FamSinyal Privacy Policy
This policy explains how the FamSinyal: Family Locator mobile app (com.famsinyal.app) and the server service running at api.viralfabriq.com process personal data. By using the app you acknowledge the processing described here.
1. Summary
This summary does not replace the full policy; it is a quick overview.
- FamSinyal is a visible, consent-based family safety app. It is not spyware.
- A permanent notification is shown on the child's device while protection is active. The app icon cannot be hidden.
- Location is shared only when an SOS is sent, while the app is open with sharing enabled, or in the background if the child's device grants “Allow all the time”.
- Location history is automatically deleted after 30 days.
- We never sell your data, never use it for advertising, and never share it with ad networks.
- We do not read messages, calls, contacts, camera, microphone, browser history or files.
- You can delete your account and all family data at any time from within the app.
2. Who is responsible for your data
- Controller: Hülagühan Labs Yazılım Teknolojileri Ltd. Şti.
- Location: İstanbul, Türkiye
- App: FamSinyal: Family Locator (`com.famsinyal.app`)
- Server service: api.viralfabriq.com
- Support: destek@hulaguhanlabs.com.tr
- Privacy and data requests: kvkk@hulaguhanlabs.com.tr
We act as the data controller within the meaning of the EU General Data Protection Regulation (GDPR) and of Turkish Law No. 6698 on the Protection of Personal Data (KVKK).
3. What FamSinyal does and does not do
FamSinyal lets a parent pair their own child's device openly and visibly so the family can stay aware of each other in emergencies (SOS) and in everyday life.
There is no hidden tracking. Installation on the child's device happens only through a pairing flow performed while you physically hold that device. After pairing, a permanent notification is displayed on the child's device and the child can always see, from within the app, that the device belongs to a family. The app has no hidden, icon-less or “invisible” mode, and none will be added.
FamSinyal never does the following:
- Read, store or decrypt SMS or messaging app content
- Access call logs or contacts
- Listen to or record the microphone or camera
- Collect browser history or keystrokes
- Scan files on the device
- Allow adults to monitor one another — parents manage the family together and do not see each other's location
- Offer arbitrary phone-number lookup or people-finding
4. What data we process and why
The tables below match our Data Safety declaration on Google Play and our App Store privacy labels.
4.1 Parent account and family data
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation, sign-in, password reset, service notices | Performance of a contract — GDPR Art. 6(1)(b) |
| Password (cryptographic hash only) | Authentication. Your password is never stored in plain text; it is hashed irreversibly with argon2id. | Performance of a contract — Art. 6(1)(b) |
| Google account identifier | Only if you use “Sign in with Google”. Your Google password is never transmitted to us. | Consent — Art. 6(1)(a) |
| Display name, language and time-zone preference | App interface and notification timing | Performance of a contract — Art. 6(1)(b) |
| Phone number, relationship to the family (Mother/Father/Guardian/Other) and avatar colour — all optional | Convenience within the family view. You may leave these blank and delete them at any time. Your phone number is shown only to you and is never served to third parties — including other family members — through our API. | Consent — Art. 6(1)(a) |
| Family name, membership and role | Creating the family and managing multiple parents | Performance of a contract — Art. 6(1)(b) |
4.2 Child device data
| Data | Purpose |
|---|---|
| Device nickname, platform, model, operating system and app version | So the parent can tell which device they are looking at, and for technical support |
| Pairing time and last-seen time | Showing whether the connection is alive |
| Battery level, charging state, connection type | “Low battery” and “offline” alerts |
| Permission states (location, notifications) and whether the protection service is active | Telling the parent that setup is incomplete |
| Consent record and accepted policy version | Evidence that pairing was performed with explicit consent |
Legal basis: performance of a contract — GDPR Art. 6(1)(b). Retained while the account is open.
4.3 Location data
Location is the most sensitive data FamSinyal processes. It is collected only in the following situations:
- When an SOS is sent — a high-accuracy location is captured.
- While the app is open and location sharing is enabled.
- In the background — only if “Allow all the time” is selected on the child's device. In that case location is collected roughly once a minute, or after about 30 metres of movement, even when the app is closed or not in use.
Fields collected: latitude, longitude, accuracy radius, altitude, speed and timestamp.
Background tracking is never silent. While protection is active, a notification that cannot be dismissed is permanently shown on the child's device: “FamSinyal protection mode is on — your location is shared with your family.” The permission is requested only after an in-app screen explaining why it is needed (prominent disclosure), and it can be withdrawn at any time from the device settings.
If background permission is not granted the app still works; location is then shared only when an SOS is sent and while the app is open.
Legal basis: consent — GDPR Art. 6(1)(a). Retention: at most 30 days, then deleted automatically.
4.4 Safety events and notifications
- SOS and “I'm safe” events, with timestamp and, where applicable, location
- A device push token, so notifications can be delivered
- Security audit records — who performed which administrative action on which family, and when — for account security and abuse detection
Legal basis: performance of a contract and legitimate interests — Art. 6(1)(b) and 6(1)(f). Retention: at most 12 months.
