Privacy Policy
Last updated: August 12, 2026
Eva — Calendar & Daily Planner ("Eva", "we", "the app") is designed with privacy as a core principle. This policy explains what data Eva accesses, how it is used, and your rights.
The Short Version
By default, Eva does not send any of your data anywhere. Everything — your tasks, settings, mood entries, habits, and preferences — lives on your device and stays there. No accounts, no tracking, no ads, no analytics SDKs.
Some optional features (like the AI assistant, sync with Eva Web, or Google Calendar import) do send data to external services, but only when you choose to use them. Nothing happens behind your back — you are always in control.
Sync & Eva Web (optional)
Off by default
Eva works fully offline. Sync exists so you can open your data in a browser (Eva Web) and keep several devices in the same state — and it does nothing until you create an account and sign in yourself. No account — no data ever leaves your phone.
What syncs
- Tasks and the trash bin
- Habits
- Notes
- "Last time" items
- Mood entries
Each of these has its own switch on the sync screen in the app. Turn one off and that section stays on your phone only — it is neither uploaded nor downloaded.
An honest word about safety
Synced data is stored on our server, tied to your email address, and transferred over an encrypted connection (TLS). We protect it as well as we can — but nobody in the world can honestly promise a 100% guarantee against hacking. Attack tools, including AI-driven ones, have become remarkably capable in recent years; even government ministries get breached. So here is our friendly advice: keep your most private things out of sync entirely. Leave their switch off — Eva is built so that this is always your choice, not ours.
Deleting your data
Eva Web settings include a "Delete account" button. It permanently erases your account and every synced record from the server — tasks, notes, habits, moods, all of it, immediately and irreversibly. Your phone keeps its local copy and keeps working offline.
AI Assistant
What data is sent
When you use the AI assistant feature, Eva sends only the data necessary to process your request:
- The text you enter
- Current date and the date you are viewing
- If relevant to your request: related task or event details (title, date, time)
Purpose of processing
Your data is used solely to understand your request and provide AI-powered features such as creating, editing, summarizing, or organizing tasks and events.
Third-party AI provider
- AI requests are processed by OpenAI (GPT family of models)
- Eva sends only the minimum data needed to complete your request — no unrelated personal data is transmitted
Consent and control
- The AI assistant is an optional feature — you do not have to use it
- Data is sent to OpenAI only when you explicitly press the send button
- If you choose not to use the AI features, no data is sent to any AI provider
Storage and retention
- Data sent for AI processing is used only to fulfill your request and is not permanently stored by Eva after processing
- Any content you save from AI responses is stored locally on your device
Google Calendar Integration
What data Eva accesses
Eva requests read-only access to your Google Calendar data using the calendar.readonly scope. Specifically, Eva accesses:
- Event titles, dates, and times from your Google Calendar
- No other Google account data is accessed
How Eva uses this data
- Imported events are displayed alongside your tasks in the app's calendar view
- All imported data is stored locally on your device only
- Eva does not send your Google Calendar data to any server
- Eva does not modify, delete, or create events in your Google Calendar
How Eva stores and protects this data
- Google Calendar data is cached on-device for offline access
- No Google user data is stored on any external server or cloud service
- Authentication tokens are stored securely in the iOS Keychain
Data sharing
- Eva does not share your Google Calendar data with any third parties
- Eva does not use your Google Calendar data for advertising, analytics, or any purpose other than displaying events to you
Your control
- Google Calendar integration is optional and disabled by default
- You can disconnect Google Calendar at any time in the app's Settings
- When disconnected, all imported Google Calendar data and tokens are removed from the app
- You can also revoke access at myaccount.google.com/permissions
Google Health Integration (Fitbit, Pixel Watch)
What data Eva accesses
If you connect a Google account that holds fitness data from a Fitbit tracker, a Pixel Watch, or another Google-connected device, Eva requests read-only access using the googlehealth.activity_and_fitness.readonly scope. Specifically, Eva accesses:
- Your daily step count — one number per day
- No other health, fitness, or Google account data is accessed. Eva does not read heart rate, sleep, weight, workouts, or location from Google.
How Eva uses this data
- Your step count is shown to you: a step ring, daily and weekly totals, and progress toward a step goal you set yourself
- A notification is delivered on your own device when you reach your step goal
- All step data is stored locally on your device only
- Eva does not send your Google Health data to any server
- Eva never writes to, modifies, or deletes anything in Google Health — access is strictly read-only
How Eva stores and protects this data
- Step data is stored on-device so it is available offline
- No Google user data is stored on any external server or cloud service
- Authentication tokens are stored securely in the iOS Keychain
Data sharing
- Eva does not share your Google Health data with any third parties
- Eva does not use your Google Health data for advertising, profiling, analytics, or any purpose other than showing you your own activity
- Your health and fitness data is never used to train any machine learning or AI model
Your control
- Google Health integration is optional and disabled by default
- You can disconnect Google at any time in the app's Settings
- When disconnected, all stored step data and tokens are removed from the app
- You can also revoke access at myaccount.google.com/permissions
Google API Services User Data Policy
Eva's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to both the Google Calendar and Google Health data described above. In particular, Eva does not transfer Google user data to third parties, does not use it for advertising, does not allow humans to read it, and does not use it to develop, improve, or train generalized machine learning or AI models. Google user data is used solely to provide the features described in this policy, directly to you.
Apple Calendar & Reminders
Eva offers two-way synchronization with Apple Calendar and Apple Reminders using the EventKit framework. This data stays on-device and is managed through standard iOS permissions that you can revoke at any time in iOS Settings.
Apple HealthKit
Eva can read and write menstrual cycle data via HealthKit. This data is never sent to any server. HealthKit access requires your explicit permission and can be revoked in iOS Settings → Privacy → Health.
Third-Party Data Sharing
Eva does not share, sell, or transfer your data to any third parties. No data is used for advertising, profiling, or any purpose other than providing app functionality directly to you.
Children's Privacy
Eva does not knowingly collect data from children under 13. The app does not require an account or collect personal information.
Changes to This Policy
We may update this policy as new features are added. The "Last updated" date at the top will reflect any changes.
Contact
If you have questions about this privacy policy, contact us at [email protected].