Your data, plainly explained

Privacy Policy

Melendar is designed around private Apple services. We do not operate an advertising or analytics business, and we do not sell your information. This policy explains exactly what the app stores and what happens when you share.

Effective 8 September 2026 · Applies to the Melendar iOS app

Overview

Melendar stores your calendar and trip information locally on your Apple devices and, when iCloud is available, in the app's private CloudKit container associated with your Apple Account. Melendar does not operate a separate developer-hosted database and contains no advertising or third-party analytics SDKs.

We do not track you.

Melendar does not use your data for advertising, profiling, data brokerage, or cross-app tracking.

Data we process

Profile

Your chosen display name, optional profile photo, time zone, locale, and random Melendar identifiers.

Calendar content

Event titles, dates, times, recurrence, notes, saved places, categories, and sharing choices.

Trip content

Trip dates, countries, cities, itinerary items, notes, saved places, and optional cover photos.

App state

Preferences, sync tokens, deletion tombstones, connection state, and whether the free trip allowance has been used.

Reminders and widgets

Your personal reminder choices and a privacy-filtered snapshot of upcoming events used by Home Screen and Lock Screen widgets.

Purchases

Apple processes payments through StoreKit. Melendar checks Apple's signed transaction information on your device to unlock Unlimited Plans. We do not receive or store your payment-card information. An opaque purchase token is retained so a non-consumable purchase can continue to be restored after app-data deletion.

Storage and security

Local primary data files use iOS file protection. Cloud content is stored in private CloudKit databases and custom record zones. Sensitive record payloads use CloudKit encrypted fields, and CloudKit encrypts assets such as profile and trip images.

Small local caches make the calendar appear immediately and reduce repeated network work. This includes map preview images and opaque CloudKit change tokens. These caches are not used for analytics and are cleared by Melendar's data-deletion control.

Sharing with your connection

Connecting to another person is optional. A private, single-use CloudKit link is used to establish the connection. When connected, your chosen display name, optional profile photo, and technical Melendar identifiers become available to that person.

Together

Both people receive full event details and can edit the event.

Shared

Your connected person receives full details, but only the owner can edit.

Busy

Only timing, recurrence, and technical ownership identifiers are shared—never the title, notes, location, category, or participant list.

Hidden

No partner-visible CloudKit record is created.

Shared trips are visible and editable by the connected partner only when sharing is enabled for that trip. When a host removes a connection, Melendar hides the former partner and their cached content immediately on the host device, then revokes the old CloudKit share in the background. The former partner's app clears inaccessible shared content when it next checks CloudKit. Removal cannot erase screenshots or independent copies another person already made.

Apple Account changes

Melendar binds its on-device data to the stable identifier of the Apple Account that first enables CloudKit sync. If the device changes to a different Apple Account, Melendar stops all CloudKit access and hides the existing calendar, trip, connection, and profile content. Switching back to the original Apple Account restores access.

Melendar does not automatically copy content between Apple Accounts. This prevents one person's local data from being uploaded into another person's iCloud. You can export the content owned by the previous Melendar profile as JSON, then deliberately clear only this device and start a separate profile under the current Apple Account. The previous Apple Account's CloudKit data is kept.

Apple services

Melendar uses Apple platform services solely to provide app functionality:

  • iCloud and CloudKit for storage, syncing, sharing, and change notifications.
  • StoreKit for purchases and restoring purchase access.
  • MapKit for place search, maps, and local map snapshots.
  • PhotosPicker when you choose a profile or trip image.
  • Apple Push Notification service for silent CloudKit change notifications.
  • UserNotifications for personal event reminders and WidgetKit for optional Home Screen and Lock Screen widgets.

Apple processes information under its own privacy policy. Melendar does not add third-party advertising or analytics services to these flows.

Retention and deletion

Active content remains until you edit or delete it. Local deletion tombstones containing only technical record identifiers and deletion dates may remain for up to 90 days to prevent an older device from restoring deleted content. System-managed iCloud retention is governed by Apple.

Delete Melendar Data

In the app, open Settings, choose Data, then choose Delete Melendar Data. After confirmation, Melendar removes your app profile, private CloudKit zones, owned shared content, connection access, on-device files, preferences, personal reminders, delivered Melendar notifications, widget snapshots, sync state, caches, and the free-trip usage marker.

If you own the shared CloudKit space, deleting your data also ends that shared space. Your non-consumable App Store purchase remains associated with your Apple Account and is not automatically refunded or deleted.

Melendar retains an opaque purchase binding and a new random, non-content reset marker in iCloud Keychain. The reset marker contains none of your former profile, event, trip, connection, or Melendar user identifiers; it exists only so another signed-in device honours the deletion instead of restoring an old local cache. The app creates a new profile only if you explicitly choose Start Fresh.

Your choices

  • Use Melendar locally when iCloud is unavailable.
  • Choose a separate privacy level for each calendar event.
  • Turn trip sharing on or off.
  • Choose whether notifications and widgets show event details or a private preview.
  • Enable, disable, or change personal reminders on your device.
  • Remove your connected person or leave a shared calendar.
  • Export your owned profile, calendar, event, and trip data as JSON.
  • Delete all Melendar data from within the app.

Privacy questions and data requests can be sent to support (at) hongliangsun (dot) com or through the Melendar Support page. The in-app deletion control does not require a support request.

Changes to this policy

We may update this policy when Melendar's features or legal requirements change. The effective date at the top of this page will change when a revised policy is published. Material changes will also be communicated in the app when appropriate.