Privacy Policy

Effective Date: July 30, 2026

1. Our Privacy Philosophy

At Celie AI, LLC ("Celie AI," "we," "us," or "our"), we believe your calendar is your private history. Our LinkMyCal service is designed as a bridge, not a database. We operate on the principle of Data Minimization: we only access and store the information necessary to help organize your life.

2. Information We Access and Collect

  • Calendar Availability (Metadata): To prevent double-bookings, our Services queries your native calendar's "Free/Busy" status. We only store titles, descriptions, locations and other appointment information where this information is necessary to provide our Services or when the appointments are created through our Services.
  • Service-Generated Data: We collect and store details of appointments made specifically through LinkMyCal, including the time, date, participants, and any notes added to that specific event.
  • Contact Information: This includes names and emails provided during setup. If you utilize our Contact Import feature, we access your native address book only with your explicit permission to facilitate invitations. We do not store your entire contact list on our servers; we only store the specific contacts you select to import.
  • Device Metadata: Basic information about your operating system and calendar version to ensure sync compatibility.
  • Usage and device data: such as IP address, device/browser type, pages viewed, approximate location (derived from IP), and diagnostic data to operate and secure the Services.
  • Cookies and similar technologies: we may use cookies/local storage for authentication, security, preferences, and Service functionality. Where we use non-essential cookies (for example, analytics), we do so in compliance with applicable law.
  • Our Statutory Capacity (Data Controller vs. Data Processor). Celie AI processes personal data in two distinct capacities under global privacy frameworks (including GDPR and CCPA/CPRA):
    • As a Data Controller: We act as an independent Data Controller for your primary account identification profile, login authentication credentials, platform settings, payment processing relationship metadata, and overall application analytics.
    • As a Data Processor / Service Provider: When you utilize LinkMyCal to schedule an appointment, event, or transaction with a commercial third party (a "Business User"), that Business User is the sole Data Controller for that specific event log, transaction ledger line, and any text notes you input into their bookable calendar slot. We process that specific data subset strictly as a Data Processor acting on the contractual instructions of that Business User.

3. How We Use "Read/Write" Permissions

To function without a standalone app, the Services requires specific permissions from your native OS (Apple, Android, Microsoft, Google, etc.):

  • Read Access: Used to identify "busy" blocks on your native calendar. This allows us to superimpose a Business’s availability over your own so you can find a slot that works.
  • Write Access: Used to "post" new appointments, updates, or cancellations directly into your native calendar app.
  • Automation: We do not manually browse your calendar. All "Read/Write" actions are performed by automated protocols to facilitate specific user-initiated actions.

4. Data Sharing & Zero-Sale Policy

CELIE AI DOES NOT SELL YOUR PERSONAL DATA OR CALENDAR HISTORY TO THIRD PARTIES.

  • We process your data under the following legal bases: (i) Contractual Necessity to provide the sync services you requested; (ii) Legitimate Interests in securing our platform and improving service performance; and (iii) Compliance with Legal Obligations.
  • Participants: Your name and selected appointment time are shared with the specific Business or Person you are scheduling with or grant visibility to.
  • Merchant of Record: Payment and billing data are handled by Lemon Squeezy. We do not store your credit card information on our servers. Lemon Squeezy collects personal information during the checkout process, including identifying information about the devices that connect to its services. This data is used to operate and improve their services, ensure transaction security, and for fraud detection. You can learn more about how your data is handled and read their privacy policy on their website https://www.lemonsqueezy.com/privacy.
  • Service Providers: We use industry-standard infrastructure to facilitate the sync bridge.
  • Legal and safety: If required to comply with local law, legal process, or to protect the rights, safety, and security of the company, users, or the public.
  • Business transfers: In connection with a merger, acquisition, financing, reorganization, or sale of assets (subject to this Privacy Policy or a successor policy).
  • We do not use your personal calendar data, event titles, or contact information to train or improve our base AI models or any other AI models. Any AI-driven insights are generated solely for your account's benefit.

5. Data Retention: "One Life, One Calendar"

We believe in a clean data footprint.

  • Sync Data: We store only the information required to maintain a consistent sync between your native calendar and the Services. We do not maintain long-term archives of your personal, non-Service related calendar history.
  • Account Deletion: If you choose to "Unlink" your calendar and delete your account, all service-generated data associated with your profile will be permanently purged from our active databases within thirty (30) days. Account Deletion and Shared Booking Records Limitation: When an individual Consumer User requests the absolute erasure or deletion of their account profile, all personal data for which Celie AI acts as a Data Controller will be permanently purged within thirty (30) days. However, any historical calendar records or booking logs residing on a Business User’s profile represent the independent service and business ledger records of that merchant. Because Celie AI acts solely as a Data Processor for those records, we cannot unilaterally modify, mask, or delete data contained within a Business User's separate enterprise environment without their authorization. We operate as a Service Provider with respect to this data. Consumers wishing to have their transactional data expunged from a Business User’s calendar histories must submit an independent erasure request directly to that merchant.
  • Inactive accounts: If your account remains inactive for a period of twenty-four (24) months, we reserve the right to notify you and subsequently delete your account and associated sync data to minimize our data footprint.

6. Security Measures

We implement commercially reasonable technical and organizational measures, including SSL/TLS encryption for data in transit, to protect against unauthorized access or data leakage. However, as stated in our Terms of Service, no internet-based service is 100% secure.

For CalDAV and CardDAV sync, we store encrypted tokens or app-specific passwords. These credentials are encrypted at rest using industry-standard encryption and are only decrypted in memory for the duration of the sync process.

7. International Compliance (GDPR/CCPA)

We comply with applicable data protection laws. Users in the EU, UK, and California have specific rights to access, port, or delete their data. Since we are a Delaware-based LLC, your data will be processed in the United States.

California-Specific Disclosures:

  • Notice at Collection: We collect the categories of personal information listed in above for the business purposes described herein and in our Terms of Service. We do not 'sell' or 'share' your personal information for cross-context behavioral advertising.
  • Data Deletion: If you submit a request to erase or delete your data, our response framework is gated by data ownership boundaries: 1. We will fulfill your request for all data we control (your primary user profile) within 30-days. But, 2. if you wish to delete data collected by one or more merchants, you will need to contact them directly since they are the controller of that data.
  • Do Not Track (DNT): Our website does not currently respond to browser 'Do Not Track' signals, though we honor Global Privacy Control (GPC) signals where required by law.
  • Shine the Light: We do not disclose personal information to third parties for their direct marketing purposes.

8. Children’s privacy

The Service is not directed to children and we do not knowingly collect personal information from individuals under 13 (or older where required by law). If you believe a child has provided personal information, contact us so we can take appropriate action.

9. International transfers

If you access the Service from outside the country where our service providers are located, your information may be transferred and processed in other jurisdictions, which may have different data protection laws.

10. Changes to this Policy

We may update this policy to reflect changes in native calendar protocols (e.g., changes to Apple or Google’s privacy APIs) or changes in our Services, offerings, or contracts. We will notify you of material changes via email or a prominent notice on our website.

11. Contact Us

For questions or to exercise your data rights, email us at contact@linkmycal.com.

For terms governing use of the Service, see Terms of Service.