Privacy Policy
The short version: your plan lives on your phone, chat goes to the AI to get a reply, and nobody is tracking you. If you ask another signed-in adult to watch a task, we send them a ping when you finish (or when a timed task ends unfinished), and you get a ping when they say yes. That is not a copy of your plan. If you are an adult and connect ChatGPT, tasks you send from it wait on our server until your phone collects them, for 14 days at most. ChatGPT can never see your plan.
1. What stays on your phone
Tasks, notes, streaks, chat history, reminders, your optional profile picture, and most settings are stored only on your device using on-device storage. Your plan stays on this phone unless a signed-in adult turns on Back up on cloud in Account, under Data; it is off until you choose it. When you chat, this week's tasks ride along so the reply fits your day; tap the lock on a task to keep it out.
If you (an adult, signed in) invite someone to watch a task, we store a short label, first names, who owns it, who is watching, and a timed task's end instant. Not the rest of your day. Finishing a task that does not repeat, or ending the watch in any way, deletes that row. See section 2b.
Links you paste or share to Buddy are kept on this phone under Saved links: the address, the day you saved it, whatever the page told us about itself, and whatever you say about it. A picture you share is copied into the app and stays on this phone. Buddy is never given the list. See section 2d.
If you (an adult, signed in) connect ChatGPT, tasks you send from it wait on our server until this phone collects them. Once collected they are deleted from our server and live in Drafts on this phone, like any other draft, until you add or skip them. See section 2e.
If you delete the app, or use Start fresh in Account, that on-device data is removed from the device.
2. What leaves the device when you use Buddy
Typed chat is free for a small number of messages each day. A few short Talk sessions a day are also free; longer Talk, unlimited chat, and High Thinking after a few free tries are part of Buddy Pro. When you use chat or voice:
- The text you type or speak (after transcription), plus enough of your current task list for context, is sent to our server (Supabase Edge Functions) and then to OpenAI to produce a reply and optional task suggestions. Tasks you lock, or every task while Keep my plan private is on in Account → Tasks, are left out. Buddy can still suggest new tasks.
- The language the app is set to is sent with these requests, as a two-letter code, so Buddy answers in it and voice is understood in it. It is not stored and not logged.
- Photos you attach in chat are sent with that turn so Buddy can reply from what is in them. They are not kept as a lasting gallery on our servers.
- PDFs you attach in chat are sent with that turn so Buddy can read them (text extract and/or OpenAI PDF processing). They are not kept as a lasting document archive on our servers.
- Voice you record while holding the mic, dictating, or while Talk mode is listening is sent so Buddy can hear you, then not kept by Buddy as a lasting recording archive.
- Spoken replies (if you turn voice replies on) are generated as audio and played on your device.
We use this only to provide the feature you asked for. We do not sell it, do not use it for advertising, and do not build a marketing profile of you from it.
OpenAI processes that content under their terms as our processor for generating replies. See OpenAI’s policies for how they handle API data.
High Thinking is a longer planning turn that can ask a few skippable questions about your schedule (days a week, hours, an exam date). A few tries are free; more is part of Buddy Pro. Those turns still send your words to OpenAI the same way. Buddy does not ask for height, weight, or other body measurements.
When you allow location for weather, approximate coordinates (rounded for privacy) are sent to our server and Apple WeatherKit so we can show current conditions. Place names are resolved on your device when possible. Weather responses may be cached on the device for a short time so we do not call the API on every open.
2b. Watching a task
Watching is optional, adult-only, and both people must be signed in. Guests cannot watch or be watched. If age is missing, Buddy treats the person as a child and the server refuses the watch.
When you tap “Invite a watcher” on a task and they say yes, we store:
- Your account id and theirs
- A short label for the task (usually the title)
- An id that points at the task on your phone (not the full plan)
- First names, if you gave them, so the pings can say who finished and who said yes
- A timed task's end instant, so we can ping once if it is still open then
- A push token for each of you, so the pings can reach your phones
We do not upload notes or the rest of your day. A timed task's end instant is stored so the second ping can fire. The watcher never sees your list. They get “{name} finished {label}.” or “{name} hasn't finished {label} yet.” You get “{name} said yes and gets a ping when you finish {label}.”
You can remove a watcher from the task, cancel a link nobody has answered, or stop sharing the task. They can say no thanks to a link, or leave from Tasks I watch. Deleting or archiving the task ends the watch, and so does finishing a task that does not repeat. Start fresh ends every watch you set up or joined. Ending a watch in any of these ways deletes the row. Delete account wipes watches and push tokens for that account.
2c. Explore
Explore is a shelf of task and plan ideas that we write and publish. When you open it, your phone downloads that list from our website, the same address as this page. The request asks for a file and carries nothing else. It does not send your name, your age, your plan, or which ideas you have added before. Opening Explore uploads nothing.
Everybody is offered the same list. Which items you actually see is decided on your phone: your age range picks the ones meant for you, and the daily shuffle is worked out on the device from a number that never leaves it. Adding an idea writes an ordinary task on this phone, and from then on it behaves like a task you typed yourself.
