Livnly · Legal

Privacy Policy

Last updated: September 28, 2026

1. Who We Are

Livnly is a calendar app for iOS and Mac, operated by JB CAPITAL BV, trading as Kuberdon, a company registered in Belgium (VAT: BE 1005.101.429). This page says what happens to your data, in the order that matters: what never leaves your device, the two places your event titles do travel, what we store, and who else touches any of it.

2. Your Calendar Stays On Your Device

Livnly is not a calendar service. It reads the calendars your device already has, through the permission you grant in iOS or macOS. Your events, and everything Livnly adds to them (colors, categories, what a block is for), live in your device's own calendar and in a database on the device itself. We do not sync your calendar to our servers and we keep no copy of your week.

Livnly never connects to Google, Microsoft or iCloud on your behalf. There is no calendar integration to authorize, because there is none. Events from those accounts show up because you linked the account in your device's own settings and the operating system synced them; Livnly only ever reads what is already there.

The other permissions work the same way. Workouts and sleep times from Apple Health, your contacts, and your location are all read on the device. Location is used in two places, both on the screen where you pick where an event is: to fill in where you are when you tap "use current location", and, when you search for a place, to put the ones near you first. Your raw address book is never uploaded: it is read to put faces on the people already on an event, and to show you a list when you are adding someone to a plan. Livnly never writes to Apple Health. It writes to your contacts in exactly one place: when you use "Add a birthday" and press Save, the birthday you chose is saved to that person's contact card, because that is where your phone keeps birthdays. That one field is the only thing Livnly can change in your address book, and it only happens when you ask for it.

Some features deliberately send limited information. Section 3: people you add and hashed identifiers sync to your account; current app versions keep their raw phone numbers and email addresses on your device. If you enable mutual discovery, hashes of permitted contacts also go to our server for matching. Section 4: when you type a plan in words or ask Livnly to change something, that sentence and the titles of the events it needs to reason about leave your device. Section 5: when you share a plan by link, that one plan is stored so the page can show it. Section 6: to put a face on a guest, a hash of their email goes to our server, never the address.

3. What We Store

Signing in is optional in the app. When you do sign in, this is everything we hold:

  • Your account: your email address, plus your name and profile picture if you set one. Profile pictures are stored in a private file bucket, readable only by you and by us.
  • Your contact details and discovery: linking your own contact copies its phone numbers and emails into local, account-specific storage. Its name can fill your account profile. Linking does not verify ownership or enable discovery. When you request verification, the chosen phone number goes to Twilio for an SMS, or the email address goes to Resend for a code. The identity directory stores server-keyed matching tokens and encrypted hashes, not those raw destinations. Hashes are still personal data. Discovery is off until you enable it. It sends hashes of the phone numbers and emails your Contacts permission allows us to read. A match is visible only when both accounts enable discovery and have saved each other's verified details. Blocking, unlinking an identity or disabling discovery removes the corresponding matches. Contact assertions expire after 30 days unless refreshed; identity verification expires after 180 days. Codes expire after 10 minutes and attempts are limited.
  • Your labels: the categories and quick-create templates you make, meaning their names, emoji and note templates, so they follow you to a new device. The labels only, never the events you put them on.
  • Your partner: if you link a partner, their name and an internal identifier sync with your settings, never their email or phone number.
  • Plans you shared by link: when you tap Send invite, we store that one event, meaning its title, time, location and your name, plus the name you have for the person you sent it to and the answer they give. That is what the page they open is made of. Only the plans you deliberately shared, never your calendar, and we delete all of it 30 days after the event.
  • What you asked Livnly to do: if you type a plan in words or ask for a change, we store that sentence, the plan it produced, and the snapshot of events it was shown, on your account. That is what lets the answer come back to you and lets you undo it.
  • Your application: the answers you send when you apply to join, including your name, email and free-text answers.
  • Sign-in and abuse records: that a sign-in code was sent to your email, and your IP address for a short window against the public forms so they cannot be flooded.

4. When You Type A Plan In Words

"Dinner with Sam on Thursday at 8" is read on your device first, by a parser that ships inside the app. That parser works signed out, offline, and when everything of ours is down.

When you are signed in, Livnly also asks a language model to check the reading, because a model is better at "half seven" than a rule is. Here is exactly what that request contains:

  • the sentence you typed
  • the titles and times of the events in the day or window the request is about, so it can place "right after the standup"
  • the names of your calendars and categories, your usual waking hours, and the current time
  • nothing else. Not your notes, not your guests, not your event locations, not your health data, not your contacts, not one thing about any other week.

Our provider for that call is OpenAI, through their API, which does not use it to train models. If the call fails, times out, or you are signed out, your device's own reading is used and the event is written anyway. The feature degrades; it never blocks.

The same goes for a screenshot you share into Livnly from another app: the picture is sent once, with the same small context (your category names, your usual hours, the current time, and the names of your people so they are spelled right), the events it names come back for you to confirm, and the picture is kept nowhere: not by us, and not by the model provider. Nothing is read from a screenshot you did not share.

