Effective September 25, 2026 · Updated September 30, 2026 · Version history
The short version
GYST is run by Light Chop LLC. We use what you put into GYST to run GYST for you, not for anything else.
We don't sell your data, share it for advertising, or use it to profile you. GYST has no ads and no ad or analytics trackers.
AI features send parts of your schedule to the AI company you choose (or to Groq, our backup). Money data never goes to AI. Apple Health data goes only if you switch it on.
You can export your data, delete your Apple Health data, and delete your whole account from inside the app (Profile → Delete Account).
GYST ("Get Your Sh*t Together") is a calendar, task, habit, list and household app for iPhone and the web at getgystapp.com. GYST is operated by Light Chop LLC, a New Mexico limited liability company based in Albuquerque, New Mexico. "We", "us" and "our" mean Light Chop LLC. This policy covers the GYST app and website. It works alongside our Terms of Service.
2. What we collect
We collect what you give us and what the features you turn on need. Most of it is optional.
Account: your email address and password. Our sign-in provider stores your password as a secure hash. Optional saved sign-in on your device is described below.
Profile: name, display name, birthday, timezone, home and work addresses, saved places, work schedule, and your app settings. Onboarding does not ask for gender.
Your content: events, tasks, reminders, routines, habits and habit logs, lists and list items (including notes, links and ratings), and notes you add to any of these.
People you add: names, relationships, birthdays and colors for your children, partner, other family members and pets, and the friends and family you connect with in GYST. Imports (for example a contacts file) can add other people's birthdays.
Optional features: Apple Health data (section 6), place-reminder locations (section 7), Gmail-derived details (section 9), and Money data (section 10), only if you turn those features on. Also your followed sports teams and stock tickers.
AI and voice keys: API keys you add for AI and voice companies. They are stored encrypted and used only to call those companies for you.
Devices: push-notification tokens for your iPhone and browsers.
App diagnostics (iPhone): Apple's own app-performance and crash reports (launch time, memory, hangs, and where in GYST's code a crash happened). Apple only provides these if you allow sharing with app developers in iOS Settings → Privacy & Security → Analytics & Improvements. They contain no calendar, task, list, health or message content.
Server logs: like any website, our host records requests: IP address, browser or device type, the page or API requested, and timing. We keep your content out of these logs.
Activity: which days you used GYST, for streaks and insights.
The web app keeps some settings in your browser's local storage. Your sign-in is not stored there: it lives in one secure sign-in cookie that the page itself can't read, and the page holds its short-lived sign-in key only in memory while it is open. The cookie ends when you log out or reset your password, and never lasts more than 30 days after you sign in. We use no advertising or analytics cookies.
If you choose Remember password on iOS, GYST saves your email and password in this device's Keychain, protected by its current Face ID or Touch ID enrollment. It also remembers the email address in the app's local settings. Logging out keeps this optional saved login; Forget saved password on the login screen removes it. Changing your password or deleting your account in the iOS app also removes the saved login on that device. In supported browsers, Remember password asks your browser's password manager to save it; storage, syncing and removal follow your browser's settings. GYST does not put saved passwords in browser local storage or share them with connected AI assistants.
3. How we use it
To run GYST: show your calendar and lists, sync your devices, send the reminders you set, and keep shared items in sync with the people you share them with.
To power the features you turn on: AI chat and daily briefs, Apple Health habits, Gmail package and booking detection, Money.
To keep GYST secure, prevent abuse, and fix problems (diagnostics and logs).
To contact you about your account: password reset links, security codes, account-deletion confirmation, and important changes to this policy or our terms. We don't send marketing email.
We do not sell your personal information, share it for cross-context behavioral advertising, rent it, or give it to data brokers. We don't use your data to train AI models.
4. AI features
AI chat, the daily brief, smart event creation and optional smart email parsing send information to an AI company to get an answer.
Who receives it
The AI companies you add keys for: OpenAI, Anthropic, Google (Gemini), xAI (Grok) and Perplexity. Your own API key is used, and that company's terms and privacy policy cover what it does with the request.
Groq, our backup: if you haven't added a key, or your chosen provider fails, AI chat is answered by Groq using GYST's own key.
Web search: when an answer needs current information, the AI writes a search query. The query goes to Perplexity or xAI (with your key) or to DuckDuckGo, and GYST's server may open the top result pages to read them. Those websites see GYST's server, not you. A daily-brief query can include your city.
