CallSlate Privacy Policy
Last updated: 11 September 2026
Applies to: the CallSlate mobile application and its supporting API.
1. Who we are
CallSlate is operated by Cinefix / Mike Eijkelenboom, based in the
Netherlands. For privacy questions or requests, contact:
For the purposes of the GDPR, the operator named above is the data controller
for the limited personal data described below.
Note: CallSlate may be transferred to a dedicated company in the future. If the
controller changes, this policy will be updated.
2. The short version
- An account is optional for planning and running projects within the free
plan. Buying or restoring CallSlate Pro requires Sign in with Apple, so
your subscription can be recognised after a reinstall or on another device.
Signing in does not sync your projects between devices.
- If you do sign in, you use Sign in with Apple. We store your Apple
identifier and, only if you choose to share it, your email address. We never
ask Apple for your name. The name you type in the app stays on your phone.
- Your most sensitive data stays on your device. Your name, crew names and
contact details, and all cost and financial figures are stored only on your
phone and are never sent to us. Two exceptions, both for a single answer and
never stored: when you use weather or a travel time, the coordinates involved
are sent to our server so it can ask Apple; and when you save a home address,
it is looked up once through our server to learn which country it is in.
Section 6 says exactly which.
- We do not use any analytics, advertising, or tracking SDKs, and we do not
use an advertising identifier. We do not track you across apps or websites.
- The app communicates with our servers for device registration and security
checks, document and AI import, shared links, Live Activities, address,
weather and travel lookups, sign-in, and purchase verification.
Sections 4 to 7 explain the information used by each feature, including
requests that happen automatically while a feature is in use.
3. Data stored only on your device (local-only)
The following data is stored locally on your device (using the app's on-device
storage). We never store it on our servers, and none of it is transmitted at
all unless a bullet below says otherwise:
- Your name and your selected role / project mode.
- Your home location. The address as you typed it is kept on your phone.
It leaves it in exactly one case: when you save it, the app sends it once to
our server to learn which country it is in, and the server answers with a
country code and nothing else is kept (see 6). Its coordinates leave it in
one more case: when the app works out a travel time from home to a venue, it
sends the two sets of coordinates to our server, which asks Apple for a
driving time and answers with the minutes. Nothing about either request is
stored (see 6).
- Your events and timeline items, including titles, dates, times, locations,
coordinates, rooms, notes, checklists, and crew names you assign to items.
Two features send a venue's coordinates onward for as long as it takes to
answer: the weather card and the travel time (see 6). Sharing a schedule does
not · a share link carries no coordinates at all.
- Cost and financial data (hourly rates, travel rates, parking, expenses,
overtime settings).
- Your gear and packing lists (equipment, saved kits, rental prices, and
their prep state).
- Your app settings (theme, date/time format, notification and alert
preferences, language).
There is no server-side sync of your projects. Our database contains no table
that can hold an event, a crew member, or a cost figure.
You can delete this data at any time by deleting individual events or items
inside the app, or by uninstalling the app, which removes your projects,
crew, gear and settings from the device. One thing can survive a reinstall: the
device registration token, which iOS keeps in the device's secure keychain. It
identifies the installed copy of the app to our server, holds no personal data,
and is deleted on our side after 12 months without contact (see §11).
Note: your subscription status is the one thing that is deliberately not
local. It is held on our server and read by the app, so that a reinstall or a
new phone cannot lose access you have paid for. See §4.6.
4. Data we process on our servers
We process the following on our servers (API hosted by Railway in Amsterdam, EU;
PostgreSQL database hosted by Neon in Frankfurt, EU) only when the relevant
feature is used:
4.1 Shared schedule links
When you share a schedule, we store a reduced snapshot of it so it can be
opened from a link or QR code. That snapshot is deliberately small:
- Included: the event title, date, start and end time, and its location if
you set one. Per item: the title, start and end time, the item type, and its
location and room if set.
- Not included: your notes, checklists, crew names, contact details, cost and
rate data, and exact coordinates. None of those ever leave your device.
Other things worth knowing:
- Each share has a random, hard-to-guess token in its URL.
- Anyone with the link can view the schedule until it expires, so treat a share
link as public. Item titles and locations are visible to anyone who has it.
- Shared schedules are automatically deleted 30 days after creation, and you
can revoke a link earlier from the app.
4.2 AI schedule import
See Section 5.
4.3 Live Activities (Lock Screen / Dynamic Island / Apple Watch)
When you run a Live Activity, we store the Apple push token and the pre-built
card content (event and item titles and countdown timing) so our server can keep
the Live Activity up to date while the app is closed. See Section 7.
4.4 Device identifier
On first use, our server issues a pseudonymous device token to your app. It
is used to count free AI imports and to associate Live Activity updates with your
device. On its own it is not linked to your name or email. If you sign in, this
device is linked to your account so we know which subscription applies to it.
