Service transparency

Third-Party Data Recipients.

Companies and recipient categories that may process personal information to help Ivy provide, protect, and improve the service.

Why providers receive data

Ivy relies on a limited set of platform and infrastructure providers. They receive only the information reasonably necessary for the function they perform, subject to contracts and applicable law.

1. Overview

This page supplements the Ivy Privacy Policy. A “recipient” may be a service provider processing information for Ivy, another user you intentionally communicate with, or an entity that receives information for a legal or business reason.

The exact information disclosed depends on your device, settings, location, and the features you choose. Not every provider receives information about every user.

2. Current platform and service providers

ProviderPurposeInformation that may be processed
Apple Inc.Sign in with Apple, App Store distribution and purchases, Apple Push Notification service, Apple Maps and device platform functionsApple account token or relay email, app and device identifiers, notification token and payload, transaction status, location searches you request
Amazon Web Services, Inc.Cloud infrastructure, application hosting, network delivery, backup, and private media/object storageAccount and service data stored by Ivy, uploaded media, IP address, request and security logs
Google LLC (Firebase Crashlytics)Crash reporting, diagnostics, stability monitoring, and troubleshootingApp version, device and operating-system details, crash traces, diagnostic identifiers, and technical event data

Apple and Google may act as independent controllers for information they collect directly through their platforms. Their own privacy notices explain those practices.

3. Other recipient categories

  • Other Ivy users: information you intentionally share in a family, community post, group, event, message, or marketplace listing is disclosed to the audience you select or the feature's intended participants.
  • Professional advisers: lawyers, auditors, insurers, accountants, and security specialists may receive limited information when necessary to protect Ivy or comply with obligations.
  • Authorities and safety recipients: courts, regulators, law enforcement, emergency services, or affected parties may receive information where required by law or reasonably necessary to protect rights, safety, and security.
  • Business transaction recipients: a potential or completed buyer, investor, lender, or successor may receive information in connection with a merger, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards.

If Ivy introduces a material new provider or processing purpose, we will update this page and provide any additional notice required by law.

4. How we protect disclosed information

We evaluate providers based on their function and risk. Where appropriate, we use contractual confidentiality, security, data protection, retention, deletion, and incident-notification terms. We also limit access, separate production roles, and use technical controls designed to protect data in transit and at rest.

No provider or security measure can eliminate all risk. Users should avoid posting sensitive information in public or shared areas unless it is necessary.

5. International processing

Some providers may process information in the United States and other countries where they or their subcontractors operate. Privacy and data-protection laws may differ by location. Where required, Ivy uses recognized transfer mechanisms and contractual safeguards.

Questions about a recipient?

Email privacy@ivyfamilyhub.com. Tell us which feature or recipient you are asking about so we can provide the most useful response.

Last updated August 21, 2026