Aide Calendar — Privacy Policy
SummerCloude · Last updated: 20 June 2026
This Privacy Policy explains how SUMMERCLOUDE PTE. LTD. ("SummerCloude", "we", "us"), a company registered in Singapore, handles personal data in connection with the Aide Calendar mobile application for iPhone and iPad ("the App"). This Privacy Policy is written with reference to Singapore's Personal Data Protection Act 2012 (PDPA) and Apple's App Store privacy requirements.
1. What Aide Calendar does
Aide Calendar lets you turn text, screenshots, photos, voice recordings
and shared content into calendar events and tasks. To do that, it uses
a SummerCloude-operated backend at
aidecalendar.summercloude.app (a Cloudflare Worker) which
forwards your content to AI providers for extraction, then returns
structured events and tasks that are stored within the App and synced
across your devices via the same backend.
Sections 4 and 5 explain exactly what leaves your device and to whom.
2. Our approach
- Account required. The App requires you to sign in to access AI extraction and sync features. You may sign in with Apple, Google, or an email address. We do not require a separate password — Apple and Google sign-in use your existing account; email sign-in uses a one-time verification code.
- No advertising. We do not show ads and do not include advertising or marketing analytics SDKs.
- No selling. We do not sell personal data to any third party.
3. Account and authentication data
When you sign in, we receive and store on our backend:
- User ID — a unique identifier for your account, derived from your Apple or Google identity token, or created when you first sign in with email.
- Email address — used to identify your account and, for email sign-in, to send the one-time verification code. We may also use it to send you important service and security notices about your account — for example, if a fault on our side affects your data. We do not use it for marketing. Apple sign-in may use Apple's Hide My Email relay; we store whatever email Apple provides.
- Display name — captured from Apple or Google sign-in if provided; not required.
- Session token — a credential minted by our backend on successful sign-in, stored in your device's Keychain. Presented with every API request to authenticate you. Session tokens expire and are refreshed on sign-in.
- Authentication provider — which method you used to sign in (Apple, Google, or email), stored locally in your device's Keychain.
Email one-time codes are sent by Resend, Inc. (resend.com), our transactional email provider, under their Privacy Policy. Resend receives your email address solely to deliver the verification code.
Google sign-in uses OAuth 2.0 with PKCE, routed through our backend. Google receives the OAuth exchange under Google's Privacy Policy. We receive only your Google-account email and a unique identifier; we do not receive your Google password or any other Google account data.
4. Data sent to our backend for extraction
When you ask the App to extract an event or task, the relevant content
is sent over an encrypted (HTTPS) connection to
aidecalendar.summercloude.app, which acts as a proxy: it
adds API credentials and forwards the request to the AI providers
listed in Section 5. Depending on the input type, this content is:
- The text you type, paste, or share into the App.
- The image (screenshot or photo) you select.
- The audio of a voice note you record.
Our backend does not operate its own database of your raw inputs. Cloudflare collects standard edge logs (IP address, time, response status) used to deliver the service and protect against abuse, under Cloudflare's Privacy Policy.
5. Third-party AI providers we use
Your explicit consent comes first. Before your first AI capture, the App shows a one-time consent screen that names the providers below, explains what each receives, and requires your explicit "I understand and agree" before any AI extraction can take place. You can review the same disclosure at any time via Settings → About → "AI & Privacy". Withdrawing consent is operationally equivalent to deleting your account — see Section 13.
To turn your content into structured events and tasks, our backend sends it to the following third-party AI providers (large language models and speech-to-text), in line with Apple App Review Guideline 5.1.2(i):
- OpenAI, L.L.C. — our primary AI provider, for understanding the text and images you share and for transcribing your voice notes. OpenAI processes requests under OpenAI's Services Agreement, our signed Data Processing Addendum, and Privacy Policy. API inputs are not used by OpenAI to train its models. OpenAI's own sub-processors are listed at platform.openai.com/subprocessors.
- Anthropic, PBC — Claude API, used as a backup for text and image understanding when OpenAI is unavailable. Anthropic processes requests under Anthropic's Commercial Terms and Privacy Policy. Under Anthropic's Commercial Terms, API inputs and outputs are not used to train Anthropic's models.