4.5 Your account (only if you sign in)
Signing in uses Sign in with Apple. We store:
- The Apple identifier for your account, a value Apple generates specifically
for CallSlate.
- Your email address, only if you choose to share it. If you use Apple's Hide
My Email, we receive and store Apple's forwarding address instead of your real
one.
- A token from Apple that lets us end the connection on Apple's side when you
delete your account.
We never ask for or store your name.
4.6 Subscriptions and purchases
Purchases are made through Apple, not through us. We never see your payment
details. When you buy or restore a subscription, your device sends Apple's signed
receipt to our server, which verifies it with Apple and stores the outcome
against your account: which product, whether it is active, when it expires,
whether it will renew, whether it was made in the sandbox or production
environment, and identifiers for the transaction.
Apple also notifies our server directly about later changes to that subscription,
such as renewals, cancellations, and refunds. We keep a record of which of those
notifications we have already handled, so a repeated delivery is not processed
twice. That record contains only Apple's own message identifier and a timestamp.
4.7 Abuse prevention
To protect the service from abuse, we temporarily record the IP address of
requests to endpoints that cost us money or could be flooded: AI import,
address lookup, weather, travel time, sharing a schedule, registering a device,
and sign-in. These records are automatically deleted after 2 days and are
used only for rate-limiting and security. IP addresses also appear in our
server's own operational logs, which are kept by our hosting provider for a
short period and are not used for anything else.
Separately, we keep counters for your free AI import allowance and, for
subscribers, fair-use ceilings. Because these count over a month, they are kept
for up to 40 days. They are keyed to a one-way hash of your device token or
account, never to an IP address.
5. AI processing
When you import a schedule from a PDF, a Word document, or pasted text, our
server sends the extracted text to OpenAI's API (model gpt-5.4-mini)
to convert it into a structured timeline. The app asks for your agreement before
this happens the first time.
- Only the schedule text is sent (truncated to the first ~60,000 characters). We
do not attach your coordinates, crew names, or cost data.
- Our servers do not log the contents of your schedule or of the AI's answer,
only technical metadata such as timing, page count, text length, and status.
- OpenAI's standard API terms apply: API inputs are not used to train their
models, and are retained only briefly (up to ~30 days) for abuse monitoring.
If you do not want a schedule processed by AI, you can build it manually or use
the calendar or paste-text import instead.
PDF files are uploaded to our server for text extraction as part of AI import.
When you select a Word document (.docx), the file is uploaded to our server
for text extraction before you review the extracted text. This extraction does
not use AI or consume an AI import. If you then choose AI processing, the text
is handled as described above. The uploaded documents are processed in memory
and are not saved to our database or file storage.
6. Location, weather & travel-time processing
- Weather is based on the event venue's location, not your device's GPS
position. Venue coordinates and a date are sent to Apple WeatherKit through
our server.
- Address lookups (geocoding) send the venue text you type to our own server,
which asks the Apple Maps Server API. A 2-letter country code is included so
results from your own country rank first. To work that code out once, your home
address is looked up the same way any other address is: it is sent to our server,
which asks Apple, and only the country that comes back is kept. The result is
remembered on your phone, so this happens once per home address rather than on
every search, and never at all when you have not set one · then the country
comes from your device's region setting. Your home address is not stored on our
servers, and the venue text no longer goes to any third party directly from your
phone.
- Travel-time and cost estimates use your device location (with your
permission) to measure distance. Start and destination coordinates are sent to
our server to calculate driving time. Converting coordinates to a readable
address is done by your device's operating system (Apple on iOS).
- Opening directions hands the destination's coordinates and label to Apple
Maps.
You control location access through your device's permission settings. If you
deny location access, travel and cost features that rely on it will be limited.
7. Push notifications & Live Activities (Apple APNs)
CallSlate uses Apple's Push Notification service (APNs) to power Live
Activities on the Lock Screen, Dynamic Island, and Apple Watch. To do this, Apple
and our server process a push token for the activity and the card content
(event and item titles, countdown timing). General reminders for upcoming items
are scheduled locally on your device.
Live Activity content appears on your Lock Screen, so it can be read by anyone
holding your phone without unlocking it. Keep that in mind for event and item
titles.
8. Third-party services
We share data only with the providers needed to deliver the features above:
- OpenAI, AI parsing: receives schedule text to produce a structured
timeline.
- Apple, Sign in with Apple: handles signing in, and gives us your Apple
identifier and optionally your email address.
- Apple, App Store and App Store Server API: processes your purchase and
tells our server about the state of your subscription.
- Apple, WeatherKit: receives venue coordinates and dates.
- Apple, Maps Server API: receives venue search text and coordinates for
address lookup and travel time.
