Calliary Privacy Policy
1. What we do not collect
We do not collect your name, phone number, email, address, date of birth, or any other directly identifying information. Because there is no company server, your events, diary, photos, decorations, and health-related records are never sent to us. We do not request the advertising identifier (IDFA) and include no third-party analytics, advertising, or crash-reporting SDKs.
2. Data stored on your device and in your iCloud
The following data is stored on your device and, if you use iCloud, synced to the private CloudKit database of your own Apple Account. It is encrypted per Apple's standards, and we have no access to it.
| Category | Items |
|---|---|
| Records | Events, repeat rules, reminder times, categories, D-Days, monthly to-dos, notes, daily diary text |
| Decorations | Placement of stickers, emoji, drawings, notes, and photos; photos you pick in the system photo picker; "custom stickers" cut out from your photos |
| Design | Saved Calendar Studio themes (palette, paper, ink, accent, font, icon set), display options |
| Cycle (opt-in) | Only if you turn it on in Settings: period dates, daily logs (symptoms, mood, discharge, basal temperature, notes), prediction settings. Off by default (Section 7). |
| Entitlement | Pro/subscription status derived from the App Store receipt; whether the invite gift was received and the CloudKit user identifiers of participants already counted (to prevent double counting; device only) |
Stored on the device only, never synced: app-lock setting, medication reminders (name, time, weekdays), scheduled local notifications, daily custom-sticker usage count.
3. Shared calendars
Sharing starts only when you invite someone and is carried out through Apple's iCloud sharing (CloudKit Shared Database). No company server is involved.
- What is shared: events in the calendars/categories you chose to share and the decorations on them are visible to participants, and participants' decorations are visible to each other. Unshared categories, diary entries, and settings are not shared.
- Participant info: a shared calendar stores each participant's chosen nickname and the share-participant identifier assigned by Apple. Other participants' Apple ID email or phone number is neither shown nor stored by the app.
- Co-decorating notifications: when someone decorates, Apple Push Notification service (APNs) wakes your device and the notification text is composed on the device. We do not send or store notification content.
- Cycle sharing (opt-in): only the scope you choose (next expected date only / cycle summary / full history) is shared. Daily details such as symptoms, mood, basal temperature, discharge, and notes are never shared at any scope.
- Stopping: owners can stop sharing or remove participants at any time; participants can leave at any time. A "lock" prevents new participants from joining.
4. Invite codes and QR
Creating an invite code stores one invite record in the Calliary public CloudKit database. The record contains the link information needed to join the share, an expiry time, and, if you set a password, its verification data. It contains none of your events, decorations, or diary. Codes are random strings; a code alone does not reveal whose calendar it is.
- Invite records expire 72 hours after creation and are then unusable and cleaned up.
- QR scanning uses the camera. Camera frames are processed on device only while reading the code and are never stored or transmitted.
- Saving an invite card image writes it to your Photos library (Section 6).
5. Importing from other calendars
Import is a one-time action you start yourself. Imported events are copied into your Calliary calendar and never sent to us. Calliary never modifies or writes back to external calendars.
- Apple Calendar: with your permission, events from the calendars you select are read.
- Google Calendar: only after you sign in to Google, events are read with the read-only scope (
calendar.readonly). The access token is discarded immediately when the import finishes or is cancelled and is never stored. No account link persists; you sign in again for the next import. - Calendar files (.ics): files you pick are parsed entirely on device.
Google user data (Limited Use)
Calliary's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used solely to provide the user-facing import feature, is never used for advertising, never sold or transferred to third parties, never transferred to any Calliary server, and never read by humans. Tokens are discarded when the import ends. You can revoke access at any time from your Google Account permissions page.
