Privacy policy
Last updated: 24 September 2026
Caterpillar Calendar reads the email you already get and pulls out the dates and the things your family has to do. To do that, you give us access to one or more mailboxes (up to three). This page explains, in plain English, exactly what that means.
Caterpillar Calendar is operated by 314 Apps. Questions: support@314-apps.com
The short version
- We read new email that arrives in the mailboxes you connect. We don't go back through your history unless you ask us to, one sender at a time.
- To find the dates, the text of a message that looks like it might carry one is sent to one of our two AI providers, Anthropic or OpenAI, and read by a model from that provider. When someone new starts emailing you, their address, name and recent subject lines go the same way, so the model can judge whether they're worth watching. None of it is used to train anyone's models.
- We keep the events and to-dos we found, who sent them, and a short model-written summary of why we thought they were there. We don't keep message bodies or attachments.
- We do keep one subject line per sender — the most recent one — so the question "keep watching this sender?" is answerable. That is a real piece of your email, and we'd rather say so than let you find out later.
- Some of what we keep is about other people: your children, the coach who emailed, other families named in a message. There's a whole section on that below.
- No ads. No cross-app tracking. Nothing sold or shared with data brokers, and nothing used to follow you across other apps or websites.
- You can delete everything from inside the app, at any time, behind two confirmations.
What we collect
Your account
You sign in with Apple, or with an email and password. Apple gives us an anonymous identifier for you and — if you let it — your name. If Apple also passes along an email address, it is usually Apple's private relay address rather than your real one. If you use email and password, we store the email and a one-way hash of the password; we never store the password itself. We also store your device's time zone, so that "Tuesday at 4" means the same thing to us as it does to you.
Your mailbox
When you connect an inbox, you authorize us — through our mailbox provider, Nylas — to read messages in that mailbox. For each new message we look at who sent it, when it arrived, and its subject. When that much suggests the message might carry a date, we read its contents too, in order to find calendar events and to-dos.
To be precise about "each new message": we read mail from every sender you haven't blocked, including senders you've never heard of and senders we haven't asked you about yet. Asking "keep watching this sender?" is about whether we keep going, not about whether we started. Blocking is the one state where we never open the message — we still see who it was from, when it arrived, and its subject line, but the body is never fetched and nothing is extracted.
Your calendar
Events go to the Google calendar that comes with the inbox you connected. We create and manage one calendar for the events we add, and we only write to that one. If you connected an Apple (iCloud) calendar while that option was offered, we keep writing to it until you switch back.
Your devices
If you turn on notifications, we store the push token Apple gives us for your device, so we can send you the app's own alerts. An alert names at most one item ("Picture day form") and one sender label ("Coach Dana") — never the message it came from.
How the app is running
We keep operational records tied to your account: when we last checked your mail, whether the connection is healthy, how many messages we processed, and what we decided about each one.
Product analytics
The app includes PostHog, a product-analytics tool. It records which screens you open, which actions you take (approving a card, blocking a sender, changing a setting), app launches, and crashes — tied to your account. That event stream is built to carry no message content at all: it counts and names actions, never titles, senders or addresses. We use it to see where the app confuses people and where it breaks. We do not sell it, and PostHog may not use it for their own purposes.
We do not record your screen. Until 24 September 2026 the app also made visual recordings of sessions through PostHog, and because this app shows you what it found in your mail, those recordings could show event and to-do titles, sender names and addresses, subject lines and summaries. We have switched session recording off. Recordings made before then are deleted by PostHog no more than 90 days after they were made; if you want any of yours deleted sooner, email support@314-apps.com and we will do it.
This website
This site counts visits, using the same tool. It is set up far more narrowly than the app is, and on purpose: it sets no cookies and stores nothing in your browser, it records no session replay, it captures no clicks, scrolls or form entries — only that a page was opened, which page, and which link brought you here, so that we can tell whether an advert we paid for actually sent anyone. It honours Do Not Track. There is no account to tie any of it to, because you do not have one until you are in the app.
What we keep, and what we don't
This is the part most people want in writing, so here it is precisely.
We keep
- The events we extracted: title, date and time, place, any notes, a short model-written summary of why we thought it was an event, and which message it came from.
- The to-dos we extracted: title, due date, and which message it came from.
- A list of senders: each sender's email address and display name, when we first and last saw them, and whether you told us to watch or block them. We keep each sender's most recent subject line — for every sender, not only the ones we ask you about — so the Review question has enough context to be answerable.
