Separate data
How is each family's data kept apart?
Every family is a space of its own. On every request, before returning a single row of data, the server checks that the person is a member of that family and what their role allows.
- Checks happen on the server, not just on screen
- Every member sees only the families they were invited to
- Role permissions apply to every area: calendar, expenses, documents and more
How a request is handled
The request
Someone opens the calendar, a document or the list.
The server check
Are they a member of this family? What does their role allow?
The answer
Only the data their role allows is returned.
Roles and permissions
Who sees what?
The family owner gives every member a role and can change the default permissions in Settings. This is the table every family starts with.
- Can edit
- Can view
- No access
| Area | Owner | Adult | Teen | Child | Guest |
|---|---|---|---|---|---|
| Calendar | Can edit | Can edit | Can edit | Can view | Can view |
| Tasks | Can edit | Can edit | Can edit | Can view | Can view |
| Shopping list | Can edit | Can edit | Can edit | Can edit | Can edit |
| Reminders | Can edit | Can edit | Can edit | Can view | No access |
| Expenses | Can edit | Can edit | No access | No access | No access |
| Important dates | Can edit | Can edit | Can view | Can view | No access |
| Documents | Can edit | Can edit | No access | No access | No access |
| Goals | Can edit | Can edit | Can view | Can view | No access |
| Memories | Can edit | Can edit | Can edit | Can view | No access |
| Chat | Can edit | Can edit | Can edit | Can edit | Can edit |
| Contacts | Can edit | Can edit | Can view | Can view | Can view |
| Emergency info | Can edit | Can edit | Can view | No access | Can view |
| Members | Can edit | Can edit | Can view | Can view | Can view |
Scroll the table sideways to see every role.
- Owner
- Full control over the family, its members, roles and plan.
- Adult
- Manages everything in the family, from the calendar to expenses and documents.
- Teen
- Calendar, tasks, lists, reminders and memories. No expenses and no documents.
- Child
- Limited access: sees the calendar and tasks, adds to the shopping list and writes in the chat.
- Guest
- Temporary access, for example for a babysitter: sees the calendar, the list and the emergency info.
Documents
How are documents stored?
Files are kept in private storage with no public address. When someone opens a document, the server first checks their permissions and only then creates a link that works for 15 minutes. For every document, you choose who can see it.
Whole family
Every member who has access to documents.
Adults only
The owner and members with the Adult role.
Private
Only you and the person the document belongs to.
Accounts
How are accounts protected?
Passwords
Never stored as text. We keep only a scrypt hash with a unique salt, from which the password cannot be recovered.
Sessions
Sign-ins are kept with secure, HTTP-only cookies that scripts on the page cannot read.
HTTPS
All traffic between your device and Familja.si is encrypted.
Control
Your data, your decision
In Settings you can export your family's data and delete your account at any time. There is no need to write to us or to wait.
What we do not do
Some things we never do
- We do not show ads.
- We do not sell your data to anyone.
- We do not create public profiles, and nothing about your family is ever shown publicly.
Service emails
Reminders, invitations, password resets and the weekly summary are sent by email. These emails may include standard open and click measurement, which tells us whether they arrive. Password reset and invitation links are not measured.
Noticed a security issue?
Write to us through the contact page and choose the subject “Other”. We look into it with priority.
Go to the contact page