This Privacy Policy explains how Flexi Calendar ("Flexi," "we," "us," or "our") handles information when you use the Flexi iOS app and its related messaging, group-planning, notification, and support services. It describes the Flexi 5.0 product as released; older app versions may handle legacy messages differently, as explained below.
1. Summary
- Flexi uses a verified phone number to create and protect your account.
- With your permission, Flexi can read contacts on your device and submit phone numbers for account matching. Flexi does not provide a global people-search directory.
- New text messages, exported-calendar attachments, and group-event revisions created by the official Flexi 5.0 client are end-to-end encrypted. Important group, calendar, RSVP, delivery, and account metadata is not end-to-end encrypted.
- Flexi uses Firebase services for authentication, cloud data, server functions, device registration, push delivery, and app attestation. Apple services support push delivery, App Attest, device calendars, photos, and QR-code scanning.
- Flexi does not include ads, advertising SDKs, or cross-app tracking. We do not sell personal information.
- You can delete your account in the app. A minimal account-identifier deny record remains for up to 48 hours to stop an already-issued sign-in token from recreating deleted data, then is scheduled for automatic removal.
2. Information Flexi handles
Account and profile information
Flexi processes:
- your phone number, Firebase Authentication user ID, authentication tokens, and SMS-verification session information;
- the display name, profile photo or emoji, local Flexi identifier, and related profile fields you choose to provide; and
- account status, creation/update timestamps, and security state needed to operate and protect the account.
Firebase Authentication and the telecommunications providers involved in SMS delivery process the phone number and verification request. Flexi stores authentication and pending-verification credentials in device-protected storage where supported. Never send an SMS verification code to support or another person.
Contacts, directory matching, and invitations
Contact access is optional and requires iOS permission. When granted, Flexi can read contact names, phone numbers, email addresses, nicknames, and organization names from the device address book so you can find people and prepare invitations.
For Flexi account matching, the app sends submitted contact phone numbers in bounded batches, together with a country or region code used for normalization, to an authenticated Firebase function. The function checks for verified Flexi accounts and returns only matching profiles; it does not return a global user directory. Operational logs record lookup counts and, on an error, may record the requesting account ID, but are not designed to log the submitted address book phone numbers.
If you choose to invite someone, Flexi may store the selected contact's name, email address, phone number, normalized phone-number forms, an invitation message, your account ID and name, and delivery status so the invitation can be processed. If you use the iOS Messages composer, Apple, your carrier, and the recipient's messaging provider also handle the invitation you choose to send.
Calendars, schedules, and device data
With iOS calendar permission, Flexi can read and write calendar and event data in accounts available through Apple EventKit. That can include calendar names, event titles, notes, locations, links, start and end times, recurrence details, reminders, time zones, and availability. Flexi also stores calendars, schedules, events, display preferences, and optional work/pay settings locally on your device.
When you choose to:
- share group availability, Flexi uploads the selected calendar name, covered date range, exact busy intervals, your account identifiers, and a visibility choice. If you select full details, interval titles are uploaded too. Shared availability and calendar details are readable by the Flexi service and are not message end-to-end encrypted;
- add a group event to a device calendar, Flexi creates a separate calendar copy governed by that calendar account's provider, sync, sharing, backup, and retention settings; or
- export, import, display, or scan a calendar QR code, the calendar package is handled on the device and is disclosed to the people or services with whom you choose to share it.
Camera access is used to scan calendar QR codes. Photo-library access is used when you select a profile or group image. Flexi does not request precise GPS location; a location typed into an event is content you provide, not device-location data.
Chats, groups, events, and RSVPs
Flexi stores data needed to operate direct and group conversations, including:
- conversation IDs, membership, participant account and local IDs, display names, phone numbers, profile images or emoji, and legacy identity fields;
- group names and pictures, moderator IDs, permissions, member nicknames, and each member's pin, mute, read, and unread state;
- shared-calendar data described above;
- encrypted-message metadata such as sender ID, device-key ID, timestamp, approximate ciphertext size, signatures, and opaque recipient-device envelope identifiers;
- encrypted group-event metadata such as event ID, scheduled or cancelled status, creator/updater IDs, creation/update times, RSVP deadline, and whether a "Maybe" response is allowed; and
- RSVP data, including event ID, respondent IDs, going/maybe/not-going response, additional-guest count, and response time.
Other group members can see information made visible in the group, including the group name and picture, member account names, permitted nicknames, roles, RSVPs, and shared availability. A nickname does not replace or conceal the member's account name.
