← Family Sentinel

Privacy Policy

Family Sentinel LLC, Texas · Effective: July 2026 · Contact: privacy@familysentinel.org

Plain-English summary: We read your loved one's incoming email only to spot fraud. Ordinary mail is never stored — only flagged threats are kept, for 14 days, as your evidence file, then deleted automatically. Our access is read-only by design: the permissions we request let us detect and alert, but make it impossible for us to send, delete, or alter mail, not just against the rules. We never sell data. You can leave and take everything with you.

1. Who we are

Family Sentinel LLC ("we"), a Texas company, provides fraud-detection and alerting services for families ("the Service").

2. What we collect

CategoryExamplesSource
Account dataNames, emails, phone numbers of the protected person and family contacts; billing informationYou
Monitored signalsIncoming email content (processed transiently)The services you authorize (Google/Microsoft read-only access). If we add optional monitoring of other signals in the future (for example voicemail or transactions), we will update this policy and ask for your consent first
Stored resultsRisk verdicts, category, plain-English reason, minimal evidence (sender, subject)Generated by us
Threat evidenceFull copies of messages flagged as suspicious or malicious — retained encrypted for 14 days for expert review and your evidence file, then automatically deleted. Ordinary (unflagged) mail is never stored. Never retained for minors' accountsGenerated by us
Service telemetryAudit logs of our own systems' accessGenerated by us
Website visits — advertising measurementWhen you arrive on this public website from one of our ads, the Reddit advertising pixel tells Reddit that a visit happened, and on which page. It receives your IP address, browser type, the page address, and a cookie Reddit sets in your browser. It runs on these public pages and on the one-time confirmation page shown after sign-up — never in the mobile app, never on your account dashboard or on any page that carries your private link, and never anywhere near monitored emailYour browser, on this website only
Red Cell game (optional)If you choose to join the game's leaderboard: the call sign you pick, your scores, the moment you agreed, and — only if you type one — your email address, stored encrypted. Held on a small, separate game system that contains nothing else and is not connected to customer accounts or monitored email. Other players see your call sign and score, never your email. Delete all of it at any time from the game's Leaderboard screenYou, in the game, after ticking the consent box
Mobile app — device dataA random identifier this app generates for your phone, and a push-notification tokenThe app on your device. Not a hardware serial, not an advertising identifier; it identifies the app installation so you can be signed out remotely and so alerts reach the right phone
Mobile app — what you send us to checkText you paste, or a photo you choose, when you ask "is this a scam?"You, only when you ask a question. Photos have their embedded metadata stripped before storage. Kept for 30 days so we can show you the answer in context, then automatically deleted; the plain-English answer itself is kept
Mobile app — crash diagnosticsThe type and location of a crash in the appGenerated by us. Filtered before it leaves your phone so it carries no email address, no sign-in token and no message content
Mobile app — breach check (optional feature)An email address you choose to check against known data breachesYou, only if you use this feature. Sent to Have I Been Pwned to answer the question, and not stored by us. Not yet enabled — this feature currently tells you it is not available until we turn it on
Mobile app — link and QR safety checkA web address you paste or scan to ask "is this link safe?"You, only when you check a link. The address's query string and any tracking portion are removed before it is sent to Google Safe Browsing to answer the question, and it is not stored by us beyond that check

We do not collect or store: passwords or credentials, ordinary email bodies at rest, bank statements, Social Security numbers, or health records.

3. How we use information — and Google user data specifically

We use the data described above solely to detect and alert on likely fraud targeting the people you enroll, to maintain the security and audit trail of our own systems, and for billing and support.

Google API Services — Limited Use disclosure. Family Sentinel's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Gmail data is used only to provide the user-facing fraud-detection features described here; it is never used for advertising; it is never sold; humans read messages only with the account holder's affirmative consent (our signed authorization), for security purposes, or as required by law; and Gmail data is never used to develop, improve, or train generalized artificial-intelligence or machine-learning models.

Email text is analyzed by Anthropic's Claude models via API under commercial terms; Anthropic does not train on API data. Processing is transient — content in, verdict out.

4. Sharing

Only with: (a) the family contacts the account holder designates (alerts); (b) service providers under contract that make the Service work — hosting, Anthropic, SMS delivery, Sentry (a crash-reporting processor that receives filtered diagnostics with no email address, sign-in token, or message content), Have I Been Pwned (only the address you submit, only if you use the mobile app's breach-check feature), and Google Safe Browsing (only the link you submit, only if you use the mobile app's link-check feature) — current list available on request; (c) law enforcement when legally required, or when we in good faith believe the protected person is the victim of a crime and the designated contacts consent. We never sell or rent personal information.

Advertising. We do advertise Family Sentinel, including on Reddit, and this public website carries Reddit's measurement pixel so we can tell how many people who saw an ad went on to visit or sign up. That is the whole of it. Nothing about a protected person, an enrolled account, or a monitored message is ever used for advertising or shared with an advertising platform — not an email address, not a verdict, not a name. The pixel is absent from your dashboard, from the enrolment and add-a-family-member pages that carry your private link, and from the mobile app entirely. The one customer page that carries it is the confirmation page shown once after sign-up, where it counts a completed enrolment and nothing else. You can switch it off for every site at once by enabling tracking protection in your browser, or by turning off ad personalisation in your Reddit account settings.

5. Security

Encryption in transit and at rest; per-client isolation with per-client encryption keys; read-only authorizations; least-privilege access; independent audit logging; a documented incident-response plan with a kill switch. Our founder is a professional Security Architect; a full security overview is available on request.

6. Retention

Flagged-threat evidence: 14 days, then automatic deletion. Verdict and alert records: 13 months, then deleted. The text or photo you send with an "is this a scam?" check in the app is deleted 30 days after we've answered it; the plain-English answer we gave you is kept. A check we have not yet answered is not deleted on a timer — we hold the payload until we can give you an answer, then the 30-day clock above applies. An address you check for breaches, or a link you check for safety, is not stored by us at all. On cancellation, all data for your household is deleted within 30 days with confirmation; backups age out within 14 days thereafter.

7. Your rights

Access, correction, deletion, and portability of your data — email privacy@familysentinel.org. We honor these rights for all customers regardless of statutory thresholds. You may revoke the Service's access to any connected account at any time, directly with the provider or by asking us. To delete your mobile app account specifically, see Delete Your Account.

8. Breach notification

If a breach affects your data we will notify affected contacts without unreasonable delay, consistent with Texas Business & Commerce Code §521.053, and tell you plainly what happened, what was and wasn't exposed, and what we are doing about it.

9. Children

Monitoring for household members under 18 is offered only with verifiable parental consent and operates in a restricted, metadata-only mode: no message content or attachments are ever retained for minors' accounts.

10. Changes

Material changes are announced by email 30 days in advance.