Privacy Policy

Last updated: 26.08.26

luvdfamily ("we", "us", "our") provides an app and website (the "Service") that helps separated or divorced parents ("Parent Users") co-parent, communicate, and track their children's achievements and wellbeing. This Privacy Policy explains what personal data we collect, why, how we use it, and the rights you and your children have.

This policy is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Information Commissioner's Office (ICO) Age Appropriate Design Code ("Children's Code"). If you access the Service from outside the UK, additional local laws (such as the US Children's Online Privacy Protection Act, COPPA) may also apply — see Section 11.

1. Who we are

luvdfamily is operated by LUVD Family, a company registered in England and Wales, registered address 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, company number pending.

Data Controller contact: hello@luvdfamily.com. Data Protection point of contact: hello@luvdfamily.com.

2. Who this policy covers

  • Parent Users — the adults who create accounts and use the Service to co-parent.
  • Children — where a Parent User adds information about a child (name, age, achievements, photos, notes, schedules). Children do not create their own accounts or log in directly unless we explicitly launch a child-facing feature, in which case this policy will be updated and additional protections applied.

3. What personal data we collect

From Parent Users directly:

  • Name, email address, phone number (if provided)
  • Account login credentials
  • Profile information you choose to add
  • Messages and communications sent through the Service to a co-parent
  • Custody/parenting schedule information you enter
  • Payment information (processed by our payment provider — we do not store full card details, see Section 7)

About children, entered by a Parent User:

  • Child's first name and age/date of birth
  • Achievements, milestones, notes, and photos added by a parent
  • Schedule and custody-related information relevant to that child

Automatically collected:

  • Device type, operating system, app version
  • IP address, general location (country/region level)
  • Usage data (features used, crash logs, session length) via analytics tools

We do not knowingly collect data directly from children, and children cannot register their own account.

4. Why we collect it and our legal basis

PurposeData usedLegal basis (UK GDPR Art. 6)
Creating and managing your accountName, email, login detailsContract (necessary to provide the Service)
Enabling co-parent communicationMessages, schedule dataContract
Recording and displaying child achievementsChild's name, age, achievements, photosConsent (from the Parent User) and Legitimate Interest (supporting the co-parenting purpose of the app)
Safeguarding and dispute preventionMessage logs, timestampsLegitimate Interest (protecting users and children; see Section 6)
Improving the ServiceUsage/analytics dataLegitimate Interest
BillingPayment dataContract
Legal complianceAny relevant dataLegal Obligation

Where we rely on consent (e.g. adding a child's photo or achievement data), the Parent User providing that consent confirms they have the legal authority (parental responsibility) to do so, and that they consent on the child's behalf per UK GDPR Article 8 / Children's Code requirements. See Section 5.

5. Special protections for children's data (ICO Children's Code)

We design luvdfamily with the "best interests of the child" as a primary consideration, in line with the ICO's Age Appropriate Design Code:

  • High privacy by default: child profile data (achievements, photos, notes) is visible only to the Parent Users explicitly linked to that child's profile — never public, never used for public-facing marketing.
  • Data minimisation: we only ask for what's needed to run the co-parenting features. We do not collect unnecessary data about children.
  • No profiling children for advertising: we do not use children's data for targeted advertising, and we do not sell or share children's data with third parties for marketing purposes.
  • No nudge techniques: the Service does not use design patterns intended to encourage children to hand over more data than necessary, or encourage extended use by children.
  • Parental responsibility verification: at signup, Parent Users confirm they hold parental responsibility for any child they add. We reserve the right to request evidence of this (e.g. in a dispute between co-parents about access).
  • Two-parent visibility model: where both parents are registered co-parents of the same child, both may see the child data added to that shared profile unless one parent's access has been restricted (e.g. due to a safeguarding concern, court order, or blocked account — see Section 9).
  • Retention limits: child data is retained only as long as necessary — see Section 8.

If we ever introduce features that children interact with directly, this Privacy Policy and our consent flows will be updated accordingly, with age-verification and parental consent mechanisms built in before launch (per UK GDPR Article 8, which sets the default digital consent age at 13 in the UK, with parental consent required below that age).

6. Sharing between co-parents

A core function of luvdfamily is enabling two (or more) parents/guardians linked to the same child to see shared information about that child. By adding a child to your account and linking a co-parent, you understand and agree that:

  • Achievement, schedule, and note data you add about a shared child may be visible to the linked co-parent(s)
  • Direct messages between you and a co-parent are visible to both parties (and may be retained for safety/record purposes, see Section 6a)
  • We are not a mediator or arbiter of custody disputes — where a legal dispute exists over access to a child's data, we may require documentation (e.g. a court order) before restricting or granting access

6a. Safety retention: because this app may be used in high-conflict co-parenting situations, we retain message logs for longer than typical chat data (see Section 8) so that, if needed, either parent can request a record for legal or safeguarding purposes. This is a legitimate interest basis for processing, balancing user safety against data minimisation.

7. Who we share data with

We share data only with:

  • Service providers who help us run the Service under data processing agreements (e.g. cloud hosting, analytics, payment processing, customer support tools)
  • Legal/safeguarding authorities, where required by law, court order, or where we have a good-faith belief it's necessary to protect a child's safety
  • A co-parent linked to the same child, as described in Section 6

We do not sell personal data or children's data to third parties, and we do not use children's data for advertising.

If any service provider is located outside the UK/EEA, we ensure appropriate safeguards (e.g. Standard Contractual Clauses) are in place for the international transfer.

8. How long we keep data

  • Active account data: retained while your account is active.
  • Message logs: retained for [3 years] after being sent, for safeguarding/record purposes described in 6a, unless you request earlier deletion and no legal reason exists to retain it.
  • Child data: retained while at least one linked Parent User maintains an active account; deleted or anonymised [X months] after both linked accounts are closed, unless legal retention is required.
  • Account closure: on request, we delete or anonymise your data within [30] days, except where we must retain it for legal, safety, or legitimate dispute-resolution reasons (in which case we'll tell you what's retained and why).

9. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you and your child's profile
  • Correct inaccurate data
  • Request deletion ("right to be forgotten"), subject to Section 8
  • Restrict or object to certain processing
  • Data portability (receive your data in a portable format)
  • Withdraw consent at any time (e.g. remove a child's photo)
  • Complain to the ICO (ico.org.uk) if you believe we've mishandled your data

To exercise any of these rights, contact hello@luvdfamily.com. We will respond within one month as required by law.

Where one parent restricts or removes access to shared child data, we may require supporting documentation (e.g. relevant court order) before acting, to avoid enabling misuse of the Service by one parent against another.

10. Security

We use industry-standard measures to protect your data, including encryption in transit, access controls, and regular security review of our hosting provider. No system is 100% secure, and we encourage you to use a strong, unique password.

11. International users

  • EU users: this policy also serves as our EU GDPR notice; our EU representative (if required) is [NAME/CONTACT].
  • US users: we comply with COPPA principles — we do not knowingly collect data directly from children under 13, and all child data is entered and controlled by a verified parent/guardian.

12. Changes to this policy

We'll notify Parent Users of material changes via email or in-app notice before they take effect.

13. Contact us

LUVD Family
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
hello@luvdfamily.com

If you're not satisfied with our response, you can contact the ICO at ico.org.uk or call 0303 123 1113.