YOUR PRIVACY AT SKYCAL

Clear answers.
Peace of mind.

Privacy policy

Effective September 13, 2026

SkyCal is a household calendar web app for shared calendars, profiles, tasks, meals, recipes, reminders, and sleep logs. This policy explains what SkyCal collects, why it is requested, and how it is used.

Information SkyCal Collects

When you sign in with Google or Microsoft, SkyCal receives your account identifier, name, email address, email verification status, and profile image. SkyCal uses this information to create your account, show who is signed in, link your account to a household profile when you choose, and protect shared calendars from unauthorized access.

SkyCal also stores the content you create in the app, including calendar names, invite codes, profiles, local events, tasks, shopping items, meals, recipes, sleep logs, notification settings, theme settings, profile preferences, and account-to-profile links.

Microsoft Outlook Calendar Data

Connecting Outlook Calendar is optional and separate from signing in. SkyCal requests permission to read and write your Microsoft calendars. Only calendars you choose are synced to your household, where other household members can see their events. SkyCal stores refresh credentials privately on its server to maintain your connection. It reads event details and changes or deletes Outlook events when you request those actions. Microsoft may notify meeting attendees after you confirm a meeting change. Disconnect the account in Settings to remove its stored credentials.

Outlook sync includes the previous three months and the next year while SkyCal is open. Recurring events appear as individual occurrences; manage series rules in Outlook.

Google Calendar Data

Connecting Google Calendar is optional. If you connect it, SkyCal requests Google Calendar access so it can show synced events inside SkyCal, keep selected calendars up to date, and create, update, or delete Google Calendar events only when you ask SkyCal to perform those actions.

SkyCal may read calendar lists, event titles, event times, event locations, event notes, and event identifiers needed for sync. SkyCal stores sync identifiers so the same event can be updated or removed later. SkyCal does not use Google Calendar data for advertising, does not sell Google user data, and does not use Google user data to train AI or machine learning models.

SkyCal's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

How SkyCal Uses Information

SkyCal uses your information to sign you in, display the correct household calendar, sync data across your devices, let invited members collaborate in a shared calendar, show profile-specific schedules, send reminders you configure, support offline use, and preserve your app settings.

The SkyCal assistant is a managed service run by SkyCal. When you send the assistant a request, your prompt and the household data you have allowed it to read are sent from SkyCal's own server to the model provider SkyCal has configured, currently either OpenAI or Anthropic, using SkyCal's own provider account. You do not supply a model provider key, and your browser does not contact the model provider directly. Assistant use is metered: SkyCal records the token counts and the cost of every run so usage can be counted against the monthly allowance for your plan.

You choose which categories the assistant may read. The categories are profiles, events, tasks, lists, meals, recipes, scrapbooks, sleep logs, rewards, and settings. Only the categories you select are sent. Photo files, API keys, invite codes, and PIN hashes are removed before anything is sent to the model provider, and scrapbook pages are reduced to their text layers. Changing your selection cancels any request that was already reading a category you removed.

If you import a recipe from Instagram, TikTok, or a website, SkyCal sends the link you paste to Apify, which fetches the public post and its video on SkyCal's behalf. SkyCal's import worker then sends the video, the post description, or the webpage HTML to Google Gemini to extract the recipe. If Apify is unavailable, the worker downloads the public video directly instead. The extracted recipe and its media are stored with the recipe in your shared calendar.

Location And Weather

The weather panel asks your browser for your precise location using the standard browser location prompt. Your latitude and longitude are sent to Open-Meteo for the forecast and to OpenStreetMap Nominatim to turn those coordinates into a place name. If your household has entered its own Google API key, the same coordinates are also sent to the Google Weather API and the Google Geocoding API. SkyCal does not write your coordinates to the shared database. The most recent weather result, including the resolved place name, is cached in your own browser. Declining the location prompt turns the weather panel off and does not affect the rest of the app.

Optional Luna Voice And Wake Listening

Wake listening starts only when you enable it. It uses on-device speech recognition when available; otherwise, with your confirmation, your browser's speech service may send microphone audio to Apple or Google for recognition. SkyCal discards ambient wake-listening transcripts rather than saving them. After "Hey Luna", or when you tap the conversation microphone, your request and conversation audio are sent through SkyCal to OpenAI. Luna's spoken replies are AI-generated. Conversation transcripts are saved in your Luna chat history, and voice usage counts toward your allowance.

Wake listening has no app-imposed duration limit while SkyCal remains visible. Browsers and devices may pause microphone access when the page is hidden or the screen locks. You can turn off wake listening or end a voice conversation at any time. SkyCal mutes its own media while waiting for the wake phrase; it cannot change your device's ringtone or other apps' volume.

Photos And The Scrapbook

Photos you add to a scrapbook page are uploaded to SkyCal's hosted file storage. Uploads are limited to JPEG, PNG, WebP, and GIF images up to 10 MB each. Recipe images and imported recipe videos are stored in a separate bucket, limited to JPEG, WebP, and MP4 up to 25 MB each. Neither bucket is public. Access is checked on every read and write against membership of the shared calendar the file belongs to, so only signed-in members of that calendar can retrieve the file. Photos are never sent to the model provider that powers the assistant.

Payments And Subscriptions

SkyCal Pro is sold as a subscription and payments are processed by Stripe. Card details are entered on Stripe's own checkout page and are never sent to or stored by SkyCal. SkyCal creates a Stripe customer for your household and tags it with the household identifier only. No name, address, card, email, or identity data is copied into that tag. From Stripe, SkyCal stores the customer identifier, the subscription identifier, its status, the price identifier, the current period end, and whether the subscription is set to cancel at the end of the period. SkyCal also records the identifier of each Stripe event it has already processed so a webhook is not applied twice.