Both providers may temporarily retain API inputs and outputs to detect abuse — typically up to 30 days, after which the data is deleted from their systems. We have configured our OpenAI organisation to minimise logging beyond this default. If you do not want your content processed by these providers, do not submit it through the App.
A note on sensitive content. Whatever you share — text, image, or voice — is sent to the AI provider(s) listed above for the time it takes to extract your event. We recommend you avoid sharing sensitive personal information through the App — for example medical details, account numbers, passwords, or other information you would not normally share with a third-party service. Everything you submit — typed text, images, and voice — is sent to OpenAI, our primary AI provider; if OpenAI is unavailable, your text and images may instead be processed by Anthropic Claude as a backup.
6. Data stored on our backend
In addition to account data (Section 3), our backend stores the following data associated with your account:
- Captured events and tasks — the structured events and tasks the App has extracted and that you have saved. These are synced across your devices so your data is available on every device you sign in to.
- Capture records — a log of your AI extraction sessions (input type, result, timestamps), used to power the in-app history view and synced for cross-device access.
- Blob storage — source files (images, audio) associated with your capture records, stored in Cloudflare R2 object storage to support cross-device sync and data export.
- Subscription entitlement — your current subscription tier (Free / Pro), usage counters, and subscription expiry. This is the authoritative record used to enforce your plan quota across all your devices.
- Push notification token — your device's APNs (Apple Push Notification service) token, registered with our backend so we can send silent sync-wakeup pushes when another device modifies your data. We use push notifications only for sync and event/task alert delivery, not for marketing.
We do not read the content of your events and tasks in the ordinary course of running the service — it is stored so we can sync it across your devices and assemble your data export. It is protected in transit (HTTPS) and at rest by our infrastructure provider, but it is not end-to-end encrypted, which means it is technically accessible to us.
7. Data that stays on your device
- Your existing Apple Calendar and Apple Reminders entries. The App reads these via Apple's EventKit framework so they can appear alongside what Aide captures, in one unified view. The App is read-only with respect to Apple Calendar and Apple Reminders — it never writes events or tasks back to them, and unedited imported entries stay local on your device. Your Apple Calendar and Reminders data itself stays under Apple's control in your Apple account. Note: if you edit or reschedule an imported item inside Aide, that edited copy becomes a normal Aide record and is then stored and synced like anything else you create (see Section 8).
- Session token and account credentials. Stored in your device's Keychain; not accessible to other apps.
8. Cross-device sync
Your saved events, tasks, and capture history are synced to our backend so they are available on every device you sign in to. Sync happens automatically on launch and when you receive a silent push notification indicating a change on another device. You can sign out to stop sync on a device; signing out clears the locally cached events, tasks, and capture records from that device.
Your app preferences (appearance, default alert and duration times, week start, time format, and voice recognition language) are also stored on our backend, but only to seed your settings once when you first sign in on a new device. After that, each device keeps its own settings — changing a preference on one device does not automatically update it on another.
9. iOS permissions the App requests
Each permission is requested only when the matching feature is used, and only for the purpose described:
- Calendar & Reminders — to read your existing Apple Calendar events and Reminders tasks and import them into Aide Calendar's unified view.
- Microphone — to record the voice notes you choose to dictate. Transcription is performed by our speech-to-text provider (Section 5), not by on-device speech recognition.
- Photos — only when you pick a screenshot or photo to extract from, via the system photo picker. The App reads only the image(s) you select.
- Camera — only when you choose to photograph an appointment card, invite, or message to extract from. The App captures only the photo you take and sends it for extraction (Sections 4–5).
- Contacts — only if you choose to link a person in a capture to your address book. Matching happens on your device and your contacts are never uploaded — see Section 9a.
- Notifications — to deliver local alerts for events and tasks at the times you set, and to receive silent sync-wakeup pushes from our backend.
