Security
What Zamily does to protect your family's data — stated plainly, including what we don't do yet.
In transit
TLSProduction traffic between the app, the website and the API runs over HTTPS/TLS. Website pages use a Content-Security-Policy; the fictional demo explicitly allows version-pinned map software and basemap tiles. The local review preview is not a production service.
Passwords & sessions
argon2Passwords are hashed with argon2 — never stored or transmitted in a recoverable form.
revocationEvery session carries a token version. Changing your password or signing out all devices invalidates old sessions immediately, even if a token was copied.
auditAdministrative actions are written to an audit log with the acting account and timestamp.
Location data
Location is end-user data, and we treat it with that weight:
- Visible to your family and the people you choose through temporary links or connected-household grants. Paused sharing hides your position from those views.
- Public share links are view-only, expire automatically, and can be revoked at any time.
- History is deleted on a schedule, not hoarded — see the retention windows on the Privacy Center.
What we don't claim (yet)
Disk-level encryption at rest is not yet in place, so we don't claim it. Data at rest lives on our own managed servers with access restricted to the operator. Full disk encryption is on the roadmap — this page will be updated the day it's true.
We'd rather under-promise here than have a checkbox on this page that isn't real.
No ads. No trackers. No data sale.
We don’t sell your family’s personal information or provide it to advertisers for marketing. Google and other providers process technical data to deliver features, as described in the privacy policy. The marketing website offers optional anonymous referral counts; it has no advertising trackers.
Found a problem?
If you've found a security issue, email support@zamily.app with details. Responsible disclosure is welcome and credited.