Privacy Policy

Last updated: 27 April 2026

1. Information We Collect

We collect information you provide directly: your name, email address, and family data you enter (events, chores, meals, etc.). We also collect usage data such as login times and IP addresses for security purposes.

2. How We Use Your Information

We use your information to provide and improve the Service, authenticate your identity, send transactional emails (invites, password resets, verification), and maintain security through audit logging.

3. Google Calendar Integration

If you connect Google Calendar, we access your calendar data solely to sync events between Skylight and Google Calendar. We store OAuth tokens securely and you can disconnect at any time, which removes all stored Google data.

4. AI Features

Our AI-powered features (Magic Import, voice input, meal planning) send your content to Google Gemini for processing. We do not store AI-processed data beyond what you explicitly save to your account.

5. Data Storage & Security

Your data is stored in a PostgreSQL database hosted on Google Cloud. Passwords are hashed using bcrypt. Sessions are encrypted and have automatic expiry. We implement security best practices to protect your data.

6. Data Sharing

We do not sell, trade, or share your personal information with third parties, except as required by law or as necessary to provide the Service (e.g., email delivery via Resend).

7. Data Retention

We retain your data as long as your account is active. When you request account deletion, your data is permanently removed after a 7-day grace period. Audit logs are retained for 90 days for security purposes.

8. Your Rights

You have the right to access, correct, or delete your personal data. You can export your data or request account deletion through the app settings. For Australian residents, we comply with the Australian Privacy Principles (APPs).

9. Cookies

We use a single session cookie (skylight_session) for authentication. We do not use tracking cookies or third-party analytics cookies.

10. Contact

For privacy-related questions or requests, contact us at privacy@riffraaf.app.