CalenPlan legal

CalenPlan Privacy Policy

Effective September 17, 2026

New Heights Innovations LLC (“New Heights Innovations,” “we,” “us,” or “our”) operates CalenPlan, a personal planning application for iPhone and iPad. This policy explains what information CalenPlan processes, why it is used, when it is shared, and the choices available to you.

Information CalenPlan processes

Account information

When you create a CalenPlan account, we process your email address, account identifier, authentication status, and security-related account information. Passwords are handled by our authentication provider and are not available to CalenPlan support staff in readable form.

Planning content

CalenPlan processes the content you choose to create or import, which may include calendars, events, event locations and notes, recurrence information, goals, goal progress, tasks, weekly reviews, journal entries, settings, and synchronization metadata. This information is used to provide the planning, offline, synchronization, export, and account-management features you request.

Apple Calendar information

If you choose to connect Apple Calendar, CalenPlan requests calendar access through Apple’s system permission flow. You select which calendars are shown or used and where eligible CalenPlan events may be written. Provider identifiers and synchronization metadata are used to prevent duplicates and coordinate updates. You can disconnect the integration without deleting unrelated Apple Calendar events. CalenPlan remains usable without Apple Calendar permission.

Google Calendar information

If you choose to connect Google Calendar, Google presents a separate authorization screen before CalenPlan receives access. CalenPlan requests the minimum approved Calendar permissions needed to list calendars and perform the two-way event operations you select. Calendar and event content, provider identifiers, incremental synchronization cursors, and encrypted authorization credentials are processed through CalenPlan’s server so the integration can synchronize and recover without placing a Google client secret or long-lived refresh credential in the app.

You can choose participating calendars, disconnect the integration, and revoke CalenPlan from your Google Account. Disconnecting does not delete unrelated Google Calendar content. CalenPlan’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Calendar information is used only to provide or improve the calendar and planning features visible to you, for necessary security, or as otherwise permitted by that policy and applicable law. It is not used for advertising, sold, or used to train a generalized artificial-intelligence model.

CalenView images

CalenView can use a photo or screenshot you select to suggest candidate events. Image interpretation uses Apple on-device frameworks in the current release. The source image is not uploaded to CalenPlan’s servers. Nothing is added to your calendar until you review the candidates and explicitly confirm them.

Friends and encouragement

If you choose Friends & Encouragement, CalenPlan processes one-time invitation records, accepted or blocked connections, your sharing preferences, the completion type and date of achievements you deliberately share, and predefined encouragement reactions. Goal and milestone names are not shared unless you explicitly enable and select that option.

Connections do not receive your email address, calendars, goal list, WHY statements, notes, journal, tasks, recap, subscription status, or other connections. CalenPlan does not upload your contacts, provide public profiles or feeds, or offer free-form chat. You can revoke an unused invitation and mute, remove, or block a connection.

Notification delivery

If you separately enable eligible Friends & Encouragement alerts, CalenPlan receives an app-specific APNs device token and associates it with your account and installation so Apple can deliver the categories you selected. Tokens are encrypted in server custody, replaced or retired when invalid, and removed from the active account scope on sign-out or account deletion.

Remote payloads use generic privacy-minimized text and an authenticated in-app route; private goal, milestone, journal, calendar, invitation, or relationship content is fetched only after the app opens and reauthorizes the account. Local planning reminders remain separate and can work without enabling these remote alerts.

Subscription information

Apple processes purchases and payment information. CalenPlan receives limited transaction and entitlement information—such as product, subscription state, transaction identifiers, expiration, and revocation status—to provide paid access, restore purchases, prevent fraud, and support your account. CalenPlan does not receive your full payment-card details.

Reliability and security information

CalenPlan and its infrastructure process limited diagnostic and security information such as request identifiers, response status classes, timestamps, app version, synchronization state, and pseudonymous account, device, or network fingerprints. Network addresses may be processed transiently by hosting providers for delivery, abuse prevention, and security. Operational logging is designed to exclude passwords, access tokens, journal text, event contents, and other private planning content.

How information is used

We use information only as needed to:

  • provide Calendar, Goals, Tasks, Plan, Weekly Review, Journal, Search, CalenView, notifications, synchronization, export, and account features;
  • provide private, user-directed Friends & Encouragement invitations, achievement sharing, predefined reactions, and connection-safety controls;
  • keep your account and data synchronized across your devices;
  • process and reconcile App Store subscription access;
  • maintain security, prevent abuse, diagnose failures, and recover service;
  • respond to support, privacy, export, and deletion requests; and
  • comply with applicable law and enforce our terms.

