Privacy policy
1. Who we are
Alfie is a family scheduling assistant. Alfie is the controller of the personal data described here. Questions about this policy, or a request about your data, go to support@alfie.family.
2. What Alfie collects
Account information
Your name, email address, password (stored only as a hash), time zone, and the dates your account was created and last used.
Household and member profiles
The households you create or join, your role in each, and the profiles you create for children or others you manage: their display name, an optional relation such as "daughter", an optional birth year, and which adults manage them.
Calendar data
For each calendar you choose to bring into Alfie, Alfie stores a copy of its events: title, start and end times, time zone, whether the event lasts all day, location, notes, recurrence rules, participants, and the identifiers and change markers the source calendar uses to keep the copy in step. Alfie stores the name, colour, type and sharing setting of each calendar. Alfie copies only the calendars you select, not everything in the connected account.
Credentials for connected accounts
Connecting Google or Microsoft stores the access and refresh tokens those services issue. Connecting Apple iCloud or another CalDAV server stores the username and the password or app-specific password you enter, because the protocol requires it on every request. Subscribing to a calendar link stores that URL. Tokens and passwords are encrypted with AES-256-GCM before they are written to the database, and are decrypted only to make a request to the service they belong to.
Assistant conversations
The questions you ask the assistant and the answers it gives, so a conversation can be continued and so problems can be investigated.
Technical data
Ordinary server logs: IP address, browser user agent, the request path and its result, and the time it happened. They are used to run and secure the service.
3. How Alfie uses it
- To keep the calendars you connect in step with Alfie, in both directions.
- To draw the household's week and apply each member's sharing choices to it.
- To answer the questions you put to the assistant.
- To send account and service email, such as an invitation to a household.
- To keep the service running, diagnose failures and prevent abuse.
Alfie does not sell personal data, does not share it with advertisers, and does not use your calendar data to build advertising profiles. Alfie does not read your email, files or contacts: the permissions it asks for cover your calendars and the email address that identifies the account.
4. Google API Services User Data Policy
Alfie's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: data from Google Calendar is used to provide the calendar and assistant features you asked for, is not transferred to anyone except as needed to provide those features or as required by law, is not used for advertising, and is not read by a human except with your explicit permission, to investigate a problem you have reported, for security purposes, or where the law requires it.
5. Who else processes it
- Railway hosts the Alfie application and its database. Everything described above is stored there.
- Google Cloud (Vertex AI) runs the model behind the assistant. When you ask a question, Alfie sends the model your question and the schedule entries needed to answer it — not your whole calendar history, and not the calendars your household has not shared with you. Alfie does not permit that data to be used to train the model.
- The calendar services you connect — Google, Microsoft, Apple, or the CalDAV server you name — receive the changes you make in Alfie for the calendars you connected. Their own privacy policies govern what they do with them.
These providers operate in several countries, so your data may be processed outside the country you live in. Alfie uses each provider's standard data protection terms.
6. Retention and deletion
- Disconnect an account and Alfie deletes the calendars it brought in, the events copied from them and the stored token or password. The calendars themselves stay where they are, in Google, Microsoft, iCloud or your own server.
- Remove a subscription link and Alfie deletes the calendar and events it created from it. The published link is untouched.
- Ask for your account to be deleted — write to support@alfie.family from the address on the account — and Alfie deletes the account, your membership of every household, the profiles only you manage, and all of the calendar data above. There is no self-service deletion in the app yet.
- Server logs are kept for a short operational period and then discarded. Backups are overwritten on their own cycle, so deleted data can persist in a backup for a limited time before it is written over.
7. Security
- Traffic between you and Alfie, and between Alfie and every calendar service, uses TLS.
- Provider tokens and CalDAV passwords are encrypted with AES-256-GCM at rest.
- Passwords for Alfie accounts are stored as salted hashes, never in readable form.
- Sharing settings are applied on the server, so a household member's client cannot request details of an event the calendar's owner has not shared.
- Access to production systems is limited to the people who operate the service.
No service can promise perfect security. If a breach affects your data, Alfie will tell you and any regulator that has to be told, as the law requires.
8. Children
Alfie does not offer accounts to children under 13, and does not knowingly collect personal data directly from them. A child appears in Alfie as a profile created and managed by a parent or guardian, who decides what goes on that profile's calendars and who in the household can see it. A parent may delete a profile and its calendars at any time. If you believe a child has created an account, write to support@alfie.family and it will be removed.
9. Your rights
Depending on where you live, you may have the right to ask for a copy of your data, to correct it, to delete it, to restrict or object to how it is used, to receive it in a portable form, and to complain to your data protection authority. Some of this is available in the app: your profile and household are editable, and calendars can be disconnected. To have your account deleted, and for anything else, write to support@alfie.family from the address on your account and you will get an answer within 30 days.
Where a legal basis is required, Alfie relies on the contract with you to provide the service, on your consent for connecting a calendar account, and on its legitimate interest in keeping the service secure and working.
10. Changes to this policy
If this policy changes in a way that affects you, Alfie will update the date at the top and tell account holders by email before the change takes effect.