CallSlate
CallSlate

Privacy Policy

CallSlate Privacy Policy

Last updated: 11 September 2026 Applies to: the CallSlate mobile application and its supporting API.


1. Who we are

CallSlate is operated by Cinefix / Mike Eijkelenboom, based in the Netherlands. For privacy questions or requests, contact:

For the purposes of the GDPR, the operator named above is the data controller for the limited personal data described below.

Note: CallSlate may be transferred to a dedicated company in the future. If the controller changes, this policy will be updated.


2. The short version


3. Data stored only on your device (local-only)

The following data is stored locally on your device (using the app's on-device storage). We never store it on our servers, and none of it is transmitted at all unless a bullet below says otherwise:

There is no server-side sync of your projects. Our database contains no table that can hold an event, a crew member, or a cost figure.

You can delete this data at any time by deleting individual events or items inside the app, or by uninstalling the app, which removes your projects, crew, gear and settings from the device. One thing can survive a reinstall: the device registration token, which iOS keeps in the device's secure keychain. It identifies the installed copy of the app to our server, holds no personal data, and is deleted on our side after 12 months without contact (see §11).

Note: your subscription status is the one thing that is deliberately not local. It is held on our server and read by the app, so that a reinstall or a new phone cannot lose access you have paid for. See §4.6.


4. Data we process on our servers

We process the following on our servers (API hosted by Railway in Amsterdam, EU; PostgreSQL database hosted by Neon in Frankfurt, EU) only when the relevant feature is used:

4.1 Shared schedule links

When you share a schedule, we store a reduced snapshot of it so it can be opened from a link or QR code. That snapshot is deliberately small:

Other things worth knowing:

4.2 AI schedule import

See Section 5.

4.3 Live Activities (Lock Screen / Dynamic Island / Apple Watch)

When you run a Live Activity, we store the Apple push token and the pre-built card content (event and item titles and countdown timing) so our server can keep the Live Activity up to date while the app is closed. See Section 7.

4.4 Device identifier

On first use, our server issues a pseudonymous device token to your app. It is used to count free AI imports and to associate Live Activity updates with your device. On its own it is not linked to your name or email. If you sign in, this device is linked to your account so we know which subscription applies to it.

4.5 Your account (only if you sign in)

Signing in uses Sign in with Apple. We store:

We never ask for or store your name.

4.6 Subscriptions and purchases

Purchases are made through Apple, not through us. We never see your payment details. When you buy or restore a subscription, your device sends Apple's signed receipt to our server, which verifies it with Apple and stores the outcome against your account: which product, whether it is active, when it expires, whether it will renew, whether it was made in the sandbox or production environment, and identifiers for the transaction.

Apple also notifies our server directly about later changes to that subscription, such as renewals, cancellations, and refunds. We keep a record of which of those notifications we have already handled, so a repeated delivery is not processed twice. That record contains only Apple's own message identifier and a timestamp.

4.7 Abuse prevention

To protect the service from abuse, we temporarily record the IP address of requests to endpoints that cost us money or could be flooded: AI import, address lookup, weather, travel time, sharing a schedule, registering a device, and sign-in. These records are automatically deleted after 2 days and are used only for rate-limiting and security. IP addresses also appear in our server's own operational logs, which are kept by our hosting provider for a short period and are not used for anything else.

Separately, we keep counters for your free AI import allowance and, for subscribers, fair-use ceilings. Because these count over a month, they are kept for up to 40 days. They are keyed to a one-way hash of your device token or account, never to an IP address.


5. AI processing

When you import a schedule from a PDF, a Word document, or pasted text, our server sends the extracted text to OpenAI's API (model gpt-5.4-mini) to convert it into a structured timeline. The app asks for your agreement before this happens the first time.

If you do not want a schedule processed by AI, you can build it manually or use the calendar or paste-text import instead.

PDF files are uploaded to our server for text extraction as part of AI import. When you select a Word document (.docx), the file is uploaded to our server for text extraction before you review the extracted text. This extraction does not use AI or consume an AI import. If you then choose AI processing, the text is handled as described above. The uploaded documents are processed in memory and are not saved to our database or file storage.


6. Location, weather & travel-time processing

You control location access through your device's permission settings. If you deny location access, travel and cost features that rely on it will be limited.


7. Push notifications & Live Activities (Apple APNs)

CallSlate uses Apple's Push Notification service (APNs) to power Live Activities on the Lock Screen, Dynamic Island, and Apple Watch. To do this, Apple and our server process a push token for the activity and the card content (event and item titles, countdown timing). General reminders for upcoming items are scheduled locally on your device.

Live Activity content appears on your Lock Screen, so it can be read by anyone holding your phone without unlocking it. Keep that in mind for event and item titles.


8. Third-party services

We share data only with the providers needed to deliver the features above:

We do not sell your data, and we do not share it with advertisers or data brokers. Each provider processes data under its own data-processing terms. Railway and Neon host and store our server-side data in the EU. OpenAI is based in the United States; the schedule text sent for AI parsing is transferred there under the EU standard contractual clauses in OpenAI's data-processing addendum, and OpenAI does not use API data to train its models. Apple processes sign-in, purchases, weather, maps and push data under Apple's developer terms.


9. Analytics, tracking & advertising

CallSlate contains no analytics, crash-reporting, or tracking SDKs (for example, no Sentry, Firebase, Amplitude, Segment, Google Analytics, Meta SDK, or AdMob), and uses no advertising identifier (IDFA). We do not track you across other apps or websites.


10. Apple App Store privacy labels

Consistent with the above, CallSlate's App Store privacy labels are:


11. Data retention


12. Your rights

Most of your data lives on your device, so several rights are exercised there directly:

We will respond to verified requests within the timeframes required by applicable law.


13. Data deletion, summary

What How to delete
Events, items, settings (on-device) Delete in the app, or uninstall the app
A shared schedule link Revoke it in the app from the event's share screen, wait for automatic 30-day expiry, or email privacy@callslate.app
Your account, email address and subscription record Delete your account in Settings
Abuse-prevention IP records Automatically deleted after 2 days

14. Children

CallSlate is a professional production tool and is not directed at children. We do not knowingly collect personal data from children.


15. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected by an updated "Last updated" date and, where appropriate, an in-app notice.


16. Contact

Cinefix / Mike Eijkelenboom · the Netherlands Privacy: privacy@callslate.app