Schedoo is a calendar and scheduling application that turns photos, screenshots, and messages into calendar events. It is developed and operated by Ksatalsin S.L., a company based in Spain (the "data controller").
For privacy questions: sl.ksatalsin@gmail.com
| Category | Examples | Why |
|---|---|---|
| Account data | Email address, display name, and a password (hashed; managed by our auth provider; we never see it in plain text) | To create and secure your account |
| Calendar content | Events, notes, and the shared groups you create or join | To provide the core service and sync it across your devices |
| Images you select | Photos/screenshots you choose for the camera or "scan library" feature | Text is extracted from them on your device (OCR) to detect events (see Section 4) |
| Text for AI parsing | Text you type, paste, share into the app, or that OCR extracts from an image | Sent to an AI provider to detect event details (see Section 4) |
| Subscription status | Whether you have an active Pro subscription | To unlock paid features. Payments are handled by Apple/Google; we never receive your card details |
| Device & push | Push (FCM) token, OS version, device type, timezone, app version | To deliver notifications and display the app correctly |
| Device calendar | Events already on your phone, if you allow it | Shown alongside Schedoo's own events so a day reads as one list. They are read on the device and are not copied to our servers |
| Usage & diagnostics | In-app interactions, crash reports, and basic analytics on our invite web pages | To improve the app and fix bugs |
| Advertising ID | The resettable advertising identifier your phone provides | Collected by Google Analytics for Firebase, which we use for product analytics. We do not serve ads, run ad campaigns, or use it to track you across other companies' apps or sites. You can reset or delete it in your device settings |
We do not collect precise GPS location, health data, your contacts, payment card numbers, or special-category data as defined by GDPR Article 9. We only access your photo library when you explicitly choose photos or start a scan, and those images are read on your device and never uploaded (see Section 4). No picture you give the app ever leaves your device.
| Processing activity | Legal basis |
|---|---|
| Creating and managing your account | Contract (Art. 6(1)(b)) |
| Storing your events, notes, and groups | Contract (Art. 6(1)(b)) |
| Extracting events from text/images you submit (AI parsing) | Contract (Art. 6(1)(b)), a feature you actively trigger |
| Sending transactional and invite emails | Contract (Art. 6(1)(b)) |
| Usage analytics and crash diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails (if you opt in) | Consent (Art. 6(1)(a)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
Schedoo only asks for a permission when you use the feature that needs it, and you can revoke any of them at any time in your device settings:
| Permission | Why we request it |
|---|---|
| Camera | To photograph a poster, flyer, or screenshot so we can detect an event from it |
| Photo library | To let you pick an image, or to scan your recent photos, for event detection |
| Calendar | To show the events already on your phone next to Schedoo's, and to write an event back to your phone's calendar when you ask for it |
| Notifications | To send event reminders and shared-group updates |
Schedoo's core feature converts text and images into calendar events:
You control this: event detection only runs when you take an action (take/select a photo, paste text, share into the app, or start a scan).
We do not sell your personal data. We share it only with the service providers we rely on to run Schedoo:
| Provider | Purpose |
|---|---|
| Supabase | Our primary backend: database, authentication, storage and serverless functions where your account, events, notes and groups are stored |
| AI providers: OpenRouter and the models it routes to, Groq, Cerebras, SambaNova, Mistral, Google Gemini | Process the text you submit to detect events (Section 4) |
| Public event, reference & photo services | Enrich public-looking events with a cover photo and short description (Section 4). Events classified on-device as personal or private are excluded |
| OpenStreetMap / Nominatim | Convert a venue's location text into map coordinates |
| Cloudflare Turnstile | Bot and abuse protection at sign-up: a lightweight challenge, no tracking cookies |
| Google Firebase (Analytics, Crashlytics, Cloud Messaging, Hosting) | Hosts our web pages, delivers push notifications, records crashes, and provides product analytics. Its analytics component collects the advertising ID (Section 2) |
| Adapty + Apple App Store / Google Play | Manage subscriptions and process payments (we never receive card data) |
| Resend | Sends transactional and group-invite emails |
| Legal authorities | Only if required by law or a valid court order |
Some providers above may process data outside the European Economic Area (EEA). Where they do, transfers are protected by EU Standard Contractual Clauses (SCCs) and/or other approved safeguards under each provider's data processing terms.
| Data | Retention period |
|---|---|
| Account, events, notes, and groups | Until you delete your account, plus up to 30 days for backup purging |
| Text sent for AI parsing | Not stored by us beyond returning the result; providers may retain transiently per their own policies |
| Usage / analytics data | Up to 14 months, then aggregated / anonymised |
| Support records | 3 years |
EEA / EU users (GDPR): you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time.
Email sl.ksatalsin@gmail.com with subject "Privacy Rights Request". We respond within 30 days.
California users (CCPA/CPRA): you have the right to know, delete, correct, and opt out of "sale"/"sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising. Email sl.ksatalsin@gmail.com with subject "CCPA Request".
In the event of a personal-data breach, we will notify affected users and the AEPD within 72 hours as required by GDPR.
Schedoo is not directed at children under 14 (Spain's minimum age under GDPR). We do not knowingly collect data from children. If you believe a child has provided us data, contact sl.ksatalsin@gmail.com and we will delete it promptly.
You can delete your account at any time:
All personal data is removed within 30 days. Aggregated, anonymised statistics that cannot identify you may be retained.
If you grant notification permission, we may send event reminders and group updates. You can disable these at any time in your device's notification settings.
For material changes, we will notify you via email or in-app notice at least 14 days before they take effect.
Ksatalsin S.L.
Spain
Email: sl.ksatalsin@gmail.com