Sabiowl Privacy Policy

Last updated: 11 August 2026 (Article 12: the database provider, Neon, is now disclosed alongside Render, and the entry for imported Google Calendar data was corrected to match Article 9 — the body of an event is stored only on your device)


Article 1 (Scope)

This Privacy Policy sets out how Sabiowl (the “Service”) handles users’ personal information and usage information.


Article 2 (Information we collect)

The Service may collect the following information.

Basic information

In-app data

Linked calendar data (only when Google Calendar integration is enabled; import only in v1.0)

Device information

Diagnostic and support data

Voice input (Quick Notes feature, v1.0.4 and later)


Article 3 (Purposes of use)

We use the information we collect for the following purposes.


Article 4 (Provision to third parties)

We do not provide your personal information to third parties without your consent. This does not apply where disclosure is required by law, or to the limited display of information that occurs when you use the Service’s friend feature (see Article 4-2).


Article 4-2 (Information sharing in the friend feature)

If you use the Service’s friend feature, only the following information is visible to other users whom you have approved as friends.

Visible to friends

Not visible to friends

The Service never shares the actual contents of your habits with other users, including friends. The motivational aspect of the friend feature is built solely on streak length, a number that reveals nothing about what you are doing.


Article 5 (Use of analytics tools)

To improve the Service, we use “PostHog”, a third-party product analytics tool provided by PostHog Inc. PostHog uses cookies and similar technologies to measure usage of the Service anonymously.

Information collected

Information not collected

Where the data is stored

PostHog Cloud (US region: https://us.i.posthog.com).

Purposes

Deletion

When you delete your account, the corresponding data in PostHog is deleted automatically. You may also contact us to request individual deletion.

Further information

See PostHog’s privacy policy at https://posthog.com/privacy.


Article 6 (Crash and performance monitoring: Sentry)

To improve app quality, we use the crash monitoring and performance measurement SDK provided by Sentry (operated by Functional Software, Inc., United States).

Information collected

Purposes

Handling of personal information

A beforeSend hook in the SDK automatically removes user-identifying information (email address, PlayerProfile ID, name, device-specific identifiers) before transmission. On the Sentry dashboard we review crashes by occurrence, not by device. For details of personal data scrubbing, see https://docs.sentry.io/platforms/flutter/enriching-events/scrubbing/.

Where the data is stored

Sentry Cloud (US region).

Further information

See Sentry’s privacy policy at https://sentry.io/privacy/ and its data processing terms at https://sentry.io/legal/dpa/.


Article 7 (Authentication service: Firebase Authentication)

We use “Firebase Authentication”, provided by Google, to authenticate users.

How we use it

Information sent to Firebase Authentication

Where the data is stored

Google Cloud (Firebase services).

Deletion

When you delete your account, we also delete the corresponding user record in Firebase Authentication automatically.

Further information

See Firebase’s privacy policy at https://firebase.google.com/support/privacy.


Article 8 (Push notifications: Firebase Cloud Messaging)

We use “Firebase Cloud Messaging (FCM)”, provided by Google, to deliver push notifications.

How we use it

Information sent to FCM

Turning notifications off

You can disable push notifications in your device’s OS settings.

Further information

See Firebase’s privacy policy at https://firebase.google.com/support/privacy.


Article 9 (Google Calendar integration)

The Service offers one-way synchronisation that imports events from Google Calendar into the Service. Using it requires your explicit consent (enabling “Google Calendar integration” in Settings, and running “Sync Google Calendar” from the calendar screen).

Change of policy from v1.0 (29 May 2026)

The previously offered “automatic reflection from the Service into Google Calendar” (two-way synchronisation) was discontinued with the v1.0 release. Events you create in the Service are never written to Google Calendar. Import from Google Calendar into the Service continues to be offered.

Google API scopes used

Information obtained

Your control

Where the data is stored

The body of imported Google Calendar events (title, date and time, notes) is stored in SQLite on your device. It is not sent to the Service’s backend servers (v1.0.2 and later). Only the “completion state” of an event (a flag indicating whether it was completed) is sent to the backend servers, for the purpose of tracking your progress.

Sharing with third parties

We do not sell, share, or transfer Google Calendar user data obtained through the Service to any third party, including for advertising or analytics purposes.

