1. Scope and roles
This Policy applies to information processed through the Service and to our support and account communications. It does not govern a third party’s independent practices, such as your device maker, internet provider, Google, or Stripe. Their policies apply when you interact directly with them.
FAIM is the operator of the Service and determines how information is processed to provide it. The adult account holder selects which devices to configure, assigns devices to household or family-member profiles, chooses filtering rules, and controls which family analytics are reviewed.
2. Information we collect
Account and contact information. We collect the account email address and information returned by the sign-in method you choose, which may include a display name or profile image. We also collect messages you send to support.
Household, family, device, and settings information. We collect household and family-member names or labels, device names and platforms, device-to-family-member assignments, time zone, setup status and tokens, filtering preferences, category and website rules, Safe Search settings, and related configuration details.
DNS and network activity. When a configured device uses the Service, we receive information needed to resolve, filter, secure, and explain DNS requests. This may include:
- The domain or hostname requested and the date and time.
- Family and device identifiers and the source IP address.
- DNS record type, connection protocol, request identifier, response time, and related routing or endpoint information.
- Whether a request was allowed, blocked, or rewritten; the applicable rule, reason, or category; and any Safe Search action or destination.
DNS information does not ordinarily include the full webpage URL or path, page contents, messages, passwords, files, exact search text typed into an encrypted webpage, or actions taken inside an app. A domain or hostname can nevertheless reveal sensitive interests or suggest that a person or device contacted a particular service.
Family analytics and inferences. We derive allowed and blocked activity, site and category summaries, likely-activity signals, grouped activity moments, recent-activity stories, weekly reports, protection notices, and longer-term family insights from DNS records and the assignments selected by the account holder. Analytics linked to a family, family member, account, or device remain personal information under this Policy even when they summarize many requests.
Billing information. Stripe receives payment card details directly. We do not store full card numbers. We receive subscription and transaction records such as Stripe customer and subscription identifiers, status, billing period, cancellation status, and payment-failure information.
Consent and authorization records. We may record that an adult account holder accepted our Terms and Privacy Policy, represented that they have authority over configured devices and family profiles, selected an age band, received a parental notice, or provided parental consent. These records may include the policy and notice versions, the consent language displayed, date and time, account and payment-verification references, IP address, and browser or device information.
Website, app, and security logs. Our servers and infrastructure providers receive standard technical information such as IP address, browser or device type, request time, authentication and session events, pages or endpoints requested, and security or error logs. We use necessary cookies and similar storage to authenticate users, maintain sessions, prevent abuse, and remember essential settings.
3. How we use information
We use information to:
- Resolve and filter DNS requests and apply family and device settings.
- Detect whether setup is working and provide device-configuration support.
- Show allowed and blocked activity, family analytics, weekly reports, and longer-term insights requested by the adult account holder.
- Create and maintain accounts, authenticate users, manage subscriptions, and process support requests.
- Maintain, troubleshoot, secure, monitor, and improve the reliability and clarity of the Service.
- Prevent fraud, abuse, unauthorized access, and violations of our Terms.
- Comply with law, enforce agreements, and protect the rights and safety of people and the Service.
We do not use family DNS activity for targeted or cross-context behavioral advertising, data-broker products, credit or eligibility decisions, or unrelated marketing profiles. The family analytics do not make decisions that have legal or similarly significant effects.
4. What family analytics can and cannot show
DNS requests may be generated by background synchronization, notifications, operating-system services, advertising, browser retries, or a shared device. A classification or family insight is an estimate based on the signals the Service received. It does not prove who held a device, what a person viewed, what occurred inside a website or app, intent, exact screen time, attention, or harm.
We may combine or de-identify information to understand reliability, capacity, classification coverage, and general Service use. We keep de-identified information in that form and do not use it to build unrelated profiles of a person or family.
5. Children’s information and parental choices
Only an adult may create or administer an easyfamilyfilter account. The Service nevertheless processes data from configured devices that may be used by children. Collection from a child-used device is passive: the device sends DNS requests as part of ordinary internet use after an adult installs or enables the configuration.
A device that the account holder identifies as belonging to a child under 13 may not be activated until we have provided direct notice and obtained verifiable consent from a parent or legal guardian where required. The notice describes the categories in Section 2, the uses in Section 3, and the service-provider disclosures in Section 6. We may use a payment transaction or another legally accepted method and take reasonable additional steps to verify that the person giving consent is the child’s parent or legal guardian.
A verified parent or legal guardian may:
- Ask what categories of information we collected from the child.
- Review or request a copy of the child’s personal information.
- Ask us to correct or delete it.
- Refuse further collection, use, or maintenance and withdraw consent.
Withdrawing consent means we will stop processing the child’s information for the affected profile or device and may terminate that portion of the Service. The adult must remove or replace the device’s DNS configuration; stopping the account alone may not remove it remotely and leaving it installed may interrupt connectivity.
The account holder must have legal authority to configure each device and act for each child identified in the account. If you believe a device was configured without appropriate authority, contact us promptly. We will verify the request and take appropriate steps, which may include disabling collection and deleting information.
6. How we disclose information
We disclose information only as reasonably necessary to provide the Service, at your direction, or for the limited legal and business purposes below.
Service providers. Providers may process information on our behalf for cloud hosting, DNS routing, databases, authentication, email, payments, security, error diagnosis, and support. Material providers currently include Supabase for account, authentication, database, and session services; Stripe for billing; Google when you choose Google sign-in; and hosting, network, and database infrastructure providers used to operate the dashboard and DNS Service. We require providers that handle personal information on our behalf to protect it and use it only for the services they provide to us, subject to their applicable terms and our agreements.
