Family Fork · Effective date: 6 July 2026
The short version: Family Fork runs a secure cloud service — hosted in Australia — so your family’s meal plans sync across your devices. We collect the minimum we need to do that: who’s in your family and the meals, plans, and photos you create. A parent sets up and controls the family, including any children’s profiles. We store your data in Australia, we never sell it, and you can delete it at any time.
This Privacy Policy describes how Outpost Labs Pty Ltd (“we”, “us”, or “our”) collects, uses, stores, and protects information in connection with the Family Fork mobile application (“the App”). The App is available internationally. We are committed to protecting your privacy and handling your information responsibly and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where they apply to you, other data-protection laws including the European Union and United Kingdom General Data Protection Regulation (GDPR) and applicable United States privacy laws. Outpost Labs Pty Ltd is the controller responsible for your personal information.
By using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.
We collect only what we need to run a shared family meal planner. This falls into a few categories.
You sign in with Sign in with Apple. Apple gives us a unique identifier for your Apple account and, depending on what you choose to share at sign-in, your name and an email address (which may be a private Apple relay address). We use this to create and secure your account and to link you to your family. We never receive your Apple ID password.
To run your family’s plan we store: your family’s (menu) name, and for each member their display name or initials, role (parent or kid), an avatar colour, and an age or age indication used to order and label members. Parents create the family and its members, including child profiles (see Section 3).
The App stores the content you and your family add: meals and their details (ingredients, method, cook time, serves), weekly dinner and lunch plans, notes, meal preferences (“loves”), shopping lists, take-out details you enter, meal photos you upload, and recipe links or text you choose to import.
We receive your subscription and entitlement status (for example, whether your family has an active subscription or trial) so we can unlock features. Payment card details are handled by Apple — we never see or store them (see Section 6).
We collect limited technical information to keep the App working and to improve it: anonymous usage analytics, and diagnostic and crash reports (which may include device model, operating system version, and app version). This is described in Section 5.
We use the information above only to provide and support the App, specifically to:
We do not use your family’s content for advertising, and we do not use it to build profiles about you.
Family Fork is designed to be set up and administered by an adult, and to let children take part in family meal planning under a parent’s control.
Children do not create their own accounts. A child takes part through a profile that a parent or guardian creates and manages within the family. By creating a child’s profile, the parent or guardian confirms they have authority to do so and consents to our handling of that child’s information as described here. We do not knowingly allow a child under 16 to create their own Family Fork account independently of a parent.
Because the App is available internationally, the age at which a person may consent to their own use varies by country — for example, 13 in the United States (under COPPA) and between 13 and 16 across the EU and UK (under the GDPR). In every case, a child takes part only through a profile that a parent or guardian creates, manages, and consents to.
We practise data minimisation for children. A child’s profile holds only what the App needs to function — typically a first name or initials, an avatar colour, an approximate age, their role, and the meal preferences and suggestions they make in the App. A child’s role is restricted: children cannot access the shopping list or finalise plans.
Parents and guardians can review, edit, or delete a child’s profile and associated content at any time within the App, or by contacting us at privacy@outpostlabs.com.au. If you believe a child has provided us with information without appropriate parental involvement, please contact us and we will delete it.
Your account and family data — profiles, plans, meals, lunches, shopping lists, and meal photos — are stored on secure Amazon Web Services (AWS) infrastructure located in the Sydney, Australia region. Your data is also held on the devices of your family’s members so the App works and syncs.
If you use the App from outside Australia, your information will be transferred to and stored in Australia, and processed by our service providers as described in Section 5. Australia’s data-protection laws may differ from those of your own country. Where we transfer the personal information of users in the EEA or UK to Australia or another country, we rely on an appropriate safeguard (such as standard contractual clauses), another lawful transfer mechanism, or your consent.
Some of our service providers process limited information outside Australia in order to provide their part of the service (for example, analytics, subscription management, crash diagnostics, and recipe parsing). Where this occurs, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles, including APP 8 (cross-border disclosure). See Section 5 and Section 7 for detail.