Compliance with the Google API Services User Data Policy

The Service’s use of information received from Google APIs adheres to the Google API Services User Data Policy (the “Policy”), including the Limited Use requirements. Specifically:

How to delete the data

You can delete all Google Calendar data imported into the Service in either of the following ways:

  1. Select “Disconnect Google Calendar” from the menu on the calendar screen.
  2. Delete your account (Settings → Delete account) — all data is deleted both from your device and from our servers.

Further information

See Google’s privacy policy at https://policies.google.com/privacy.


Article 10 (Email delivery: Resend)

We use “Resend”, an email delivery service provided by Resend Inc., to reply to enquiries and to send important announcements.

Information sent to Resend

Purposes

Further information

See Resend’s privacy policy at https://resend.com/legal/privacy-policy.


Article 11 (Payment processing: Apple App Store and RevenueCat)

Since v1.0.1 (July 2026) the Service offers in-app purchases (one-time Diamond packs). We use the following external services for payment processing and receipt validation.

11-1. Apple App Store (payment processing)

Payments for in-app purchases are processed through the “App Store” operated by Apple Inc.

Information sent to Apple

Further information

See Apple’s privacy policy at https://www.apple.com/legal/privacy/.

11-2. RevenueCat (receipt validation and purchase history management)

We use “RevenueCat”, provided by RevenueCat, Inc., to validate purchase receipts and manage purchase history.

Information sent to RevenueCat

Information not sent to RevenueCat

Where the data is stored

RevenueCat’s cloud infrastructure (US region).

Purposes

Deletion

When you delete your account, we send a deletion request for the identifier associated with your use of the Service on RevenueCat. Purchase history retained by the Apple App Store is under Apple Inc.’s control and cannot be deleted by us.

Further information

See RevenueCat’s privacy policy at https://www.revenuecat.com/privacy.


Article 12 (Where data is stored: Render / Neon)

The Service’s backend servers run on the cloud infrastructure of “Render”, provided by Render Services Inc. The database runs on the cloud infrastructure of “Neon”, provided by Neon, LLC (a Databricks, Inc. group company).

Data stored

Note: the body of events imported from Google Calendar (title, date and time, notes) is stored only in SQLite on your device and is not sent to the Service’s backend servers (v1.0.2 and later). See Article 9 for details.

Storage region

Singapore (Asia Pacific), for both.

Security

Communications are encrypted with TLS, and the database is accessible only from authenticated backend servers.

Further information

See Render’s privacy policy at https://render.com/privacy, and Neon’s privacy policy (the Databricks Privacy Notice) at https://www.databricks.com/legal/privacynotice.


Article 13 (Deletion of data)

You can delete your account and all associated data using “Settings → Delete account” in the Service.

Data that is deleted

Data that is not deleted (statistics only)

Data that is not deleted (external services)

Restoration

Deleted data cannot be restored, so please consider carefully before proceeding.


Article 14 (Revisions)

We may revise this Privacy Policy as necessary. If there is a significant change, we will notify you within the Service.

You can review the history of past revisions in the commit history of the GitHub repository where this document is published.


Appendix A — Your California privacy rights

This section applies if you are a resident of California. It supplements, and does not replace, the rest of this Privacy Policy.

Categories of personal information we collect

Over the past 12 months we have collected the categories of personal information described in Article 2, namely: identifiers (name or nickname, email address, provider UID, internal identifiers, device token), commercial information (records of in-app purchases), internet or other electronic network activity information (in-app events, screen transitions, crash and performance data), and the content you create in the Service (habits, notes, timeline entries).

We collect this information for the purposes described in Article 3, from you directly and from the OAuth provider you sign in with.

We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law. We have not done so in the past 12 months. We do not knowingly collect or sell the personal information of minors under 16.

Your rights

Subject to the limits set by law, you have the right to:

How to exercise them

The fastest route is “Settings → Delete account” in the app, which deletes your account and the associated data described in Article 13. For any other request, or if you would like us to act on your behalf, contact us using “Settings → Contact” in the app. We will verify your request through the email address associated with your account before acting on it.


Contact

For enquiries about this Privacy Policy, please contact us from “Settings → Contact” in the Service’s app.


© 2026 Sabiowl. All rights reserved.
← Back to top