Privacy Policy
Last updated: October 9, 2026
Chimely needs to read your calendar to do its job, and that is a meaningful thing to hand over. This page says exactly what is collected, why each piece is necessary, where it lives, and how to get rid of it.
What Chimely collects
Your account
When you sign in, whether with Apple or with a code sent to your email, we store an account identifier and your email address. If you sign in with Apple using its private relay address, that relay address is all we ever see.
Your calendar
When you connect Google Calendar, Chimely requests read-only access. It stores the email address of the Google account you connected, so you can tell your connections apart, and the parts of your calendar it needs to decide when to set alarms:
- For each calendar: its name, description, color, time zone, and whether it is your primary calendar.
- For each upcoming event: its title, start and end times, time zone, whether it is all-day, whether it is confirmed, tentative or cancelled, whether you accepted or declined, its location, its meeting link, and a link to open it in Google Calendar.
Location and the two links are stored so the app can show them and open them for you. Your acceptance status matters because a meeting you declined should not wake you up.
Your alarm settings
The alarm timings you choose for each calendar and meeting, the days and hours alarms are allowed to ring, your time zone, whether Chimely is paused, and whether you work remotely, in an office, or both.
Silent zones
If you set up a silent zone, a place where alarms vibrate instead of ringing, Chimely stores the name you give it, its center point and its radius, so it carries over to a new phone or a reinstall. Your phone uses location permission to notice when you enter or leave a zone, and decides that on the device. Your location itself is never sent to Chimely. Without a silent zone, Chimely does not use your location.
Your device
A push notification token, whether you granted notification permission, whether background refresh is enabled, and how far ahead your phone currently has alarms scheduled. The last of these is how the server knows whether your phone is up to date without sending your calendar back and forth. Chimely also records which alarms your phone has reported holding and which notifications were sent to it, which is how it notices an alarm that did not get set and tells you about it.
What Chimely does not do
- No advertising, and no advertising identifiers.
- Your data is never sold, rented, or shared for marketing.
- No analytics or tracking SDKs are embedded in the app. Chimely does not build a profile of you.
- No one reads your calendar. Event data is processed automatically. A person looks at it only if you ask for help and explicitly agree to it, or where it is necessary for security, such as investigating abuse, or to comply with the law.
- Chimely cannot create, edit, move, or delete calendar entries. The permission it holds is read-only, so this is enforced by Google rather than promised by us.
Google user data
Chimely requests the calendar.readonly scope, plusopenid and email to identify your account.
Chimely uses this access to read your calendars and upcoming events, decide when your alarms should ring, show your meetings in the app, and tell you when a change to a meeting affects one of your alarms. It never writes to your calendar.
Chimely's use and transfer to any other app of information received from Google APIs will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements.
In particular, Google user data is used only to provide and improve the alarm features you can see in the app. It is never used for advertising, never sold, and never transferred to others except as needed to provide those features, to comply with the law, or as part of a merger, acquisition or sale of assets. It is not used to develop, improve or train generalized artificial intelligence or machine learning models.
How your credentials are stored
The long-lived token that lets Chimely keep reading your calendar is never sent to your phone. It is encrypted and held in a dedicated secrets store, separate from the ordinary database tables, and only the server processes that refresh your calendar can decrypt it. A signed-in user querying their own account cannot retrieve it, because the database permissions do not expose those columns at all.
Disconnecting a calendar destroys the stored credentials immediately rather than leaving them dormant.
Who else is involved
- Google — the source of your calendar data, when you choose to connect it.
- Apple — handles Sign in with Apple, processes subscription payments, and delivers notifications. Notifications about your alarms include the meeting's title and start time, so that text passes through Apple's push notification service on its way to your phone. Chimely never sees your payment details.
- Supabase — provides the database and server infrastructure where the data described above is stored.
These are service providers, not partners we share data with for their own purposes.
How long data is kept
Calendar events are kept only for the near-term window Chimely plans alarms across, and older events are continuously discarded as they pass. Notices about alarm changes and missed alarms repeat a meeting's title and time, and are deleted 30 days after the meeting. Records of notifications sent to your phone, which do not contain meeting titles, are kept for 180 days. Account details and settings are kept while your account exists.
Deleting your data
You can disconnect a calendar at any time in the app, which removes that calendar's events and credentials.
You can delete your entire account from within the app. Doing so removes your profile, connected accounts, calendars, events, alarm rules, and registered devices. Chimely also stops watching your calendar for changes and, unless that Google account is connected to another Chimely account, revokes its access with Google. This is immediate and cannot be undone. If you would rather it be handled for you, emailprivacy@chimelyapp.com.
Revoking Chimely's access directly from yourGoogle account permissions page also works, and stops any further syncing at the source.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Emailprivacy@chimelyapp.com and we will action it.
Children
Chimely is not directed at children and we do not knowingly collect data from anyone under 13.
Changes
If this policy changes in a way that materially affects how your data is handled, the app will tell you rather than relying on you re-reading this page.
Contact
Questions about any of the above:privacy@chimelyapp.com.