9a. Contacts
Aide Calendar can link a person mentioned in a capture to someone in your address book, so you can quickly call, message, or email them. This is optional and works as follows:
- Matching happens on your device. When the App looks for a captured name in your contacts, it queries your address book locally. Your contacts are never uploaded to our servers, and we never receive a copy of your address book.
- Only the person you choose is saved. When you explicitly pick or confirm a specific contact, the App stores that person's name and the phone number or email you selected (plus a local reference to the contact) on the event or task — much like a note. Because that event syncs across your devices (Section 8), this saved detail syncs with it. Automatic match suggestions you do not act on are not saved.
- The manual picker needs no permission. Adding a person through the system contact picker runs outside the App and does not require Contacts access; only the automatic on-device matching does.
10. App Attest
To prevent abuse of our paid backend, the App uses Apple's App Attest framework to verify that requests come from a genuine, unmodified copy of Aide Calendar running on a real Apple device. Our backend stores only a per-device public key and a monotonic counter for this purpose. App Attest data does not identify you personally.
11. Subscriptions and payments
Aide Calendar offers an optional in-app Pro subscription (monthly or annual) delivered through Apple's StoreKit. All payment, billing, renewal and refund handling takes place between you and Apple under Apple's Privacy Policy and the App Store terms. We never see your credit-card number, Apple account password, or other payment credentials. The App sends Apple's StoreKit transaction ID to our backend, which verifies it against Apple's App Store Server API to confirm your subscription tier. Apple processes this verification under their own privacy terms.
12. Data export
You can request a copy of your data from within the App (Settings → Account → Export Data). Our backend assembles a ZIP archive of your account data and makes it available for download in-app and by email. Download links are valid for 7 days, after which you can request a new export.
13. Account deletion
You can permanently delete your account from within the App (Settings → Account → Delete Account). The flow we require depends on whether you have an active subscription and how old your account is:
- Any active Pro subscription — deletion always uses the 30-day grace flow described below, whatever your account's age, so you do not lose access mid-subscription and we can remind you to cancel billing with Apple.
- No subscription, less than 2 hours old — one-tap immediate deletion, no further confirmation required.
- No subscription, 2 hours to 7 days old — confirmation via a one-time code sent to your account email, then immediate deletion.
- No subscription, 7 days or older — confirmation via a one-time code, after which your account is scheduled for permanent deletion 30 days later. During the 30-day grace period the App is locked except for a "Cancel Deletion" button, so you can sign in on any device and reverse the deletion at any time before day 30. We email you when the deletion is scheduled, again 7 days before it completes, and once more when deletion is finished.
In all cases, deletion permanently removes your account data, captured events and tasks, capture records, and blob files from our backend. After deletion, signing in with the same Apple, Google, or email identity creates a fresh account with no prior data.
Apple subscriptions are not cancelled by account deletion. Your Pro subscription, if any, is managed by Apple. To cancel it, go to Settings → Apple ID → Subscriptions on your iPhone. Deleting your Aide Calendar account alone does not stop Apple from billing future renewals.
14. Information you send us by email
If you contact us at [email protected], we receive your email address and any information you choose to share. We use this solely to respond to your enquiry and to keep a record of our correspondence. We do not add you to any marketing list.
15. Information we do not collect
- We do not use third-party advertising or marketing analytics SDKs. (We do operate a small first-party diagnostic-error reporter — see Section 16a — which you can disable.)
- We do not access your device location or your full photo library, and we never upload your address book — contact matching happens on your device (see Section 9a). We do not use your microphone outside the voice-note feature.
- We do not sell personal data to any third party.
16. Apple App Store data
Apple may collect download, crash and aggregated usage information under its own privacy terms when you download the App. If you choose to share anonymous diagnostics with app developers in your iOS settings, Apple may forward non-identifying crash and performance reports to us so we can fix bugs.
16a. Diagnostic error reports
Separately from Apple's diagnostics, the App itself sends a short, pseudonymous error report to our backend whenever something goes wrong on a screen you can see. Each report contains:
- The app version, the iOS version, and the device model
(e.g.
iPhone17,2); - A truncated, PII-scrubbed description of the error (email addresses, long digit sequences, and UUID-shaped values are replaced with placeholders before sending);
- A SHA-256 hash of your user id (or, for not-signed-in users, a hash of a per-device anonymous identifier) so we can de-duplicate repeated reports from the same install.