6. Device permissions: when and why
No permission is requested at first launch. Each is requested only when you turn on or tap the related feature, and declining leaves the rest of the app fully usable.
| Permission | When | Purpose and retention |
|---|---|---|
| Calendars | Import → "From Apple Calendar" | Read-only event import. Never writes to external calendars. |
| Camera | "Scan QR code" | Used only while reading an invite QR. No frames stored or sent. |
| Face ID / Touch ID | Settings → App Lock | Verifies you when opening the app. Biometrics are handled by the OS; the app receives only success/failure. |
| Health (read/write) | Settings → Health app sync | Exchanges cycle records with Apple Health (Section 7). |
| Health (steps, read) | Settings → Show steps | Shows that day's step count on screen only. Not stored, synced, or shared. |
| Location (while using) | Settings → Weather | City-level approximate location sent to Apple Weather (WeatherKit) only while fetching. Coordinates are not stored; only a weather icon per date remains. |
| Photos (add only) | Saving invite cards, stickers, calendar images | Adds the image you chose to save. Never reads your library. |
| Photo picker | Attaching photos, making custom stickers | Only photos you pick in the system picker reach the app. Cut-outs are processed on device (Apple Vision). |
| Notifications | First event reminder, cycle reminder, or medication reminder | Local notifications on the device. Cycle reminders use a masked wording on the lock screen by default. |
7. Cycle and health data
Cycle tracking is off by default and runs only if you turn it on. Records are stored as described in Section 2. Predictions and insights are computed on device, are for reference only, and are not medical diagnoses.
- Apple Health sync (opt-in): exchanges cycle records with the Health app (iPhone, iPad). Health data never leaves your device and your iCloud; we have no access.
- Deletion: "Delete all cycle data" in Settings immediately deletes all records, predictions, and scheduled reminders. Data written to Apple Health is managed and deleted separately in the Health app.
- Never used for ads or analytics: Calliary has no advertising or analytics. Health data is never sent to us for any purpose.
8. Purchases
Calliary Pro (monthly and yearly subscriptions, lifetime pass) is sold through Apple in-app purchase. Apple processes payment; we never collect or store card numbers or other payment details. The app checks entitlement, subscription, and free-trial status with the App Store to unlock features; this check happens between Apple and your device.
9. Widgets, Apple Watch, Mac
Home-screen widgets and the Apple Watch app share data with the app on the same device (or paired watch). Sync between iPhone, iPad, Mac, and Watch happens only through your own iCloud.
10. Export
Exporting a calendar or diary as PDF or image saves it only where you choose (Files, Photos, or the share sheet). Nothing is sent to us.
11. Retention and deletion
- We hold no user data, so there is no company-side deletion process.
- On-device data is deleted when you delete it in the app or delete the app. iCloud data can be deleted from iPhone Settings → Apple Account → iCloud → Manage app data.
- Shared-calendar data disappears for a participant when the owner stops sharing or the participant leaves.
- Invite records expire and are cleaned up after 72 hours.
12. Your rights
You can view, edit, and delete your records in the app at any time; stop sharing, remove participants, or leave; revoke location, health, camera, calendar, photo, and notification permissions in the Settings app; and revoke Google account access. Because we hold no personal data, access or correction requests to us do not apply, but any question can be sent to the contact in Section 16.
13. Children
Calliary is not directed at children under 14 and does not knowingly collect personal information from children. With no company server, no information, including age, ever reaches us.
14. International transfer and processors
We hold no user data and therefore transfer none abroad and engage no processors. Services you use may process data on servers outside your country under their own policies: Apple iCloud/CloudKit (storage, sync, sharing, invite records), Apple Push Notification service, Apple Weather (WeatherKit), Apple Health, App Store purchases, and Google Calendar import if you choose it.
15. Security measures
- Data is stored inside the Apple OS app sandbox and encrypted by Apple in iCloud storage and transit.
- App Lock (Face ID / Touch ID) requires verification each time the app opens.
- Google access tokens are used in memory only and never stored.
- No advertising, analytics, or tracking SDKs are included.
16. Provider and privacy officer
- Provider: Honeybee Mobility (꿀벌모빌리티), Republic of Korea
- Business registration no.: 797-03-03820
- Privacy officer: Representative, Honeybee Mobility
- Email: krausehaileydanielle@gmail.com
17. Changes
Changes are posted on this page with the effective date. Key changes in this revision (September 3, 2026): advertising (AdMob) clauses removed as advertising was dropped from the app; subscriptions and free trial added; invite code/QR section added; camera, Face ID, photo-add, steps, medication reminder, and export sections added; security and provider details expanded.