Push notifications and device registration
To deliver notifications, Flexi processes Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) tokens, a Firebase installation or device identifier, app/build version, APNs environment, notification settings, delivery status, badge state, public encryption-key records, and related registration metadata. Notification workers may log conversation/message identifiers, delivery results, and in some error cases a recipient account ID.
For encrypted Flexi 5.0 notifications, APNs and FCM receive generic visible text plus encrypted custom data and delivery metadata. The notification service extension on your device attempts to decrypt a preview. If it cannot safely decrypt and verify the preview, it shows a generic "New encrypted message" notice. iOS notification and Lock Screen settings ultimately control what appears on your device.
App integrity, diagnostics, and logs
Release builds use Firebase App Check with Apple's App Attest to help confirm that requests come from a genuine Flexi app on an Apple device. Apple and Firebase may process attestation tokens, app/device integrity signals, and related request data. App Check helps prevent abuse; it does not make service-readable metadata end-to-end encrypted.
Flexi uses Firebase Authentication, Firestore, Cloud Functions, Installations, Messaging, and App Check. These SDKs and services may process device/app identifiers, OS and app versions, network request details, error information, and other diagnostic or operational data. The Firebase SDK privacy manifests used by the app classify certain non-linked diagnostic data for analytics or app-functionality purposes and certain device/other data for app functionality. Flexi does not include the Firebase Analytics or Firebase Crashlytics product in the app target.
Our backend also records limited operational and security logs, such as request results, counts, function errors, notification status, report identifiers/categories, and deletion-cleanup totals. Network providers may automatically receive information such as IP address and request timing as part of providing an internet service.
Reports, blocks, and safety information
Flexi cannot proactively read or scan end-to-end encrypted message and event content on the server. A local text filter can flag certain obvious violations before sending, but a modified client may bypass it.
When you submit a report, Flexi processes the report category, content type, conversation/content identifiers, reporter and reported-account IDs where applicable, status, timestamps, and any details you type. You must explicitly choose whether to include selected decrypted content. If you opt in:
- a message report can include only the selected message text, not adjacent conversation history;
- an event report can include the event title, location, link, and notes shown to you; and
- a group-profile report can include a bounded snapshot of visible group names, nicknames, calendar names, and full-detail interval titles.
Content included with a report is stored in plaintext for safety review. Reports and rate-limit records are accessible to the trusted service, not other clients. Blocking creates a service record linking the blocker and blocked account and suppresses presentation and notifications in the ways described by the app. Blocking does not remove either account from a shared group, hide membership/RSVP/calendar metadata, revoke delivered copies, or cryptographically erase earlier content. Ciphertext may be downloaded and decrypted before the app suppresses its display.
3. What end-to-end encryption covers—and what it does not
For new text messages, exported-calendar attachments, and group-event revisions created by the official Flexi 5.0 client, the app encrypts content before it is stored in Firebase and wraps the content key separately for selected participant devices. Protected group-event content includes the title, notes, location, link, occurrence times, all-day setting, time zone, and reminder. The official 5.0 client does not use a plaintext fallback for those payloads.
End-to-end encryption does not cover the service metadata listed in this policy, including group names and pictures, member and moderator lists, permissions, nicknames, shared-calendar contributions, RSVPs, block relationships, report metadata, or content you explicitly include in a report. It also does not cover copies you add to Apple Calendar or another calendar provider.
Messages created by older Flexi versions may remain as legacy plaintext records. Encryption also cannot prevent a legitimate participant from copying content after decryption. Flexi 5.0 has no safety-number/key-transparency system, no private-key backup, and no history-transfer protocol. A new device can decrypt only records addressed to that device key, and losing the only private key for a device can make its encrypted history unrecoverable.
4. How Flexi uses information
We use information to:
- authenticate accounts and provide profiles, calendars, messaging, groups, events, RSVPs, invitations, and notifications;
- match address-book phone numbers to verified Flexi accounts at your request;
- synchronize and display data across authorized devices and group members;
- secure the service, verify app integrity, prevent abuse, enforce permissions and rate limits, and troubleshoot failures;
- process reports, blocks, account deletion, and support requests;
- maintain reliability and understand technical performance through limited operational and SDK diagnostics; and
- comply with valid legal obligations and protect users, the public, and the service.
Flexi does not use personal information to serve ads or track you across unrelated companies' apps or websites.
