Legal

Privacy Policy

Last updated 13 August 2026. This is the whole policy — there is no second, longer version.

Consistency Calendar turns a goal into a private calendar you tick off. To do that it has to hold your plan and your progress. This page says exactly what that means, in the order you'd actually want to know it.

The short version

Who we are

Consistency Calendar is operated by Responsive Data Solutions Limited, a company based in the United Kingdom. Responsive Data Solutions Limited is the data controller for the information described here. Contact: hello@consistencycalendar.com.

ICO registration
Registration referenceZC219158
Date registered10 August 2026
Registration expires9 August 2027
Payment tierTier 1
Data controllerResponsive Data Solutions Limited
Address8 Mead Road, Cranleigh, GU6 7BG

What we collect, and why

DataWhyLegal basis (UK GDPR)
Email address — only if you create an accountSo you can log back in and see your calendars on another device, and so we can send password resets and sign-in linksContract
Google account identifier — only if you choose Continue with GoogleTo recognise the same verified Google account on later sign-ins. We store Google's stable account ID and verified email, not your Google password, profile photo, contacts or filesContract
Password — stored only as a salted hash, never as textTo secure your accountContract
Your plan — goal, dates, sessions, habits, any notes or documents you attachIt is the product; without it there is no calendarContract
Your progress — which sessions you ticked, habit history, weekly countersStreaks, stats and the coaching signals the app shows youContract
Optional tracked metric — e.g. body weight, if you choose to add oneDrawing your progress against a guide curveExplicit consent (see below)
Product events — timestamps of things like "a calendar was created", "a calendar was opened"To know whether the product works. These record that something happened, never what your plan saysLegitimate interests
Page analytics — the page path you viewed, a random browser identifier, and the coarse source you arrived from (for example a search engine's name, or which of our pages linked you)To see which pages people actually reach and where they give up. Run by us on our own infrastructure. Private calendar and share links are never recorded — those addresses are the credential, so the path is shortened to /c or /s before anything is stored. Query strings are never recordedLegitimate interests
Founding-price choice — which monthly price band you pick on the pricing page, if you pick oneTo decide what a future subscription should cost. Stored as a number on its own, with no name, email or account attachedLegitimate interests
Payment and subscription references — Stripe customer, Checkout and subscription identifiersTo know what you paid for, provide paid features, prevent duplicate webhook processing, manage cancellation and handle refundsContract / legal obligation
Optional Pro research response — the monthly price you select and what recurring job would make Pro usefulTo decide whether and how to launch the optional subscription. This form is shown to signed-in users, and is separate from the anonymous price choice on the pricing pageLegitimate interests

Health-related data

If you choose to track body weight, or describe an injury or medical constraint when planning, that is health data — a special category under UK GDPR. We only process it because you have explicitly chosen to provide it, we use it for nothing except showing you your own plan and progress, and you can remove it at any time by deleting the metric or the calendar. Consistency Calendar is a planning and tracking tool, not medical advice, and it is not a medical device.

What we don't collect

No card numbers. No government identifiers. No advertising identifiers. No advertising or cross-site tracking, and no analytics company outside our own.

Three things are stored in your browser. A sign-in cookie, if you have an account. A random analytics identifier in local storage, created the first time you load a page — a string of random characters with no name, email or account attached, used only to tell one visit from another in our own counts. And your calendar itself, so it opens and ticks off without a connection: your plan and progress are held on the device and synced when you are back online, and if you add the calendar to your home screen a copy of the page is kept too. All of it is on your device and none of it is shared. Clearing your browser storage removes all three; your calendar is safe on the server and reloads next time you open it.

Who else processes it

We use a small number of processors, each for one job:

ProcessorWhat it handlesWhere
CloudflareHosting, and the databases your account, plan and progress live inGlobal edge network
StripePayments. Card details are entered on Stripe's own checkout and never reach usUS / EU
ResendSends password-reset and sign-in emails. Receives your email address onlyUS
AnthropicBuilds and revises your plan. Receives your goal description and answers — not your email, not your tick historyUS
Cloudflare Workers AISame job as above, used only as a fallback if Anthropic is unavailableGlobal edge network
GoogleIf you choose Continue with Google, Google verifies your identity and supplies your verified email and stable account ID. Separately, if you connect Google Calendar, we create one calendar in your account and write your sessions to it — we cannot see your other calendarsUS

Some of these transfer data outside the UK. Where they do, they rely on the UK International Data Transfer Addendum or equivalent safeguards.

If you use Consistency Calendar through an AI assistant

You can connect Consistency Calendar to an assistant like Claude or ChatGPT. In that case the conversation happens in their product under their privacy policy, and they send us only what is needed to build or update your calendar. We never receive your wider chat history. Equally, anything you type into that assistant is subject to its own terms, not ours.

How long we keep it

Your rights

Under UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or withdraw consent for the optional metric.

You don't have to ask us for the two most common ones. In ⚙ Settings on any calendar, Download my data gives you the whole thing as JSON, and Delete this calendar permanently removes the plan, every version, all your progress, every snapshot and any attached documents. Deleting your account takes all of its calendars with it. Both are immediate and irreversible.

For anything else — correction, restriction, objection — email hello@consistencycalendar.com and we'll act within one month.

If you think we've got this wrong, you can complain to the Information Commissioner's Office — though we'd rather you told us first so we can fix it.

Security

Everything is served over HTTPS. Passwords are salted and hashed, never stored as text. Session cookies are signed, HttpOnly and Secure. Calendar links and feed links are long random tokens, and you can revoke or rotate them yourself from Settings. Optional per-calendar passcodes add a second lock.

Anyone holding a calendar link or feed link can read the calendar information exposed by that link. A combined account feed includes sessions from every calendar saved to that account. That is how calendar subscriptions work, so treat these links like passwords and rotate or disable them if they are shared accidentally.

Children

Consistency Calendar is not intended for children under 13, and we do not knowingly collect their data. Our planning assistant is instructed to decline to build a plan for anyone who says they are under 16.

Changes

If we change this policy materially we'll update the date at the top and, if you have an account, email you.