Flexi Calendar

Privacy Policy

Effective: August 16, 2026  ·  Updated: August 16, 2026

This Privacy Policy explains how Flexi Calendar ("Flexi," "we," "us," or "our") handles information when you use the Flexi iOS app and its related messaging, group-planning, notification, and support services. It describes the Flexi 5.0 product as released; older app versions may handle legacy messages differently, as explained below.

1. Summary

2. Information Flexi handles

Account and profile information

Flexi processes:

Firebase Authentication and the telecommunications providers involved in SMS delivery process the phone number and verification request. Flexi stores authentication and pending-verification credentials in device-protected storage where supported. Never send an SMS verification code to support or another person.

Contacts, directory matching, and invitations

Contact access is optional and requires iOS permission. When granted, Flexi can read contact names, phone numbers, email addresses, nicknames, and organization names from the device address book so you can find people and prepare invitations.

For Flexi account matching, the app sends submitted contact phone numbers in bounded batches, together with a country or region code used for normalization, to an authenticated Firebase function. The function checks for verified Flexi accounts and returns only matching profiles; it does not return a global user directory. Operational logs record lookup counts and, on an error, may record the requesting account ID, but are not designed to log the submitted address book phone numbers.

If you choose to invite someone, Flexi may store the selected contact's name, email address, phone number, normalized phone-number forms, an invitation message, your account ID and name, and delivery status so the invitation can be processed. If you use the iOS Messages composer, Apple, your carrier, and the recipient's messaging provider also handle the invitation you choose to send.

Calendars, schedules, and device data

With iOS calendar permission, Flexi can read and write calendar and event data in accounts available through Apple EventKit. That can include calendar names, event titles, notes, locations, links, start and end times, recurrence details, reminders, time zones, and availability. Flexi also stores calendars, schedules, events, display preferences, and optional work/pay settings locally on your device.

When you choose to:

Camera access is used to scan calendar QR codes. Photo-library access is used when you select a profile or group image. Flexi does not request precise GPS location; a location typed into an event is content you provide, not device-location data.

Chats, groups, events, and RSVPs

Flexi stores data needed to operate direct and group conversations, including:

Other group members can see information made visible in the group, including the group name and picture, member account names, permitted nicknames, roles, RSVPs, and shared availability. A nickname does not replace or conceal the member's account name.

Push notifications and device registration

To deliver notifications, Flexi processes Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) tokens, a Firebase installation or device identifier, app/build version, APNs environment, notification settings, delivery status, badge state, public encryption-key records, and related registration metadata. Notification workers may log conversation/message identifiers, delivery results, and in some error cases a recipient account ID.

For encrypted Flexi 5.0 notifications, APNs and FCM receive generic visible text plus encrypted custom data and delivery metadata. The notification service extension on your device attempts to decrypt a preview. If it cannot safely decrypt and verify the preview, it shows a generic "New encrypted message" notice. iOS notification and Lock Screen settings ultimately control what appears on your device.

App integrity, diagnostics, and logs

Release builds use Firebase App Check with Apple's App Attest to help confirm that requests come from a genuine Flexi app on an Apple device. Apple and Firebase may process attestation tokens, app/device integrity signals, and related request data. App Check helps prevent abuse; it does not make service-readable metadata end-to-end encrypted.

Flexi uses Firebase Authentication, Firestore, Cloud Functions, Installations, Messaging, and App Check. These SDKs and services may process device/app identifiers, OS and app versions, network request details, error information, and other diagnostic or operational data. The Firebase SDK privacy manifests used by the app classify certain non-linked diagnostic data for analytics or app-functionality purposes and certain device/other data for app functionality. Flexi does not include the Firebase Analytics or Firebase Crashlytics product in the app target.

Our backend also records limited operational and security logs, such as request results, counts, function errors, notification status, report identifiers/categories, and deletion-cleanup totals. Network providers may automatically receive information such as IP address and request timing as part of providing an internet service.

Reports, blocks, and safety information

Flexi cannot proactively read or scan end-to-end encrypted message and event content on the server. A local text filter can flag certain obvious violations before sending, but a modified client may bypass it.