- A record of each message we processed: an internal identifier, when it arrived, which sender it came from, and what we decided about it. No content. These records age out after 90 days.
- Your account details and calendar connection as described above.
We don't keep
- Message bodies. They exist only in memory, for as long as it takes to read the dates out of them, and are then discarded.
- Attachments. Two kinds are downloaded and read. A calendar invitation (
.ics), because it is the most accurate description of an event there is. And a PDF — a newsletter, a season schedule, a permission slip — whose text we read to find the dates in it. Nothing else is downloaded, and neither file is kept. - Full email headers.
- Your payment details. The subscription is billed by Apple through the App Store. Your card never touches us — and neither does your subscription status. The app asks Apple on your own device whether this Apple Account is subscribed; our servers are never told the answer, so we do not hold a record of whether you pay, who paid, or with what.
- Your Google password or your Apple ID password. Those are typed into Google's or Nylas's own pages, in your own browser. They never reach us. If you connect an Apple calendar, the app-specific password that connection uses is also typed on Nylas's page, never ours. The Caterpillar Calendar password, if you set one, is stored only as a one-way hash — we never keep the password itself.
Inside our code, message content is wrapped in types that cannot be printed or logged, and automated tests fail the build if anyone tries. That is a guardrail, not a promise about the two things above it: the summary is prose a model wrote about your message, and the sender subject line is a line your correspondent wrote. Both are kept, on purpose, and both are described here.
Children, and other people who never signed up
Caterpillar Calendar is used by an adult, on an adult's mailbox. But the mail is about other people, and some of what we keep is therefore about them too. We'd rather set that out than bury it.
- Your children. School and team email names them. So the events and to-dos we extract routinely carry a child's first name, their team, their classroom, their teacher, and where they'll be at 4pm on Thursday — in the title, in the notes, and in the model-written summary. That information lives in your account, is shown to you, and is written onto the calendar you chose.
- The people who emailed you. We keep each sender's email address and display name, and each sender's most recent subject line — for every sender, not only the ones we ask you about. Those senders — teachers, coaches, club administrators, other parents — did not sign up for anything. They emailed you, and we are the tool you use to read your mail.
- People mentioned inside a message. If a coach's email names another family, that name can end up in an event title, a note, or a summary we keep. We don't seek it out and we don't build profiles of anyone, but we won't pretend our extraction is surgical enough to exclude it.
What we do with all of it is the same thing we do with everything else here: use it to show you your own family's schedule, and nothing else. We don't sell it, we don't share it with advertisers, we don't use it to build a profile of any child or any sender, and we don't use it to train AI models.
Children are not our users. Caterpillar Calendar is not directed to children, is not offered in Apple's Kids Category, and holds no account for anyone under 13. We don't knowingly let a child create an account or connect a mailbox. If you believe a child has signed up, email support@314-apps.com and we will delete the account.
If you're a teacher, coach or club administrator whose address appears in someone's sender list and you want to know what we hold about you, write to support@314-apps.com. We'll answer, though bear in mind that what we hold sits inside a parent's private account, which limits what we can change on your behalf.
Who else touches your data
We use a small number of service providers. Each is bound by its agreement with us, and none of them may use your data for their own purposes.
| Provider | What they do | What they see |
|---|---|---|
| Nylas | Connects to your mailbox and your calendar on our behalf. The Google sign-in screen you see when you connect is Google's own, presented through Nylas. | Your messages and your calendar, as our processor. The Gmail permission we ask for is read-only (gmail.readonly). If you pick a Google calendar as the destination, the calendar permission granted at the same time covers your calendars generally. |
| Anthropic | Runs a model (Claude) that does two jobs. It reads a message and returns the dates and to-dos in it: when a message looks like it might carry a date, its text is sent to be read. Messages that clearly don't are never sent — and neither is a message whose attached calendar invitation we could read ourselves. Text we pull out of an attached PDF goes with the message when it is sent. It also helps decide whether a new sender is worth watching: for that we send the sender's email address and display name, how many messages they sent and on how many different days, and up to 20 of their recent subject lines — no message bodies. | The text of a message, at the moment it is processed; and, for a new sender, their address, name, message counts and recent subject lines. None of it is used to train models. |
| OpenAI | Runs a model (GPT) that does the same two jobs as Anthropic's, on the same inputs. Which of the two providers reads a given message, or judges a given sender, is our choice, not yours, and we can move work from one to the other. | The same as Anthropic: the text of a message, at the moment it is processed; and, for a new sender, their address, name, message counts and recent subject lines. None of it is used to train models. |
| Amazon Web Services | Hosts the service and stores our database. | Everything we keep, encrypted at rest. |
| Apple (APNs) | Delivers push notifications. | The alert text we send, which names at most one item title and one sender label. |
| PostHog | Product analytics and crash reporting in the app, as described above, plus page counts on this website. Hosted in the United States. | In the app: which screens you open and what you do in them, and crashes. Until 24 September 2026 it also held visual recordings of sessions, as described above; those are deleted within 90 days of being made. On this website: that a page was opened, which page, and the referring link — no cookies, no recording, no clicks. |
That is the complete list. We don't use advertising networks, attribution SDKs, or data brokers. We don't sell your personal information, we don't share it for cross-context behavioural advertising, and we don't track you across other companies' apps or websites — there is no advertising identifier in this app, and nothing here is linked to anyone else's data about you.