2d. Saved links, and the pictures you share
Nothing is fetched. Buddy never opens the page, the post or the video you saved. It does not download the picture on that page, and it does not ask any other service about it. That is why a saved link has no name until either your browser hands one over with the share or you write one yourself.
When you share a web page from a browser, the share itself carries what the page says about itself: its title, a short description, the site's name and the address of its preview image. Your browser reads those from a page you already had open and passes them along with the address. We keep them so the row has a name. The preview image is never downloaded or shown. Shares from most apps carry none of this, which is why those rows show only a domain.
Buddy is not shown your saved links. The list is not part of what is sent when you chat. Two things can leave the phone, and only because you ask for them. Tapping Talk it through starts a chat message containing your own sentence about the item, never the address, because Buddy cannot open one. If that item is a picture you saved, the picture is attached to that message so Buddy can read it, exactly as a photo you attach in chat is: it goes when you press send and not before. And if you turn a saved link into a task, the address is kept in that task's note, which travels with your tasks as described in section 2.
Removing a saved link deletes its picture from the phone with it, and Start fresh removes them all.
2e. Tasks you send from ChatGPT
If you use ChatGPT, you can connect it to Buddy so it can send tasks to your Buddy Drafts. This is optional and free, and it works one way. ChatGPT can send tasks in. It can never see your plan, your chats with Buddy, your saved links, or anything else in the app.
To connect, Buddy shows you a code (Account → Tasks → ChatGPT) and you type it on a page on this website that ChatGPT opens. The code works once, for 10 minutes. That page asks for nothing else and sets no cookies. It also has a sign-in box that only OpenAI's reviewers use, with a test account of ours. Before anything can arrive, Buddy on your phone asks you to allow the connection.
Before anything is sent, ChatGPT can show you the tasks as a card, where you can leave some out, ask for changes, and send them one at a time or all together. To draw that card, ChatGPT passes the tasks to our server to be checked each time it shows them. We do not store or log them. They reach Buddy only when you choose to send them, with Send on the card or by asking ChatGPT in the chat. What you leave out stays in ChatGPT; we are not told.
When you send tasks, we receive and store only the tasks themselves:
- Each task's title, and its note if it has one
- A day, a part of the day or a start time, and how long it should take, when ChatGPT gives them
- A reminder, and a repeat with the day it stops, when you ask for them
- A task profile name, and whether the task is private or keeps a streak, when you ask for them
- An emoji, if ChatGPT picks one
- A name for the plan, and a random reference that keeps one plan's tasks together in Drafts
They are kept with your Buddy account id so they reach your phone and nobody else's. We do not receive your ChatGPT conversation. ChatGPT also attaches details of its own to each request, such as your language and an approximate location; we do not read, log or store them. In return, ChatGPT is told how many tasks arrived, which of the tasks it showed you Buddy already received in the last 2 days, and where to find them in Buddy. It is never told anything from your plan or your Drafts.
We use these tasks for one thing: getting them to your phone. They are not used for advertising, and they are not sold or shared. Waiting tasks are held by Supabase, which runs our server. Requests from ChatGPT and from the connect page pass through Netlify, which hosts this website and forwards them to that server. Both act for us as service providers. Once you add a task from Drafts, it is an ordinary task on your phone and is treated like any task you typed, as described in sections 1 and 2.
How long we keep them. Tasks are deleted from our server as soon as your phone collects them: when you open Buddy, or shortly after they arrive if Buddy is already open. Tasks your phone never collects are deleted after 14 days. We also keep a record that your account is connected, with when it was connected and last used, while you stay connected and for 30 days after you disconnect. The keys ChatGPT uses to send are stored only in a scrambled form that cannot be turned back into the key, until they expire. To stop an accidental repeat from arriving twice, and to limit how many tasks can arrive in an hour or a day, we keep fingerprints of what you send, never its text, for up to about 2 days, and counts of recent sends. Disconnecting and deleting your account delete those fingerprints straight away, and so does Start fresh when you are signed in and the phone is online. Supabase, the service our server runs on, backs up its database once a day and keeps each backup for 7 days, so something deleted from our server can stay in a backup for up to 7 days before it is gone.
Your controls.
- Disconnect in Buddy (Account → Tasks → ChatGPT) stops ChatGPT sending and deletes any tasks still waiting. Tasks already in Drafts stay on your phone until you add or skip them.
- Delete account removes the connection and anything still waiting.
- Removing Buddy Day Planner (listed as buddydayplanner) in ChatGPT's own settings also ends the connection and deletes any tasks still waiting.
Adults only. Connecting is offered only to adults who are signed in. Our server checks the age range on your Buddy account when Buddy makes a code, when ChatGPT connects, and every time it sends. If the account is not marked 18 or over, or has no age at all, the answer is no: an existing connection is ended and anything waiting is deleted.
