GroupLock
Privacy Policy

Privacy should be a product rule, not a slogan.

This policy explains what GroupLock collects, why it is needed, who processes it, the choices you have, and how account deletion works.

Effective / version: 2026-08-07

1. Scope and who operates GroupLock

This Privacy Policy applies to the GroupLock website, mobile applications, messaging features, Family features, Organization features, and related support services. “GroupLock,” “we,” “us,” and “our” refer to the GroupLock service and the developer or legal entity identified as the publisher in the applicable app-store or product listing.

If you have a privacy or data request, use our Support & Privacy Request form.

2. Information we collect

Account and identity data

We process your email address, display name, optional phone number and bio, account role, email-verification status, legal-policy acceptance records, and account creation information. GroupLock does not currently accept arbitrary external profile-image URLs; first-party avatar uploads may be added later with privacy controls.

Authentication and security data

Password accounts store a one-way password hash rather than the plain-text password. GroupLock also processes sessions, password-reset and email-verification tokens, login-attempt records, and Google or Microsoft account identifiers when you choose those sign-in methods.

Communication and consent data

We process circles and their names/descriptions, invitations, inviter and invitee relationships, proposed and accepted membership, Accept/Decline states, messages, message timestamps, read/typing state, attachments, mute/archive preferences, and privacy-rule outcomes needed to deliver consent-based messaging.

People and privacy controls

We process contacts you add to GroupLock, trusted and blocked people, Safe Circles, invite rules, spam-filter preferences, reports, and other privacy settings you configure. People discovery is intentionally limited: partial-email/domain enumeration is not supported, displayed email addresses are masked, and Invisible Mode users are excluded from discovery unless they have chosen to include the viewer in their contacts.

Family and Organization data

For Family features, we process plan ownership, membership invitations, accepted members, pending consent, roles, and Family settings. For Organizations, we process organization identity, teams/departments, roles, membership invitations, organization circles, policy settings, and administrative audit records.

Billing data

For web subscriptions, Stripe processes payment details. GroupLock stores billing identifiers and subscription status such as Stripe customer, checkout, and subscription identifiers, plan type, and current billing period. GroupLock does not need to store your full payment-card number. Native iOS/Android store purchases will use the applicable platform-approved billing flow when that purchase path is enabled.

Push, files, and support

When you enable notifications, we store the device/browser push subscription needed to deliver alerts. Uploaded files are stored in GroupLock’s configured cloud object storage. Message attachments are delivered through GroupLock access checks tied to conversation membership. The production storage bucket must also be configured without direct public-read access so the application authorization layer cannot be bypassed with a raw object URL. If you contact support, we process the email address, category, message, status, and timestamps needed to handle the request.

3. How we use information

  • Authenticate accounts, verify email ownership, and secure sessions.
  • Show invitations before access and enforce Accept/Decline decisions.
  • Deliver messages, attachments, notifications, Family/Organization features, and requested account settings.
  • Apply blocking, trusted contacts, contacts-only rules, anti-spam settings, and other privacy choices.
  • Process subscriptions, maintain entitlement state, and prevent overlapping or unauthorized billing.
  • Investigate safety reports, abuse, spam, unauthorized access, or technical problems.
  • Comply with applicable legal obligations and enforce GroupLock’s Terms.

4. Consent decisions and visibility

GroupLock is designed so an invitation is not the same as membership. A pending invite may show the group creator, purpose, and proposed participants so you can make an informed decision. You do not receive active conversation access until you accept.

Blocking is intentionally treated as a private safety choice. Where technically supported, GroupLock avoids creating a visible decline record merely because the inviter is blocked.

5. Messages are not currently represented as end-to-end encrypted

Important: GroupLock does not currently claim that chat content is end-to-end encrypted. The service and infrastructure providers must be able to process message and file data as necessary to store, transmit, secure, moderate, troubleshoot, and operate the service.

Use appropriate judgment before sharing highly sensitive information. If GroupLock later introduces a different encryption model, this policy and the product disclosures will be updated before that model is represented to users.

6. Service providers and data disclosures

We use service providers to operate GroupLock. Depending on the feature you use, these may include Floot-managed application, database, authentication, push, and transactional-email infrastructure, Cloudflare R2-compatible object storage for uploaded media, Stripe for web billing, and Google or Microsoft for optional identity-provider sign-in.

We may also disclose information when reasonably necessary to protect users or the service, investigate abuse, comply with valid legal process, or complete a business transaction subject to appropriate protections.

GroupLock does not currently use third-party advertising networks or sell personal information for advertising.

7. Retention and deletion

We generally keep account and service data while your account remains active and as needed to provide the feature for which it was collected. Some temporary security records and tokens expire automatically.

You can initiate permanent account deletion in Settings → Delete account. The deletion process is designed to cancel GroupLock-managed Stripe billing where applicable, remove the user’s uploaded-media prefix, remove authentication links, and delete/cascade associated GroupLock account records. If required external cleanup cannot be confirmed, GroupLock stops the destructive deletion rather than knowingly leave active billing or orphaned media.

Some safety records created by other people may remain in de-identified or structurally necessary form after your account is deleted—for example, a report about a deleted account may remain while the direct user reference is removed. We may also retain information when required by applicable law or necessary to establish, exercise, or defend legal claims.

For an external browser-accessible deletion path, visit Account Deletion.

8. Your controls

  • Accept or decline each group, Family, and Organization invitation addressed to you.
  • Manage trusted/blocked people, contacts-only invites, auto-decline, visibility, anti-spam, and other available privacy settings.
  • Enable or disable push notifications through device/browser controls and GroupLock settings.
  • Update profile information and leave groups or Family memberships where supported.
  • Manage web subscription billing through the Stripe billing portal when the subscription is Stripe-backed.
  • Delete your account and associated data through GroupLock settings.

Depending on where you live, applicable law may provide additional access, correction, deletion, portability, objection, or appeal rights. Submit a privacy request to exercise a right that is not already available in the product.

9. Security

GroupLock uses technical and organizational controls appropriate to the service, including account sessions, email verification, password hashing, permission checks, signed webhook verification, server-side entitlement checks, and access-control rules. No system can guarantee absolute security, and users should protect their credentials and devices.

10. Children and minors

GroupLock’s general direct-to-consumer account flow is intended for users age 13 and older. We do not currently enable independent accounts for children under 13 through the general account flow.

Schools or other organizations must not deploy GroupLock for children under 13 until GroupLock has enabled a documented child-specific authorization/privacy process appropriate to that deployment. GroupLock does not claim that the current general account flow satisfies COPPA, FERPA, or every school/student privacy requirement.

If you believe a child under 13 created an account through the general flow, submit a privacy request.

11. International processing

GroupLock and its service providers may process information in locations different from where you live. Where applicable law requires protections for cross-border data transfers, the responsible parties will use legally recognized safeguards appropriate to the transfer.

12. Changes to this policy

We may update this policy as GroupLock changes. The version date appears at the top of this page. If a change is material enough to require renewed agreement or acknowledgment, GroupLock’s versioned legal-consent system can require signed-in users to review the updated documents before continuing to protected features.

13. Contact

For privacy, deletion, billing, or safety questions, submit a request through GroupLock Support. The publisher/developer identity for the commercial release will also be identified in the applicable app-store or product listing.