Carbon Family

Beta privacy notice

Carbon Family privacy

This notice explains the privacy boundary for the Carbon Family iPhone beta. It supplements any account-level terms or notices shown during Carbon ID sign-in.

Last updated July 20, 2026

1. The short version

In configured private-sync mode, Carbon Family end-to-end encrypts sensitive family content before it leaves a family device. Carbon operates the service, but does not hold the family keys needed to read those encrypted payloads.

Carbon is not completely blind. We can access account, household, membership, child-profile, device-enrollment, and other control-plane metadata needed to operate and secure the beta. We can also observe metadata about encrypted relay traffic, such as timing, size, and routing.

2. Information Carbon can access

Depending on how your family uses the beta, the service may process:

  • Carbon ID account details used to authenticate adult guardians.
  • Family membership, role, invitation, child-profile, and device-enrollment records.
  • Device public keys, credential hashes, push-delivery registrations, and recovery workflow records.
  • Encrypted-envelope metadata needed to authenticate, route, retain, and remove ciphertext.
  • Security, abuse-prevention, availability, and support records needed to operate the beta.

Please do not send recovery codes, private keys, precise locations, or other sensitive family content in a support email.

3. End-to-end encrypted family data

The current private-sync path encrypts these categories for authorized family devices:

  • Current and historical location records, including speed and course when available.
  • Device health, battery state, low-battery events, and Place events.
  • The family Place library, alert subscriptions, and Place labels.
  • Profile photos.
  • Adult sharing policies and adult location records shared with children.

The relay stores ciphertext and independently wrapped keys. Authorized family devices verify signatures and decrypt locally. Generic Apple push notifications act as wake hints and are designed not to include a child, family, Place, location, battery level, or readable alert.

4. Location and notification permissions

A sharing phone needs iOS Location Services. Reliable background sharing requires the phone's user to grant Always access; Precise Location improves map and Place accuracy. Carbon Family is transparent about sharing status inside the app and does not promise reliable background tracking with only When In Use access.

Notifications are optional but are needed for readable family alerts. A selected profile photo is processed through Apple's system photo picker. Apple independently processes permission, Core Location, TestFlight, and push-notification data under its own terms.

5. How information is used and shared

We use accessible information to authenticate users, manage families and devices, route encrypted records, deliver generic wake notifications, prevent abuse, troubleshoot the beta, and respond to support requests. We do not use precise family locations or other encrypted family content for ads.

We may use infrastructure, authentication, database, and notification providers to operate the service. They receive only the information needed for their role. We may also disclose accessible records when required by law, to protect users or the service, or as part of a business transfer, subject to applicable obligations. We cannot disclose plaintext we do not possess.

6. Retention and deletion

Encrypted location history follows the family's selected 7 or 30-day retention window. Encrypted configuration and the control-plane records needed to keep a family operating may persist while the family or device remains active. Security and support records may be retained as reasonably needed for safety, fraud prevention, legal compliance, and service integrity.

Removing local data from one phone does not by itself remove records from another authorized family device or the service. Use Carbon Family's account and family controls, or contact support, for a deletion request. Some encrypted records may remain temporarily in backups or delivery queues before normal expiration.

7. Keys, recovery, and reinstalling

Family encryption keys are controlled by authorized devices. The app provides a Recovery Kit and can optionally synchronize a Recovery Code through iCloud Keychain when the user explicitly enables that option. Apple, not Carbon, controls iCloud Keychain availability and recovery behavior.

Carbon support cannot reconstruct a lost Recovery Kit or decrypt family data. Store recovery material securely and never send it to us.

8. Children and guardian-managed use

Carbon Family is designed for parent- or guardian-managed family use. A guardian initiates child-device setup, reviews the device identity, and controls family membership and sharing policies. Guardians are responsible for using the service consistently with applicable law and for explaining location sharing to family members in an age-appropriate way.

This supervised beta is intended for a parent or legal guardian setting up their own family. We do not represent guardian-led setup by itself as a substitute for any legally required verifiable parental-consent process. Additional children's-privacy, legal, and consent review remains a requirement before public launch.

If you believe a child is participating without appropriate guardian authorization, contact us promptly.

9. Security, limitations, and your choices

We use signed requests, device-bound credentials, end-to-end encryption, and privacy-safe diagnostics, but no beta or security system is perfect. Carbon Family is not an emergency service. Location, alerts, recovery, and delivery can be delayed or unavailable because of device settings, connectivity, operating system behavior, service outages, or beta defects.

You can change iOS permissions, adult sharing policy, Place subscriptions, history retention, and the family controls currently exposed by the app. A person can revoke app permissions at any time in iOS Settings. Complete lost-device revocation and family-wide stream-key rotation are not yet supported in this beta, and a local erase does not revoke another phone. Some choices reduce or stop functionality; revoking a permission does not automatically delete records already retained by the service or other authorized family devices.

10. Contact and changes

For privacy questions or requests, email [email protected]. We may update this notice as the beta changes. Material updates will be reflected here with a new date and, when appropriate, communicated in the app or beta release notes.