OpenAI's role. ChatGPT is made by OpenAI. You use it under OpenAI's own terms and privacy policy, and what you say to ChatGPT is covered by those, not by this policy. For this feature OpenAI is not acting for us and is not our processor. That is different from Buddy's own chat, where OpenAI does work for us as described in section 2.
3. Optional sign-in
Signing in with Google, Apple or a phone number is optional. Phone sign-in is offered only to people who told us they are 13 or over. If you sign in, we store a small cloud profile so a new phone can feel familiar:
- The email address on your Google or Apple account, which is how we recognise your account. Apple may give us a private relay address instead of your real one
- If you sign in with Google, the name and the link to the profile picture on your Google account. Google sends them with every sign-in and our sign-in service keeps them, but Buddy does not use or show either one
- Your phone number, if you signed in with it, so you can sign in again
- Your first name (if you provided one)
- Your age range, if you chose one, so watching and connecting ChatGPT can stay adult-only
- A couple of display preferences (for example voice-reply and text-size settings)
- If you connect ChatGPT, a record of that connection (see section 2e)
When you sign in with a phone number, the number is sent to Twilio, a messaging service acting as our processor, only to send you the sign-in code. The code arrives by text. The number is not used for marketing and is never shared for any other purpose.
Your tasks and chats still stay on this phone unless you turn on Back up on cloud. Tasks you send from ChatGPT wait on our server only until this phone collects them. You can remove the cloud account anytime with Delete account in Account. That deletes the authentication account and the cloud profile, and any ChatGPT connection with the tasks still waiting for it. On-device tasks remain until you also use Start fresh or delete the app.
4. Permissions
- Microphone: while you hold the mic, dictate, or use Talk mode. A listening state is visible whenever the mic is on.
- Notifications: local reminders are still scheduled on your device. If you watch someone else’s task, we also send a remote ping when they finish (or when a timed task ends unfinished). If someone says yes to watching your task, you get a ping too. These remote notifications use a push token on our server, and Expo (650 Industries) and Apple's or Google's push service deliver them. There is no marketing push.
- Location (optional): only if you allow it, and only while the app is open, so Today can show local weather and a city name. Approximate coordinates are sent to our server and then to Apple WeatherKit. Buddy does not track you in the background, does not keep a location history, and works fully if you say no.
5. Ads, analytics, and selling data
Buddy does not include ads. Buddy does not include analytics or tracking SDKs for advertising or behavioural tracking. We do not sell your personal information.
We may add crash-only reporting later (no advertising identifiers, no event tracking). If we do, this policy will be updated before that ships.
6. Children and mixed audience
Buddy is for all ages, including children under 13. It is not in Apple’s Kids Category because adults use it too.
If a child talks or types to Buddy, that message and any voice clip go to OpenAI so Buddy can reply, the same path as for an adult, described in section 2. If a child attaches a photo or a PDF in chat, or sends a picture they saved using Talk it through, that file goes to OpenAI for that turn the same way, so Buddy can reply from what is in it. It is not kept as a lasting gallery. Tasks, notes, and chat history still stay on the phone. We do not use a child’s chat to advertise or to build a marketing profile.
We ask for an age range (or “prefer not to say”) so Buddy uses shorter, safer replies for children. That range is sent with the chat request only to pick those rules. Explore uses it on the phone, to leave out ideas that are not meant for children, and sends nothing to do it. If age is missing, Buddy treats the person as a child.
Watching is not offered to children. The server checks that both accounts are marked 18 or over. A child’s tasks are not written to the watch table.
Connecting ChatGPT is not offered to children, to teenagers, or to anyone who has not told us their age. The server checks that the account is marked 18 or over before it makes a code, when ChatGPT connects, and on every send, so a child’s tasks are never written to the table where tasks from ChatGPT wait.
Phone sign-in is not offered to children, or to anyone who has not told us their age, so we do not ask a child for a phone number.
Signing in is optional and not required to plan a day. The optional cloud profile is a first name, the age range if one was chosen, and a couple of display settings. Parents or guardians with questions can email us.
7. How to delete your data
- On this phone: Account → Data → Start fresh, or delete the app.
- Cloud account: Account → Delete account (removes the signed-in account and cloud profile).
- Watches: remove the person on the task, leave from Tasks I watch, Start fresh, or Delete account (wipes watches and push tokens).
- ChatGPT: Account → Tasks → ChatGPT → Disconnect removes the connection and any tasks still waiting. Delete account does the same, and so does Start fresh when you are signed in and the phone is online. If you signed out first, sign in and use Disconnect, or remove Buddy Day Planner (listed as buddydayplanner) in ChatGPT's settings.
- Subscription: managed in your Apple / Google account settings, not by deleting the Buddy account alone.
Our server's database is backed up once a day, and each backup is kept for 7 days. So anything deleted from our server, a deleted account included, can stay in a backup for up to 7 days, and then it is gone.
8. Contact
Questions about privacy: support@buddydayplanner.com
Buddy Day Planner · Privacy Policy · Home