Voice: if you turn on a spoken brief, the brief's text goes to OpenAI or ElevenLabs using your key. The iPhone's built-in voice stays on your device.
On-device AI (iPhone): on supported iPhones, many requests are handled by Apple's on-device model and never leave your phone. Questions it can't answer, including health questions, are sent to AI chat as described here.
What is sent
Your request, plus the context needed to answer it: your name; your home and work addresses and work schedule; the names and relationships of people in your Family section; your events from a week ago to 90 days ahead (titles, times, locations and notes), plus the titles and cancel notes of events you cancelled in the past five weeks; and your open tasks. For the daily brief, also weather, web-search results, reminder badges (titles only — never bill amounts), package deliveries GYST found in your email (description, carrier and expected date), and the first part of yesterday's brief (so it isn't repeated).
Events and package details derived from your connected Gmail account enter that context only while Enhanced Email Parsing is on. Turning it off also excludes them from on-device AI tools and connected assistants. A saved brief that may contain email details must be regenerated with the setting off before GYST sends it for cloud voice or reuses it as AI context.
Never sent to AI: Money data of any kind, your passwords or API keys (a key goes only to its own company), Apple Health data unless you turn on Include Apple Health data (section 6), and information GYST extracts from your connected Gmail account while Enhanced Email Parsing is off.
If you turn on Enhanced Email Parsing, the sender, subject line and first 500 characters of matching emails go to your chosen AI company (Groq, Anthropic or OpenAI, using your key) to pick out dates, amounts and places. It is off by default.
5. AI assistants you connect
You can connect an outside AI assistant (for example Claude, ChatGPT or Grok) to your GYST account. When you connect one, you choose what it can see and change: calendar, tasks, habits and routines, lists, people and family, and settings, each as "see" or "change". The assistant then reads and changes those things when you ask it to.
Connected assistants never get: Money data, Apple Health data (including workouts and step counts), your password, your API keys, or the ability to delete your account.
Gmail-derived events and suggestions are available only while Enhanced Email Parsing is on. Assistants cannot turn that setting on, connect or scan a mailbox, or read raw mail, Gmail tokens or message references.
Access codes are stored only as one-way hashes. An access token lasts 12 hours and a refresh token 60 days, replaced each time it's used.
See and disconnect assistants any time in Profile → Security → Connected Agents. Disconnecting stops access immediately.
An assistant can introduce itself to GYST when you first connect it: it registers its name and the web address its sign-in returns to, or GYST reads them from a page the assistant publishes. None of that is your data. If GYST can't confirm an assistant's name, the connection screen says so and shows the address it connects through.
The assistant's own company decides what it does with data it reads through GYST. Its privacy policy applies to that.
6. Apple Health (iPhone)
If you connect Apple Health, GYST reads your workouts, sleep (including stages), steps, heart rate, breathing rate, heart-rate variability, blood oxygen, sleeping wrist temperature, sleep apnea events and activity rings. GYST never writes anything to Apple Health.
We store it in your GYST account to track your habits, show workouts and sleep on your timeline, and show sleep insights. Workouts appear as events with duration, distance and calories.
It is never used for advertising, never sold, and never used for data mining. It is not stored in iCloud by GYST.
AI: Apple Health data goes to an AI company only if you turn on Profile → AI → Include Apple Health data. It is off by default. Before it turns on, GYST shows you which companies would receive it. Your yes covers only those companies: if you later add a key for another AI or voice company, GYST pauses sharing and asks you again. That company's own policy then covers how long it keeps it.
Connected assistants never receive it, and you can't share an Apple Health workout with friends or family.
Delete it: Profile → Apple Health → Delete Apple Health data from GYST disconnects Apple Health and erases everything GYST synced from it. Deleting your account erases it too. You can also turn off GYST's access in the iPhone Health app.
7. Location
Place reminders ("remind me when I get to the store") are GYST's only use of your device's location. You pick a place; GYST saves its coordinates, radius and name so the reminder syncs across your devices.
On iPhone, iOS watches for you arriving at or leaving those places. Your movements stay on your iPhone and are never sent to GYST. The alert is created on your phone.
iPhone asks for location "While Using" when you first set a place reminder, and "Always" only when you save one, because iOS needs it to alert you when the app is closed.
