Privacy notice
Your information stays in your hands.
This notice covers the Deck service. It explains what Deck processes, why it is needed and the choices available to you.
Proposed effective date: 13 August 2026.
Information Deck processes
Account and invitations
Deck processes your verified email address, account identifier, authentication records and session information to create and protect your account. Deck does not ask for an individual profile name or telephone number in this beta. A household owner can give the shared household a name. Household and spouse invitations use the verified Deck identities of the sender and recipient and record invitation and revocation status.
Calendar and email connections
When you connect Google Calendar, Gmail or Apple Calendar, Deck uses the permission you grant to identify matters that may need attention. Deck is designed to reduce source material to the minimum information needed for a Deck moment. This can include an email snippet or calendar title, description, time and location while Deck creates and supports its evidence-backed conclusion. It does not use connected email or calendar content for advertising or general model training. Connection credentials are encrypted, and disconnecting a source stops future access.
Location, local dates and zmanim
If you choose current location, Deck receives and transmits precise coordinates to Deck’s beta API and its configured location service for that request. You may instead choose a place. Deck retains the latest confirmed coordinates, place, country and time zone needed for local dates, public holidays and zmanim. Private Deck may also retain a temporary travel location inside its protected device vault. Deck does not build or keep movement history.
Family Deck
Family Deck contains household membership, roles, invitations, responsibilities, shared plans, calendar items, shopping needs and photos you choose to attach. Access is enforced by household role and permission. Family membership never grants access to Private Deck.
Private Deck
Private Deck may contain health-related menstrual-cycle observations and sensitive records about your private calendar and religious practice. These records are user-linked information used only to provide Private Deck. Sensitive records are encrypted and kept out of ordinary Deck surfaces, notifications, analytics and general diagnostic logs.
Spouse sharing
Private Deck sharing is separate from Family Deck. It occurs only after the owner creates an explicit, scoped and revocable grant to a verified Deck identity. The recipient receives only the read-only projection selected by the owner. Revoking or pausing the grant ends that access.
Diagnostics and security
Deck keeps privacy-reduced operational records needed to run, secure and troubleshoot the beta, such as request identifiers, service health, delivery outcomes and security events. Authorization headers, credentials, message bodies, calendar descriptions, Private Deck content and shopping photos must not be written to diagnostic logs. The current beta does not upload an APNs push token or persistent Apple device identifier. Private reminders use local iPhone notifications.
How Deck uses information
Deck uses the information above to provide app functionality, protect accounts, fulfil user-authorized sharing, deliver requested service messages and maintain a reliable beta. Deck does not sell personal information. Deck does not track people across other companies’ apps or websites, serve advertising, build third-party advertising profiles or provide data to data brokers.
Service providers and sources
Deck uses carefully limited infrastructure and providers to operate the service, including Amazon Web Services for beta hosting, database, encryption, location lookup and allowlisted service email; Google for connections you authorize; Apple EventKit for calendars you authorize on your device; and Hebcal for Hebrew dates, observances and zmanim. These providers may process only the information needed for their part of the service under their applicable terms.
Retention, deletion and export
Deck keeps information only for the service, security, legal and recovery periods documented for each data class. Verification and recovery challenges expire after 30 minutes and purge within seven days. Revoked provider credentials delete within seven days, connection-health records within 90 days, and security/audit records within 12 months. Reasoning evidence for an earned Moment is normally retained for 30 days. Deleted data can remain only in protected, inaccessible backups until those backups expire, no later than 35 days under Deck’s current policy.
Removing a Personal Layer stops future checks and removes its configuration. Disconnecting a provider revokes future access and deletes its stored connection. Account deletion revokes provider access, sessions, invitations and spouse-sharing grants and deletes the account and its associated data. A household owner is warned that deleting the account also deletes the household and its shared data. Privacy-reduced security records retained to prove deletion are detached from the deleted account identifier and expire under the period above. Private Deck provides a separate encrypted export and deletion control.
See Your privacy choices for the controls available to you.
Withdrawing consent
You can withdraw an optional permission at any time by disconnecting the source, removing its iOS permission, removing location or a Personal Layer, leaving or revoking a household invitation, or pausing or revoking spouse sharing. Withdrawal stops the relevant future use; it does not invalidate processing already completed while permission was active. You may export your information before deleting it.
Children, changes and contact
Deck is not directed to children. Household child roles are permission-restricted and do not expose adult-only or Private Deck information. Material changes to this notice will be shown before they take effect. Questions or reports can be sent using the options on the Deck support page.