4.5 Subscription
FamSinyal runs on a paid subscription. Payment is handled entirely by the app store; your card or bank details never reach us and are never stored by us. We receive and store only whether the subscription is active, the plan type and the renewal date, from our billing provider (RevenueCat).
Legal basis: performance of a contract — Art. 6(1)(b). Retained while the account is open.
4.6 Screen time (optional)
If the Usage Access permission is granted manually on the child's device, we collect only the application name and the time spent in it, and show the parent a daily summary. App content, conversations, what was watched and keystrokes are never collected. This permission is optional and can be switched off at any time in the device settings.
Legal basis: consent — Art. 6(1)(a).
5. Features not present in this version
The following are not available in this version, and the related data is not collected:
- Geofence (safe-zone) entry and exit records
- App locking or usage blocking
If these are added later, this policy will be updated and the change announced inside the app.
6. Children's data and parental consent
FamSinyal is installed and paired on the child's device by the parent, while physically holding that device. A child's data is visible only to the active parent members of the same family.
Informing children who are old enough to understand, and obtaining their agreement where possible, is a requirement both of the app's design and of this policy — which is why a permanent notification is shown on the child's device while protection is active.
Under GDPR Art. 8, processing a child's personal data on the basis of consent requires the authorisation of the holder of parental responsibility. Only a parent or legal guardian may create an account and pair a device. The account holder must be 18 or older.
7. Who we share data with
We do not sell your personal data, do not use it for advertising and do not share it with ad networks. Data is shared only with the parties required to operate the service:
| Recipient | Purpose |
|---|---|
| Active parent members of your family | The core function of the app |
| Our server infrastructure provider | Hosting the data |
| Google Play Billing / RevenueCat | Subscription validation |
| Expo push notification service | Delivering notifications (push token only) |
| Competent public authorities | Only where legally required and properly requested |
8. International data transfers
The data controller is established in Türkiye, which is outside the European Economic Area and is not covered by a European Commission adequacy decision. Where personal data of users in the EEA or the United Kingdom is transferred to us, the transfer is made on the basis of appropriate safeguards — Standard Contractual Clauses adopted by the European Commission — or, where applicable, your explicit consent.
Some infrastructure providers we use may host servers outside your country. In those cases the same safeguards apply. Under Turkish law (KVKK Art. 9), transfers abroad are likewise carried out on an appropriate legal basis.
You may request a copy of the safeguards applied to a transfer by writing to kvkk@hulaguhanlabs.com.tr.
9. How we protect data
- All connections are encrypted with TLS (HTTPS)
- Passwords are hashed irreversibly with argon2id
- The database enforces row-level security: one family's data is invisible to another family at the database level — this is not merely a check in application code but a constraint of the database itself
- Session tokens are kept in the operating system's secure storage on the device
- Passwords, tokens, pairing codes and location coordinates are masked in server logs
In the event of a personal data breach we notify the competent supervisory authority without undue delay and, where required, within 72 hours, and we inform affected users where the breach is likely to result in a high risk to their rights and freedoms.
10. How long we keep data
| Data | Retention |
|---|---|
| Account and family information | While the account is open |
| Location records | At most 30 days, then deleted automatically |
| Safety events (SOS, check-in) | At most 12 months |
| Audit records | At most 12 months |
| Deletion request records | At most 12 months, as evidence that the request was fulfilled |
11. Deleting your account and data
In the app, go to Settings → Delete my account and data to request deletion of your account and all associated family data.
This screen is always reachable, even if you have no subscription, and is never behind a paywall.
Once a deletion request is received your account is closed immediately and the data is permanently deleted within 30 days at the latest. Records we are legally required to keep are retained for the period prescribed by law. Uninstalling the app on its own does not delete your data — use the flow above or write to us.
Step-by-step instructions are on the account and data deletion page.
12. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data and receive a copy of it (Art. 15)
- Rectification — have inaccurate or incomplete data corrected (Art. 16)
- Erasure — have your data deleted (Art. 17)
- Restriction — have processing restricted in certain circumstances (Art. 18)
- Data portability — receive your data in a structured, machine-readable format (Art. 20)
- Object — object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3))
- Lodge a complaint with a supervisory authority in your country of residence, work or the place of the alleged infringement (Art. 77)
Users in Türkiye hold equivalent rights under KVKK Art. 11 and may complain to the Turkish Personal Data Protection Authority.
To exercise any of these rights, write to kvkk@hulaguhanlabs.com.tr. We respond free of charge and within 30 days at the latest.
13. Changes to this policy
If this policy is updated, the effective date and version number change. Changes that materially affect the types of data collected or the purposes of processing are announced inside the app before they take effect.
14. Contact
For questions about this policy write to destek@hulaguhanlabs.com.tr. See also our Terms of Service and account deletion guide.