These reports never include your event content, photos, voice recordings, or direct identifiers like your name, email, or raw account id. They exist solely to help us fix bugs. The identifier is a one-way hash — the raw user id cannot be recovered from it — but because it is the same hash each time, it links your reports to your account, so they are erased when you delete your account.
You can turn diagnostic reports off at any time: Settings → About → Send diagnostic reports in the App.
17. Data retention
- Account data — retained until you delete your account in-app or request deletion by email.
- Events, tasks, and capture records — retained until you delete them in the App or delete your account. Items you delete in the App stay in the "Recently Deleted" view for 30 days so you can restore them, then are permanently purged from our backend.
- Blob files (images, audio) — retained until the associated capture record is deleted, or your account is deleted.
- Export archives — available for 7 days after the export job completes, then deleted from our servers.
- Push notification tokens — retained while your account is active. Removed on account deletion, and on sign-out (best-effort — if the device is offline at sign-out, removal completes on the next sign-in).
- Anthropic and OpenAI inputs/outputs — temporarily retained by each provider for abuse monitoring per their published terms (typically up to 30 days, then deleted).
- Cloudflare edge logs — retained per Cloudflare's policies.
- Database backups — our database provider (Cloudflare D1) keeps automatic point-in-time backups for up to 30 days before they are cycled out. Data you delete is removed from the live database immediately, but may persist in these routine backups until they expire.
- Diagnostic error reports — retained up to 90 days, then automatically deleted, and also deleted when you delete your account.
- AI-capture usage history — retained up to 180 days for abuse monitoring and plan-limit enforcement, then deleted.
- Sign-in codes — one-time email codes are deleted after use; any unused codes are purged within 60 days.
- Sign-in sessions — inactive session records are cleared after about 180 days, or immediately when you sign out or delete your account.
- Email correspondence — retained for as long as necessary to handle your enquiry and keep reasonable business records.
18. International transfers
Our backend runs on Cloudflare's global edge network. Our AI providers (Anthropic, OpenAI) and our email provider (Resend) are based in the United States. By using the App you acknowledge that your account data and content submitted for extraction may be processed in jurisdictions outside Singapore, including the United States.
For users in the European Economic Area, Switzerland, or the United Kingdom, the following safeguards apply:
- EEA / Swiss data — routed through OpenAI Ireland Limited under the EU Standard Contractual Clauses (SCCs).
- UK data — routed under the SCCs as amended by the UK Addendum issued by the Information Commissioner's Office.
- Anthropic transfers — covered by the SCCs incorporated into Anthropic's Commercial Terms.
19. Your privacy rights
SummerCloude is the data controller for your personal data; our AI and email providers act as our processors under our instructions. If you are an individual whose personal data we hold, you may contact us to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate personal data;
- Withdraw your consent to our continued use of your personal data. Because AI extraction is the core function of the App, withdrawing consent is operationally equivalent to deleting your account — see Section 13. Once your account is deleted, all AI processing of your content stops.
Depending on where you live, you may have additional rights under your local laws — for example Singapore's PDPA, the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, Australia's Privacy Act, or New Zealand's Privacy Act. These may include the right to access, correct, delete, export (data portability), or object to or restrict certain processing, and to withdraw consent. We honor these requests for all users wherever they live: the in-app Export Data and Delete Account tools cover access, portability, and erasure directly, and you can contact us for anything else. We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
Send any such request to [email protected]. You may also delete your account directly from within the App, which removes all personal data we hold about you from our backend.
20. Children's privacy
Aide Calendar is intended for users 16 and over. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child under 16 has created an account — or you otherwise become aware that someone under 16 has signed up — please contact us at [email protected]. We will look into the report and, where we confirm the account holder is under 16, delete the account and its data.
21. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated date at the top of this page.
22. Contact
For any privacy-related question or request, please contact our Data Protection contact at [email protected].
SUMMERCLOUDE PTE. LTD. — registered in Singapore.