Effective date: September 8, 2026
This Privacy Policy explains how SmoothWeek ("SmoothWeek," "we," "us," or "our"), operated by independent developer Zsolt Magyar, handles information when you use the SmoothWeek iPhone app or this website. Contact: [email protected].
1. Local-first workspace and private iCloud backup
SmoothWeek is local-first. The following core workspace data is stored in the app’s local container on your iPhone and, where needed for widgets and Live Activities, in SmoothWeek’s private Apple App Group container:
- your professional profile, working hours, preferences, templates, and settings;
- client names, email addresses, phone numbers, notes, session types, usual schedules, and communication preferences;
- session dates and times, recurrence, attendance, reminders, activity history, and day-close records;
- payment-status records, expected amounts, currencies, and prepaid-package balances.
When iCloud is available, SmoothWeek automatically sends a versioned backup of this workspace to the private CloudKit database associated with your Apple Account. It uses that backup to restore an empty workspace after reinstalling or moving to an eligible device. The backup is for recovery, not a SmoothWeek account, shared workspace, public database, or real-time collaboration service. Apple controls the iCloud account, storage, platform encryption, and service availability.
Information opened in WhatsApp, Messages, Mail, or another app at your direction is handled by that service under its own terms.
2. Temporary calendar links
When you explicitly choose Calendar or Both and start an SMS, WhatsApp, or Instagram send action, SmoothWeek creates a temporary bearer link for the recipient. To create it, the app sends only the event title, start time, end time, time zone, and an optional location to the SmoothWeek calendar-link service hosted by DreamHost. The service also records the creation time and technical expiry time.
The calendar-link service does not receive or place in the calendar file prices, currencies, invoices, payment status, package balances, internal notes, NEW or other internal client classifications, phone numbers, email addresses, Instagram usernames, or other client contact details. The calendar description is generic and contains no financial communication.
Anyone who possesses the link can open or import the appointment, so treat it like a bearer link and share it only with the intended recipient. The recipient chooses whether to import the event into their own calendar. SmoothWeek does not automatically add, edit, or delete an event in the recipient’s calendar.
Email calendar sharing remains a standard .ics attachment prepared on the device and does not require the temporary link service.
3. Subscriptions and purchase information
Apple processes App Store purchases, billing, renewal, cancellation, refunds, and payment credentials. SmoothWeek does not receive your full card or bank details. Apple provides purchase and entitlement information needed to unlock Pro and comply with billing decisions.
SmoothWeek uses RevenueCat to reconcile subscription products and Pro entitlement status. RevenueCat may process an anonymous app-user identifier, product identifier, purchase/receipt information, entitlement status, subscription dates, offer type, storefront or country information made available by Apple, and technical request data necessary to provide the service. Automatic device-identifier collection is disabled in SmoothWeek’s RevenueCat configuration. RevenueCat’s global PostHog integration is not enabled.
4. Optional Product Analytics
Product Analytics is off until you make an explicit choice after onboarding. Refusing does not restrict the app. You can change the choice at any time under Settings → Privacy & Security → Product Analytics.
If you allow analytics, SmoothWeek sends a limited event stream to our EU-hosted PostHog project. It includes a random app-scoped install identifier; event names; aggregate client/session counts; closed categories such as entry point, plan, offer type, and subscription source; and app version, build, platform, locale, plan state, and analytics schema version.
Analytics does not include client or provider names, phone numbers, email addresses, notes, message text, locations, client/session IDs, exact session dates or times, PIN or biometric information, payment free text, Apple Account identifiers, advertising identifiers, or cross-app tracking data. SmoothWeek does not use PostHog autocapture, session replay, heatmaps, advertising features, or feature-flag polling.
Before consent, eligible one-time milestones may be retained locally but are not sent. Repeatable and subscription events are not backfilled. Opting out stops future delivery and clears the pending local analytics queue. Events already received by PostHog are not automatically erased solely by changing the setting; you may request deletion as described below.
5. Device permissions and system features
- Calendar: EventKit access is separate from the calendar-link service and is requested only when you enable conflict checking. SmoothWeek reads timed events from the Apple calendars you select to check overlaps. Calendar events are processed on device, are not copied into the SmoothWeek workspace or cloud backup, and are never created, edited, or deleted by SmoothWeek. SmoothWeek does not automatically write calendar-link events to a client’s calendar; the recipient imports an event themselves.
- Notifications: permission is requested contextually. SmoothWeek schedules local reminders on your device, including session and known Pro-expiry warnings. It does not operate a remote-push notification service.
