Privacy Policy
Snap to Calendar · Effective August 30, 2026
Snap to Calendar is published by Acorn Labs LLC and is built to know as little about you as possible. There are no accounts, no sign-ins, and no user database. We never sell your data. We do not use your photos to train our own models. Anthropic does not use commercial API inputs or outputs to train its models by default.
Photos you scan
- When you snap or choose a photo, it is resized and re-encoded on your device, then sent over an encrypted connection (HTTPS) to our processing service, which uses an AI model to read the events on it.
- When you tap Screenshot, the app asks for Photos access and looks for the newest image in your Screenshots album. This lookup happens only after your tap: the app does not monitor or upload your library. Only the image you choose, or the newest screenshot you explicitly request, is processed.
- Because the image is re-encoded on your device before it is sent, the uploaded copy does not carry the original file's embedded metadata, including GPS location (EXIF).
- We do not deliberately store the uploaded image in our application database or file storage. It is passed transiently to Anthropic's commercial API to produce the list of events. Anthropic does not use commercial API inputs or outputs to train its models by default, but under its standard API terms may retain inputs and outputs for up to 30 days for abuse monitoring, unless a different retention agreement applies; legal or usage-policy exceptions may last longer.
- The events the AI reads are shown to you for review and are saved only on your device and into your own Apple Calendar — never on our servers.
Temporary review recovery on your device
- If you choose Open Settings from the review screen to turn on Calendar access, the app temporarily keeps the reviewed event details, your checked choices and alert setting, the selected calendar reference, and a local reference to the source image in the app's private storage. This lets the same review return if iOS closes the app while Calendar access changes.
- This recovery draft is never uploaded to us or sent to analytics. It is eligible for restoration for up to 30 minutes. The app removes it before writing events to Calendar; it also attempts removal when you go back, begin another scan, or Settings cannot open.
- An invalid or expired draft is removed the next time the app opens. If the app is not opened again, an expired draft may remain in its private storage until a later launch or until you delete the app.
Local scan history, when available
- After a successful Calendar save, the app attempts to copy the source image into private storage on your device and create scan history. When local scan history is created successfully, you can use scan history or the link added to a saved event to reopen the source.
- A local scan copy is not uploaded to Acorn Labs and is not readable by other apps.
- When a local copy is available, it remains until you delete the scan or the app. If the attempt fails, the Calendar save still succeeds and no history entry is created.
- Deleting a saved scan removes only the local photo. Calendar events you already saved are not touched.
Your calendar
- The app adds only the events you approve, to the calendar you choose. It never reads, changes, or shares events it didn't create.
What we collect
- Anonymous per-installation usage and app-integrity records (a random installation identifier; on supported devices, an Apple App Attest hardware-key identifier, public verification key, signed fraud-assessment receipt, Apple's approximate count of keys created by that device in the prior 30 days, distribution/build validation status, replay-prevention counter, and timestamps; and scan counts/cost totals per day) used solely to enforce the free tier, authenticate genuine copies of the app, control costs, and prevent abuse. A higher Apple risk count places processing in a separate, more tightly bounded shared abuse-control pool; it does not by itself block the app or reduce that installation's ordinary-use allowance. These identifiers are not your Apple ID, your name, or your device's advertising identifier, and we do not link them to your identity.
- Anonymous product-usage events (from version 1.2 onward), sent to PostHog so we can tell whether the app is actually working: that the app was installed, updated, opened, or put in the background; that a scan started, finished, or failed and how many events it found; whether the review screen opened and how many events it showed; whether Calendar permission was granted, whether a writable calendar was available, whether the permission check errored, and whether it ran after the app returned from Settings; how many events were selected to save and how many were successfully saved or failed; whether the flow used the built-in sample schedule; whether the app flagged a page as possibly incomplete; the processing time, image payload size, and number of processing attempts for a completed scan; when the upgrade screen was shown; when an upgrade was bought or a previous purchase restored; and when the scan history was opened. Our custom event details are limited to numbers and yes/no values. PostHog may also attach standard anonymous technical metadata such as a random device identifier, session identifier, app version and build, operating-system version, device model/type, screen dimensions, SDK version, and event time. We never send PostHog your photos, event titles, locations, notes, links, or text read from a page; custom string fields are stripped before an analytics event leaves the device.
- For new analytics events, PostHog is configured not to store client IP addresses and not to add IP-derived location fields. We do not collect GPS or precise location. Historical analytics events created before August 10, 2026 may still contain IP-derived location fields collected under the prior configuration; changing the live settings does not erase that existing history.