Product Analytics

SkyCal keeps a first party events table inside its own database to count how the app is used, for example how many households finish setup or add a first grocery item. These events are recorded by SkyCal and are not sent to any third party analytics service. SkyCal does not use third party advertising or tracking pixels. Analytics events are tied to a household and, where relevant, to the signed-in account, and are used to improve the product, not to build advertising profiles.

Children And Household Profiles

SkyCal is built for households with school-age children, and a household will normally create a profile for each child. A profile stores a display name, a chosen avatar emoji or an uploaded avatar image, and two color choices. SkyCal does not ask for a child's date of birth, age, address, phone number, or school. A child's profile can be referenced by events, tasks and chores, rewards, meals, sleep logs, and scrapbook pages, so a child's schedule, chore history, reward balance, bedtime and wake times, sleep quality ratings, and any photos placed on a scrapbook page are stored under the household's shared calendar.

A child profile does not require its own account. Profiles can exist with no sign-in at all, which is the usual arrangement for a household tablet. The adult who owns the shared calendar controls that data. Adults who have joined the calendar can view and edit it, invite other members, and delete it. Child profile data is not sold, is not used for advertising, and is not used to train machine learning models. Photos are excluded from everything sent to the assistant's model provider.

Sharing And Disclosure

Shared calendar content is visible to signed-in users who have joined that same SkyCal calendar. Calendar owners can invite other signed-in users, and a signed-in user can link their account to a profile. Profiles can also exist without their own account, such as a child or household member who only uses a shared tablet.

SkyCal does not sell your information and does not share it for advertising. SkyCal uses the service providers listed below, and each one processes information only as needed to operate SkyCal. SkyCal may disclose information if required by law or to protect the security, integrity, or rights of SkyCal and its users.

Service Providers

  • Supabase provides authentication, the database, and the file storage buckets. It holds your account record, your shared calendar content, your uploaded photos, and your stored Google Calendar tokens.
  • Fly.io hosts the SkyCal web app and the recipe import worker. It receives the network requests your browser makes to SkyCal.
  • Stripe processes subscription payments and hosts the checkout page and the billing portal. Stripe receives your payment details directly.
  • Google provides sign-in, and Google Calendar sync when you connect it. Google Gemini receives the recipe video, post description, or webpage content during a recipe import. If your household supplies its own Google API key, the Google Weather and Geocoding APIs also receive your coordinates.
  • Apify receives the Instagram or TikTok link you paste during a recipe import and fetches the public post and its video on SkyCal's behalf.
  • OpenAI and Anthropic. One of these is configured at any time as the model provider behind the SkyCal assistant, and it receives your assistant prompt together with the household categories you allowed.
  • Open-Meteo receives your coordinates to return a forecast, and OpenStreetMap Nominatim receives your coordinates to return a place name.

SkyCal is an independently run project and is not owned by, or a part of, any of the providers listed above. Formal notices, including legal and privacy notices, should be sent to the SkyCal project owner at sxnorthrop15@gmail.com.

Product Usage Measurements

SkyCal records which days a verified account opens or interacts with the app, and a daily marker for supported feature views and actions such as completing a chore, planning a meal, checking a shopping item, saving a calendar event, or saving an imported recipe. These first-party records are stored with our Supabase database provider to understand repeat use and improve everyday usefulness. They contain an account identifier, UTC date, and fixed action name, not household content, child profiles, precise location, IP addresses, or device fingerprints. They are restricted to our service and administrator reports and are removed when the account is deleted. Assistant operational records also help us measure request reliability and applied or undone changes. We do not load third-party advertising trackers for these measurements.

Storage, Security, And Offline Use

SkyCal stores app data in a hosted database for syncing. It may also cache selected app data in your browser so the app can continue working in a limited offline state on a tablet or personal browser. SkyCal protects data using HTTPS, OAuth sign-in, access-controlled database rules, and calendar membership checks.

The optional Google API keys a household can enter, for weather and for its own Google client, are kept local to your browser and are stripped out before settings are saved to the shared SkyCal database. The assistant's model provider key is not one of these. It belongs to SkyCal, is set only by an administrator, and is stored encrypted on the server.

Retention And Deletion

SkyCal keeps account and calendar data while your account or shared calendar remains active. You can edit or delete events, tasks, meals, recipes, sleep logs, profiles, and settings inside the app. Resetting all data removes the calendar content for that shared calendar. Browser caches can be cleared from your browser settings.

Assistant conversation text is short-lived. The prompt and reply for a run are deleted seven days after the run, and a prepared change that you never confirm expires after fifteen minutes. The accounting record for a run, which holds token counts and cost and no conversation text, is kept so plan allowances can be counted. Deleting a conversation in the app removes its runs, its prepared changes, and its stored text. Uploaded photos and imported recipe media stay in storage until the page or recipe that uses them is deleted. Billing records are kept for as long as required for tax and accounting purposes.

You can disconnect Google Calendar access in SkyCal and revoke SkyCal's Google access from your Google account security settings. You can request account or calendar deletion by contacting SkyCal at the address below.

Policy Updates

SkyCal may update this policy when features, data practices, or legal requirements change. The effective date at the top of this page shows when the policy was last updated.

Contact

For privacy questions, access requests, or deletion requests, contact the SkyCal project owner at sxnorthrop15@gmail.com.