CalenPlan does not sell personal information, use planning content for advertising, or track you across other companies’ apps or websites. The current release contains no third-party advertising or behavioral-analytics SDK.

Service providers and disclosure

CalenPlan uses:

  • Apple for iOS and iPadOS frameworks, optional Apple Calendar access, local and APNs notifications, App Store distribution, purchases, and subscription management;
  • Google for the optional user-authorized Google Calendar integration under Google’s applicable terms and user-data policies;
  • Supabase for native-app authentication, hosted PostgreSQL data storage, API functions, backups, and related infrastructure; and
  • Resend for transactional authentication and account email delivery.

These providers process information to perform services for CalenPlan under their own applicable terms and privacy commitments. We may also disclose information when required by law, to protect rights or safety, to address fraud or security, or as part of a business transaction subject to appropriate safeguards. We do not give providers permission to use private planning content for advertising.

The existing CalenPlan web application is a separate service in the first native release. Native accounts and web-app accounts are not linked, and the native app does not retrieve or migrate existing web-app content. The optional user-directed transfer workflow imports only a file the user deliberately chooses and confirms.

Storage, security, and international processing

CalenPlan uses encrypted network transport and Apple Keychain for native authentication sessions. Access to server data is scoped to the authenticated account, and private content is not intended to be visible to another account. No system can guarantee absolute security. Information may be processed in the United States or other locations where approved providers operate, subject to applicable safeguards.

Retention and deletion

Active account and planning data is retained while your account remains active. User-deleted content is removed from active CalenPlan application systems within 30 days, except when temporary retention is required for security, fraud prevention, legal compliance, dispute resolution, or an active legal hold. When you delete your CalenPlan account through a valid request, closed-account data is deleted or de-identified from active application systems within 30 days.

App Store subscriptions are managed separately through Apple; deleting a CalenPlan account does not automatically cancel a subscription. Security and diagnostic logs are retained for up to 90 days unless more time is reasonably necessary to investigate a documented security incident. Support correspondence is retained for up to 24 months. Subscription, transaction, tax, and accounting records are retained only for the period required by applicable law or legitimate accounting obligations.

The CalenPlan Production database uses Supabase Pro automatic daily database backups with a seven-day rolling retention period. Point-in-Time Recovery is not represented as enabled. Supabase database backups include database information and associated Storage metadata, but not files stored through the Supabase Storage API.

Deleted information may remain temporarily in encrypted or access-restricted backups until those backups expire through the ordinary seven-day backup cycle. Deleted information will not be intentionally restored to active use. If disaster recovery restores a backup containing previously deleted records, CalenPlan will reapply recorded deletion requests where technically feasible. Narrowly scoped information may be retained beyond the ordinary period when required by law, necessary to resolve a dispute, or reasonably necessary for a documented security or fraud investigation. Legal and security holds are not used as a general exception to the deletion policy.

Your choices and rights

Depending on your location, you may have rights to access, correct, export, or delete personal information and to appeal or complain about a response. CalenPlan provides local export and in-app account deletion controls. You can also:

  • change Apple Calendar access in iOS Settings or disconnect it in CalenPlan;
  • disconnect Google Calendar in CalenPlan or revoke CalenPlan in your Google Account;
  • change notification permission in iOS Settings and notification categories in CalenPlan;
  • choose achievement recipients, keep names private, revoke an eligible share, and mute, remove, or block a Friends & Encouragement connection;
  • manage or cancel a subscription through Apple; and
  • contact us about a privacy request.

We may need to verify your account before fulfilling a request. Support and privacy requests are acknowledged within two business days and tracked through completion within the period required by applicable law. We will not ask you to send a password, verification code, access token, or private journal or calendar content by email.

Children’s privacy

CalenPlan is not directed to children under 13 and does not knowingly permit children under 13 to create accounts. Users under the age of legal majority must have permission from a parent or legal guardian. Contact us if you believe a child has provided information contrary to this policy.

Changes

We may update this policy as CalenPlan, its providers, or legal requirements change. We will update the effective date and provide additional notice when required.

Contact

New Heights Innovations LLC
Mark@NewHeightsInnovations.com

CalenPlan uses email-only public contact at launch. A public mailing address is not published.