Privacy Policy

Effective September 2, 2026 · Version 2026-09-02

Plain-language draft, pending final legal review. We wrote this to describe honestly and specifically how ManagedFamily actually works — not to give you a false sense of protection with boilerplate. A qualified attorney should review and finalize this text before ManagedFamily is offered to the public, and some bracketed details (our legal entity, address, and governing law) are placeholders until then.

ManagedFamily is operated by GLAT LLC, a Michigan limited liability company (“ManagedFamily,” “we,” “us”), which is the data controller for the information described below. ManagedFamily is a private vault for a family’s most important documents — IDs, wills, deeds, insurance, and medical records. Because of what you trust us to hold, this policy is written to be specific about exactly what we collect, how it is protected, and the choices you have. It applies to the ManagedFamily website and application.

1. Information we collect

We collect only what the product needs to work:

  • Account information — your name and email address, and a one-way, irreversible hash of your password (we never store the password itself). If you enable two-factor authentication, we store the secret needed to verify your codes (encrypted at rest).
  • Your documents and their details — the files you upload and the metadata you or the app add: titles, descriptions, categories, tags, expiry dates, the people a document is about, medical fields, and text we extract from a document to make it searchable (see “OCR,” below).
  • Family structure — the families you create or join, the other members, and each member’s role (owner, admin, adult, or child).
  • A phone number — only if you choose to add and verify one for SMS check-in reminders. It is optional and you can remove it at any time.
  • Sharing details — when you share documents with someone outside your family, the recipient’s email address and a record of when the link was opened.
  • Security and activity logs — an audit trail of significant actions (sign-ins, uploads, downloads, deletions, membership and role changes), recorded with the IP address and browser/device (user-agent) that made the request. This log is how we can answer “who touched my will?” — a core reason a family uses a vault.
  • Notification subscriptions — if you turn on push notifications, the subscription details your browser provides so we can deliver reminders to that device.

We do not use advertising trackers, and we do not sell your personal information.

2. How we use your information

We use the information above only to provide and protect the service:

  • To store, organize, preview, search, and let you retrieve your documents.
  • To run your family: invitations, roles, and access decisions.
  • To send you service messages — invitations, share access codes, password resets, expiry reminders, and (if you opt in) check-in nudges and alerts.
  • To keep the service secure: malware scanning, rate limiting and account lockout, the audit trail, and diagnosing errors.
  • To meet legal obligations when they apply.

We do not use the contents of your documents to train advertising or third-party machine-learning models.

3. OCR and automated text extraction

To make documents findable and to suggest details like an expiry date, we run optical character recognition (OCR) on uploads and read the resulting text. This runs on our own infrastructure. Any suggestion the app produces is just a suggestion — it is never applied to your document until you confirm it.

4. How your documents are protected

Documents are encrypted with AES-256-GCM before they are written to storage, and all traffic is protected in transit with TLS. Passwords are hashed with Argon2id. You can read the full, honest breakdown on our Security page.

One point we state plainly there and here: encryption at rest is not a zero-knowledge design. Our servers hold the decryption key because they need it to show you your own documents, so we are not cryptographically prevented from accessing what is stored — the same as most hosted services. If that distinction matters for something you are about to upload, it is a reasonable thing to weigh. Separately, document titles, descriptions, and extracted text are kept unencrypted in our database so that search can work.

5. When information is shared

We share your information only in these situations:

  • With your family members, according to each document’s visibility setting and each member’s role — as you configure it.
  • With people you deliberately share with. When you create a share link, the named recipient can view the specific documents you selected, after proving they control the email address by entering a one-time code. You can revoke a share at any time.
  • With service providers (sub-processors) that help us operate, under contracts limiting them to that purpose — for example, our hosting and storage provider, an email delivery provider, our SMS provider (Twilio, only if you use phone check-ins), a payments provider (Stripe, only if paid plans are active), and the browser push services operated by Apple, Google, and Mozilla (only for notifications you enable).
  • When required by law, such as a valid legal request, or to protect the rights, safety, and security of users and the public.
  • In a business transfer, such as a merger or acquisition, in which case we will notify you and this policy will continue to govern your information unless you agree otherwise.

6. Your rights and controls

  • Export your data. From Settings you can download a ZIP of your family’s documents plus a machine-readable manifest — the honest answer to “what if ManagedFamily disappears?”
  • Delete your account. From Settings you can delete your account after re-entering your password. This removes your documents; families you solely own must first be transferred or deleted.
  • Access and correct. You can view and edit your account details and document metadata at any time in the app.
  • Depending on where you live, you may have additional rights (for example, under the GDPR or the CCPA) to access, correct, delete, or port your information, and to object to certain processing. Contact us to exercise them; we will not discriminate against you for doing so.

7. Retention

We keep your information for as long as your account is active. When you delete a document or your account, we remove it from the live service; residual copies may persist in encrypted backups for a limited period before those backups rotate out. Security and audit logs may be retained longer where needed for security or to meet legal obligations.

8. Children

ManagedFamily is designed for adults to manage a household’s documents, which may include documents about their children. Accounts are intended for adults; a “child” member is added and managed by an adult in the family. ManagedFamily is not directed to children for independent sign-up, and we do not knowingly let a child under 13 create their own account. If you believe a child has created an account without appropriate consent, contact us and we will address it.

9. International users

ManagedFamily is operated from the State of Michigan, United States. If you access it from elsewhere, your information may be processed in that jurisdiction, which may have different data-protection rules than your own.

10. Changes to this policy

If we make a material change, we will update the version and effective date above and, where appropriate, notify you in the app or by email. The version shown is also the version recorded against your account when you signed up, so you can tell which text you agreed to.

11. Contact

Questions or requests about your privacy can be sent to support@managedfamily.com. For security-specific reports, see our security.txt.