On the web, "use my location" for a place reminder uses your browser's location. Addresses you type are looked up with Komoot's Photon service directly from your browser.
On iPhone, the weather card may use your approximate location with Apple's WeatherKit. Our own weather service uses a fixed area and receives no location from you.
Turn location off any time in iOS Settings or your browser. Place reminders stop working; nothing else changes.
8. Sharing with people you choose
GYST shares things only with people you connect with and only what you share.
Friends: can see your display name and any family role or child you link with them (the color you pick for a friend is yours alone). They see an event or task only if you share it, and they can view it but not change it. Before they accept, they see its title, date, time and that it came from you. After they accept, they also see its notes and location. Anyone you give your invite link or code (it works for 7 days) can find you and send you a friend request; you decide whether to accept.
Family group: only co-parents share. When you and another person both agree to be co-parents, you form a family of two: you see and can edit each other's events marked "Family", and the children's records you share. A parent, sibling or other relative you connect with as family is a label on both your friend cards — nothing is shared with them. Events you link to a child you share are visible to your family group, as are events you mark "Family". Adults you add (for example a partner or parent) are never shared into the family group. When a family ends, each of you keeps your own events plus a copy of the children's records and the children's events; nothing else is copied to the other person.
Shared lists: everyone on a list sees its items (with notes, links and ratings), who checked what off, everyone invited (including people who haven't accepted yet), and an activity history for up to 90 days.
Wishlists: the list's owner never sees who claimed a gift, and other members never see the owner's history of received gifts. Members do see each other's claims.
If you delete your account, lists you own are deleted for everyone on them, your shares end, and your check-offs, claims and activity are removed from other people's lists. Children you share with a co-parent stay with your co-parent, together with the children's events you added — they could already see and edit them. Everything else of yours is deleted.
9. Gmail (optional)
If you connect Gmail, GYST gets read-only access to your email so it can find:
shipping and delivery emails (to track packages),
flight, hotel, restaurant and event-ticket confirmations,
appointment confirmations, bills and subscription renewals,
and turn them into package tracking and suggestions for you to review. Nothing is added to your calendar until you approve it, including bills, renewals and packages. Approved events start as private, even if your usual calendar default is Family. GYST searches only for those kinds of emails and reads matching messages to pick out the details. It stores only what it extracts (tracking number, carrier, dates, amount, place, the subject line and a message reference), never whole emails. It never sends, changes or deletes email.
No person at GYST reads your email. It's never used for ads and never used to train AI models. It's only sent to an AI company if you turn on Enhanced Email Parsing (section 4).
Your Google sign-in tokens are stored encrypted.
Disconnect any time in Profile. GYST revokes its access at Google, deletes its tokens, and removes Gmail-sourced packages and pending suggestions. Events already on your calendar stay until you delete them.
GYST remembers processed message references for 90 days so dismissed or removed items are not imported again during its 30-day scanning window. Disconnecting clears those references; reconnecting can find those messages again.
GYST's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10. Money (optional)
Bank connections (Plaid)
If you link a bank or card, GYST uses Plaid. You sign in to your bank through Plaid; your bank username and password never reach GYST. Plaid's handling of your data is covered by the Plaid End User Privacy Policy. Through Plaid, GYST receives and stores account names, types and last four digits, balances (with a daily history), and up to two years of transactions (dates, merchant, amount, category). If your bank later withdraws a transaction (for example, a pending charge that posts under a new ID), GYST deletes it at the next sync, unless it is on an account you've hidden: then it stays hidden until you unlink the bank. If you link a bank again to replace its connection (to repair it, or to bring in two years of history), GYST moves the old connection's history, names and hidden accounts to the new one, then removes the old connection. The token that lets GYST read your accounts is encrypted.
Your own entries
Budgets, manually tracked assets (like a house or car), loan details and recurring bills you type in. If you turn on automatic values for an asset, the address goes to RentCast, or the vehicle's VIN (and mileage, if you enter it) goes to VinAudit and the U.S. government's free NHTSA decoder. Estimates are labeled as estimates. Stock quotes come from Twelve Data, which receives only ticker symbols.
Protections
Money requires a second check (a passkey or a code emailed to you) on top of your sign-in. It lasts 15 minutes, or until the app is closed if you verified at sign-in with Protect your GYST (up to 12 hours).
