Legal

Privacy Policy

Last updated 5 October 2026

In plain terms: we collect only what the app needs to work, we store it in the UK, we never sell it or use it for advertising, and you can delete everything yourself at any time from Settings.

1. Who we are

Kerfuff is operated by Dean O'Meara, trading as Kerfuff, based in West Yorkshire, United Kingdom. We are the data controller of the personal data described in this policy under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contact: hello@kerfuff.app

2. What data we hold

We collect the following categories of personal data:

  • Account data: your email address, display name, and a hashed password — or, if you sign in with Google or Microsoft, the identity token they provide (we never see your Google or Microsoft password).
  • Household data: member names and roles, household profiles (names, colours, optional birthdays and avatars), chores, routines, lists, meals and recipes you create.
  • Calendar data: event titles, start and end times, locations and notes from calendars you connect, and events you create in Kerfuff.
  • Uploaded files: photos you upload for the screensaver, and letters, PDFs or emails you submit for AI scanning.
  • Technical data: paired display devices and when they last connected, push notification subscriptions, your approximate location (coordinates only, used for weather and display dimming — never a full address), IP address in server logs, and browser type.
  • Billing data: your subscription status and renewal date. We do not store card numbers — all payment data is held by Stripe (see processors below).

A family calendar inevitably contains information about children. We collect only what the features require, use no advertising or profiling, and never sell data.

3. Google Calendar data

If you connect a Google Calendar account, Kerfuff requests OAuth permission to read your calendar events and, for two-way sync, to create and update events on your behalf. We access only the calendars and event fields needed to show your schedule to your household and to write events you create in Kerfuff back to your Google Calendar.

We do not use Google Calendar data for advertising, we do not share it with third parties except our processors listed below (and only to the extent necessary to operate the service), and no employee reads your calendar data except with your explicit consent for support purposes or where required by law.

Limited Use: Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Access tokens are encrypted at rest. You can disconnect your Google account at any time in Settings → Calendar accounts, which immediately revokes our access and removes the synced event data.

4. Microsoft Outlook data

If you connect a Microsoft Outlook account, Kerfuff requests read-only OAuth permission (Calendars.Read) to display your Outlook events in your household calendar. We do not write events back to Outlook.

The same principles apply as for Google: data is used only to provide the calendar service, is never used for advertising or profiling, and is deleted when you disconnect the account.

5. Apple Calendar and iCloud data

If you connect an Apple Calendar via CalDAV, Kerfuff uses an app-specific password you generate (your Apple ID password is never shared with us) to read and write calendar data via the CalDAV protocol. This connection is two-way: events you create in Kerfuff are written to your iCloud calendar.

The app-specific password is encrypted at rest and is used only to sync your calendar. You can revoke it at any time from your Apple ID settings or disconnect the account in Kerfuff.

6. AI scanning

When you photograph a school letter or forward an email for AI scanning, the image, PDF or text is sent from our servers (never directly from your device) to Anthropic's API to extract event dates and list items. Anthropic processes the content under a data processing agreement that prohibits use of your data for model training.

We log only metadata (job ID, processing time, token counts, confidence scores) — never the content of the source document, the extracted drafts, or your review decisions.

Source files are deleted after 30 days. Unreviewed drafts are deleted after 7 days. Nothing is added to your calendar until you explicitly approve it.

7. Payments

Subscription payments are processed by Stripe. When you upgrade, you are redirected to Stripe's secure checkout. Kerfuff never receives or stores your card number, expiry date or CVV. Stripe is PCI DSS compliant.

We receive confirmation of payment status and your Stripe customer ID from Stripe webhooks. We store your subscription plan, renewal date and Stripe customer ID to manage your access.

8. Sub-processors (who else sees your data)

We use the following sub-processors, each bound by a data processing agreement:

ProcessorPurposeLocation
SupabaseDatabase, file storage, authenticationUK (AWS eu-west-2)
VercelApplication hosting and edge deliveryEU / Global CDN
AnthropicAI extraction from scanned documentsUSA (DPA in place)
StripePayment processing and subscription managementUSA / EU
ResendTransactional email (invites, notifications)USA (DPA in place)
PostHogProduct analytics — no calendar content, no ad targetingEU
SentryError monitoring — no personal calendar dataUSA (DPA in place)
GoogleCalendar sync (if you connect a Google account)USA (SCCs in place)
MicrosoftCalendar sync (if you connect an Outlook account)USA/EU (SCCs in place)

10. Children

Children can have a household profile (visible on the calendar) and, with a parent's explicit invitation, a limited login account that allows them to tick chores but not delete events or access settings. Child accounts are created and managed entirely by an adult in the household.

We apply high-privacy defaults for all household data: no public profiles, no contact with people outside the household, no location tracking beyond the optional household-level coordinates for weather.

11. How long we keep data

  • Account and household data: for as long as your account exists.
  • Calendar sync history (change log): 14 days, used for incremental sync.
  • Scanned source files: 30 days.
  • Unreviewed AI drafts: 7 days.
  • Server logs: 30 days.
  • Database backups: roll off within 35 days.
  • Billing records: 7 years (legal obligation).

Deleting your account in Settings → Account → Delete account permanently deletes all household data. For owners, this includes all members' profiles, events, tasks, photos and messages. This action cannot be undone.

12. Your rights

Under UK GDPR you have the right to:

  • Access: download all your household data from Settings → Account → Your data.
  • Rectification: update your name, email and household data yourself in the app, or ask us to correct it.
  • Erasure: delete your account in Settings, or email us.
  • Restriction: ask us to stop processing your data while a dispute is resolved.
  • Portability: download your data in machine-readable format from Settings.
  • Object: to processing based on legitimate interests.
  • Withdraw consent: revoke push notification or location permission in your browser settings at any time.

You can also lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.

13. Cookies and local storage

We use HTTP-only session cookies for authentication and short-lived cookies to manage OAuth state during sign-in (expired after 10 minutes). We do not use third-party advertising cookies.

Display devices use browser local storage (IndexedDB) to cache your household calendar for offline use. This data stays on the device and is never sent to third parties.

PostHog sets an analytics cookie to count unique visitors. It does not contain calendar content or personal identifiable information beyond an anonymous ID.

14. Changes to this policy

We will notify you by email and by an in-app notice at least 14 days before any material change to this policy. The date at the top of this page shows when it was last updated.

15. Contact

For any privacy question, data subject request, or complaint, email us at hello@kerfuff.app. We aim to respond within 5 working days.