5. When You Share A Plan

When you send someone a plan, they see that plan: what it is, when it is, where it is, and who invited them. They see nothing else about your week, and they need no Livnly account, no app and no sign-in to open it. Nothing is shared by default, and there is no way for anyone to see the shape of your week unless you deliberately send it to them.

Sending a link is the one moment a plan leaves your phone. We store that single event so the web page can show it, and the name you have for the person you sent it to, so the page can greet them and so their answer comes back to the right face in your app. Anyone holding the link can see the plan, so treat it like any other message: if you send it to the wrong thread, you can turn the link off from the event, which stops every copy of it working, including forwarded ones. We delete the plan and the name 30 days after the event, whether or not you turn the link off.

Your first name and your profile photo appear on that page, so the plan arrives from a person rather than from a stranger. Only your first name: your last name stays on your account and is never published. The app tells you this before the first link is created, and only links you make from then on carry your photo. Because the page reads your profile as it is now, changing your name or your photo changes what a link you already sent will show; taking your photo off in the app takes it off those pages too. One thing turning a link off cannot undo: if a preview of it is already sitting in a chat, that picture stays in the conversation, because messaging apps keep their own copy.

6. Faces From Public Avatar Sources

Livnly shows a face next to the people on your plans. For someone whose photo is in your address book, that photo is matched on your device, as section 2 describes. For someone who is not, the app asks our own server for the picture that person deliberately published on a public avatar service, Gravatar or Libravatar. What the app sends is a one-way hash (SHA-256) of that person's email address, in the address of an image request: not the address itself, not their name, not which plan they are on, and not your account. The request works the same signed out, so our server cannot tell whose calendar asked. Those avatar services receive the same hash anyone who knows the address could compute, and nothing else. Our own dashboard uses the same lookup for members without a profile picture. For a company domain we may also fetch the logo the domain owner published in DNS (BIMI) or as a favicon.

What our server keeps is the hash, which source answered, and a small copy of the picture so it does not have to be fetched again, stripped of any hidden metadata, with no link to any member. Per-source detail is deleted after 90 days; a picture nobody has asked for in 180 days is deleted with its record. On your phone the picture is cached like any other image and is never written into your contacts or your account. Anyone can ask never to be looked up at kuberdon.eu/livnly/avatar/opt-out: confirm by email, and that address is suppressed permanently and everything held for it is deleted.

7. Who Else Touches Your Data

We do not sell your personal information. This is the whole list of companies involved:

  • Supabase: the database, the private file bucket, and sign-in.
  • DigitalOcean: hosting for our websites (kuberdon.eu, and the pages your shared plan links open) and our API.
  • OpenAI: reading a sentence you typed or a screenshot you shared, exactly as described in section 4.
  • PostHog (EU): product analytics. Which screens get opened and which steps get finished, never your event titles.
  • Sentry: crash and error reports, so a bug on your device becomes something we can fix.
  • Resend: our email, meaning sign-in and identity verification codes, and replies to your application.
  • Twilio: the phone number you choose to verify, to deliver and check its verification code.
  • Apple: Sign in with Apple, and Apple Maps when you search for a place to put on an event: the words you type in that search go to Apple, along with roughly where you are if you have allowed location so the results near you come first, the same way they do in the Calendar app, and nothing else does. When membership billing opens, the payment itself is collected by the payment provider of the platform you subscribe on, the way the Terms describe. We never see or store your card details.
  • Gravatar, Libravatar and Google: a hash of a person's email, or a company domain, when the app or our dashboard looks up a public avatar or logo, as section 6 describes. Never the address.
  • People you invite: the plan you chose to send them, and nothing else.

8. What We Never Do

  • We never sell your data, and we never hand it to advertisers or data brokers.
  • We run no ads, and we never read your calendar to target anything at you.
  • We never show anyone the shape of your week: not another member, not a company, not us in our own marketing.
  • Livnly is paid for by the people who use it, never by advertisers, so you are the customer. There is no second business model hiding behind the first.

9. Data Retention

What we store lives as long as your account does, and you can delete your account from inside the app, which deletes it. Your calendar is not ours to delete: it stays on your device, untouched, whether the app is there or not. A plan you shared by link is the one thing on a clock of its own: it and the invited person's name are deleted 30 days after the event, whether or not you turn the link off and whether or not you keep your account. Application answers are kept until you ask us to remove them or you become a member. Abuse-prevention records expire on their own within a day.

10. Your Rights

Under GDPR you have the right to access, correct, export or delete your personal data, and to object to how we handle it. Email [email protected] and a person answers. You also have the right to complain to the Belgian Data Protection Authority.

This applies whether or not you use Livnly. If someone sent you a plan link, we hold your name and your answer because they invited you, and you can have both removed by writing to the same address. You do not need an account to ask, and you will not be asked to make one.

11. Security

Everything travels over encrypted connections. Each member's rows are isolated at the database level, so one account cannot read another's even through a bug in our code. Sign-in is a one-time code or Sign in with Apple; we store no passwords.

12. Changes To This Policy

If a data flow changes, this page changes with it, in the same release. We will update the "Last updated" date above, and tell members directly when the change is material.

13. Contact Us

Questions about any of this, including the parts you think we got wrong:

JB CAPITAL BV, trading as Kuberdon
Email: [email protected]
Belgium