Version: 2.0
Effective Date: 7 August 2026
Last Updated: 7 August 2026
1. Introduction
This Privacy Policy explains how FamilySafe Ltd collects, uses, stores and protects personal data when you use FamilySafe, visit our websites, contact us, purchase a plan or use related FamilySafe services.
FamilySafe helps individuals and families organise important household, financial, legal, property, vehicle, personal, probate and other sensitive information.
Privacy and security are central to the service. FamilySafe is designed around zero-knowledge principles for protected vault content, so encrypted private vault information cannot ordinarily be read by FamilySafe.
2. Who We Are
FamilySafe Ltd is the data controller for the personal data described in this Privacy Policy.
- FamilySafe Ltd
- Company number: 16675534
- Registered office: Sisters of St. Joseph, Workhouse Lane, Greetland, Halifax, England, HX4 8BS
- Website: https://familysafe.co.uk
- Privacy: privacy@familysafe.co.uk
- Support: support@familysafe.co.uk
- Security: security@familysafe.co.uk
Where another organisation operates a co-branded, white-label or specialist portal with FamilySafe, that organisation may also have its own data-protection responsibilities. Any different arrangement will be explained where relevant.
3. Vault Content and Service Data
FamilySafe handles protected vault content differently from the account and operational data needed to run the service.
Protected vault content may include card fields and notes, account and policy details, property and vehicle information, personal instructions, documents, files and photographs. This content is encrypted using the FamilySafe security architecture and cannot ordinarily be read or decrypted by FamilySafe during normal vault storage.
FamilySafe must still process limited account and operational information so the service can function, including:
- name, email address, account identifiers and profile information;
- authentication, verification and account-recovery information;
- subscription, billing and payment status;
- service settings, plan entitlements and usage allowances;
- information needed to deliver reminders, notifications and user actions;
- sharing, invitation, executor and access-management records needed to operate those workflows;
- security, audit, diagnostic and system logs;
- support requests and communications;
- browser, device, IP address and technical usage information.
We aim to minimise the operational information we can access. Access to service metadata does not give FamilySafe permission or technical ability to inspect encrypted private vault content.
4. Personal Data We Collect
Depending on how you use FamilySafe, we may collect or process:
- Account information: name, email address, profile details and account identifiers.
- Security information: authentication events, MFA status, verification and recovery activity, passkey or authenticator configuration, and security logs.
- Subscription and billing information: plan, payment status, invoice information and limited payment-related information received from payment providers.
- Usage and technical data: IP address, browser, device, login activity, diagnostics, performance data and feature usage.
- Support and communications: messages sent to FamilySafe and records of service communications.
- Sharing and access data: invitations, sharing relationships, adviser or authorised-contact relationships, executor nominations and access events.
- Reminder and action data: information required to schedule, snooze, dismiss or deliver reminders and notifications.
- Partner or referral data: referral code, referring partner or attribution data where you join through an approved FamilySafe partner.
- Cookie and analytics data: essential cookies and, where permitted, optional analytics or similar technologies.
- Encrypted vault content: information, documents and files you choose to store, protected as described in this Policy.
5. Information About Other People and Children
FamilySafe accounts are intended for adults aged 16 or over. We do not knowingly allow children to create their own FamilySafe account.
An adult account holder may store information relating to family members, children, dependants, executors, trusted contacts or advisers as part of legitimate family administration. If you add information about another person, you are responsible for ensuring that it is appropriate and lawfully handled.
6. How We Use Personal Data
We use personal data where necessary to:
- create and manage your FamilySafe account;
- authenticate you and protect access to the service;
- provide vault, sharing, reminder, notification, probate, executor, export and other product features;
- manage subscriptions, payments, invoices and plan entitlements;
- provide customer support and respond to privacy or security enquiries;
- detect and prevent fraud, misuse, unauthorised access and security incidents;
- monitor reliability, diagnose faults and maintain platform performance;
- improve usability and understand feature use using the minimum data reasonably required;
- meet legal, tax, accounting, regulatory and law-enforcement obligations;
- send important service, security, billing and legal notices.
We do not sell your personal data. We do not use encrypted private vault content for third-party advertising.
