← Family Farms Forever
Security & Privacy Commitment
Last updated July 26, 2026 · Family Farms Forever LLC
Our apps help people learn, eat local food, follow local news, track golf, understand government, and explore energy. That only works if people trust us with their data. This page describes practices we actually implement (Firebase/Google Cloud platform security, product access rules, payment design, and public policies). We do not claim certifications we have not completed.
Report a vulnerability
If you find a security issue in any of our products, email the product contact below (or info@farmooly.com). Please do not post exploits publicly. Good-faith research is welcome. We aim to acknowledge within 2 business days.
What we commit to — every app
- Encrypt data in transit and at rest using HTTPS for network traffic and Firebase/Google Cloud encryption-at-rest for hosted data stores.
- Signed-in access control — private records are protected with Firebase Auth and Firestore security rules so they are not left world-readable (including role links such as parent↔child or teacher↔class where the product provides them).
- We do not sell personal data to advertisers or data brokers. That is our product policy, not a claim about every third-party subprocessors' advertising products (see each app's Privacy Policy for processors we use).
- Minimize what we collect — only what the product needs to work.
- Card payments go through Apple, Google, and/or Stripe — our design is that full card numbers are not stored in our application databases.
- You can delete your account from the product (or by request) so your data is not trapped forever.
- Honest about AI — when AI helps draft content or answers, we say so; private records (especially children’s) are not open to public AI crawlers.
- Public machine-readable APIs are rate-limited (and, where keys are issued, usage-metered) so automated bulk access is constrained.
What we do not claim (yet)
World-class practices matter more than logos. We design to modern standards and will publish formal audits as the business scale warrants them.
- We do not currently advertise a completed SOC 2 Type II letter for every product.
- We do not run a paid public bug-bounty program yet (responsible disclosure is open).
- When a third-party pen-test or formal certification is complete for a product, we will say so on that product’s security page.
Product security pages
Each app has its own security page with product-specific details:
Contact
Family Farms Forever LLC · Building useful apps people can trust.