5. When information is disclosed
Information may be disclosed:
- to other Flexi members, when required for a direct chat or group feature or when you choose to share a profile, RSVP, calendar, event, message, invitation, or other content;
- to service providers, including Google/Firebase for authentication, cloud storage, functions, app diagnostics, installations, messaging, and App Check, and Apple for APNs, App Attest, device permissions, and Apple calendar services;
- to a calendar, messaging, or sharing provider you choose, when you add an event to that provider, send an invitation, or export/share a calendar package;
- to safety reviewers or advisors, when needed to review a report, prevent harm, protect users, or operate the service; and
- when legally required or necessary for safety, such as responding to valid legal process, an emergency, fraud, abuse, or a threat to rights or security.
Provider privacy information is available from Firebase and Apple. Their services are governed by their own terms and policies.
6. Retention and account deletion
We retain account and service data while needed to provide Flexi and for legitimate security, safety, dispute, support, and legal purposes. Exact retention can vary by data type and service-provider configuration. Data shared with other members or copied to another provider may remain in their possession after you leave a group or delete your account.
You can request permanent account deletion from Settings > Delete Flexi Account in the app. The deletion workflow removes your Flexi authentication account, profile and private subcollections, push registrations, invitations you authored, block records, group membership/projections, nicknames, read/pin/mute state, owned shared calendars, RSVPs, messages you sent, public encryption keys, and events you created or last edited. It also removes local session material and the account's local encryption identity from the device completing the workflow.
Important deletion limits:
- Other members retain their own messages and any screenshots, exports, notifications, or calendar copies they made.
- Signed records created by other members can retain opaque recipient-device identifiers and wrapped key envelopes because changing them would invalidate the sender's signature.
- A group event is removed when the deleting account created it or supplied its latest revision, which can remove an event originally created by another member.
- Safety reports involving the account may be retained as safety evidence under a new random identifier after matching account references are scrubbed. Included report text/details and operational logs may be retained when needed for safety or legal purposes.
- A minimal Firebase document containing the account ID in its path, deletion status, and deletion timestamps remains for up to 48 hours. It denies writes by an already-issued authentication token and is then scheduled for automatic deletion.
- Copies controlled by other people, Apple/iCloud, another calendar provider, a carrier, or another independent service cannot be remotely deleted by Flexi.
7. Your choices and controls
Depending on your device and location, you can:
- allow, limit, or deny Contacts, Calendar, Camera, Photos, and Notifications access in iOS Settings;
- choose which profile photo, group picture, nickname, event, RSVP, calendar, or invitation information to provide;
- choose busy/free availability instead of full calendar details when sharing with a group;
- mute or leave groups, remove your own shared calendar, block or unblock accounts, and report content;
- delete a calendar copy from the calendar provider where you added it;
- sign out or permanently delete your Flexi account in the app; and
- contact us to ask a privacy or support question.
Local law may provide additional rights to access, correct, delete, or object to certain processing. To make a request, contact us using the details below. We may need to verify that you control the account before fulfilling a request.
8. Security
Flexi uses device-protected Keychain storage, file protection, Firebase access rules, authenticated server functions, App Check, cryptographic signatures, and end-to-end encryption for the content described above. No method of storage, transmission, or endpoint protection is guaranteed to be completely secure. Protect your device passcode, phone account, and verification codes. Contact us promptly if you believe your account or device has been compromised.
9. Children and minors
Flexi does not ask for a date of birth and does not have an age-verification system. Minors should use Flexi only with any permission or supervision required from a parent or guardian and should not share sensitive personal information in profiles, groups, events, calendars, or messages. Group organizers and moderators should use extra care when a group includes minors.
If you are a parent or guardian and believe a minor has provided personal information through Flexi without appropriate authorization, contact us. We will review the request and take appropriate steps, which may include restricting or deleting the account or information after verification.
10. International processing
Flexi and its service providers may process information in the United States and other locations where they operate. Privacy laws and government-access rules may differ from those in your location. We use providers and technical safeguards appropriate to operating the service, but this policy does not make a legal-compliance guarantee for every jurisdiction.
11. Changes to this policy
We may update this policy as Flexi changes. We will change the "Last updated" date and provide additional notice in the app or through another reasonable channel when an update is material.
12. Contact
For privacy questions, account help, or safety concerns:
- Support: realexpenseapp.com/contact
- Email: updates@realexpenseapp.com
- Website: realexpenseapp.com
For an immediate danger or emergency, contact local emergency services. Flexi support is not an emergency-response service.