Household boundaries first
Every household-owned record is designed to carry its household boundary, with relationships and access checks enforced beyond the interface.
Designed for household trust
Privacy is not a setting we add at the end. It shapes the account model, database boundaries, child participation, notifications, analytics, and every sensitive module we choose to build.
Every household-owned record is designed to carry its household boundary, with relationships and access checks enforced beyond the interface.
Content marked private to one adult is intended to remain inaccessible to other household adults, including administrators.
A child PIN will create limited, server-verifiable access. It will not simply hide adult controls while leaving adult authority active.
Planofam’s analytics will measure product health without collecting event titles, tasks, lists, child names, documents, finances, or precise location.
Managed-child protections
Children should be able to see what is next and take part in family routines without needing an email account or gaining access to household administration.
A guardian creates and manages the profile and capability preset.
Adult settings, billing, exports, invitations, and private adult content remain unavailable.
Age-appropriate wording and privacy-safe lock-screen content by default.
Data principles
We ask for an email address, consent, and optional broad household context so we can recruit useful beta groups.
Our public forms are not a place for sensitive household information.
Private beta
Help shape Planofam with your household. The private beta is free.