Maddy Privacy Policy
Effective date: July 28, 2026
Last updated: July 28, 2026
App-version notice: The UK analytics-consent screen and Settings control described below are included in the next installed iOS build. Existing installations must update to receive these controls.
Maddy is an AI-assisted planning and scheduling application operated by Maddy Labs ("Maddy," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Maddy iOS app, its extensions and widgets, the Maddy website, and related services that link to this Policy (collectively, the "Services").
This Policy does not replace the privacy notices of Apple, OpenAI, or other third-party services you choose to use with Maddy.
1. Privacy At A Glance
- Maddy processes messages, selected images, and relevant planning context to understand what you ask it to do.
- Maddy uses OpenAI's API to interpret many messages and images. Before Maddy first sends your personal information to OpenAI, Maddy identifies OpenAI, explains what will be sent and why, and asks for your explicit permission.
- Google Firebase Analytics is optional. For users whose device region is set to the United Kingdom, Maddy asks for consent before enabling product analytics. Choosing Not Now does not limit functionality. All users can disable product analytics in Maddy Settings.
- Calendar, photo, camera, location, and notification access are optional iOS permissions. You can change them in iOS Settings.
- Maddy does not sell personal information, run third-party advertising, or use advertising identifiers for cross-app tracking.
- Maddy's administrative tools show account, usage, and operational metadata by default, not raw conversations, screenshots, calendar contents, or personal files.
- You can delete Maddy data in the app. Calendar events already saved to Apple Calendar and records we must or reasonably need to retain for security, fraud prevention, subscriptions, legal compliance, or dispute resolution may remain as described below.
2. Information We Process
The information Maddy processes depends on the features and permissions you use.
Account And Profile Information
We may process:
- A randomly generated Maddy account or installation identifier.
- Your display name, username, profile photo, and verified email address, if provided.
- Sign in with Apple identifiers and authentication records when you choose Apple account recovery or sign-in.
- Account status, beta status, join date, last login, last active time, app version, device family, and subscription status.
- Session credentials, credential version, and device-integrity records used to secure access.
You may use core Maddy functionality without providing an email address where the app offers that option.
Messages, Assistant Content, And Feedback
We process the messages, instructions, corrections, feedback, and other text you send to Maddy. This may include names, deadlines, school or work information, locations, relationship details, and other information you choose to include.
When conversation continuity is enabled, recent chat history and compact assistant context may be retained on your device for up to 30 days, subject to a maximum record count. You can disable continuity or clear this data in Maddy.
Images, Screenshots, Camera Content, And OCR
When you select or capture an image, Maddy may process:
- The selected image.
- Text recognized from the image using optical character recognition (OCR), which begins on-device.
- Image type, scheduling details, and processing status.
- Temporary handoff, job, and result records used to complete the request and prevent duplicate actions.
Maddy does not access photos you do not select. If screenshot cleanup is enabled, Maddy only attempts to delete screenshots you explicitly shared through the Maddy share extension; images selected or captured inside Maddy are not deleted from Photos by that feature.
Calendar, Reminder, Routine, And Planning Information
With your permission, Maddy may read or write information needed to provide scheduling features, including:
- Event and reminder titles, dates, times, recurrence, notes, locations, and calendar identifiers.
- Nearby or relevant calendar items used to assess availability, conflicts, duplicates, and follow-up requests.
- Tasks, routines, workload plans, sleep windows, reminder preferences, scheduling priorities, and execution receipts.
Maddy is designed to send a limited, relevant planning context for a request rather than your entire calendar. The exact context can still contain personal information.
Preferences, Memory, And Personalization
We may process settings and information Maddy learns from your explicit instructions or feedback, such as:
- Scheduling priorities and preferred times.
- Sleep or rest windows and exceptions.
- Reminder and notification preferences.
- Important people, nicknames, routines, and planning preferences.
- Compact context frames used to understand follow-up requests.
Much of this information is stored locally on your device. Relevant portions may be included in an assistant request when needed to respond.
Friends And Shared Scheduling
If Friends or shared scheduling features are available and you use them, we may process:
- Searchable username and public profile fields.