- Apple, Push Notifications (APNs): receives push tokens and Live Activity
content.
- Apple Maps on your device: receives destination coordinates and a label
when you open directions.
- Expo / EAS, app delivery and updates: standard app and over-the-air update
metadata.
- Railway, API hosting (Amsterdam, EU): runs our API server and processes
standard request metadata such as IP address.
- Neon, database hosting (Frankfurt, EU): stores the server-side data
described above.
We do not sell your data, and we do not share it with advertisers or data
brokers. Each provider processes data under its own data-processing terms.
Railway and Neon host and store our server-side data in the EU. OpenAI is based
in the United States; the schedule text sent for AI parsing is transferred there
under the EU standard contractual clauses in OpenAI's data-processing addendum,
and OpenAI does not use API data to train its models. Apple processes sign-in,
purchases, weather, maps and push data under Apple's developer terms.
9. Analytics, tracking & advertising
CallSlate contains no analytics, crash-reporting, or tracking SDKs (for
example, no Sentry, Firebase, Amplitude, Segment, Google Analytics, Meta SDK, or
AdMob), and uses no advertising identifier (IDFA). We do not track you
across other apps or websites.
10. Apple App Store privacy labels
Consistent with the above, CallSlate's App Store privacy labels are:
- Data used to track you: None.
- Data collected and linked to you: User ID (your Apple sign-in identifier
and our account number, only if you sign in); Email Address (only if you sign
in and choose to share it); Purchase History (your subscription state);
Location; Other User Content (shared schedules, AI-imported text, Live Activity
content); a Device Identifier. All for app functionality only.
- Collected, not linked to you: IP address, used for rate-limiting and
abuse prevention only. We declare it rather than rely on an exemption.
- Not collected: your name, health data, financial or payment details,
browsing history, and usage or diagnostic analytics.
11. Data retention
- Shared schedules: automatically deleted 30 days after creation, or
immediately when you revoke the link.
- Abuse-prevention IP records: automatically deleted after 2 days.
- AI allowance counters: kept up to 40 days, because they count over a
month. Keyed to a hash of your device or account, not to an IP address.
- Live Activity records: cleaned up automatically. Records of ended Live
Activities are deleted after 2 days, and stale registrations are closed
after 12 hours and then removed on the same schedule.
- Your account and subscription record: kept for as long as your account
exists, and deleted when you delete your account.
- Apple notification bookkeeping: identifiers of subscription notifications
we have already handled. These contain no personal data and are currently kept
indefinitely.
- Pending Apple disconnections: if we cannot reach Apple to end the
connection at the moment you delete your account, the Apple token is kept, on
its own and no longer linked to you, purely so we can retry. It is deleted as
soon as the disconnection succeeds.
- Device registration: the record for an installed copy of the app (its
token, AI allowance counter, push registration and, while you are signed in,
the link to your account) is deleted automatically after 12 months in
which that device has not contacted our server. It contains no name or email
address.
- On-device data: kept until you delete it or uninstall the app.
12. Your rights
Most of your data lives on your device, so several rights are exercised there
directly:
- Access and portability: your schedule data lives on your device. You can
export a schedule as a calendar (
.ics) file or share it as a link.
- Erasure of on-device data: delete events or items in the app, or uninstall
the app to remove all local data.
- Erasure of shared links: shared schedules expire automatically after 30
days. You can also revoke a link early from the share screen of the event,
which deletes it from our server immediately. Alternatively, contact
privacy@callslate.app with the link and we will remove it.
- Deleting your account: if you signed in, you can delete your account from
Settings inside the app. This removes your account record and your subscription
record from our servers, signs out every device linked to it, and ends the Sign
in with Apple connection at Apple. Your on-device data is not affected, and
your subscription itself is managed by Apple, so cancel it in your Apple
subscription settings if you have not already.
- Other GDPR rights (objection, restriction, complaint to a supervisory
authority, in the Netherlands the Autoriteit Persoonsgegevens): contact us at
privacy@callslate.app.
We will respond to verified requests within the timeframes required by
applicable law.
13. Data deletion, summary
| What |
How to delete |
| Events, items, settings (on-device) |
Delete in the app, or uninstall the app |
| A shared schedule link |
Revoke it in the app from the event's share screen, wait for automatic 30-day expiry, or email privacy@callslate.app |
| Your account, email address and subscription record |
Delete your account in Settings |
| Abuse-prevention IP records |
Automatically deleted after 2 days |
14. Children
CallSlate is a professional production tool and is not directed at children.
We do not knowingly collect personal data from children.
15. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected
by an updated "Last updated" date and, where appropriate, an in-app notice.
16. Contact
Cinefix / Mike Eijkelenboom · the Netherlands
Privacy: privacy@callslate.app