit-trail integrity. Approximate windows:

Deleted calendar rows
~1 day
Deleted list rows
~30 days
Diagnostic metadata
~30 days
Removed-member cleanup
~90 days
Completed Android beta requests
~90 days
Pending Android beta requests
up to 180 days
No. 17

Sign-in providers

Ūna supports authentication with Apple, Google, and Microsoft. When you sign in, your chosen provider gives Ūna a stable account identifier and may provide your name and email, depending on your provider settings and consent. Ūna uses the provider identifier to create or restore your account and connect you to your household. Your sign-in session is cached in protected storage on your device. Your provider name and email are not stored on our backend beyond what is required for transient authentication. Apple, Google, or Microsoft processes the sign-in request under its own privacy policy.

No. 18

Agents & assistants

Ūna lets adults create assistant connections with selected, revocable access they control. An assistant connection is not a household member. Adults choose capabilities, then grant access to specific people, calendars, and lists. Availability checks can stay limited to whether someone is busy or free unless event details are explicitly allowed.

Where decryption happens

Ūna’s hosted endpoint stores and returns encrypted household payloads and does not decrypt them. Ūna never gives an assistant the household key. Approved assistant content is protected with a separate agent-readable key wrapped to the connection’s public setup key.

The chosen trusted runtime uses its private key to decrypt approved records. That moment—not merely creating the connection—is where readable household information enters the assistant’s processing environment.

Fully local or self-hosted

If the connector, model, logs, and storage all run on infrastructure you control, and readable content is not forwarded to another service, the selected plaintext can remain within the boundary you operate. Your own hosting, logging, backup, and access practices still determine who can see it.

Running only the connector yourself does not make the complete assistant local. If that connector calls a hosted model API, the readable details included in that request leave your infrastructure.

Hosted assistants and model APIs

If decrypted details are sent to ChatGPT, Claude, or another hosted assistant or model API—or if a provider-hosted runtime holds the connection secret and performs decryption—the selected plaintext is processed in that provider’s environment.

The provider’s privacy, storage, retention, and model-training policies apply to the plaintext it receives. Ūna does not use household content to train AI models, but that promise cannot govern an external provider chosen by the user.

Scope, review, and revocation

Assistants only receive content intentionally made agent-readable and granted. Adults can review access, rotate tokens, revoke a connection, or remove a revoked entry from the visible list.

Revoking a connection blocks future calls. It cannot recall or delete readable information that an external assistant or provider already received; deletion requests for that copy must follow the provider’s controls and policies.

No. 19

Children & household profiles

Ūna is made for adults and caregivers managing a household. Children can be represented as household profiles, with a name, colour, and birthday — but they do not need Ūna accounts, and we do not collect personal information from them directly.

No. 20

Android beta requests

When you request Android beta access, Ūna stores the Google Play email address you provide together with consent, request-status, and operational timestamps. We use it only to review the request, add approved testers, send testing-related messages, and prevent duplicate requests. Cloudflare hosts the request service and uses Turnstile to protect the form from automated abuse; Cloudflare processes the limited browser and network information needed to perform that verification under its own privacy terms. We do not store the Turnstile token, your IP address, or its verification response in the beta-request database, and we do not use the submitted address for unrelated marketing. Pending requests are deleted after no more than 180 days; completed requests are deleted after around 90 days. You can ask us to remove a request sooner by contacting support@unafamily.app.

No. 21

Account deletion

You can delete your account in Ūna at any time. If other adults remain in the household, Ūna removes your account link, your device keys, and your private content while keeping shared household content for them. If you are the last adult, deleting your account also deletes the household and its content. Cleanup runs asynchronously — see Retention windows above for typical timing.

Delete your account online →
Reach us

Privacy questions, always.

Support is available inside the app, under Settings. For privacy and data questions, email us directly.