- Friend requests, friendship status, blocks, and participant identifiers.
- Booking titles, dates, times, locations, notes, responses, suggestions, and status.
The people included in a shared booking may receive the booking information necessary to participate. Do not include sensitive or confidential information in a shared booking unless everyone involved should receive it.
Location And Weather
If you grant location permission and use a feature that evaluates weather for an outdoor plan, Maddy may request an approximate current location (configured for approximately 100-metre accuracy) and use it on your device with Apple's WeatherKit service. Maddy uses the result to generate a local weather advisory. It does not intentionally send your current coordinates to Maddy's backend or maintain a location-history database. Event locations and coordinates already present in calendar information may still be processed as planning context when relevant to your request.
Notifications, Widgets, And Campaigns
If you enable notifications, we may process:
- An APNs device token, device identifier, platform, and notification environment.
- Reminder, follow-up, booking, delivery, impression, and interaction metadata.
- Notification text and pending-action records needed to deliver or complete an action.
Widgets and local notifications may display event, reminder, time, priority, or location information on your device. Your iOS notification-preview and device-lock settings affect who can see that information.
Maddy may also display one-time in-app service announcements. In-app pop-ups can be dismissed.
Purchases And Subscription Information
Purchases are processed by Apple. We may receive and store product identifiers, an app account token, entitlement status, subscription source, expiration, and transaction-validation results. We do not receive your full payment-card number.
Product Analytics, Usage, And Diagnostics
We collect limited event and operational metadata to operate and improve Maddy, such as:
- App opens, active days, onboarding completion, feature use, campaign impressions, and session duration.
- AI request route, request type, model, token counts, estimated cost, success or failure status, and quota use.
- Event creation, task scheduling, screenshot scheduling, routine, reminder, and similar feature counters.
- App version, build/source version, device family, and operating-system version.
- Request, transaction, and worker-version identifiers; validation or execution status; error category; and privacy-safe receipt digests.
Maddy's analytics payload is designed not to include raw messages, OCR text, screenshots, calendar contents, or personal files. Product analytics events are linked to a pseudonymous Maddy account identifier so that metrics such as retention and feature adoption can be calculated.
When product analytics is enabled, we use Google Firebase Analytics. Firebase automatically collects basic app-use events and may receive a pseudonymous app-instance identifier, device identifiers such as the Identifier for Vendor, device and app information, language, time zone, broad region derived from an IP address, interaction timestamps, and allowlisted product-event metadata. Maddy's custom Firebase events are designed not to include raw messages, OCR text, screenshots, calendar contents, personal files, precise location, Apple's advertising identifier, or authentication secrets. We also store privacy-filtered analytics metadata in Maddy's backend to operate the administrator dashboard and calculate product metrics.
For users whose device region setting is the United Kingdom (GB), Firebase Analytics remains off until Maddy evaluates the stored choice. Maddy presents the analytics consent screen once during onboarding or, for an existing user who has not yet made a choice, before the app opens. Choosing Not Now is stored as a decline, does not block core or paid functionality, and keeps optional behavioral analytics disabled. Maddy checks the device's region setting on the device for this purpose and does not collect or transmit location information to decide whether to show the consent screen.
For users outside the United Kingdom, product analytics is enabled by default unless they disable it. All users can change their choice through Settings → Privacy → Share Product Analytics. Disabling analytics stops future optional Firebase events and Maddy product-event uploads and clears queued product-analytics uploads. It does not remove information that has already been aggregated or that must be retained for security or legal purposes.
Essential operational telemetry is separate from optional product analytics and continues regardless of the analytics choice. It is limited to information needed to secure, operate, debug, and monitor the Services, such as route, status, latency, request identifier, and error category. It is designed to exclude raw messages, screenshots, OCR text, calendar contents, authentication secrets, and full AI payloads. We will provide additional notice and obtain consent where required before materially changing the analytics services, information categories, or purposes we use.
Security, Fraud Prevention, And Network Information
We process information needed to authenticate requests, enforce limits, and protect the Services, including:
- Session and installation tokens.
