Maddy Privacy Policy

Effective date: July 28, 2026

Last updated: July 28, 2026

App-version notice: The UK analytics-consent screen and Settings control described below are included in the next installed iOS build. Existing installations must update to receive these controls.

Maddy is an AI-assisted planning and scheduling application operated by Maddy Labs ("Maddy," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Maddy iOS app, its extensions and widgets, the Maddy website, and related services that link to this Policy (collectively, the "Services").

This Policy does not replace the privacy notices of Apple, OpenAI, or other third-party services you choose to use with Maddy.

1. Privacy At A Glance

2. Information We Process

The information Maddy processes depends on the features and permissions you use.

Account And Profile Information

We may process:

You may use core Maddy functionality without providing an email address where the app offers that option.

Messages, Assistant Content, And Feedback

We process the messages, instructions, corrections, feedback, and other text you send to Maddy. This may include names, deadlines, school or work information, locations, relationship details, and other information you choose to include.

When conversation continuity is enabled, recent chat history and compact assistant context may be retained on your device for up to 30 days, subject to a maximum record count. You can disable continuity or clear this data in Maddy.

Images, Screenshots, Camera Content, And OCR

When you select or capture an image, Maddy may process:

Maddy does not access photos you do not select. If screenshot cleanup is enabled, Maddy only attempts to delete screenshots you explicitly shared through the Maddy share extension; images selected or captured inside Maddy are not deleted from Photos by that feature.

Calendar, Reminder, Routine, And Planning Information

With your permission, Maddy may read or write information needed to provide scheduling features, including:

Maddy is designed to send a limited, relevant planning context for a request rather than your entire calendar. The exact context can still contain personal information.

Preferences, Memory, And Personalization

We may process settings and information Maddy learns from your explicit instructions or feedback, such as:

Much of this information is stored locally on your device. Relevant portions may be included in an assistant request when needed to respond.

Friends And Shared Scheduling

If Friends or shared scheduling features are available and you use them, we may process:

The people included in a shared booking may receive the booking information necessary to participate. Do not include sensitive or confidential information in a shared booking unless everyone involved should receive it.

Location And Weather

If you grant location permission and use a feature that evaluates weather for an outdoor plan, Maddy may request an approximate current location (configured for approximately 100-metre accuracy) and use it on your device with Apple's WeatherKit service. Maddy uses the result to generate a local weather advisory. It does not intentionally send your current coordinates to Maddy's backend or maintain a location-history database. Event locations and coordinates already present in calendar information may still be processed as planning context when relevant to your request.

Notifications, Widgets, And Campaigns

If you enable notifications, we may process:

Widgets and local notifications may display event, reminder, time, priority, or location information on your device. Your iOS notification-preview and device-lock settings affect who can see that information.

Maddy may also display one-time in-app service announcements. In-app pop-ups can be dismissed.

Purchases And Subscription Information

Purchases are processed by Apple. We may receive and store product identifiers, an app account token, entitlement status, subscription source, expiration, and transaction-validation results. We do not receive your full payment-card number.

Product Analytics, Usage, And Diagnostics

We collect limited event and operational metadata to operate and improve Maddy, such as:

Maddy's analytics payload is designed not to include raw messages, OCR text, screenshots, calendar contents, or personal files. Product analytics events are linked to a pseudonymous Maddy account identifier so that metrics such as retention and feature adoption can be calculated.

When product analytics is enabled, we use Google Firebase Analytics. Firebase automatically collects basic app-use events and may receive a pseudonymous app-instance identifier, device identifiers such as the Identifier for Vendor, device and app information, language, time zone, broad region derived from an IP address, interaction timestamps, and allowlisted product-event metadata. Maddy's custom Firebase events are designed not to include raw messages, OCR text, screenshots, calendar contents, personal files, precise location, Apple's advertising identifier, or authentication secrets. We also store privacy-filtered analytics metadata in Maddy's backend to operate the administrator dashboard and calculate product metrics.

For users whose device region setting is the United Kingdom (GB), Firebase Analytics remains off until Maddy evaluates the stored choice. Maddy presents the analytics consent screen once during onboarding or, for an existing user who has not yet made a choice, before the app opens. Choosing Not Now is stored as a decline, does not block core or paid functionality, and keeps optional behavioral analytics disabled. Maddy checks the device's region setting on the device for this purpose and does not collect or transmit location information to decide whether to show the consent screen.