We use a small number of reputable third-party services to run the App. We share only the minimum necessary with each, and none of them are permitted to use your information for their own purposes.
| Service | Purpose | What it handles |
|---|---|---|
| Apple (Sign in with Apple, App Store, StoreKit) | Sign-in identity and payment processing | Your Apple identifier and the name/email you choose to share; payment handled entirely by Apple. See Apple’s Privacy Policy. |
| Amazon Web Services (Cognito, DynamoDB, S3, CloudFront, Lambda) | Account identity, data storage, photo hosting, and app backend | Your account, family, plan, and meal data and photos, stored in the AWS Sydney (Australia) region. |
| Amazon Bedrock | Recipe parsing (Section 7) | The recipe text or page content you choose to import, processed transiently to structure it. |
| TelemetryDeck | Anonymous usage analytics | Anonymous, non-identifiable usage events. See TelemetryDeck’s privacy policy. |
| RevenueCat | Subscription management | An anonymous app-user identifier and your subscription/purchase status, to manage entitlements. See RevenueCat’s privacy policy. |
| Sentry | Crash and error diagnostics | Diagnostic and crash data such as device model, OS version, and error details, to help us fix problems. See Sentry’s privacy policy. |
We do not use advertising networks, ad-tracking SDKs, or social media tracking SDKs in the App.
Subscriptions are processed through Apple’s App Store using StoreKit, with entitlements managed via RevenueCat. We do not collect, process, or store your payment card details — all payment is handled by Apple under Apple’s Media Services Terms and Conditions. We receive your subscription status so we can unlock features for your family, and aggregate, non-identifying sales information.
When you choose to import a recipe by pasting a URL or recipe text, the App sends that content to an automated service (Amazon Bedrock) that converts it into a structured list of ingredients and method steps. The content is processed to produce this result and is not used to train the underlying models. This feature runs only when you choose to import a recipe.
The App does not make any decision that has a legal or similarly significant effect on you through automated means. This disclosure is provided for transparency, including in light of the automated-decision-making transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth).
Photos you add to a meal are uploaded to our storage (AWS S3, Sydney region) and served back to your family’s devices via a content delivery network (CloudFront). They are used only to display that meal within your family. You are responsible for ensuring you have the right to upload any photo, and for the consent of anyone identifiable in it — including, for a child, the consent of their parent or guardian. You can delete a photo at any time within the App.
We do not sell, rent, or trade your personal information. We share information only:
We keep your family’s data for as long as your account and family remain active, so the App works across your devices and members. You control your data:
When you delete data or your account, we remove it from our active systems. Residual copies may remain in encrypted backups until they are overwritten in the ordinary course of our regular backup-rotation cycle. We may also retain the minimum information required to meet a legal obligation for as long as that obligation requires, after which it is deleted or de-identified.
We take reasonable steps to protect your information, including:
No method of transmission or storage is completely secure, but we work to protect your information and to keep our practices up to date.
If a data breach occurs that is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires. For users protected by the EU or UK GDPR, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals where the breach is likely to result in a high risk to their rights.
Under the Australian Privacy Principles, you have rights in relation to your personal information. You can:
If you are in the EEA or UK, you also have the right to object to or request restriction of certain processing, the right to data portability, and the right to withdraw consent at any time (without affecting processing already carried out). If you are in California or another US state with an applicable privacy law, you have the right to know what personal information we collect and to request its deletion; we do not sell your personal information or share it for cross-context behavioural advertising. To exercise any of these rights, contact us at privacy@outpostlabs.com.au.
For a child’s information, these rights are exercised by their parent or guardian.
We are committed to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth). While Outpost Labs Pty Ltd may currently fall within the small business exemption under the Privacy Act, we have chosen to handle personal information in accordance with the Australian Privacy Principles regardless, because the App involves families and children and because we believe it is the right standard to hold ourselves to. In particular, we collect only what we need, store account and family data in Australia, are transparent about our practices, give you control over your data, and take reasonable steps to keep it secure.
Where the EU or UK GDPR applies to you, we rely on the following legal bases to process your personal information: performance of a contract (to provide the App and sync your family’s plans), our legitimate interests (to secure, maintain, and improve the App, balanced against your rights and freedoms), consent (which a parent or guardian provides for a child’s participation, and which can be withdrawn), and compliance with our legal obligations. You may withdraw consent or object to processing based on legitimate interests as described in Section 12.
If you have questions about this Privacy Policy or our privacy practices, or wish to make a privacy request or complaint, please contact us:
Outpost Labs Pty Ltd
Email: privacy@outpostlabs.com.au
Melbourne, Victoria, Australia
We will acknowledge and respond to privacy complaints within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). If you are in the EEA or UK, you may also lodge a complaint with your local data protection supervisory authority.
We may update this Privacy Policy from time to time to reflect changes in our practices, the App’s features, or applicable laws. When we make changes, we will update the “Effective date” at the top of this page. If we make material changes that affect how we handle your information, we will notify you through the App or via an app update.