AI-assisted domain classification. In a limited operator-assisted workflow, we may send registrable domain names and limited aggregate operational metadata, such as aggregate query and household counts or first- and last-seen time ranges, to Anthropic’s Claude service to help assign a general domain category. That workflow does not include account or family-member names, family or device identifiers, source IP addresses, or the underlying raw DNS event rows. Anthropic receives no field connecting a submitted domain to a particular customer, child, household, or device. The resulting category is associated with the domain for use across the Service; it is not a judgment about a particular child or household.
Legal, safety, and integrity. We may disclose information if we reasonably believe it is required by valid legal process; necessary to protect a person from danger of death or serious physical injury; or reasonably necessary to protect the rights, security, and integrity of the Service, investigate fraud, or enforce our Terms. We evaluate demands and provide notice when legally permitted.
Business transfers. If FAIM is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to this Policy and applicable law. We will provide notice before personal information becomes subject to materially different practices.
With your direction or consent. We may disclose information for another purpose when the authorized adult account holder directs us or provides consent and the disclosure is permitted by law.
7. No sale, data brokerage, or targeted advertising
We do not sell or rent personal information, exchange it for money or other valuable consideration, or share it for cross-context behavioral advertising. We do not serve targeted advertising based on DNS activity, permit advertising networks to collect family DNS activity through the Service, or provide personal information to data brokers. We have not sold or shared personal information for targeted advertising during the preceding 12 months. We do not monetize children’s personal information.
8. Retention and deletion
We keep personal information only for the time reasonably necessary for the purpose described in this Policy, subject to the following rules:
- Raw DNS query events: deleted from active telemetry systems on a rolling basis no later than 90 days after collection.
- Family analytics and historical insights: retained while the account is active so the account holder can review recent and longer-term family patterns. Child-linked analytics are included in a verified child-deletion request. Historical reports may still show an earlier family-member name after that profile is renamed or removed unless you ask us to delete the associated history.
- Account, household, device, and configuration records:retained while the account is active and generally deleted from active systems within 30 days after a verified account-deletion request.
- Billing, consent, security, and legal records: retained only for the period required by applicable tax, accounting, fraud-prevention, dispute, and legal obligations.
- Backups: protected backups may retain deleted information for a limited period until overwritten through the normal backup cycle. If restored, deletion rules are reapplied.
- De-identified or aggregate information: may be retained longer when it cannot reasonably be linked to a person, family, household, account, or device. We do not attempt to re-identify it.
Canceling or allowing a subscription to lapse does not by itself request account deletion. Contact us if you want the account and associated information deleted sooner.
9. Your privacy rights
Subject to applicable law, an authorized account holder may request access to, correction of, deletion of, or a portable copy of personal information associated with the family account. You may withdraw consent, object to or restrict certain processing where applicable, and appeal a denial of a privacy request. A verified parent or legal guardian may exercise these rights for a child.
Submit a request to [email protected]. Tell us the account email and the request you are making, but do not email raw DNS history or passwords. We may verify your identity and authority before disclosing or deleting information. We generally respond within 45 days, or sooner when required, and will explain a permitted extension or denial. You may appeal a denial by replying to our decision with “Privacy appeal” in the subject line.
We will not discriminate against you for exercising a privacy right. Some information may be exempt from a request, such as records we must retain by law or need to protect security and the rights of others.
10. U.S. state disclosures
Residents of states with consumer privacy laws may have rights to know or access, correct, delete, and obtain a portable copy of personal information, as well as rights to opt out of sale, targeted advertising, or certain profiling and to appeal a denied request. We offer the core rights in Section 9 to U.S. customers even when a particular statute’s business-size threshold does not apply to us.
DNS activity and related categories can reveal or suggest sensitive interests. We use that information only to provide and operate the family filtering and analytics Service requested by the adult account holder, not to infer characteristics for advertising or to make eligibility decisions. Because we do not sell personal information or use it for targeted advertising, there is no sale or targeted-ad opt out needed for our current practices. We honor legally applicable browser-based opt-out preference signals.
Because DNS activity may reveal that a device sought health-related information or services, we also publish a separate Consumer Health Data Privacy Notice.
11. Security
We use administrative, technical, and organizational safeguards designed for the sensitivity of family DNS information, including encrypted connections, access restrictions, protected credentials, service monitoring, secure-development practices, and security requirements for providers. Personnel and administrator access is limited to legitimate operational, security, legal, and support needs.
No system is perfectly secure. We cannot guarantee that unauthorized access, loss, or disclosure will never occur. If an incident affects personal information, we will investigate and provide notices required by law.
12. United States availability and processing
FAIM is based in Utah, United States. The consumer Service is currently offered only to United States residents for devices used primarily in the United States. We may use billing-country information, account representations, and limited technical signals to enforce this restriction.
Information is primarily processed in the United States. Some service providers may process information in other locations where they operate, subject to their applicable terms and our agreements. If an eligible customer temporarily travels, information may continue to be processed as described in this Policy, but availability and operation outside the United States are not guaranteed.
13. Cookies and tracking choices
We use cookies and similar technologies necessary to authenticate users, maintain sessions, protect accounts, prevent abuse, and remember essential preferences. We do not use advertising cookies or cross-site behavioral tracking to monetize family activity. Browser “Do Not Track” signals do not have a uniform legal meaning; because we do not sell information or use it for targeted advertising, changing those settings does not alter our current practices.
14. Changes to this Policy
We may update this Policy. We will post the updated version with a new effective date and provide reasonable notice of material changes by email, in the Service, or another appropriate method. We will obtain new consent before a material change to children’s information practices when required by law.
15. Contact us
For privacy questions, parental requests, or requests about personal information, email [email protected].
FAIM LLC, Utah, United States.