Privacy policy
DRAFT for legal review before launch. Last updated 4 October 2026.
Who we are
[Company name, address, contact email]. We are the controller of the personal data described here under UK GDPR.
What we hold
- Your account: email, name, password hash (or the Google / Microsoft identity you signed in with).
- Your household: member names and roles, people profiles (names, colours, optional birthdays), chores, lists, meals, recipes.
- Calendar events from the calendars you connect, and events you create here: titles, times, locations, notes.
- Photos you upload for the screensaver, and letters, PDFs and emails you scan.
- Technical data: paired screens and when they last connected; push notification subscriptions.
A family calendar inevitably contains information about children. We collect only what the features need, use no advertising, do no profiling, and never sell data.
Google and Microsoft calendar data
If you connect a Google or Microsoft calendar we access only the calendar data needed to show your events and, for Google two-way sync, to write events you create here. We use it only to provide the calendar to your household. We do not use it for advertising, we do not transfer it to others except our processors below, and humans at our company do not read it except with your consent for support or where legally required. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Access tokens are encrypted at rest and can be removed any time by disconnecting the account in Settings, which also deletes the synced events.
AI scanning
When you scan a letter, the image or text is sent from our servers (never from your device) to Anthropic's API to extract dates and items. [Confirm: provider, processing region, zero-retention terms and that data is not used for training.] The source file and drafts are deleted after 30 days, and unreviewed drafts after 7 days. Nothing is added to your calendar until you approve it. We do not log the content of scans.
Where data lives
Our database and file storage are hosted in the UK (London, AWS eu-west-2) via Supabase. Other processors: Vercel (hosting), Resend (email), Stripe (payments), PostHog (product analytics, no calendar content), Sentry (error reports, no personal data).
Why we use it (legal basis)
To provide the service you asked for (contract); to keep it secure and fix problems (legitimate interests); to send security notices and renewal reminders (legal obligation and contract); optional notifications and analytics where you choose them (consent).
Children
Children can have a household profile and, with a parent's invitation, a limited login that can tick chores but cannot delete events. Accounts for children are created and controlled by an adult in the household. High-privacy defaults apply: no public profiles, no contact with strangers, no location tracking.
How long we keep it
While your account exists. Deleting your account in Settings deletes your household's data. Change history is kept for 14 days for sync. Backups roll off within 35 days.
Your rights
You can download all your household data and delete your account yourself in Settings, and you can ask us to correct or restrict data. You may complain to the ICO (ico.org.uk).
Contact
[privacy contact email]