Google user data — Limited Use
Because your Gmail is reached through Google's APIs, this section is required, and we mean every word of it.
Caterpillar Calendar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely:
- We use Gmail data only to provide and improve the features you can see in this app — finding events and to-dos, and showing you where they came from.
- We do not transfer Gmail data to anyone except the service providers named above, as necessary to run the app, to comply with applicable law, or as part of a merger or acquisition with your prior notice.
- We do not use Gmail data for advertising of any kind.
- We do not allow humans to read your Gmail data, and we do not use it to develop, improve or train generalized artificial-intelligence or machine-learning models. The only exceptions are the narrow ones Google permits: your own explicit consent, what is necessary for security purposes, to comply with applicable law, or where the data has been aggregated and anonymized. The AI provider that reads your mail for us, Anthropic or OpenAI, does not train its models on it either. It does keep what we sent it, and what it sent back, for up to 30 days and then deletes it, and it keeps it longer only if it is looking into misuse of its service or the law requires it to.
We request the narrowest Gmail permission that works: read-only. We can never send, delete or modify mail, because we did not ask for the ability to.
For calendars we hold a broader Google permission than we would like. Google's narrow, app-created-calendar-only permission is not available to us through our provider, so the permission you grant covers your calendars generally. Our code writes only to the calendar you selected, and nowhere else. We would rather tell you this than let you discover it on the consent screen.
How long we keep it
- Events, to-dos and senders: as long as your account exists.
- Processing records: 90 days from the last time we touched the message.
- Push tokens: until you turn notifications off, or the device stops being registered.
- Session recordings: none are made any more. Those made before 24 September 2026 are deleted by PostHog 90 days after they were made.
- Analytics events (which screen, which action, crashes — no message content): up to 84 months.
- Message bodies and attachments: not kept at all — discarded within the same operation that reads them.
When you delete your account
Settings → Delete account, two confirmations, and we erase your account, your inbox connection, your sender list, your to-dos and the events we created. That happens immediately, in our live systems.
One honest caveat. Our database is backed up continuously and encrypted, so that a bad day for us is not a bad day for your family's schedule. Deleted data remains inside those encrypted backups, unreachable by the app, for up to 35 days after deletion, and then it is gone from there too. We can't shorten that window without giving up the protection it exists for.
Calendar events we already added to your calendar are yours — they stay where they are, and we simply stop managing them. If you want them gone, delete them in your calendar app.
Your choices
- Delete everything. Settings → Delete account. Two confirmations, and it's done.
- Stop us reading a sender. Settings → Senders → block. We never open a blocked sender's messages: we still see who it was from, when it arrived, and the subject line, but the body is never fetched and nothing is extracted.
- Disconnect. Revoke our access at any time from your Google account's security settings, or — for an Apple calendar — by revoking the app-specific password at appleid.apple.com. Either kills our access immediately, without needing us.
- Turn off notifications. In the app, or in iOS Settings.
- Ask us anything. Email support@314-apps.com to request a copy of what we hold, to correct it, or to have it deleted. We answer within 30 days.
Security
Everything we store is encrypted at rest and in transit. Access to production systems is limited to the people who operate the service. Our internal logging is built so that message content cannot enter a log line even by accident: log fields whose names could carry content are rejected outright, and any over-long log line is discarded before it is written.
Changes to this policy
If we change how we handle your data, we'll update this page and change the date at the top. If the change is material, we'll tell you in the app before it takes effect.
Contact
support@314-apps.com
314 Apps