When you submit a report, Flexi processes the report category, content type, conversation/content identifiers, reporter and reported-account IDs where applicable, status, timestamps, and any details you type. You must explicitly choose whether to include selected decrypted content. If you opt in:

Content included with a report is stored in plaintext for safety review. Reports and rate-limit records are accessible to the trusted service, not other clients. Blocking creates a service record linking the blocker and blocked account and suppresses presentation and notifications in the ways described by the app. Blocking does not remove either account from a shared group, hide membership/RSVP/calendar metadata, revoke delivered copies, or cryptographically erase earlier content. Ciphertext may be downloaded and decrypted before the app suppresses its display.

3. What end-to-end encryption covers—and what it does not

For new text messages, exported-calendar attachments, and group-event revisions created by the official Flexi 5.0 client, the app encrypts content before it is stored in Firebase and wraps the content key separately for selected participant devices. Protected group-event content includes the title, notes, location, link, occurrence times, all-day setting, time zone, and reminder. The official 5.0 client does not use a plaintext fallback for those payloads.

End-to-end encryption does not cover the service metadata listed in this policy, including group names and pictures, member and moderator lists, permissions, nicknames, shared-calendar contributions, RSVPs, block relationships, report metadata, or content you explicitly include in a report. It also does not cover copies you add to Apple Calendar or another calendar provider.

Messages created by older Flexi versions may remain as legacy plaintext records. Encryption also cannot prevent a legitimate participant from copying content after decryption. Flexi 5.0 has no safety-number/key-transparency system, no private-key backup, and no history-transfer protocol. A new device can decrypt only records addressed to that device key, and losing the only private key for a device can make its encrypted history unrecoverable.

4. How Flexi uses information

We use information to:

Flexi does not use personal information to serve ads or track you across unrelated companies' apps or websites.

5. When information is disclosed

Information may be disclosed:

Provider privacy information is available from Firebase and Apple. Their services are governed by their own terms and policies.

6. Retention and account deletion

We retain account and service data while needed to provide Flexi and for legitimate security, safety, dispute, support, and legal purposes. Exact retention can vary by data type and service-provider configuration. Data shared with other members or copied to another provider may remain in their possession after you leave a group or delete your account.

You can request permanent account deletion from Settings > Delete Flexi Account in the app. The deletion workflow removes your Flexi authentication account, profile and private subcollections, push registrations, invitations you authored, block records, group membership/projections, nicknames, read/pin/mute state, owned shared calendars, RSVPs, messages you sent, public encryption keys, and events you created or last edited. It also removes local session material and the account's local encryption identity from the device completing the workflow.

Important deletion limits:

7. Your choices and controls

Depending on your device and location, you can:

Local law may provide additional rights to access, correct, delete, or object to certain processing. To make a request, contact us using the details below. We may need to verify that you control the account before fulfilling a request.

8. Security

Flexi uses device-protected Keychain storage, file protection, Firebase access rules, authenticated server functions, App Check, cryptographic signatures, and end-to-end encryption for the content described above. No method of storage, transmission, or endpoint protection is guaranteed to be completely secure. Protect your device passcode, phone account, and verification codes. Contact us promptly if you believe your account or device has been compromised.

9. Children and minors

Flexi does not ask for a date of birth and does not have an age-verification system. Minors should use Flexi only with any permission or supervision required from a parent or guardian and should not share sensitive personal information in profiles, groups, events, calendars, or messages. Group organizers and moderators should use extra care when a group includes minors.

If you are a parent or guardian and believe a minor has provided personal information through Flexi without appropriate authorization, contact us. We will review the request and take appropriate steps, which may include restricting or deleting the account or information after verification.

10. International processing

Flexi and its service providers may process information in the United States and other locations where they operate. Privacy laws and government-access rules may differ from those in your location. We use providers and technical safeguards appropriate to operating the service, but this policy does not make a legal-compliance guarantee for every jurisdiction.

11. Changes to this policy

We may update this policy as Flexi changes. We will change the "Last updated" date and provide additional notice in the app or through another reasonable channel when an update is material.

12. Contact

For privacy questions, account help, or safety concerns:

For an immediate danger or emergency, contact local emergency services. Flexi support is not an emergency-response service.