Privacy
Clear about what FamVerify knows.
FamVerify uses only the information needed to connect you to your trusted phone, organise your Circles and complete fresh identity checks. It is not a call-recording, messaging or deepfake-analysis service.
Last updated: 4 September 2026
Who is responsible for your information
Andrew Tech operates FamVerify and is the controller for the personal information described in this notice. Andrew Tech is an independent UK studio led by Andrew Misselbrook.
Contact: hello@andrewtech.co.uk. The easiest route for support, privacy requests and security reports is explained on our Contact page.
This notice covers the FamVerify website, iPhone and Android apps, API and related support. Apple and Google process app-store and device-platform information under their own privacy notices.
Information we handle
- Account and profile: your chosen display name, initials, icon colour, recent profile-change history, random user identifier, account status and any contact information you choose to give support. A private nickname you create for another person is stored with your account and shown only to you.
- Trusted phone: an automatically generated phone label, platform, app version, public device key and fingerprint, hardware-assurance level, trust status and relevant timestamps.
- Circles: Circle names, members, roles, invitations, join requests, approvals, rejections and removals.
- Verification: participant identifiers, the authorising Circle and responding phone, result, security events and timestamps. We do not ask for the reason behind a check.
- Circle Check-in: the Circle, initiator, fixed participant list, each person's I'm OK or I need help response, response times, acknowledgement or resolution details, status and start, expiry and end times.
- Security and sessions: short-lived challenges, token digests, session state, audit events and limited keyed network signals used to prevent abuse.
- Notifications: if you enable them, an Apple or Google delivery token and delivery status. Tokens are encrypted before database storage. On supported iPhones, a request-scoped encrypted token may also update a verification or Circle Check-in Live Activity.
- Recovery: your Recovery Guardian relationship, authorising Circle, nomination and recovery status, protected pairing and claim-token digests, replacement-phone reference and relevant times. Raw one-time pairing details are not retained.
- Subscriptions: store product, transaction and entitlement references, Circle allocation and renewal dates. Apple or Google handles your payment method; we do not receive full card or bank details.
- Support: your message, contact details and the information needed to resolve the request.
We receive information from you, your phone, Apple or Google, and the actions of people who share a Circle with you. A valid invitation also tells us which Circle and inviter it belongs to.
What FamVerify does not collect
- No call recordings, microphone audio, video or deepfake samples.
- No message contents, bank details, transfer amounts or reason for a verification.
- No Face ID, fingerprint, biometric template, biometric image or phone passcode.
- No device private key, full address book, precise location or advertising identifier.
- No advertising profile, data-broker sharing or cross-app tracking.
Face ID, Touch ID, fingerprint or passcode checks are performed by iOS or Android. FamVerify receives only the outcome needed to allow one protected signing operation.
Why we use information
- Create and protect your FamVerify identity and trusted phone.
- Let you personalise your profile, review changes and recognise people with private nicknames.
- Create Circles, process invitations and manage deliberate trust relationships.
- Deliver identity checks and display short-lived results.
- Run Circle Check-ins, show who has responded and surface requests for help to current Circle members.
- Set up a Recovery Guardian and protect a lost-phone recovery with one-time details and a safety window.
- Send limited action and safety notifications for checks, joins, Circle changes and recovery when you enable them.
- Maintain sessions, prevent replay and abuse, investigate incidents and keep the service reliable.
- Manage Circle subscriptions, respond to support and meet accounting or legal duties.
- Understand aggregate website use and improve accessibility and performance.
The lawful basis depends on the purpose. We use contractto create your account, manage trusted phones and Circles, deliver checks and check-ins, support recovery, and administer subscriptions. We use our legitimate interests to prevent replay, fraud and abuse, secure the service, diagnose faults and understand aggregate website use; those interests are running a safe, reliable service while using limited and pseudonymous signals. We use legal obligation where tax, accounting or another law requires a record or response.
An “I need help” response may reveal health or safety information in context. We ask for your explicit consent at the point you choose to share it with current Circle members. You can change the response while the check-in is open or ask us to delete it; withdrawing consent does not affect processing that was lawful before withdrawal. We do not ask for a diagnosis or the reason for the response.
A display name, trusted-phone key and basic account identifiers are required to create and secure an account. Circle relationship data is required only when you create or join a Circle. Without required information, we cannot provide the relevant account, Circle, verification or recovery feature. Notifications and website analytics are not required to use the core app.
FamVerify does not use your information for advertising or make a legal or similarly significant decision about you solely by automated means.
What other people can see
FamVerify is not end-to-end encrypted. We can read the display names, Circle names and relationship information needed to provide the service.
- Active Circle members can see the Circle, other active members’ current display names, initials, icon colours and roles, and recent checks in that Circle: who requested them, who responded, the result and relevant times.
- Active Circle members can see a Circle Check-in's participants, responses, progress, requests for help, acknowledgement or resolution and relevant times.
