Schedoo

Privacy Policy

Last updated: September 8, 2026  ·  Effective: September 8, 2026

1. Who We Are

Schedoo is a calendar and scheduling application that turns photos, screenshots, and messages into calendar events. It is developed and operated by Ksatalsin S.L., a company based in Spain (the "data controller").

For privacy questions: sl.ksatalsin@gmail.com

2. What Data We Collect

CategoryExamplesWhy
Account dataEmail address, display name, and a password (hashed; managed by our auth provider; we never see it in plain text)To create and secure your account
Calendar contentEvents, notes, and the shared groups you create or joinTo provide the core service and sync it across your devices
Images you selectPhotos/screenshots you choose for the camera or "scan library" featureText is extracted from them on your device (OCR) to detect events (see Section 4)
Text for AI parsingText you type, paste, share into the app, or that OCR extracts from an imageSent to an AI provider to detect event details (see Section 4)
Subscription statusWhether you have an active Pro subscriptionTo unlock paid features. Payments are handled by Apple/Google; we never receive your card details
Device & pushPush (FCM) token, OS version, device type, timezone, app versionTo deliver notifications and display the app correctly
Device calendarEvents already on your phone, if you allow itShown alongside Schedoo's own events so a day reads as one list. They are read on the device and are not copied to our servers
Usage & diagnosticsIn-app interactions, crash reports, and basic analytics on our invite web pagesTo improve the app and fix bugs
Advertising IDThe resettable advertising identifier your phone providesCollected by Google Analytics for Firebase, which we use for product analytics. We do not serve ads, run ad campaigns, or use it to track you across other companies' apps or sites. You can reset or delete it in your device settings

We do not collect precise GPS location, health data, your contacts, payment card numbers, or special-category data as defined by GDPR Article 9. We only access your photo library when you explicitly choose photos or start a scan, and those images are read on your device and never uploaded (see Section 4). No picture you give the app ever leaves your device.

3. Legal Basis for Processing (GDPR)

Processing activityLegal basis
Creating and managing your accountContract (Art. 6(1)(b))
Storing your events, notes, and groupsContract (Art. 6(1)(b))
Extracting events from text/images you submit (AI parsing)Contract (Art. 6(1)(b)), a feature you actively trigger
Sending transactional and invite emailsContract (Art. 6(1)(b))
Usage analytics and crash diagnosticsLegitimate interests (Art. 6(1)(f))
Marketing emails (if you opt in)Consent (Art. 6(1)(a))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

4. Permissions, AI & Photo Processing

Schedoo only asks for a permission when you use the feature that needs it, and you can revoke any of them at any time in your device settings:

PermissionWhy we request it
CameraTo photograph a poster, flyer, or screenshot so we can detect an event from it
Photo libraryTo let you pick an image, or to scan your recent photos, for event detection
CalendarTo show the events already on your phone next to Schedoo's, and to write an event back to your phone's calendar when you ask for it
NotificationsTo send event reminders and shared-group updates

Schedoo's core feature converts text and images into calendar events:

You control this: event detection only runs when you take an action (take/select a photo, paste text, share into the app, or start a scan).

5. Who We Share Data With (Sub-processors)

We do not sell your personal data. We share it only with the service providers we rely on to run Schedoo:

ProviderPurpose
SupabaseOur primary backend: database, authentication, storage and serverless functions where your account, events, notes and groups are stored
AI providers: OpenRouter and the models it routes to, Groq, Cerebras, SambaNova, Mistral, Google GeminiProcess the text you submit to detect events (Section 4)
Public event, reference & photo servicesEnrich public-looking events with a cover photo and short description (Section 4). Events classified on-device as personal or private are excluded
OpenStreetMap / NominatimConvert a venue's location text into map coordinates
Cloudflare TurnstileBot and abuse protection at sign-up: a lightweight challenge, no tracking cookies
Google Firebase (Analytics, Crashlytics, Cloud Messaging, Hosting)Hosts our web pages, delivers push notifications, records crashes, and provides product analytics. Its analytics component collects the advertising ID (Section 2)
Adapty + Apple App Store / Google PlayManage subscriptions and process payments (we never receive card data)
ResendSends transactional and group-invite emails
Legal authoritiesOnly if required by law or a valid court order

6. International Data Transfers

Some providers above may process data outside the European Economic Area (EEA). Where they do, transfers are protected by EU Standard Contractual Clauses (SCCs) and/or other approved safeguards under each provider's data processing terms.

7. Data Retention

DataRetention period
Account, events, notes, and groupsUntil you delete your account, plus up to 30 days for backup purging
Text sent for AI parsingNot stored by us beyond returning the result; providers may retain transiently per their own policies
Usage / analytics dataUp to 14 months, then aggregated / anonymised
Support records3 years

8. Your Rights

EEA / EU users (GDPR): you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time.

Email sl.ksatalsin@gmail.com with subject "Privacy Rights Request". We respond within 30 days.

You may also lodge a complaint with the Agencia Española de Protección de Datos (AEPD)
www.aepd.es  ·  Phone: +34 901 100 099

California users (CCPA/CPRA): you have the right to know, delete, correct, and opt out of "sale"/"sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising. Email sl.ksatalsin@gmail.com with subject "CCPA Request".

9. Security

In the event of a personal-data breach, we will notify affected users and the AEPD within 72 hours as required by GDPR.

10. Children's Privacy

Schedoo is not directed at children under 14 (Spain's minimum age under GDPR). We do not knowingly collect data from children. If you believe a child has provided us data, contact sl.ksatalsin@gmail.com and we will delete it promptly.

11. Account Deletion

You can delete your account at any time:

All personal data is removed within 30 days. Aggregated, anonymised statistics that cannot identify you may be retained.

12. Push Notifications

If you grant notification permission, we may send event reminders and group updates. You can disable these at any time in your device's notification settings.

13. Changes to This Policy

For material changes, we will notify you via email or in-app notice at least 14 days before they take effect.

14. Contact

Ksatalsin S.L.
Spain
Email: sl.ksatalsin@gmail.com