This page is maintained by Famly.ca to answer common security and privacy questions about how the service protects your family's information. It describes the controls that are enabled today. It is not a third-party certification and is not legal advice.
Encryption
- In transit: All connections to famly.ca use HTTPS/TLS. Data moving between your device and our servers is encrypted.
- At rest: The database and file storage that hold your account data are encrypted at rest by the underlying cloud infrastructure.
Account isolation
- Every user-facing table uses row-level security. Signed-in users can only read and write their own family members, pets, reminders, wellness chats, reading progress, and Founders Club records.
- Administrative access is gated by a separate roles table and a server-side role check — it cannot be granted from the browser.
- Uploaded avatars are stored in private storage buckets and served through signed, time-limited URLs.
Authentication
- Passwords are hashed before they are stored. Famly.ca staff cannot see your password.
- New and changed passwords are checked against known-breached password lists (Have I Been Pwned) so common leaked passwords are rejected.
- Password reset is delivered by a time-limited link sent to the email address on file.
- Famly.ca is currently designed for one adult organizer account per household.
Secrets and API keys
- Server-side keys (database service credentials, AI provider keys, email provider keys) are stored as server-only secrets and are never shipped to the browser.
- Only the public, non-sensitive keys that a browser needs to talk to the backend are included in the app bundle, and those keys are gated by the row-level security rules above.
Hosting and shared responsibility
Famly.ca is built on Lovable Cloud, which runs on Supabase and AWS infrastructure. Supabase maintains a SOC 2 Type II report for the platform Famly.ca is hosted on. That report covers the underlying platform, not Famly.ca as an application — Famly.ca is responsible for how the app is built, which controls are enabled, and how your data is used.
What Famly.ca does not claim
Famly.ca does not currently hold its own SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Famly.ca is a personal organizer and is not medical, veterinary, legal, financial, or emergency advice, and it is not intended to be a system of record for regulated health information. Please do not upload data that requires HIPAA or similar protections.
Privacy and your data
Detail on what is collected, how it is used, retention, and your rights lives in the Privacy Policy. Famly.ca does not sell your personal information.
Reporting a security issue
If you believe you have found a security vulnerability in Famly.ca, please email security@famly.ca with a description and, where possible, steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before public disclosure. We appreciate responsible reports.
General support
For account, billing, or general questions, contact support@famly.ca.