For users outside the United Kingdom, product analytics is enabled by default unless they disable it. All users can change their choice through Settings → Privacy → Share Product Analytics. Disabling analytics stops future optional Firebase events and Maddy product-event uploads and clears queued product-analytics uploads. It does not remove information that has already been aggregated or that must be retained for security or legal purposes.

Essential operational telemetry is separate from optional product analytics and continues regardless of the analytics choice. It is limited to information needed to secure, operate, debug, and monitor the Services, such as route, status, latency, request identifier, and error category. It is designed to exclude raw messages, screenshots, OCR text, calendar contents, authentication secrets, and full AI payloads. We will provide additional notice and obtain consent where required before materially changing the analytics services, information categories, or purposes we use.

Security, Fraud Prevention, And Network Information

We process information needed to authenticate requests, enforce limits, and protect the Services, including:

Production logging is designed to exclude raw messages, screenshots, OCR text, calendar details, authentication secrets, and full model payloads.

Support And Administration

If you contact us, we may process your contact information, support request, and any material you choose to provide. Authorized administrators may create internal account notes, link a user to a feature request, record account actions, and review a timeline of account and product events. These internal notes are not shown to other users.

3. How We Collect Information

We collect information:

4. Why We Use Information

We use information to:

We do not use personal information for third-party targeted advertising.

5. AI Processing And Third-Party Disclosure

Maddy uses OpenAI's API to interpret many text and image requests and to produce structured proposed actions or answers. Depending on your request, information sent to Maddy's backend and OpenAI may include:

Maddy may also send selected screenshots, OCR text, or profile images to OpenAI's Moderation API for safety screening.

Before Maddy first sends personal information to OpenAI, Maddy presents a separate disclosure that identifies OpenAI, describes the categories of information that may be sent, explains why the disclosure is necessary, links to this Policy, and asks for your explicit permission. If you decline, Maddy does not send your personal information to OpenAI and AI-dependent features will not be available.

You can withdraw this permission through the privacy controls in Maddy Settings. After withdrawal, Maddy will not send new personal information to OpenAI unless you grant permission again. Withdrawal does not affect processing already completed or information retained as described in this Policy. Calendar, image, and other device permissions can be changed separately in iOS Settings.

OpenAI states that data submitted to its API is not used to train or improve its models unless the API customer expressly opts in. Maddy currently uses the Responses API's default storage settings. Under OpenAI's current documentation, Responses API application state is stored for at least 30 days; abuse-monitoring logs may be retained for up to 30 days, or longer when legally required or reasonably necessary to protect services or third parties; and prompt-cache application state may persist for up to 24 hours. These periods and exceptions are controlled by OpenAI and may change. Maddy does not represent that provider-side content is immediately deleted.

AI output may be inaccurate. Maddy applies additional validation and permission checks, but you should review important dates, times, recipients, and calendar changes.

6. When We Disclose Information

We disclose information only as described in this Policy:

We require service providers acting on our behalf to protect personal information and use it only for authorized purposes. Third-party services also operate under their own terms and privacy notices.

7. International Processing

Maddy is operated from Canada. Maddy and its providers, including Cloudflare, OpenAI, Google, and Apple, may process information outside your province, state, or country, including in Canada, the United States, and other places where they or their subprocessors operate. Foreign authorities may be able to access information under the laws that apply where it is processed.

We use contractual, organizational, and technical measures appropriate to the information and processing involved. Contact us for information about safeguards that apply to international processing.

8. Retention

We keep personal information only as long as reasonably necessary for the purposes described in this Policy, subject to legal, security, fraud-prevention, subscription, and dispute-resolution needs.

