Legal
Privacy Policy
Last updated 13 August 2026. This is the whole policy — there is no second, longer version.
Consistency Calendar turns a goal into a private calendar you tick off. To do that it has to hold your plan and your progress. This page says exactly what that means, in the order you'd actually want to know it.
The short version
- You can create and use a calendar without giving us an email address. An account is optional and only exists so you can find your calendars again.
- We never see your card details — payments go through Stripe.
- We do not sell your data and do not advertise. We run our own product analytics — no outside analytics company, no advertising trackers — and it records pages, never plan contents.
- Your goal description is sent to an AI provider to build your plan. Nothing else is.
- You can export or permanently delete everything yourself, at any time, from ⚙ Settings — no need to ask us.
Who we are
Consistency Calendar is operated by Responsive Data Solutions Limited, a company based in the United Kingdom. Responsive Data Solutions Limited is the data controller for the information described here. Contact: hello@consistencycalendar.com.
| ICO registration | |
|---|---|
| Registration reference | ZC219158 |
| Date registered | 10 August 2026 |
| Registration expires | 9 August 2027 |
| Payment tier | Tier 1 |
| Data controller | Responsive Data Solutions Limited |
| Address | 8 Mead Road, Cranleigh, GU6 7BG |
What we collect, and why
| Data | Why | Legal basis (UK GDPR) |
|---|---|---|
| Email address — only if you create an account | So you can log back in and see your calendars on another device, and so we can send password resets and sign-in links | Contract |
| Google account identifier — only if you choose Continue with Google | To recognise the same verified Google account on later sign-ins. We store Google's stable account ID and verified email, not your Google password, profile photo, contacts or files | Contract |
| Password — stored only as a salted hash, never as text | To secure your account | Contract |
| Your plan — goal, dates, sessions, habits, any notes or documents you attach | It is the product; without it there is no calendar | Contract |
| Your progress — which sessions you ticked, habit history, weekly counters | Streaks, stats and the coaching signals the app shows you | Contract |
| Optional tracked metric — e.g. body weight, if you choose to add one | Drawing your progress against a guide curve | Explicit consent (see below) |
| Product events — timestamps of things like "a calendar was created", "a calendar was opened" | To know whether the product works. These record that something happened, never what your plan says | Legitimate interests |
| Page analytics — the page path you viewed, a random browser identifier, and the coarse source you arrived from (for example a search engine's name, or which of our pages linked you) | To see which pages people actually reach and where they give up. Run by us on our own infrastructure. Private calendar and share links are never recorded — those addresses are the credential, so the path is shortened to /c or /s before anything is stored. Query strings are never recorded | Legitimate interests |
| Founding-price choice — which monthly price band you pick on the pricing page, if you pick one | To decide what a future subscription should cost. Stored as a number on its own, with no name, email or account attached | Legitimate interests |
| Payment and subscription references — Stripe customer, Checkout and subscription identifiers | To know what you paid for, provide paid features, prevent duplicate webhook processing, manage cancellation and handle refunds | Contract / legal obligation |
| Optional Pro research response — the monthly price you select and what recurring job would make Pro useful | To decide whether and how to launch the optional subscription. This form is shown to signed-in users, and is separate from the anonymous price choice on the pricing page | Legitimate interests |
Health-related data
If you choose to track body weight, or describe an injury or medical constraint when planning, that is health data — a special category under UK GDPR. We only process it because you have explicitly chosen to provide it, we use it for nothing except showing you your own plan and progress, and you can remove it at any time by deleting the metric or the calendar. Consistency Calendar is a planning and tracking tool, not medical advice, and it is not a medical device.
What we don't collect
No card numbers. No government identifiers. No advertising identifiers. No advertising or cross-site tracking, and no analytics company outside our own.
Three things are stored in your browser. A sign-in cookie, if you have an account. A random analytics identifier in local storage, created the first time you load a page — a string of random characters with no name, email or account attached, used only to tell one visit from another in our own counts. And your calendar itself, so it opens and ticks off without a connection: your plan and progress are held on the device and synced when you are back online, and if you add the calendar to your home screen a copy of the page is kept too. All of it is on your device and none of it is shared. Clearing your browser storage removes all three; your calendar is safe on the server and reloads next time you open it.
Who else processes it
We use a small number of processors, each for one job:
| Processor | What it handles | Where |
|---|---|---|
| Cloudflare | Hosting, and the databases your account, plan and progress live in | Global edge network |
| Stripe | Payments. Card details are entered on Stripe's own checkout and never reach us | US / EU |
| Resend | Sends password-reset and sign-in emails. Receives your email address only | US |
| Anthropic | Builds and revises your plan. Receives your goal description and answers — not your email, not your tick history | US |
| Cloudflare Workers AI | Same job as above, used only as a fallback if Anthropic is unavailable | Global edge network |
| If you choose Continue with Google, Google verifies your identity and supplies your verified email and stable account ID. Separately, if you connect Google Calendar, we create one calendar in your account and write your sessions to it — we cannot see your other calendars | US |
Some of these transfer data outside the UK. Where they do, they rely on the UK International Data Transfer Addendum or equivalent safeguards.
If you use Consistency Calendar through an AI assistant
You can connect Consistency Calendar to an assistant like Claude or ChatGPT. In that case the conversation happens in their product under their privacy policy, and they send us only what is needed to build or update your calendar. We never receive your wider chat history. Equally, anything you type into that assistant is subject to its own terms, not ours.
How long we keep it
- Your calendar and progress — until you delete it, or until 24 months after your last visit, whichever comes first.
- Daily snapshots of your progress, so you can restore after a mistake — about 13 months, then automatically discarded.
- Your account — until you ask us to delete it.
- Product events — 24 months.
- Payment records — 6 years, because UK tax law requires it.
- Pro research responses — until Pro launches, you delete your account, or 24 months after you provide the response, whichever comes first.
Your rights
Under UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or withdraw consent for the optional metric.
You don't have to ask us for the two most common ones. In ⚙ Settings on any calendar, Download my data gives you the whole thing as JSON, and Delete this calendar permanently removes the plan, every version, all your progress, every snapshot and any attached documents. Deleting your account takes all of its calendars with it. Both are immediate and irreversible.
For anything else — correction, restriction, objection — email hello@consistencycalendar.com and we'll act within one month.
If you think we've got this wrong, you can complain to the Information Commissioner's Office — though we'd rather you told us first so we can fix it.
Security
Everything is served over HTTPS. Passwords are salted and hashed, never stored as text. Session cookies are signed, HttpOnly and Secure. Calendar links and feed links are long random tokens, and you can revoke or rotate them yourself from Settings. Optional per-calendar passcodes add a second lock.
Anyone holding a calendar link or feed link can read the calendar information exposed by that link. A combined account feed includes sessions from every calendar saved to that account. That is how calendar subscriptions work, so treat these links like passwords and rotate or disable them if they are shared accidentally.
Children
Consistency Calendar is not intended for children under 13, and we do not knowingly collect their data. Our planning assistant is instructed to decline to build a plan for anyone who says they are under 16.
Changes
If we change this policy materially we'll update the date at the top and, if you have an account, email you.