- Apple App Attest keys, challenges, assertions, counters, and validation receipts.
- Rate-limit, idempotency, quota, subscription, and anti-abuse records.
- IP address or a derived value used for network security and rate limiting.
- Technical logs that identify route, status, latency, request identifiers, and error category.
Production logging is designed to exclude raw messages, screenshots, OCR text, calendar details, authentication secrets, and full model payloads.
Support And Administration
If you contact us, we may process your contact information, support request, and any material you choose to provide. Authorized administrators may create internal account notes, link a user to a feature request, record account actions, and review a timeline of account and product events. These internal notes are not shown to other users.
3. How We Collect Information
We collect information:
- Directly from you when you type, upload, configure, purchase, contact us, or use a feature.
- From your device and Apple frameworks when you grant a permission or use Sign in with Apple, StoreKit, App Attest, APNs, EventKit, Photos, Camera, Location, or Weather services.
- Automatically from your use of Maddy, such as product events, request status, and security records.
- From other Maddy users when they send you a friend request or include you in a shared scheduling request.
4. Why We Use Information
We use information to:
- Provide, personalize, and maintain the Services.
- Interpret messages and images and return structured scheduling results.
- Check availability, conflicts, duplicates, and sleep or preference constraints.
- Create, update, move, or delete calendar events, reminders, tasks, routines, and bookings as requested or confirmed.
- Preserve continuity across follow-up messages.
- Authenticate accounts, restore access, validate subscriptions, and synchronize supported features.
- Deliver notifications, in-app announcements, support, and service communications.
- Measure onboarding, reliability, feature adoption, retention, usage, and cost.
- Enforce free and paid limits and prevent fraud, abuse, duplicate actions, or unauthorized access.
- Debug failures, monitor availability, protect users, and comply with legal obligations.
- Establish, exercise, or defend legal claims.
We do not use personal information for third-party targeted advertising.
5. AI Processing And Third-Party Disclosure
Maddy uses OpenAI's API to interpret many text and image requests and to produce structured proposed actions or answers. Depending on your request, information sent to Maddy's backend and OpenAI may include:
- Your current message and recent relevant conversation context.
- Selected images and OCR text.
- Relevant calendar items, reminders, people, preferences, learned context, and sleep settings.
- Current date, time, time zone, app context, and request metadata.
Maddy may also send selected screenshots, OCR text, or profile images to OpenAI's Moderation API for safety screening.
Before Maddy first sends personal information to OpenAI, Maddy presents a separate disclosure that identifies OpenAI, describes the categories of information that may be sent, explains why the disclosure is necessary, links to this Policy, and asks for your explicit permission. If you decline, Maddy does not send your personal information to OpenAI and AI-dependent features will not be available.
You can withdraw this permission through the privacy controls in Maddy Settings. After withdrawal, Maddy will not send new personal information to OpenAI unless you grant permission again. Withdrawal does not affect processing already completed or information retained as described in this Policy. Calendar, image, and other device permissions can be changed separately in iOS Settings.
OpenAI states that data submitted to its API is not used to train or improve its models unless the API customer expressly opts in. Maddy currently uses the Responses API's default storage settings. Under OpenAI's current documentation, Responses API application state is stored for at least 30 days; abuse-monitoring logs may be retained for up to 30 days, or longer when legally required or reasonably necessary to protect services or third parties; and prompt-cache application state may persist for up to 24 hours. These periods and exceptions are controlled by OpenAI and may change. Maddy does not represent that provider-side content is immediately deleted.
AI output may be inaccurate. Maddy applies additional validation and permission checks, but you should review important dates, times, recipients, and calendar changes.
6. When We Disclose Information
We disclose information only as described in this Policy:
- OpenAI: to interpret messages and images and perform safety moderation.
- Cloudflare: to host Maddy's API, database, key-value storage, rate limiting, and related infrastructure.
- Google Firebase Analytics: to measure app use, adoption, engagement, and reliability using the limited analytics information described above.
