← Back to GYST
Privacy Policy
Last updated: August 13, 2026
What is GYST?
GYST ("Get Your Sh*t Together") is a personal calendar and productivity app. We help you organize your schedule, tasks, and life — with optional AI-powered features and integrations.
What We Collect
When you create a GYST account, we store:
- Account info: Email address and hashed password
- Profile data: Name, timezone, work schedule, preferences you configure
- Calendar data: Events, tasks, reminders, and routines you create
- API keys: Third-party API keys you provide (stored encrypted, used only to call those services on your behalf)
Gmail Integration (Optional)
If you choose to connect your Gmail account, GYST requests read-only access to your email. We use this to:
- Scan for shipping confirmation emails from known carriers (USPS, UPS, FedEx, Amazon)
- Extract tracking numbers and estimated delivery dates
- Automatically create and update delivery events on your calendar
What we do NOT do with your email:
- We never read, store, or index the full content of your emails
- We never send emails on your behalf
- We never share your email data with third parties
- We only process emails matching specific shipping-related search queries
You can disconnect Gmail at any time from your Profile settings. When disconnected, we delete all stored tokens and stop accessing your email immediately.
Financial Data (Optional, via Plaid)
If you connect a bank or investment account, GYST uses Plaid to retrieve your data. You authenticate directly with your bank through Plaid — your bank credentials never touch GYST's servers and we never see them.
Through Plaid we receive and store: account names and types, balances, transactions (date, merchant, amount, category), and institution names. Plaid's handling of your data is governed by the Plaid End User Privacy Policy.
The access token that lets GYST read your accounts is encrypted at rest (AES-256-GCM). Unlinking a bank permanently deletes the bank's accounts, balance history, and transactions from GYST immediately, and we ask Plaid to revoke the access token. Deleting your GYST account deletes all financial data — see Data Retention below.
Automatic Asset Values (Optional)
If you turn on automatic values for a manually tracked asset, GYST sends the details you provide to a valuation service to obtain a market estimate: for real estate, the property address goes to RentCast; for vehicles, the VIN (and mileage, if you enter it) goes to VinAudit, and the VIN is also sent to the U.S. government's free NHTSA decoder to identify the vehicle. These details are stored only with that asset and are permanently deleted when you delete the asset or turn automatic values off. Estimated values are automated approximations, not appraisals, and are always labeled as estimates.
Access to financial features requires a second verification step (a passkey, or a code emailed to you) every time, on top of your normal sign-in — even if your GYST session is already open. We ask for your explicit, versioned consent before any bank data is collected, and you can withdraw that consent at any time, which unlinks every connected bank and deletes the associated data.
How We Use Your Data
- To provide and improve the GYST service
- To generate AI-powered features (daily briefs, natural language event creation) — using your API keys, not ours
- To deliver push notifications you've opted into
- To track package deliveries from your email (if Gmail is connected)
We do not sell your data. We do not rent it, and we do not share it with advertisers or data brokers.
Subprocessors
These are the services GYST relies on to operate, and what each one handles:
- Plaid: bank linking — retrieves account, balance, and transaction data on your behalf when you connect a financial institution
- Supabase: database and authentication — stores your account data and issues your sign-in credentials
- Railway: application hosting — runs the GYST server itself
- Resend: transactional email — delivers financial-feature verification codes only; does not receive your calendar or financial content. (Sign-in links and password-reset emails are sent by our authentication provider's own email system, not by GYST calling Resend directly.)
- Cloudflare: DNS and edge network — routes traffic to getgystapp.com
Third-Party Services
GYST also integrates with the following services when you configure them:
- AI providers (OpenAI, Anthropic, Google, Perplexity, Grok): Your API key is sent directly to these providers to process your requests. Their privacy policies apply to that data.
- Google Gmail API: Used for package tracking email scanning. Governed by Google API Services User Data Policy.
- Carrier APIs (USPS, UPS, FedEx): Tracking numbers are sent to carrier APIs to retrieve delivery status. No personal information beyond the tracking number is shared.
Data Storage & Security
- Your data is stored in a PostgreSQL database hosted by Supabase (AWS, US East)
- All connections use HTTPS/TLS encryption in transit
- API keys are stored encrypted and never exposed in API responses
- Authentication uses JWT tokens with secure session management
- We do not store credit card or payment information
Data Retention
- Account data: Retained as long as your account is active
- Calendar events & tasks: Retained until you delete them
- Package tracking data: Automatically deleted 30 days after delivery
- Gmail tokens: Deleted immediately when you disconnect Gmail
- Daily briefs: Retained for 90 days, then automatically purged
- Financial data (Plaid): Retained while the bank connection is active; deleted immediately and permanently when you unlink a bank or delete your account
Your Rights
You can at any time:
- Export all your data (Profile → Import/Export)
- Delete individual events, tasks, or your entire account
- Disconnect Gmail or revoke any third-party access
- Remove API keys from your profile
Children's Privacy
GYST is not intended for children under 13. We do not knowingly collect data from children under 13.
Changes to This Policy
We may update this policy as we add features. Significant changes will be communicated through the app. The "Last updated" date at the top reflects the most recent revision.
Contact
Questions about privacy, or a security concern to report? Contact us at [email protected] — this is also our security contact address.
GYST — getgystapp.com