Privacy Policy
Last updated September 13, 2026
What this app does
What we collect
- Your name and email address, from Google Sign-In.
- Calendar event data (titles, times, and which calendar they're on) — read-only access, via Google's
calendar.readonlyscope. We never write to, modify, or delete your calendar events. A calendar you have labelled Work or Personal can be markedHide details
, in which case we read only its times — seeCalendars you've marked Hide details
below. - If you connect an Apple Calendar: the sharing link you paste in, and the events we read from it. Apple offers no calendar sign-in, so this works differently from Google and Outlook — see
Apple Calendar links
below. - Family details you enter directly: kids' names, birthdays, your home ZIP code, and (optionally) a co-parent's name and email. We never ask for a street address. When you save your ZIP code we resolve it once into a city and state name, the approximate coordinates of that ZIP code's area, and your time zone — see
Location and weather
below.
How we use it
Apple Calendar links
Apple does not offer a way to sign in and grant read access to a calendar, the way Google and Outlook do. The only way to share an Apple calendar with something that is not Apple is to turn on Public Calendar
in Apple's own sharing settings, which produces a long, random link. If you choose to connect an Apple calendar, that link is what you paste in and what we store.
That link is public. Anyone who has it can read that calendar, without a password and without asking us — that is how Apple's feature works, not something we add. We keep the link in order to fetch your calendar each morning and we do not publish or share it, but we cannot make it private, and you should treat it the way you would treat any link you would not want forwarded.
We read these calendars and nothing else about your Apple account: there is no password involved, no access to your mail, contacts or photos, and nothing we can write, change or delete. Everything else on this page applies to Apple calendar events exactly as it does to Google ones, including Hide details
.
Removing the calendar in Data sources stops us reading it and deletes the stored link. It does not un-publish the calendar — to do that, turn Public Calendar
back off in Apple's settings, which also makes the old link stop working for everyone.
Location and weather
Your ZIP code does two jobs: it sets your time zone, so your briefing arrives at the right hour in your morning and your events are shown in your own local time, and it lets us include a short local forecast for the day ahead.
When you save your ZIP code, we send it to Zippopotam.us to look up the matching city, state, and approximate coordinates, and we send those coordinates to Open-Meteo to determine your time zone. Each morning, we send the same approximate coordinates to Open-Meteo again to retrieve that day's forecast for your briefing.
Neither service receives your calendar events, your name, your email address, or anything else identifying you — only a ZIP code, or a pair of coordinates for the area it covers. Your briefing also includes a “see detailed forecast” link. It points to a Google web search for your local weather; opening it sends your ZIP code to Google — or, for accounts saved before we started asking for a ZIP, your city and state — exactly as typing that search yourself would. Nothing is sent unless you choose to click it.
Weekly local suggestions
Some briefings end with a local suggestion — a nearby place worth visiting, or a roundup of things happening near you that weekend. To find those, we send a search query to Perplexity that names your general area (the city and state resolved from your ZIP code, or the metro area you fall within). We never send your calendar, your name, your email address, or your kids' details as part of that search.
The weekend roundup is looked up once per metro area rather than once per family, so that search says nothing about you specifically beyond the region you live in.
Knowing whether the briefing was opened
Each briefing contains a small invisible image. When your mail app loads it, Postmark records that the email was opened, when, and roughly which mail app and device it was opened in. We use this for one thing: to see whether the briefings we send are actually being read, so we can tell a product that is working from one that is quietly landing in nobody's morning.
This is recorded for every address a briefing is sent to, which includes a co-parent or family member added by the account owner. It is not tied to anything you do elsewhere, it is never used for advertising, and it is never sold or shared beyond Postmark, who record it on our behalf. Many mail apps block that image by default, in which case nothing is recorded at all.
If you would rather not be counted, turning off remote or automatic image loading in your mail app prevents it, and the briefing itself will still read normally. Anyone added to a household briefing can also stop receiving it entirely using the unsubscribe link at the foot of the email.
Who we share your data with
We work with a small number of service providers to run the app, each bound to use your data only to provide their service to us, under strict confidentiality and security obligations:
- Google Gemini API (Google LLC) — receives your calendar event data (titles, times, locations, and which calendar they're on) and the family details you've entered (kids' names and ages, parent names) plus that day's local forecast, as input to generate the text of your daily briefing. See
AI/ML — Limited Use compliance
below. - Anthropic Claude API (Anthropic PBC) — receives exactly the same information as the Gemini API above, and only when Gemini is unavailable at the moment your briefing is due. It acts as a backup so a briefing isn't lost to an outage at a single provider.
- Postmark (ActiveCampaign, Inc.) — receives your email address and the finished briefing content, solely to deliver your daily briefing email, and records whether each briefing was opened (see Knowing whether the briefing was opened).
- Supabase — hosts our database and stores your account, family details, and Google Calendar connection (including OAuth tokens) on our behalf, encrypted and access-controlled so only you can read your own data.
- Open-Meteo — receives the approximate coordinates resolved from your ZIP code, to return your time zone when you first save it and your local forecast each morning. No calendar data, name, or email address is sent.
- Zippopotam.us — receives your 5-digit ZIP code once, when you save it, to resolve it to a city, state, and approximate coordinates. Nothing else about you is sent.
- Perplexity (Perplexity AI, Inc.) — receives a search query naming your general area, used to find the local suggestions some briefings end with. See
Weekly local suggestions
above. No calendar data, name, or email address is sent.
As we add features, we may bring on additional service providers (subprocessors) to operate them. We vet every one for strong data security and confidentiality practices before any of your data reaches them, and we'll keep this page current with who they are. Beyond the providers listed here, we do not sell, share, or otherwise disclose your data to anyone else, and we never use it for advertising.
AI/ML — Limited Use compliance
calendar.readonly scope is used only to generate your own personalized daily briefing through the Gemini API, and is never used to train, improve, or develop generalized or foundational AI/ML models.Where it's stored
The “Listen to briefing” link
Your controls
If someone added you
What reaches you is the household's one briefing, not a copy tailored to you. It names the family's events and each connected parent's own day, so an event on a calendar labelled Work or Personal — the account holder's, or yours if you connect one — is described in it. A calendar marked
Hide detailscontributes only its times, as above.
If that is you, the first briefing that reaches you is followed by one invitation email, sent the same morning, naming the account holder who added you and offering you your own login. That invitation and the daily briefing are the only things we ever send an added family member. To stop the emails, use the unsubscribe link at the bottom of any briefing — it needs no account and no password, just the link. You can also reply and ask, or ask the account holder to remove you; removing you stops your copy that day.
Unsubscribing records the date you did so against your entry, so we can honour it. It does not delete the entry itself — the account holder entered it and can see and remove it — and it does not stop them from adding your address again, so if briefings resume, ask them directly or contact us below.