Privacy Policy
1. Who We Are
Maxie ("we", "us", "our") is a privacy-first family calendar app designed for parents and carers. We're based in the United Kingdom and operate globally.
2. Who Can Use Maxie
Maxie is designed for parents — it's adult use only. You must be 18 years or older to create an account. We do not knowingly collect personal information from children under 18. If you believe we have collected information from someone under 18, please contact us so we can delete it.
3. What Data We Collect
We only collect what's needed to make Maxie work for you:
| Data Category |
Examples |
Purpose |
| Account Info |
Name, email address |
Create and manage your account |
| Family Info (optional) |
Names, birthdays of family members |
Calendar events & reminders |
| Event Details |
Event title, date, time, location, prep tasks, uploaded files |
Populate your calendar |
| Device Info |
Browser type, IP address |
Security & troubleshooting |
| Third-Party Integration Data |
Google Calendar events, account identifiers (if linked) |
Sync and manage external calendars |
| Support Communications |
Emails, chat transcripts |
Resolve support queries |
We discourage uploading sensitive data (e.g., health details). If you do, we will treat it with appropriate safeguards and, where required, obtain explicit consent.
4. How We Use Your Data (Purposes & Legal Bases – UK/EU)
| Purpose |
Legal Basis |
| Provide Maxie services (calendar, reminders, file storage, sync) |
Contract |
| Secure your account and prevent fraud |
Legitimate interests |
| AI event creation ("Tell Maxie AI") |
Contract; Explicit consent if special-category data is included |
| AI image parsing ("Upload a file") |
Contract; Explicit consent if special-category data is included |
| Improve and troubleshoot the service |
Legitimate interests |
| Send service messages (reminders, updates) |
Contract |
| Send marketing emails (if opted-in) |
Consent or soft opt-in |
5. Who We Share Data With
We only share your data with trusted providers acting on our instructions:
- Supabase – hosting, database, authentication, file storage
- OpenAI – AI text and image event processing (see Section 9)
- Google APIs – calendar sync when connected (see Section 8)
- Resend – email delivery for invites, reminders, notifications
We do not sell or share your data for advertising purposes.
6. International Transfers
We store data in the UK/EU where possible. Where data is transferred internationally:
- US providers certified under the EU-US Data Privacy Framework / UK-US Data Bridge are covered by that adequacy decision.
- For others, we use Standard Contractual Clauses + UK Addendum/IDTA and conduct transfer risk assessments.
- For NZ residents, we ensure comparable safeguards under IPP 12.
7. Your Rights
UK/EU: Access, rectify, erase, restrict, port data, object to processing, withdraw consent, complain to the ICO/EU authority.
USA (CA + others): Know/access, delete, correct, data portability, appeal decisions. We do not sell/share personal data or use sensitive personal information for additional purposes.
Australia: Access/correction, complaint to OAIC, details on cross-border disclosure.
New Zealand: Access/correction, complaint to the Privacy Commissioner.
Canada (PIPEDA & Québec Law 25): Access/correction, complain to the OPC or Québec CAI, transparency on automated decision-making (we do not use solely automated decisions with legal/significant effects).
8. Google API Disclosure
Maxie's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Scope: read/write Google Calendar events for sync.
- No secondary use, no unauthorised transfers, minimal retention.
9. OpenAI Disclosure
When you use "Tell Maxie AI" or AI image upload:
- Only the text/images you submit are sent to OpenAI for processing.
- OpenAI does not use API data to train models by default.
- Data may be retained briefly for abuse monitoring before deletion.
10. Marketing vs Service Emails
- Service emails (e.g., reminders, invites) are essential to providing Maxie.
- Marketing emails are only sent with your consent or under a "soft opt-in" and can be unsubscribed from at any time.
11. Cookies & Analytics
If we use non-essential cookies/SDKs, we will request your consent (UK/EU). Essential cookies are used for security and login.
12. Retention Schedule
| Data Type |
Retention |
| Account info |
Life of account + 24 months |
| Calendar content |
Until deleted or account closure |
| Audit logs |
90 days |
| Backups |
35 days |
| Support tickets |
24 months |
| Marketing consent records |
6 years |
13. Security
We use encryption in transit and at rest, Row-Level Security, signed URL access for files, and strict access controls.
14. Changes to This Notice
We may update this notice and will notify you by email or in-app for significant changes.
15. How to Contact Us
Email: privacy@maxie.family
Postal: 27 Robarts Crescent, Haddington, UK, EH41 3FA
Complaints:
- UK – ico.org.uk
- EU – Your national data protection authority
- Australia – oaic.gov.au
- NZ – privacy.org.nz
- Canada – priv.gc.ca / quebec.ca/en/government/departments-and-agencies/cai
Date of last update: 26th March 2026