We ask for your consent before collecting any bank data, and record the version you agreed to, when, and from which IP address and device. We keep a security log of Money actions (never balances or amounts) for 18 months.
Money data never goes to AI companies or connected assistants, and it isn't in the in-app export. You can view it in the app, or email us for a copy.
Unlinking and withdrawing consent
Unlinking a bank deletes its accounts, balance history and transactions from GYST right away and asks Plaid to revoke access. It also deletes what Money learned only from that bank: its recurring-bill settings and the money events it put on your calendar, past and future.
If you revoke GYST's access at your bank or Plaid, GYST deletes that bank's data the same way and shows a notice in Money naming the bank, until you dismiss it or link the bank again (at most 90 days).
If Money is turned off for your account, the money events on your calendar are hidden right away and deleted within a few hours.
Withdrawing consent (in the app: Profile → Security → Money, after a second check; or email [email protected]) asks Plaid to revoke every bank connection and deletes everything in Money, right away: your linked banks; their accounts and balance history; their transactions; the bills and paychecks you typed into Money; your loan details (and the loan balances they add); your settings for detected bills (which are bills, how they're paid, payment counts and calendar choices); the money events on your calendar, past and upcoming; your budgets; and the assets you track yourself (like a house or car), with their value history and the address or VIN used for automatic values. You see the exact list, with names and counts, and type DELETE MONEY to confirm; afterwards GYST emails you that it's done. You can do this even if Money has been turned off for your account. Nothing you put in Money stays: GYST keeps only the record that you withdrew consent and Money's security log (see the retention table). If Plaid can't be reached for a bank, its data is still deleted right away; GYST keeps only that connection's record (the bank's name and the encrypted key needed to close it) and retries the disconnection automatically until Plaid confirms it.
If what you agree to for Money changes, GYST asks you again before it syncs or shows your bank data.
11. Siri, Shortcuts and notifications
Siri and Shortcuts (iPhone): you can ask Siri to create, change or delete events, reminders and lists. GYST asks you to confirm before changing anything. A Shortcuts automation that runs without you can only add, look up or complete things; it can't change or delete them. When you ask, Siri can see the titles of your events, tasks and lists. Apple handles Siri requests under Apple's privacy policy.
Notifications: reminders, task alerts and list invites are delivered through Apple Push Notification service (iPhone) or your browser's push service (Apple, Google or Mozilla). They include the name of the event, task, habit, routine or list, and may show on your lock screen. Turn them off in Profile or your device settings.
12. Companies that handle your data
These companies run parts of GYST for us, or receive data when you use a feature. They get only what that job needs.
Company
What for
What it receives
Supabase
Database and sign-in
All GYST data (stored in the United States)
Railway
Runs the GYST server
Data passing through the server; server logs
Cloudflare
Domain and network
Web traffic to getgystapp.com
Resend
Account email
Your email address, password reset links, security codes, account notices
Apple
Push, Siri, Apple Health, WeatherKit, crash reports
Notification text and device tokens; what Siri needs; see sections 6, 7, 11
Google, Mozilla
Web push notifications
Notification text, depending on your browser
Google (Gmail API)
Gmail feature
Your Gmail access, if you connect it
OpenAI, Anthropic, Google, xAI, Perplexity
AI, with your key
AI requests and context (section 4)
Groq
AI backup, with GYST's key
AI chat requests and context (section 4)
ElevenLabs, OpenAI
Spoken brief, with your key
The brief's text
DuckDuckGo
Web search
Search queries (no account details)
Plaid
Bank connections
Your bank link (section 10)
RentCast, VinAudit, NHTSA
Asset values
An address, or a VIN and mileage
Twelve Data
Stock quotes
Ticker symbols only
ESPN
Sports schedules
Team names (from our server); your device's IP address when team logos load
Komoot (Photon)
Address search on the web
Address text you type (from your browser)
Open-Meteo
Weather
A fixed location, nothing about you
AI assistants you connect
Your chosen assistant
What you allowed it (section 5)
We may also disclose information when the law requires it, to protect people's safety or GYST's security, or as part of a sale or merger of our business, in which case this policy would still apply to your data.
13. Security
All connections use HTTPS/TLS.
Bank tokens, Google tokens and your AI and voice API keys are encrypted at rest with AES-256-GCM, with keys kept separately from the database.
