Your data, plainly explained
Privacy Policy
Melendar is designed around private Apple services. We do not operate an advertising or analytics business, and we do not sell your information. This policy explains exactly what the app stores and what happens when you share.
Overview
Melendar stores your calendar and trip information locally on your Apple devices and, when iCloud is available, in the app's private CloudKit container associated with your Apple Account. Melendar does not operate a separate developer-hosted database and contains no advertising or third-party analytics SDKs.
Melendar does not use your data for advertising, profiling, data brokerage, or cross-app tracking.
Data we process
Profile
Your chosen display name, optional profile photo, time zone, locale, and random Melendar identifiers.
Calendar content
Event titles, dates, times, recurrence, notes, saved places, categories, and sharing choices.
Trip content
Trip dates, countries, cities, itinerary items, notes, saved places, and optional cover photos.
App state
Preferences, sync tokens, deletion tombstones, connection state, and whether the free trip allowance has been used.
Reminders and widgets
Your personal reminder choices and a privacy-filtered snapshot of upcoming events used by Home Screen and Lock Screen widgets.
Purchases
Apple processes payments through StoreKit. Melendar checks Apple's signed transaction information on your device to unlock Unlimited Plans. We do not receive or store your payment-card information. An opaque purchase token is retained so a non-consumable purchase can continue to be restored after app-data deletion.
Storage and security
Local primary data files use iOS file protection. Cloud content is stored in private CloudKit databases and custom record zones. Sensitive record payloads use CloudKit encrypted fields, and CloudKit encrypts assets such as profile and trip images.
Small local caches make the calendar appear immediately and reduce repeated network work. This includes map preview images and opaque CloudKit change tokens. These caches are not used for analytics and are cleared by Melendar's data-deletion control.
Apple Account changes
Melendar binds its on-device data to the stable identifier of the Apple Account that first enables CloudKit sync. If the device changes to a different Apple Account, Melendar stops all CloudKit access and hides the existing calendar, trip, connection, and profile content. Switching back to the original Apple Account restores access.
Melendar does not automatically copy content between Apple Accounts. This prevents one person's local data from being uploaded into another person's iCloud. You can export the content owned by the previous Melendar profile as JSON, then deliberately clear only this device and start a separate profile under the current Apple Account. The previous Apple Account's CloudKit data is kept.
Apple services
Melendar uses Apple platform services solely to provide app functionality:
- iCloud and CloudKit for storage, syncing, sharing, and change notifications.
- StoreKit for purchases and restoring purchase access.
- MapKit for place search, maps, and local map snapshots.
- PhotosPicker when you choose a profile or trip image.
- Apple Push Notification service for silent CloudKit change notifications.
- UserNotifications for personal event reminders and WidgetKit for optional Home Screen and Lock Screen widgets.
Apple processes information under its own privacy policy. Melendar does not add third-party advertising or analytics services to these flows.
Retention and deletion
Active content remains until you edit or delete it. Local deletion tombstones containing only technical record identifiers and deletion dates may remain for up to 90 days to prevent an older device from restoring deleted content. System-managed iCloud retention is governed by Apple.
Delete Melendar Data
In the app, open Settings, choose Data, then choose Delete Melendar Data. After confirmation, Melendar removes your app profile, private CloudKit zones, owned shared content, connection access, on-device files, preferences, personal reminders, delivered Melendar notifications, widget snapshots, sync state, caches, and the free-trip usage marker.
If you own the shared CloudKit space, deleting your data also ends that shared space. Your non-consumable App Store purchase remains associated with your Apple Account and is not automatically refunded or deleted.
Melendar retains an opaque purchase binding and a new random, non-content reset marker in iCloud Keychain. The reset marker contains none of your former profile, event, trip, connection, or Melendar user identifiers; it exists only so another signed-in device honours the deletion instead of restoring an old local cache. The app creates a new profile only if you explicitly choose Start Fresh.
Your choices
- Use Melendar locally when iCloud is unavailable.
- Choose a separate privacy level for each calendar event.
- Turn trip sharing on or off.
- Choose whether notifications and widgets show event details or a private preview.
- Enable, disable, or change personal reminders on your device.
- Remove your connected person or leave a shared calendar.
- Export your owned profile, calendar, event, and trip data as JSON.
- Delete all Melendar data from within the app.
Privacy questions and data requests can be sent to support (at) hongliangsun (dot) com or through the Melendar Support page. The in-app deletion control does not require a support request.
Changes to this policy
We may update this policy when Melendar's features or legal requirements change. The effective date at the top of this page will change when a revised policy is published. Material changes will also be communicated in the app when appropriate.