Privacy Policy

Version 1.1 · Effective 2026-09-25

MaybeSitter is a planner and reminders app. It keeps the commitments you confirm and reminds you before they are due, when notifications are enabled. This policy explains, service by service, what we collect, why, where it is stored and how to get rid of it.

A captured commitment becomes a commitment in your account only after confirmation. Temporary capture proposals are stored while you review them and have an expiry; this is separate from confirming a commitment.

Who we are

The controller of your personal data is anas akkari, an individual developer operating the MaybeSitter app and the website at maybesitter.com.

For any privacy question, request or complaint, write to privacy@maybesitter.com. For anything else, write to support@maybesitter.com.

Firebase Authentication

We use Firebase Authentication to sign you in. Depending on the method you choose, we receive and store your email address, your display name, the provider user ID from Apple or Google, and the Firebase UID that identifies your account inside MaybeSitter.

Sign-in with Apple, sign-in with Google and email/password sign-in are all supported. If you use Apple's "Hide My Email", we receive the relay address instead of your real one, and that works perfectly well — we never need your real address.

This data is kept while your account exists and is deleted when you delete your account.

Firestore

Your content lives in Cloud Firestore: your commitments, your captures, your plans, the memory facts MaybeSitter has learned about you, your consents and your settings.

Every memory fact is visible to you in the app and can be deleted by you. Firestore data is stored in the European Union, in the europe-west1 region, and is kept until you delete it or delete your account.

Cloud Run

The MaybeSitter API runs on Google Cloud Run in the European Union (europe-west1). Requests from the app are processed there.

Request logs are kept for 30 days for reliability and abuse prevention. Those logs record that a request happened — not what was in it. We do not log request or response bodies.

Vertex AI Gemini

Cloud AI processing depends on the build and server configuration and your AI consent. The production deployment configuration currently disables the Gemini provider. Where enabled, capture text (including text transcribed from speech or shared for capture) and optional self-description text used by those AI features are sent through Google Cloud Vertex AI after consent. Withdrawing consent prevents subsequent model requests. Capture can use a deterministic server-side fallback; this does not mean all processing happens on your device.

Speech

When you dictate instead of typing, speech recognition runs on your device through the operating system's own recognizer — Apple's on iOS, Google's on Android.

Where the operating system cannot do it on-device, the OS vendor processes the audio under its own terms, not ours. In every case, MaybeSitter never receives your audio. We receive only the resulting text.

Calendars

MaybeSitter can look at your calendar so it does not remind you in the middle of something.

Device calendars

With your permission, the device calendar API returns event data locally. The app filters out titles, notes, locations and attendees before uploading busy intervals. It can also write and update commitments you choose to sync to a selected device calendar.

Google Calendar

If you connect Google Calendar, MaybeSitter requests exactly two scopes:

MaybeSitter's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

ICS feeds

If you subscribe to an ICS calendar feed, the feed URL is stored encrypted, because such a URL is itself a secret that grants access to the calendar.

Disconnecting

You can disconnect any calendar at any time, and delete the data imported from it, without deleting your MaybeSitter account.

Share to MaybeSitter

Shared content is treated as untrusted input. Reviewing a share can create a temporary stored proposal; a commitment is created only after you confirm it.

FCM

Reminders use Firebase Cloud Messaging. Device registration stores a push token, an installation ID and notification permission state under your account. Sign-out attempts to deregister the device and delete its push token; this can fail and is not a guarantee of immediate provider-side invalidation. Uninstalling the app does not guarantee immediate removal of its server registration.

Crashlytics

The app does not explicitly attach an account ID to Crashlytics reports, but SDK installation identifiers and device metadata exist. Firebase states that crash data and associated identifiers are retained for 90 days before removal from live and backup systems begins. This is not a guarantee that removal is complete on day 90. Deleting your MaybeSitter account does not itself delete these reports.