- Apple: when you use services such as Sign in with Apple, StoreKit and the App Store, App Attest, Apple Push Notification service, and WeatherKit. Calendar, Photos, Camera, and Location permissions are also governed by iOS and Apple's platform rules; some related processing occurs only on your device.
- Other Maddy users: when you use Friends or shared scheduling features.
- Professional advisers and service providers: such as legal, accounting, security, or support providers who need access for their work and are subject to appropriate duties.
- Legal and safety recipients: when reasonably necessary to comply with law, legal process, enforce our agreements, investigate abuse, protect rights or safety, or respond to an emergency.
- Business transaction recipients: in connection with financing, due diligence, merger, acquisition, reorganization, or sale, subject to confidentiality and applicable law.
We require service providers acting on our behalf to protect personal information and use it only for authorized purposes. Third-party services also operate under their own terms and privacy notices.
7. International Processing
Maddy is operated from Canada. Maddy and its providers, including Cloudflare, OpenAI, Google, and Apple, may process information outside your province, state, or country, including in Canada, the United States, and other places where they or their subprocessors operate. Foreign authorities may be able to access information under the laws that apply where it is processed.
We use contractual, organizational, and technical measures appropriate to the information and processing involved. Contact us for information about safeguards that apply to international processing.
8. Retention
We keep personal information only as long as reasonably necessary for the purposes described in this Policy, subject to legal, security, fraud-prevention, subscription, and dispute-resolution needs.
Our current retention approach is:
| Information | Current retention approach |
|---|---|
| Local chat history | Up to 30 days when conversation continuity is enabled; disabled continuity removes retained chat history. |
| Local timeline and notification interaction history | Generally up to 7 days for the timeline store; other operational stores vary and are cleared through deletion/reset controls. |
| Share-extension image handoff | Deleted after consumption or swept after approximately 30 minutes. |
| Pending screenshot and notification records | Temporary; pending screenshot replies are designed to expire after 24 hours. Expired server records are cleaned opportunistically. |
| Usage and client execution records | Generally 90 days. |
| Product analytics events | For as long as reasonably needed to measure product adoption, retention, reliability, and service performance. Account deletion deletes or irreversibly de-identifies analytics events that can be associated with your Maddy account, except for limited records that must be retained for security or legal purposes. |
| Google Firebase Analytics | User-level and event-level analytics data is subject to the retention configured for Maddy's Google Analytics property, which is up to 14 months for a standard property. Aggregated reporting data may remain longer. |
| OpenAI Responses content | Application state is stored for at least 30 days under the current settings; abuse-monitoring logs may be retained for up to 30 days or longer in the circumstances described above; prompt-cache application state may persist for up to 24 hours. |
| Profile, Friends, and shared bookings | Until changed, removed, or deleted through account deletion, subject to lawful retention exceptions. |
| Subscription and App Store records | For the life of the entitlement and afterwards as reasonably needed for restoration, accounting, fraud prevention, disputes, and legal compliance. |
| Security and device-integrity records | For as long as reasonably needed to prevent account or trial abuse and protect the Services. |
| Account-deletion audit | For as long as reasonably needed to document deletion, prevent abuse, resolve disputes, and meet legal obligations. |
| Calendar events written to Apple Calendar | Remain in Apple Calendar until you delete them there, even if you delete Maddy. |
Backup copies, if any, may remain for a limited period before being overwritten. We may retain aggregated or de-identified information where it cannot reasonably be used to identify you.
9. Your Choices And Rights
Depending on where you live, you may have rights to:
- Know whether and how we process your personal information.
- Access personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete personal information, subject to lawful exceptions.
- Withdraw consent, where processing is based on consent.
- Object to or restrict certain processing.
- Receive a portable copy of certain information.
- Appeal or complain to a privacy regulator.
You can also:
- Change Calendar, Photos, Camera, Location, and Notification permissions in iOS Settings.
- Grant or withdraw permission to disclose personal information to OpenAI through the privacy controls in Maddy Settings.
- Enable or disable optional product analytics through Settings → Privacy → Share Product Analytics. For UK users, optional product analytics remains off until they choose Allow Analytics; choosing Not Now persists as a decline and does not limit functionality.