- Anonymous Apple Ads attribution (from version 1.3.2 onward). On supported iPhones, Apple provides the app with a short-lived AdServices attribution token, which the app sends directly to RevenueCat. RevenueCat exchanges it with Apple and stores the returned campaign, ad-group, ad, and keyword identifiers; whether an ad impression or tap led to the install; conversion details; and campaign country or region. RevenueCat associates those values with its anonymous purchase record so we can measure which of our Apple Ads lead to installs, subscriptions, and campaign return.
- We do not receive your Apple ID, name, IDFA, GPS location, photos, or calendar contents through Apple Ads attribution. The app has no third-party advertising, builds no advertising profile, does not track you across apps or websites, and does not request App Tracking Transparency permission.
- Nothing else. No accounts or personal profiles, no precise-location tracking, no data sold or shared with data brokers.
Service providers we use
- Supabase — hosts the processing function your photo is sent to.
- Apple App Attest — lets our server verify that paid processing requests come from a genuine, Apple-distributed copy of Snap to Calendar. We independently validate and store Apple's signed receipt, then exchange it with Apple for an approximate 30-day count of App Attest keys created on that device as a fraud-risk signal. Apple does not give us your Apple ID or advertising identifier.
- Anthropic — provides the commercial AI API that reads the events from the photo. Commercial API inputs and outputs are not used to train its models by default. Standard API retention is up to 30 days unless a different retention agreement applies, with possible longer retention for legal or usage-policy enforcement.
- RevenueCat — validates App Store purchases and reports anonymous Apple Ads attribution. It receives an anonymous app/device identifier, purchase history, the short-lived Apple token, and the Apple-returned campaign information described above — never your name, Apple ID, photos, or calendar contents.
- Sentry — receives anonymous crash and error diagnostics.
- PostHog — provides the anonymous app and website analytics described here. It does not receive your photos or your calendar events.
- These providers process data on our behalf and are not permitted to use it for their own purposes. Data may be processed in the United States; where required, appropriate transfer safeguards apply.
This website
- We measure traffic on snaptocalendar.app using PostHog, so we can see which pages people find useful and whether they go on to the App Store. We record the page visited and the referring site, plus a click when someone follows a link to the App Store. New website events are marked to disable GeoIP, and PostHog is configured not to store the request IP.
- This is configured to run without cookies and without session recording. We do not build advertising profiles, and we do not track you across other websites.
- Website analytics are entirely separate from the app: PostHog never receives your photos, your scans, or your calendar events.
- To opt out entirely, enable "Do Not Track" or a content blocker in your browser, or simply do not visit the site — none of the app's functionality depends on it.
Purchases
- Subscriptions are sold and processed by Apple. We never see or receive your payment details.
Diagnostics
- The app may send anonymous crash reports and error diagnostics so we can fix problems. These contain technical data only — never your photos, and never your calendar contents.
How long we keep things
- Photos in our application storage: not retained. The processing function does not write the image to our database or file storage. Anthropic's standard commercial API retention described above may retain the API input or output for up to 30 days, subject to its stated exceptions.
- Local scan history, when created: kept until you delete the scan or the app.
- Temporary Calendar Settings recovery drafts on your device: eligible for restoration for up to 30 minutes, with removal on the terminal actions described above or on the next launch after expiry. If the app is never opened again, the expired local draft remains until a later launch or app deletion.
- Anonymous daily scan/cost records older than 90 days and inactive App Attest key records — including their most recently verified fraud receipt and approximate key count — older than 400 days are removed during later verified requests. A one-use hash is stored only after an App Attest proof succeeds; expired hashes are removed during later verified requests. If there is no later verified request, these anonymous operational records may remain until our next service cleanup.
- Anonymous product and website analytics: retained according to our PostHog project retention settings. Historical events created before August 10, 2026 may contain IP-derived location fields; new events do not.
- Anonymous purchase and Apple Ads attribution records: retained by RevenueCat as needed to validate subscriptions and report their long-term campaign results, then deleted or aggregated when no longer needed. Because there is no account and the records are not linked to your identity, we generally cannot identify which anonymous record is yours.
- Crash diagnostics: retained on a rolling basis (typically up to 90 days) and then deleted.
Children
- The app is rated 4+ but is designed for general audiences, is not directed at children under 13, and does not knowingly collect personal information from children. Because we collect no accounts or personal details, we hold no children's personal data.
Your rights
- Depending on where you live (for example, under the GDPR in the EU/UK or the CCPA/CPRA in California), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict its processing. Because we do not maintain accounts and hold no information that identifies you, we usually have no personal data to look up. Deleting the app removes the data stored on your device.
- We do not sell or share personal information as those terms are defined under California law.
- To ask a question or make a request, email hello@snaptocalendar.app.
Changes
- If this policy changes, the effective date above will change. Material changes will be highlighted in the app or on this page.
Contact
Acorn Labs LLC · Questions? Email hello@snaptocalendar.app. See also our Terms of Use.