7. Our Lawful Bases
Under UK data-protection law, FamilySafe must have a lawful basis for processing personal data. Depending on the purpose, we rely on:
- Contract – where processing is necessary to provide FamilySafe, manage your account, deliver requested features or administer a paid plan.
- Legitimate interests – where reasonably necessary to secure the platform, prevent fraud, diagnose problems, improve the service or protect FamilySafe and its users, provided those interests are not overridden by your rights.
- Legal obligation – where we must keep or disclose information to comply with law, taxation, accounting, court orders or regulatory requirements.
- Consent – where the law requires consent, for example certain optional cookies, analytics, marketing or other optional processing.
If a feature requires a different lawful basis or an additional condition under data-protection law, we will provide appropriate information before that processing takes place.
8. Sensitive and Special Category Information
The information you choose to store may include sensitive information, including health information or other special category personal data. In ordinary encrypted vault storage, FamilySafe cannot ordinarily read that protected information.
If you deliberately use an optional feature that requires particular content to be processed outside ordinary encrypted storage, such as document processing or an AI feature to which you actively submit content, the information needed for that task may be processed for that purpose under appropriate safeguards.
9. Document Processing
FamilySafe may allow you to upload a document for automated processing so that information can be extracted and used to create a draft record.
When you deliberately submit a file to this feature, the information needed to perform the processing may be made available to FamilySafe systems and/or a contracted document-processing provider for that limited purpose. This processing is separate from ordinary encrypted vault storage.
Extracted information remains a draft until you review and confirm it. Temporary or intermediate processing data is retained only for as long as reasonably necessary to complete, troubleshoot and secure the workflow, subject to legal and operational requirements.
10. FamilySafe AI Features
FamilySafe may provide an AI-powered assistant and other AI-supported features. The assistant can help with product guidance, navigation, what information may be useful to store, security, sharing and probate-related organisation.
Where an AI feature only provides general product help, it does not need access to encrypted vault content. If you choose to submit information to an AI feature or deliberately authorise a feature to use information from your vault, the information required for that request may be processed to generate the requested response.
FamilySafe does not use AI output to make solely automated decisions about you that produce legal or similarly significant effects unless we clearly tell you otherwise and provide the protections required by law.
11. Sharing, Adviser and Executor Access
If you choose to share information with another person through FamilySafe, we process the minimum sharing and access information needed to create and manage that relationship.
FamilySafe may also process executor nominations and verification records required to operate probate-access features. Naming someone within FamilySafe does not by itself appoint that person as an executor in law.
Once a recipient has legitimately received information, they may have their own responsibilities for how they use or retain it.
12. Reminders, Notifications and Communications
FamilySafe may use account and service information to send reminders, renewal notices, user-action prompts, security alerts, billing messages and other service communications by email, in-app notification or another supported channel.
Where you can choose reminder or notification frequency, we use those preferences to control delivery. Essential security, legal, account and billing messages may still be sent even where optional reminders or marketing communications are disabled.
13. Payments and Billing Providers
Payments may be processed by third-party providers such as Stripe or GoCardless. FamilySafe does not need to store complete card or bank-payment credentials in order to provide the service.
FamilySafe receives the information needed to manage your subscription, such as payment status, transaction references, invoice information and limited payer details. Payment providers also process information under their own legal obligations and privacy terms.
14. Service Providers and Data Sharing
We do not sell personal data. We may make limited personal data available to carefully selected service providers where necessary to operate FamilySafe, including:
- cloud infrastructure, hosting and encrypted storage providers;
- payment providers;
- email and notification delivery providers;
- monitoring, logging, security and support providers;
- analytics providers where optional analytics is enabled lawfully;
- document-processing or AI providers where you actively use a feature that requires them;
- professional advisers such as legal, accounting, insurance or security advisers where appropriate.
Service providers may process personal data only for agreed purposes and must apply appropriate security and data-protection safeguards.
We may disclose information where required by law, court order or lawful authority, or where reasonably necessary to protect FamilySafe, users or others from fraud, abuse or serious security threats. Our zero-knowledge design means such a request does not give us technical access to encrypted vault content that we do not possess the means to decrypt.
