The short version
- Without an account, nothing leaves your device. Ever.
- With an account, we store your email, your schedule and your appointments so they can appear on your other devices.
- We do not sell your data, and there are no analytics, trackers or advertising in this app.
- You can delete your account and everything in it from the Settings tab, without asking us.
1. Who is responsible
AibhlinnAI, ABN 70 810 791 817, of South Australia, Australia, is responsible for the personal information described here. Contact: support@aibhlinn.ai.
2. If you do not create an account
The app works fully offline. Your schedule, appointments and settings are stored only in your browser's local storage on that device. We cannot see them, and no request carrying them is ever sent anywhere.
There is no sign-up wall, no email capture, and no tracking on the free version.
3. If you create an account
We then store:
- Your email address — to sign you in and to contact you about your account.
- Your weekly schedule and appointments — so they appear on your other devices.
- Your settings — theme, alert preferences and so on.
- Push subscription details and your time zone — only if you switch on alerts for when the app is closed, so we know when and where to send them.
- Subscription status — whether you are on a trial, paying, or have complimentary access.
We do not store your name, your location, your device identifiers, your browsing behaviour, or anything you do outside this app.
4. If you connect a calendar
This is the most sensitive thing the app touches, so it is worth being precise.
Connecting a calendar gives us read-only access. We fetch it on a schedule, take the title, start and end of upcoming events, and store those so your next appointment can be shown. Nothing in this app can create, alter or delete anything in your calendar.
To do that we hold either a private iCal address or a Google refresh token. Both are effectively keys to that calendar. They are never sent back to your browser after you save them — the app can only see whether a calendar is connected, not the credential itself — and only our sync server can read them.
They are not encrypted at rest. They are held in our database, protected by row-level security and our hosting provider's disk encryption. We would rather tell you that than imply more protection than exists. You can disconnect at any time, which deletes the stored credential and, for Google, revokes our access at Google's end as well.
We only fetch events in a short window around today, and we delete stored events older than a day.
5. Where your data is held
Account data is stored with Supabase in the ap-southeast-2 (Sydney) region. Your schedule, appointments, settings and calendar data stay in Australia.
Two exceptions, so this is not misleading. Sign-in emails are sent through Resend, and your email address passes through their systems overseas to deliver them. If you pay, Paddle handles the transaction and holds your billing details under their own policy, also overseas. Neither of them receives your schedule, your appointments or your calendar.
6. Who else touches your data
| Who | What they get | Why |
|---|---|---|
| Supabase | Everything in section 3 and 4 | Database, sign-in and server functions |
| Resend | Your email address | Sending your sign-in link |
| Paddle | Billing details you give them directly | They are the seller; we never see your card |
| Only if you use Google sign-in or Google Calendar | Authentication and reading your calendar | |
| Cloudflare | An anonymised bot-check signal | Stopping the sign-in form being abused to email strangers |
| GitHub (GitHub Pages) | Your IP address and browser, in standard web server logs | Serving the app files to your device |
That is the complete list. We do not sell, rent or trade personal information to anybody, and we do not use it to train anything.
7. Sign-in protection
To stop the sign-in form being used to send unwanted email to other people, we count recent attempts. We store only a one-way hash of the email address and IP address involved, never the values themselves, and we delete those records after a day.
8. How long we keep things
- Account data — until you delete your account.
- Calendar events — a rolling window; older than a day is deleted automatically.
- Sign-in attempt hashes — one day.
- Billing records — held by Paddle under their policy, and for as long as Australian tax law requires.
9. Cookies and tracking
There are none. No analytics, no advertising pixels, no third-party trackers, no cross-site tracking. The app stores your settings in local storage and, if you sign in, a session token in your browser. That is all.
10. Your rights
You can, at any time and without contacting us:
- See and change everything we hold, from inside the app.
- Export it as a file, from Settings.
- Delete your account and all associated data, from Settings. This is immediate and cannot be undone.
If you would prefer we did it, or you want a copy in another format, write to support@aibhlinn.ai and we will respond within 30 days.
If you are in the EU or UK you also have the rights given by the GDPR, including objection, restriction and portability, and the right to complain to your local supervisory authority. In Australia you may complain to the Office of the Australian Information Commissioner.
11. Children
This app is not directed at children under 16. We do not knowingly collect their information. If you believe a child has created an account, tell us and we will delete it.
12. Data breaches
If personal information is exposed in a way likely to cause you serious harm, we will notify you and the relevant regulator as required by the Notifiable Data Breaches scheme, and we will tell you plainly what happened.
13. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.