Money always requires a second check on the server (section 10). You can also turn on Protect your GYST in Profile → Security to require Face ID, a passkey or an email code to open the app. Outside Money, this is a lock on the app's screen on that device: it keeps someone who picks up your phone or open browser out, but it doesn't add a second check on our servers the way Money does, so keep your sign-in password safe too.
Access to production systems is limited to Light Chop LLC's operator, protected by multi-factor authentication, and used only to run GYST, help you when you ask, or meet legal obligations. Each time the operator views your account as you or deletes it, GYST records who did it, when and why (no content).
If you have Protect your GYST on and lose both your email and your passkey, we can turn protection off for you only after checking details your account already had (including signing in with your password), emailing your current address right away, and waiting 72 hours from that email. Unlocking with your passkey or an emailed code during those 72 hours cancels it. If you ask us to move your account to a new email address, we keep that address only until the change is made.
Account, profile, events, tasks, habits, lists, people
Until you delete them or your account
Apple Health data
Until you delete it (section 6) or your account
Daily briefs
90 days
Shared-list activity history
90 days
In-app notifications
90 days
Gmail packages
90 days after delivery (180 days if never delivered)
Gmail tokens
Until you disconnect Gmail
Gmail processed-message references
90 days, or until you disconnect Gmail or delete your account
Bank data
Until you unlink the bank, it stops sharing with GYST, you withdraw consent, or you delete your account
Money budgets and the assets you track yourself
Until you delete them, withdraw Money consent, or delete your account
Money notice that a bank stopped sharing
Until you dismiss it or link the bank again (at most 90 days)
Money consent records
For the life of your account
Money security log
18 months
App diagnostics (iPhone)
180 days
Connected-assistant access
Until you disconnect it; expired tokens are removed daily
Web sign-in ("stay signed in")
Until you log out or reset your password, or 30 days after you sign in, whichever comes first; then deleted within 7 days
AI app registrations
Deleted after 30 days with no one connected through them. One we have blocked is kept, so it can't register again
Reminder delivery log (which occurrence of a repeating event or task a reminder already went off for — no titles or notes)
30 days
Missed-repeat history (which occurrences of a repeating task passed without being done — shown only when you turn on "Show missed")
12 months, or until you delete the task
Record of operator actions on your account (who, what, when and why — no content)
18 months. If you delete your account, it is cut down to ids only (the reason is removed) and kept 18 months after the deletion
Push tokens
Until you sign out or turn notifications off
Server logs
A limited period set by our host, then deleted
Browser security reports (which kind of content a page blocked, with no personal data)
30 days
Database backups
Encrypted daily backups kept up to 7 days, then overwritten
When you delete your account, everything above is deleted at once, except that copies in database backups disappear as those backups expire (up to 7 days), children you share with a co-parent (with the children's events you added) stay with your co-parent — see section 8 — and the record of operator actions on your account is cut down to ids only and kept for 18 months.
15. Your choices and rights
See and export: Profile → Import & Export downloads a copy of your data (events, tasks, people, routines, lists, habits, Apple Health data, reminders, friends and settings). For your Money data, email us.
Correct: edit anything in the app.
Delete: delete individual items, delete your Apple Health data, or delete your account: Profile → Delete Account, on iPhone or the web. We confirm by email.
Turn things off: disconnect Gmail, banks, Apple Health or assistants; turn off AI health sharing, location or notifications; remove your API keys.
U.S. state privacy rights
Depending on where you live (for example California, Colorado, Connecticut, Virginia, Utah, Texas or Oregon), you may have the right to know what personal information we have about you, get a copy, correct it, delete it, and opt out of its sale, sharing for targeted advertising, or profiling. We don't sell or share personal information for advertising or profiling, so there is nothing to opt out of, and we treat browser opt-out signals (like Global Privacy Control) as a request not to. We won't treat you differently for using your rights.
To make a request, use the in-app tools above or email [email protected] from your account's email address (or have an authorized agent do so). We'll confirm it's you and respond within 30 days. If we turn down a request, you can appeal by replying to our answer, and we'll respond to the appeal within 45 days.
16. Age and children's information
You must be 16 or older to create a GYST account. We don't knowingly collect personal information from anyone under 16. If you believe a child under 16 has an account, email us and we'll delete it.
