Privacy Policy
This policy covers App4Dad (app4dad.com) and App4Mom (app4mom.com), together “App4”, “we”, or “us” — a private, AI-powered assistant for family caregivers.
Overview
App4 helps caregivers keep track of a family’s logistics. We are built privacy-first: the information you put into App4 is encrypted so that only you can read it. We do not sell your data, we do not use it for advertising, and we do not share it except as described here.
Zero-knowledge, on-device by design
App4 uses envelope encryption with a key only you hold. Sensitive data is encrypted on your device before it is stored, and our servers hold only ciphertext they cannot decrypt. When you connect an outside service (like Google), the connection is used on your device; plaintext email and calendar content is not stored on our servers in readable form.
Google data we access
When you choose to connect Google, App4 requests only the scopes below. You are shown these on Google’s consent screen and can disconnect at any time. Each is listed with exactly what it accesses, how it is used, whether it is shared, and how long it is kept.
gmail.readonly
Restricted
- Why
- Surface time-sensitive logistics from your inbox — appointments, school notices, bills — so The Liaison can help you keep track of your family’s week.
- Data accessed
- Message metadata (sender, subject, date), snippets, and — only with your explicit, per-use consent — message bodies. Read-only: App4 never sends, deletes, or modifies your email.
- Sharing
- Never sold, and never shared for advertising. Processing happens on your device; if you consent to an AI summary, only the minimum necessary text is sent ephemerally to the model and is not retained.
- Retention
- Not stored on our servers in readable form. Facts The Liaison extracts live only in your zero-knowledge vault, which only you can decrypt. Disconnecting Gmail or deleting your account removes the connection and the derived data.
calendar.readonly
Sensitive
- Why
- Show your upcoming events alongside your family logistics and let The Liaison reason about your schedule.
- Data accessed
- Event titles, times, locations, and attendees on the calendars you connect. Read-only.
- Sharing
- Never sold or shared for advertising. Same on-device, zero-knowledge handling as above.
- Retention
- Not stored on our servers in readable form; derived facts live only in your zero-knowledge vault. Disconnecting or deleting your account removes the connection and derived data.
calendar.events
Sensitive · write
- Why
- Add events you explicitly confirm back to your Google Calendar — for example, an appointment The Liaison surfaced and you approved.
- Data accessed
- Creates and updates calendar events you confirm. App4 does not delete your existing events, and writes nothing without your explicit confirmation.
- Sharing
- Never sold or shared for advertising. The event you approve is written directly from your device to Google.
- Retention
- App4 stores no copy of your calendar in readable form; confirmed events live in your Google Calendar and, as derived facts, in your zero-knowledge vault. Disconnecting or deleting your account removes the connection and derived data.
Why we request a restricted Gmail scope
Gmail read access is a Google Restricted scope. We request it so The Liaison can surface time-sensitive logistics buried in your inbox. Our use is minimized by design: your email is processed on your device as a user-agent acting on your behalf, and is never stored on or transmitted through our servers in readable form. This on-device, zero-knowledge posture is the core of how we honor Google’s Limited Use requirements.
Google API Services User Data Policy — Limited Use
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Read the full Google API Services User Data Policy.
Specifically: we do not use Google user data for advertising; we do not allow humans to read it except with your consent, for security, or as required by law; and we do not transfer it to others except to provide or improve features you asked for, for security, to comply with law, or as part of a merger where this policy continues to apply.
Data retention & deletion
Facts App4 derives from your connected services live only in your zero-knowledge vault, which only you can decrypt. To remove your data:
- Disconnect a service (Settings → Connections) — removes the connection and the facts derived from it.
- Delete your account (Settings → Account → Delete account) — permanently removes your vault and associated records. Because your data is encrypted with a key only you hold, deleting the key renders any remaining ciphertext unreadable.
Operational logs are scrubbed of personal identifiers and are not a readable record of your content. To request help with deletion, contact us at the address below.
Your rights & California residents
You can access, correct, export, or delete your data using the in-app controls above. Because App4 is zero-knowledge, we cannot read your content to fulfill a request on your behalf — the controls put that directly in your hands.
California residents have rights under the CCPA/CPRA, including to know, delete, and opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined. A fuller rights process is in progress.
Security
We use encryption in transit and at rest, least-privilege access controls, and a zero-knowledge architecture that keeps plaintext user content off our servers. No system is perfectly secure, but our design goal is that a breach of our infrastructure does not expose readable user data.
Contact
Questions about this policy or your data: privacy@app4dad.com.