- Face ID and local authentication: Apple’s LocalAuthentication framework confirms whether authentication succeeded. SmoothWeek does not receive, store, or transmit biometric templates.
- Contacts: if you choose the native contact picker, Apple lets you select a contact. Selected fields are copied into the local client record and included in the private workspace backup; SmoothWeek does not upload your address book as a whole.
6. Why we process limited external data
- to create a temporary calendar link only when you request that action;
- to create and restore the private iCloud workspace backup you expect from the app;
- to provide, verify, restore, and secure subscription access;
- to comply with Apple purchase, refund, and entitlement decisions;
- with your consent, to understand aggregate product activation, reliability of core flows, and subscription lifecycle;
- to answer support and privacy requests you send to us;
- to protect the service, enforce our terms, or meet legal obligations.
Where the GDPR or similar law applies, the relevant legal bases are performance of the service contract for requested calendar-link, backup, and subscription functionality; consent for optional Product Analytics; legitimate interests in security and support where those interests are not overridden by your rights; and compliance with legal obligations.
7. Retention and deletion
Calendar-link event data and the link expire and are deleted after the event’s end time plus 30 days. Expired records are removed automatically or during service maintenance and can no longer be imported from that link.
Core workspace data remains locally until you delete individual records, use Erase All Data, or remove the app. Removing the app erases its local container according to iOS behavior but normally leaves the private iCloud backup available for automatic restoration after reinstalling with the same eligible Apple Account. Erase All Data deletes the local workspace and requests deletion of SmoothWeek’s private CloudKit backup. Neither action cancels an Apple subscription.
Subscription expiration, revocation, or billing retry never deletes workspace data locally or from iCloud. SmoothWeek instead enters Locked Demo Mode, where records remain visible but business-data changes are disabled until Pro entitlement is restored. Restore Purchases restores access rights; cloud restore restores the retained workspace, so they are separate operations.
Pending optional analytics events are kept in a bounded local queue and deleted when you opt out. Data delivered to PostHog and subscription data processed by RevenueCat are retained only as necessary for the described purposes, processor obligations, security, dispute resolution, and applicable law. You may contact us to request deletion of data we control. Apple purchase and private iCloud records remain governed by Apple.
8. Service providers and international transfers
- Apple Privacy Policy — private iCloud/CloudKit backup, App Store purchases, and Apple platform services.
- RevenueCat Privacy Policy — subscription entitlement infrastructure.
- PostHog Privacy Policy — optional consented product analytics, using EU hosting.
- DreamHost Privacy Policy — website hosting, the dynamic calendar-link service, and ordinary technical and security logs that may include request time, network address, user agent, status, and requested link path.
These providers may process information in countries different from yours. Where required, transfers rely on applicable contractual or legal safeguards. The website does not use advertising pixels or product-analytics scripts. DreamHost may maintain ordinary request and security logs for hosting, abuse prevention, and reliability.
9. Your choices and privacy rights
Depending on where you live, you may have rights to be informed, access, correct, delete, restrict or object to processing, withdraw consent, obtain portable data, and complain to a supervisory authority. California residents may also have rights to know, correct, or delete certain personal information and to receive equal service when exercising applicable rights. SmoothWeek does not sell or share personal information for cross-context behavioral advertising.
Email [email protected] with “Privacy request” in the subject. We may ask for limited information needed to verify and locate the relevant install or support record. We aim to respond within the period required by applicable law. Because core workspace data is local and we have no user account, we may not possess or be able to remotely retrieve it.
10. Children
SmoothWeek is a general productivity tool for independent professionals and is not directed to children under 13. We do not knowingly collect personal information from children through the app. If you believe a child has provided information through support or optional analytics, contact us.
11. Security
We use reasonable technical and organizational safeguards appropriate to the limited data flow, including local app-container protections, Apple’s private CloudKit database and encrypted asset storage, optional device authentication, HTTPS for external requests, strict request allowlists, cryptographically random calendar-link tokens, hashed token storage, rate limiting, limited retention, strict analytics allowlists, and minimized identifiers. Calendar links are not searchable by design, but possession grants access until expiry; protect them like other private shared links. No system is completely secure, and you should protect your device, Apple Account, passcode, backups, links, and exported communications.
12. Changes and contact
We may update this policy when the app, providers, or law changes. The effective date above identifies the current version. Material changes will be presented through an appropriate in-app or website notice when required.
SmoothWeek / Zsolt MagyarEmail: [email protected]
Support: smoothweek.com/support