Parents and guardians can add information about their own children (like names, relationships and birthdays) to organize family life. That information belongs to the parent's account and is deleted with it — unless the parent shares that child with a co-parent in GYST, in which case the child's record and events stay with the co-parent. By adding anyone else's information, including children, family members, friends or imported contacts, you confirm you're allowed to share it with us. Children's names and relationships are included in AI context as described in section 4.
17. Where GYST operates
GYST is offered to people in the United States. Your data is stored and processed in the United States.
18. If something goes wrong
If a security incident exposes your personal information, we'll email you, and tell you in the app, within 72 hours of confirming it. We'll say what happened, what information was involved, what we've done, and what you can do. We'll also notify regulators and partners where the law or our agreements require.
19. Changes to this policy
We'll update this policy when GYST changes how it handles data. For significant changes we'll tell you in the app and by email before they take effect. The version history below lists every change.
October 1, 2026: Password reset emails are sent by GYST through Resend; Supabase still generates and verifies the reset link.
September 30, 2026: Email-derived details reach AI and connected assistants only while Enhanced Email Parsing is on. Gmail finds suggestions for you to approve; approved events start private. Processed message references are kept for 90 days to prevent repeats, or until you disconnect Gmail or delete your account.
September 30, 2026: When a repeating task's next occurrence arrives before you did the last one, GYST notes that it was missed (the task and the date, no other content) so your task history can show it if you turn on "Show missed". Kept 12 months.
September 30, 2026: A Shortcuts automation that runs without you can only add, look up or complete things; changing or deleting something needs you to confirm it.
September 30, 2026: Each time GYST's operator views your account as you or deletes it, GYST records who did it, when and why. The record holds no content; if you delete your account it keeps only ids, for 18 months after the deletion. Describes how we help someone locked out of Protect your GYST: checks against details the account already had, an email to the current address, and a 72-hour wait.
September 30, 2026: Only co-parents share children and family events; a parent, sibling or other relative is family by label only. An invite link now sends a friend request the other person accepts. The color you pick for a friend is yours alone, and shared events and tasks are view-only.
September 30, 2026: When a family ends, each person keeps their own events plus the children's records and events — other family events are no longer copied to the other person. Deleting your account leaves the children you share with a co-parent (and the children's events you added) with your co-parent instead of deleting them.
September 30, 2026: Linking a bank again to repair it or to bring in two years of history keeps its history. Withdrawing Money consent in the app now asks you to type DELETE MONEY, emails you when it's done, and works even if Money was turned off for your account.
September 29, 2026: Reminders on repeating events and tasks now go off for every occurrence. To never send one twice, GYST keeps a short log of which occurrence each reminder already went off for (no titles or notes), deleted after 30 days.
September 29, 2026: A web sign-in now lasts at most 30 days, then you sign in again. The web app no longer keeps its sign-in key in local storage.
September 29, 2026: Says plainly that Protect your GYST outside Money is a lock on the app's screen, not a second check on our servers.
September 29, 2026: Apple Health sharing with AI covers only the companies you agreed to; adding a new AI or voice company pauses it until you agree again.
September 29, 2026: An assistant's own details (its name and sign-in address) are saved only when you press Allow, and an AI app we have blocked keeps its registration so it can't sign up again.
September 29, 2026: Describes the web's "stay signed in" cookie and how long a web sign-in lasts.
September 29, 2026: Money consent can be withdrawn in the app. Withdrawing now deletes everything in Money, including your budgets, the assets you track yourself and the bills and loan details you typed in. If what you agree to for Money changes, we ask again before syncing or showing bank data. Unlinking a bank, or a bank revoking access, now also deletes the bill settings and calendar money events learned from it, and a revocation leaves a notice in Money; turning Money off removes its calendar events. The withdrawal section now lists exactly what is deleted. A transaction your bank withdraws is now deleted at the next sync instead of kept hidden until you unlink, except on an account you've hidden. These changes delete more, sooner, at your request, so you don't need to agree again.
September 25, 2026: Rewritten. Names Light Chop LLC as the operator. Adds sections on Apple Health, location, AI (including the Groq backup and the Apple Health switch), connected assistants, Siri, notifications, sharing, children's information and U.S. state rights. Corrects Gmail to describe everything it looks for. Adds in-app account deletion, Apple Health deletion, a full list of companies, and a complete retention table. Minimum age is now 16.
September 15, 2026: Added app diagnostics (iPhone).
August 13, 2026: Added Money (Plaid) and automatic asset values.