- Disable conversation continuity or clear learned data in Maddy.
- Edit or delete calendar events in Apple Calendar.
- Manage or cancel subscriptions through your Apple account.
- Use Delete My Data in Maddy Settings.
To make a privacy request, email hello@maddylabs.com. We may need to verify your identity. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising a privacy right.
Maddy does not sell personal information or share it for cross-context behavioral advertising. We therefore do not offer a sale or targeted-advertising opt-out for the Services described in this Policy.
Account And Data Deletion
Using Delete My Data is designed to:
- Delete server-side profile, Friends, shared-booking, push-token, temporary screenshot, notification, idempotency, linked-identity, administrator-note, feature-link, and personal timeline records associated with your Maddy identity.
- Delete or irreversibly de-identify product-analytics records that can be associated with your Maddy identity, except for limited security or legally required records.
- Clear Maddy's local chats, screenshots, friends, nicknames, preferences, reminders, routines, and other Maddy-owned local data.
- Revoke prior Maddy session and installation credentials.
- Revoke Maddy's Sign in with Apple authorization when your account is linked through Sign in with Apple.
After deletion, Maddy may retain a pseudonymous account record, entitlement and App Store history, registered App Attest keys and related device-integrity records, limited security or usage records, and an account-deletion audit only for subscription restoration, quota enforcement, fraud and abuse prevention, security, legal compliance, or legal claims. We limit retained fields to what is reasonably necessary for those purposes. They are not used to restore deleted user content or for product analytics.
Deleting Maddy does not cancel an Apple subscription and does not delete events already saved in Apple Calendar. Maddy tells you before account deletion that Apple billing may continue and provides access to Apple subscription management. Manage subscriptions through Apple and delete calendar events from Apple Calendar. You can also manage apps connected to Sign in with Apple through your Apple Account settings.
10. Legal Bases For EEA And UK Users
If EEA or UK data-protection law applies, our legal bases may include:
- Contract: to provide requested app, account, scheduling, and subscription functions.
- Consent: for optional permissions, third-party AI disclosure where required, and optional processing.
- Legitimate interests: to secure, maintain, analyze, and improve the Services, prevent fraud, and support users, balanced against your rights.
- Legal obligation: to comply with law, accounting, regulatory, or valid legal-process requirements.
Maddy does not currently make decisions based solely on automated processing that produce legal or similarly significant effects. AI may propose scheduling actions, but app permissions, deterministic validation, confirmation rules, and user controls remain part of the process.
11. Children
Maddy is a general-audience productivity service and is not directed to children under 14. You must be at least 14 years old to use Maddy. If the law where you live requires a higher age to consent to data processing or enter the Terms, you must meet that age or have legally valid permission from a parent or guardian.
Maddy does not currently provide a verified parental-consent process. If we learn that we collected personal information from a child who could not lawfully provide it, we will take reasonable steps to delete it. A parent or guardian may contact hello@maddylabs.com.
12. Security
Maddy uses safeguards intended to protect personal information, including HTTPS, signed and expiring credentials, Keychain storage for sensitive local credentials, iOS file protection, request validation, rate limits, idempotency controls, account suspension, privacy-safe logging, restricted administrator access, and optional Apple device attestation.
No security method is perfect. Do not send highly sensitive content that is unnecessary for your scheduling request. Notify us promptly at hello@maddylabs.com if you believe your account or information has been compromised.
13. Changes To This Policy
We may update this Policy as Maddy changes. We will update the "Last updated" date and provide additional notice in the app or by another appropriate method when a change is material. Where required, we will obtain new consent before using personal information for a materially different purpose or disclosing it to a new type of third party.
14. Contact And Complaints
The organization responsible for personal information is:
Maddy Labs, Privacy Officer
Email: hello@maddylabs.com
Country: Canada
You may also complain to the privacy regulator responsible in your jurisdiction, including the Office of the Privacy Commissioner of Canada or an applicable provincial privacy authority. Please contact us first if you would like help identifying the appropriate regulator.