Optional Microsoft Clarity replay

Production recording is currently disabled. In enabled builds, recording requires a separate opt-in for the current signed-in session; analytics consent does not enable it. Clarity receives masked screen layout, taps, navigation and SDK device/session metadata. Text and images are masked, and WebView recording is disabled. Revoking consent stops future capture. Deleting your MaybeSitter account does not delete recordings already uploaded to Clarity.

Production replay must remain disabled until the owner approves and publishes its retention period and deletion-request process. These decisions are still pending; this policy does not promise a retention period.

Analytics

Product analytics are collected only if you turn on the analytics consent in the Trust Center. The default is off. If you leave it off, no analytics events are sent. You can turn it off again at any time.

Analytics events are linked to your account, so they are pseudonymous, not anonymous. They never contain the text you type, the titles of your commitments or anything you told MaybeSitter about yourself.

If analytics is off, we do not turn the records the app needs in order to work — your account, your commitments, your activity history — into analytics about you.

This website itself has no analytics, no cookies and no third-party scripts of any kind.

Early-access sign-up

If you join the test on this website, we collect your email address, your phone type (iPhone or Android), the language you would use, whether you know the founder personally, the campaign code and message version in the link you followed, and the time you signed up. We collect a WhatsApp number only if you tick the box asking us to message you there.

We use these details only to contact you about early access and the test, and to count, in total and never per person, which invitation messages bring people who join. A WhatsApp number is used only to message you about the test, never for marketing. We do not ask for your name, and nothing about your commitments is collected through this form.

Sign-ups are stored in Google Cloud Firestore in the European Union (europe-west1) for as long as we run early access, unless you ask us to remove yours sooner. To see, correct or delete your sign-up, write to privacy@maybesitter.com from the address you signed up with.

Account deletion

You can delete your account in two ways:

Account deletion removes the live account and its content, subject to completion of the deletion steps. Retained proof records, recovery data and external-provider handling are explained on the deletion page. A completed deletion cannot be undone.

After account deletion, a pseudonymous deletion receipt is marked for expiry after 400 days and a deletion-job record after 30 days. These configured expiry periods are not a guarantee of the exact purge time. They retain a keyed hash rather than your raw account ID; the completed job no longer contains your UID. These records support proof of deletion and safe repeat requests.

An incomplete or stuck deletion job can still contain the account UID so the deletion can be resumed. Completed jobs receive a 30-day expiry timestamp. Firestore TTL for that field was verified active in production on 25 September 2026; deletion after expiry is asynchronous, not a guarantee of removal exactly on day 30.

Early-access website registrations are separate from an app account and are not automatically removed by account deletion. To request removal, use the contact route in the privacy policy.

Your rights

You have the right to:

Most of this is available directly in the app. For anything else, write to privacy@maybesitter.com and we will respond and follow up on your request within 30 days of receiving it. This is a human operational commitment to respond and follow up, not a guarantee that every deletion or technical action will be completed within that period.

Legal basis

MaybeSitter is operated from Israel and processes personal data under the Israeli Privacy Protection Law, 5741-1981, and its regulations, including the Privacy Protection (Data Security) Regulations, 5777-2017.

We process your data to provide the service you asked for. Optional processing — AI features and analytics — happens only on the basis of the consent you give in the app, and you can withdraw that consent at any time.

Age

MaybeSitter is not directed at people under 18, and we do not knowingly collect data from them. If you believe someone under 18 has created an account, write to privacy@maybesitter.com and we will delete it.

No sale of data, no advertising

We do not sell your personal data. We do not share it with data brokers. There is no advertising in MaybeSitter, and we do not build advertising profiles or track you across other apps and websites.

The only third parties that process your data are the infrastructure providers named in this policy, acting as our processors under contract.

Changes to this policy

For any future material change, we will update the document version and effective date on this website. Before the change takes effect, we will email affected users at the address linked to their account when we have a valid address for contacting them. We do not currently promise an in-app notice.

Version 1.1 · Effective 2026-09-25