15. International Transfers
FamilySafe aims to minimise international transfers of personal data. Some service providers may process limited information outside the United Kingdom or use global support infrastructure.
Where UK personal data is transferred internationally, we use a lawful transfer mechanism and appropriate safeguards required by UK data-protection law.
16. Cookies and Analytics
FamilySafe uses cookies and similar technologies where necessary to operate the website and service, maintain sessions, remember settings and protect account security.
Optional analytics, performance, support or marketing technologies are used only where permitted by law and, where required, after you have made a choice through our cookie controls. You can review or change available preferences through those controls.
17. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary to provide the service, maintain security and audit records, and meet legal obligations.
While your account is active, we retain the data needed to provide FamilySafe. If a paid subscription ends, your account may move to a lower-plan or read-only state in accordance with the Terms and the product rules then in force.
If you request account and data deletion, we will delete or irreversibly destroy applicable data and cryptographic material within a reasonable period, subject to technical processing time, backups and information we are legally required or permitted to retain. Destroying relevant cryptographic material can make encrypted vault content permanently unrecoverable.
Billing, accounting, fraud-prevention, security, consent and legal records may need to be retained for longer where required or justified by law.
18. Security
FamilySafe uses technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, alteration, disclosure or destruction. Measures may include:
- encryption controls for protected vault content;
- encrypted communications in transit;
- multi-factor authentication and passkey support where available;
- access controls and separation of operational privileges;
- security logging, monitoring and alerting;
- backup, recovery and resilience measures;
- security review, vulnerability management and testing.
No online service can guarantee that a security incident will never occur. If we identify a personal-data breach, we will investigate it and make any notifications required by law.
19. Your Data-Protection Rights
Depending on the circumstances, UK data-protection law gives you rights to:
- access personal data we hold about you;
- correct inaccurate or incomplete personal data;
- ask us to erase personal data in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests in certain circumstances;
- receive certain personal data in a portable format where the right applies;
- withdraw consent where processing is based on consent;
- complain to the Information Commissioner’s Office (ICO).
Because FamilySafe cannot ordinarily decrypt protected vault content, a data-access request to FamilySafe may not enable us to produce the readable contents of your encrypted vault. You can access and export information you can decrypt through your own FamilySafe account, subject to available features.
To exercise your rights, contact privacy@familysafe.uk. We may need to verify your identity before acting on a request.
20. Account Security and Recovery
You are responsible for keeping your login credentials, passkeys, authentication methods and recovery information secure.
Because FamilySafe uses zero-knowledge protections, there may be circumstances where we cannot recover or decrypt protected content if the required credentials, keys or recovery mechanisms are lost. Account-recovery events may be logged and monitored for security and fraud-prevention purposes.
21. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to FamilySafe, our processors, security architecture, legal requirements or how personal data is used.
The current version will show its last-updated date. Where a change materially affects how we use personal data or your rights, we will provide reasonable notice by email, in-app notification, website notice or another appropriate method.
22. Contact and Complaints
For privacy questions or to exercise a data-protection right:
- Email: privacy@familysafe..co,uk
- Postal address: FamilySafe Ltd, Sisters of St. Joseph, Workhouse Lane, Greetland, Halifax, England, HX4 8BS
For general support, contact support@familysafe.uk. For security concerns, contact security@familysafe.uk.
You also have the right to complain to the Information Commissioner’s Office (ICO) if you are unhappy with how your personal data has been handled.
23. Plain-English Summary
In summary:
- FamilySafe Ltd is the data controller for the FamilySafe service.
- You own and control the information you place in your vault.
- Protected vault content is encrypted so FamilySafe cannot ordinarily read it.
- FamilySafe can access the limited account, billing, security and operational data needed to run the service.
- If you deliberately use document processing or an AI feature that needs particular content, that content may be processed for the requested task.
- We do not sell your personal data or encrypted vault content.
- You control who you share information with through FamilySafe.
- Deletion of cryptographic material can make encrypted information permanently unrecoverable.
- You have rights under UK data-protection law and can contact privacy@familysafe.co.uk to exercise them.