- Owners and admins can see the display name of someone asking to join.
- Active Circle members can see recorded membership rejections, including who rejected whose request and when.
- A person holding a valid invitation can see the Circle name and inviter’s display name.
- The people taking part in a live verification see the other person’s display name, result and relevant times.
- Your profile-change history and the private nicknames you create are shown only to you. FamVerify can still process that information because the service is not end-to-end encrypted.
- A recovery-start safety alert may identify the recovering person, Guardian and authorising Circle to the relevant Circle members.
Share invitation links only with the intended person. Possessing a link does not create membership, but it reveals the limited preview above.
Service providers and international transfers
We use carefully selected providers to operate FamVerify:
- Vercel for website and API hosting and cookie-free aggregate website analytics.
- Neon for managed PostgreSQL database hosting.
- Doppler for deployment-secret management.
- Apple APNs and Google Firebase Cloud Messaging for optional push delivery. Push text is generic; the provider receives the delivery token, notification type and opaque record identifiers needed to open the right in-app view.
- Apple App Store and Google Play for purchases, subscriptions and entitlement events.
Vercel Analytics may process a page path, timestamp, referrer, coarse location, browser, operating system and device type for aggregate statistics. It does not use third-party analytics cookies, and FamVerify excludes private invitation paths.
A provider may process information outside the UK. Where a transfer is restricted by UK data-protection law, we use an applicable adequacy regulation or contractual safeguard and complete the required transfer assessment. Contact us for more information about a relevant safeguard.
We may disclose the minimum necessary information where law requires it, to establish or defend legal claims, or to protect somebody from a serious security threat. We do not sell personal information.
How long we keep information
- Account and active Circles: while active. Access ends immediately when an account or Circle is deleted; eligible data is then erased or pseudonymised, subject to the limited periods below.
- Verification detail: 90 days after completion; a minimised security record may remain for up to 24 months.
- Circle Check-in detail: 90 days after completion, cancellation or expiry; a minimised security record may remain for up to 24 months.
- Invitations: expired unclaimed invitations for 30 days and terminal invitation records for up to 90 days.
- Join decisions: up to 12 months after the request ends.
- Revoked phones, recovery and security audit: generally up to 24 months. A minimised public-key fingerprint may be retained longer to prevent unsafe key reuse.
- Sessions: until expiry or revocation, with terminal token lineage for 30 days.
- Push tokens: until the phone, token or account is removed; invalid tokens are removed promptly.
- Application logs: 30 days searchable, or up to 90 days where a confirmed security need requires it.
- Subscriptions: entitlement detail while the Circle is active and for 24 months afterwards; accounting records only for as long as law requires.
- Encrypted backups: rolling backups expire within 35 days, with deletion records reapplied after any restore.
Information stored on your phone
- The private signing key remains in protected iOS or Android storage and is not exportable to FamVerify.
- The rotating refresh token is held in this-device-only secure storage; access tokens are kept in memory.
- Production profile, Circle, trusted-person, phone and pending-check information is cached in an encrypted SQLCipher database for the interface and read-only offline display.
- Favourites, appearance and Simple view are local preferences stored on that phone.
Signing out clears the encrypted cache and revokes the session, but deliberately keeps the protected device key so the same trusted phone can authenticate again. FamVerify also relocks after time in the background, obscures content in the app switcher and blocks screenshots or recordings on Android.
Your choices and privacy rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or portability, or object to particular use. You can disable notifications in phone settings, change or remove your Recovery Guardian, leave a Circle and manage local preferences from the app.
You have the right to object to processing based on our legitimate interests, including security analytics and aggregate website analytics. Tell us what you object to and why; we will stop unless we demonstrate compelling legitimate grounds or need the processing for legal claims. You can also withdraw an optional consent at any time.
You can start account deletion in Settings → Privacy → Delete account or use our web deletion guidance. We use a trusted-phone check or another proportionate method so a support email alone cannot delete somebody else’s established identity.
Account deletion is permanent and immediately disables new activity, revokes the trusted phone and sessions, closes Circles you own and cancels open recovery requests. Eligible profile, contact, push and operational information is then erased or pseudonymised. Minimal security and accounting records remain only for the periods explained above. Deleting an account does not cancel an Apple or Google subscription; cancel it separately through the store.
Contact hello@andrewtech.co.uk. We normally respond to privacy-rights requests within one month. You can also raise a concern with the UK Information Commissioner’s Office.
Children and changes to this notice
FamVerify accounts are available from age 13. Anyone under 18 must have permission from a parent or legal guardian, who should help them understand Circles, invitations and verification results. We do not knowingly allow an under-13 account. Contact us if you believe a younger child has registered.
We apply high-privacy defaults and do not use children’s information for advertising or profiling. We review child access and privacy risks as the product changes.
We date material updates to this notice and explain important app changes before they take effect. An earlier lawful use remains governed by the notice that applied at that time.