Privacy Policy
Effective and last updated September 6, 2026
This is the Privacy Policy for the RecallHaven study and productivity application available at recallhaven.com.
This Privacy Policy describes how RecallHaven ("RecallHaven," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the RecallHaven website, study workspace, and connected services.
Information RecallHaven collects
- Account and authentication data: name, email address, password hash, Google account identifier if you use Google Sign-In, email-verification status, profile image URL, language, time zone, account role, settings, and subscription plan.
- Study and productivity content: courses, sections, notes, note blocks, uploaded images, quizzes, quiz answers and scores, spaced-repetition history, tasks, routines, day plans, focus sessions, and public-note sharing settings.
- AI requests: prompts, chat messages, selected notes or note images, requested actions, approval decisions, and context required to answer or perform the feature you requested.
- Google Calendar data: when you separately connect Calendar, event identifiers, titles or summaries, start and end dates or times, all-day dates, event status, availability or transparency, and Google Calendar event links.
- Usage and diagnostics: pages and features used, product interactions, errors and performance information, browser and device properties, IP address, and approximate location derived from IP. Optional analytics are subject to consent where required.
- Billing data: customer, subscription, product, transaction, and payment-status information returned by our payment provider. RecallHaven does not store complete payment-card numbers.
- Communications: verification emails, support requests, and information you include when contacting us.
How RecallHaven uses information
RecallHaven uses this information to:
- create and authenticate accounts, prevent abuse, and maintain account security;
- store and synchronize notes, learning material, tasks, plans, preferences, and progress;
- generate quizzes, explanations, feedback, schedules, and note edits when a user requests an AI feature;
- calculate spaced-repetition schedules, due work, progress, and study statistics;
- display Calendar commitments and prevent planner blocks from overlapping existing events;
- process subscriptions, enforce plan limits, and send operational messages;
- diagnose errors, monitor reliability, understand feature usage, and improve RecallHaven; and
- comply with applicable law and protect users, RecallHaven, and the public.
RecallHaven does not sell personal information and does not use personal information for targeted or interest-based advertising.
Google API data: access, use, storage, and sharing
This section specifically explains every Google integration currently offered by RecallHaven.
Google Sign-In
RecallHaven requests the openid, email, and profile permissions. We access your Google account identifier, name, email address, email-verification status, and profile image. We use this data only to authenticate you, create or link your RecallHaven account, display your profile, and protect the sign-in process.
The temporary Google access token used to retrieve this profile is not stored after sign-in. The linked Google account record and profile data are retained with your RecallHaven account until you delete the account.
Read-only Google Calendar
Calendar connection is optional and separate from Google Sign-In; you may connect a different Google account. RecallHaven requests only https://www.googleapis.com/auth/calendar.readonly. This permits viewing Calendar data but does not permit RecallHaven to create, edit, or delete Google Calendar events.
When you open Calendar or Day Plan, RecallHaven fetches events from your primary Google Calendar for the displayed time range. Event titles, times, status, availability, and links are used to show those events to you and detect scheduling conflicts. Event records are processed on demand and are not written to RecallHaven's application database or persistent browser query cache.
To keep the connection working, RecallHaven stores the Google OAuth refresh token and granted scope in its database. The refresh token is encrypted at rest and is used only to obtain a short-lived access token when RecallHaven needs to fetch your events.
If you explicitly ask the AI planner to propose or apply a schedule, busy start times and durations derived from Calendar events may be sent to RecallHaven's contracted AI-processing provider solely to avoid time conflicts and provide that user-requested feature. Event titles, descriptions, identifiers, and links are not included in that AI planner context.
Google data commitments
- We do not sell Google user data, use it for advertising, determine creditworthiness, or transfer it to data brokers or information resellers.
- We do not allow humans to read Google user data except with your affirmative permission for support, when necessary for security or abuse investigation, or when required by law.
- We do not use or transfer Google Workspace API data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
- We share Google data only with processors needed to provide the user-facing feature described here, under confidentiality and data-protection obligations, or when legally required.
RecallHaven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How information is shared
We disclose information only in the following circumstances:
- Infrastructure and storage: hosting, database, networking, content-delivery, and object-storage providers process account data and content so RecallHaven can operate.
- AI processing: the configured AI provider receives only prompts and context needed for an AI feature you invoke. Google Calendar data is limited as described above.
- Analytics: PostHog processes consented product-usage and diagnostic events to help us understand and improve the service.
- Email and billing: Resend processes transactional email, and Polar processes subscriptions and payments.
- At your direction: information is disclosed when you connect a service, create a revocable public note link, export content, or otherwise ask us to share it.
- Legal and safety: we may disclose information when reasonably necessary to comply with law, enforce our terms, investigate fraud or abuse, or protect rights and safety.
- Business transfer: information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to this Policy and appropriate safeguards.
Processors may handle information in countries other than yours and are permitted to use it only to provide their contracted service to RecallHaven.
Cookies, local storage, and analytics
RecallHaven uses browser storage for authentication, appearance and editor preferences, offline-capable workspace data, and selected application caches. We use essential storage to operate the service. PostHog analytics may use cookies or local storage for product analytics and diagnostics; where consent is required, this analytics collection is optional until you consent.
Retention and deletion
- Account information and user-created content are retained while your account is active or until you delete the relevant content.
- Google Sign-In profile and linking data are retained until the linked RecallHaven account is deleted.
- The encrypted Google Calendar refresh token is retained until you disconnect Calendar or delete your RecallHaven account.
- Google Calendar event records are fetched for the requested time range and processed in memory; RecallHaven does not durably store those event records in its application database.
- Security, transactional, and diagnostic records are retained only as long as reasonably needed for security, support, legal compliance, dispute resolution, and service operation.
- Residual copies may remain temporarily in encrypted backups until those backups rotate, unless longer retention is legally required.
Your controls and deletion instructions
You can disconnect Google Calendar inside RecallHaven by opening Calendar and selecting Disconnect Google. This deletes the stored Calendar credential and scope from RecallHaven. You can separately revoke RecallHaven from your Google Account connections.
You can delete your RecallHaven account from Settings. Account deletion removes the account, linked Google credentials, and associated application content from active systems, subject to temporary backup and legally required retention described above. You may also contact us to request access, correction, deletion, restriction, objection, or portability where applicable.
Security
RecallHaven uses HTTPS in transit, access controls, password hashing, encrypted Google Calendar refresh tokens, and other reasonable technical and organizational safeguards. Access to production data is limited to what is needed to operate and secure the service. No online service can guarantee absolute security.
Children
RecallHaven is not directed to children under 13 or under the minimum age required to consent to an online service in their country. If you believe a child supplied personal information without appropriate permission, contact us so we can investigate and delete it.
Policy changes and contact
We will keep this Policy current with RecallHaven's data practices. If our handling of Google user data or other personal information materially changes, we will update the effective date and provide additional notice when appropriate.
For privacy questions, requests, or complaints, contact the RecallHaven development team at support@recallhaven.com.