Our current retention approach is:

Information Current retention approach
Local chat history Up to 30 days when conversation continuity is enabled; disabled continuity removes retained chat history.
Local timeline and notification interaction history Generally up to 7 days for the timeline store; other operational stores vary and are cleared through deletion/reset controls.
Share-extension image handoff Deleted after consumption or swept after approximately 30 minutes.
Pending screenshot and notification records Temporary; pending screenshot replies are designed to expire after 24 hours. Expired server records are cleaned opportunistically.
Usage and client execution records Generally 90 days.
Product analytics events For as long as reasonably needed to measure product adoption, retention, reliability, and service performance. Account deletion deletes or irreversibly de-identifies analytics events that can be associated with your Maddy account, except for limited records that must be retained for security or legal purposes.
Google Firebase Analytics User-level and event-level analytics data is subject to the retention configured for Maddy's Google Analytics property, which is up to 14 months for a standard property. Aggregated reporting data may remain longer.
OpenAI Responses content Application state is stored for at least 30 days under the current settings; abuse-monitoring logs may be retained for up to 30 days or longer in the circumstances described above; prompt-cache application state may persist for up to 24 hours.
Profile, Friends, and shared bookings Until changed, removed, or deleted through account deletion, subject to lawful retention exceptions.
Subscription and App Store records For the life of the entitlement and afterwards as reasonably needed for restoration, accounting, fraud prevention, disputes, and legal compliance.
Security and device-integrity records For as long as reasonably needed to prevent account or trial abuse and protect the Services.
Account-deletion audit For as long as reasonably needed to document deletion, prevent abuse, resolve disputes, and meet legal obligations.
Calendar events written to Apple Calendar Remain in Apple Calendar until you delete them there, even if you delete Maddy.

Backup copies, if any, may remain for a limited period before being overwritten. We may retain aggregated or de-identified information where it cannot reasonably be used to identify you.

9. Your Choices And Rights

Depending on where you live, you may have rights to:

You can also:

To make a privacy request, email hello@maddylabs.com. We may need to verify your identity. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising a privacy right.

Maddy does not sell personal information or share it for cross-context behavioral advertising. We therefore do not offer a sale or targeted-advertising opt-out for the Services described in this Policy.

Account And Data Deletion

Using Delete My Data is designed to:

After deletion, Maddy may retain a pseudonymous account record, entitlement and App Store history, registered App Attest keys and related device-integrity records, limited security or usage records, and an account-deletion audit only for subscription restoration, quota enforcement, fraud and abuse prevention, security, legal compliance, or legal claims. We limit retained fields to what is reasonably necessary for those purposes. They are not used to restore deleted user content or for product analytics.

Deleting Maddy does not cancel an Apple subscription and does not delete events already saved in Apple Calendar. Maddy tells you before account deletion that Apple billing may continue and provides access to Apple subscription management. Manage subscriptions through Apple and delete calendar events from Apple Calendar. You can also manage apps connected to Sign in with Apple through your Apple Account settings.

10. Legal Bases For EEA And UK Users

If EEA or UK data-protection law applies, our legal bases may include:

Maddy does not currently make decisions based solely on automated processing that produce legal or similarly significant effects. AI may propose scheduling actions, but app permissions, deterministic validation, confirmation rules, and user controls remain part of the process.

11. Children

Maddy is a general-audience productivity service and is not directed to children under 14. You must be at least 14 years old to use Maddy. If the law where you live requires a higher age to consent to data processing or enter the Terms, you must meet that age or have legally valid permission from a parent or guardian.

Maddy does not currently provide a verified parental-consent process. If we learn that we collected personal information from a child who could not lawfully provide it, we will take reasonable steps to delete it. A parent or guardian may contact hello@maddylabs.com.

12. Security

Maddy uses safeguards intended to protect personal information, including HTTPS, signed and expiring credentials, Keychain storage for sensitive local credentials, iOS file protection, request validation, rate limits, idempotency controls, account suspension, privacy-safe logging, restricted administrator access, and optional Apple device attestation.

No security method is perfect. Do not send highly sensitive content that is unnecessary for your scheduling request. Notify us promptly at hello@maddylabs.com if you believe your account or information has been compromised.

13. Changes To This Policy

We may update this Policy as Maddy changes. We will update the "Last updated" date and provide additional notice in the app or by another appropriate method when a change is material. Where required, we will obtain new consent before using personal information for a materially different purpose or disclosing it to a new type of third party.

14. Contact And Complaints

The organization responsible for personal information is:

Maddy Labs, Privacy Officer

Email: hello@maddylabs.com

Country: Canada

You may also complain to the privacy regulator responsible in your jurisdiction, including the Office of the Privacy Commissioner of Canada or an applicable provincial privacy authority. Please contact us first if you would like help identifying the appropriate regulator.