Last updated
What Pealo does
Pealo connects to your Google Calendar or device calendars, detects new events, and schedules real system alarms on your iPhone using Apple’s AlarmKit — even when the app is closed, silenced, or locked.
Account and identity
When you first open Pealo, we generate a random user identifier (UUID) stored in your device’s Keychain. This identifier ties your data together on our server. We do not require a username or password.
When you connect a Google Calendar, we receive your Google account email address to display which account is connected. We store the OAuth refresh token encrypted at rest (AES-256-GCM) on our server. We never store your Google password.
Email addresses
We collect email addresses in two contexts:
Google account email — received via OAuth when you connect your calendar. Used solely to show which account is connected.
Contact email (optional) — if you choose to provide your email for our newsletter or when submitting feedback. Used for marketing communications and customer support. You can unsubscribe at any time.
Calendar data
Event details (titles, start and end times, response status) are fetched from your calendar provider when a webhook notifies us of a change. We use this data to schedule and update your alarms.
Most event content passes through our server and is not stored permanently. However, we do retain:
The title of your next upcoming alarm — stored temporarily on our server to render the countdown on your Lock Screen via Live Activity.
Event titles in pending rescue notifications — stored temporarily so we can send you a fallback notification if an alarm fails to schedule.
These titles are overwritten as new events arrive and are not used for any other purpose.
We also store connection metadata: which calendars are linked, their names, colors, sync status, and armed/disarmed state.
Push notifications and Live Activity
We collect your APNs push token and Live Activity token to deliver:
Silent push notifications — to trigger alarm sync when your calendar changes.
Live Activity updates — to show a countdown on your Lock Screen before an alarm.
Rescue notifications — to warn you if an alarm could not be scheduled.
These tokens are device-level identifiers stored on our server alongside your user ID.
Subscription and purchases
When you subscribe to Pealo, we verify your purchase using Apple’s StoreKit. We store your subscription product ID, expiry date, transaction environment, and a signed transaction (JWS) on our server to manage your entitlement. Payment is handled entirely by Apple — we never see your payment card or billing details.
Diagnostics
We collect diagnostic events to detect and fix alarm failures. These include: event name, timestamp, app state, screen lock state, result, alarm count, permission status, event ID, and alarm ID. This data is tied to your user ID and used solely to ensure your alarms work reliably. We do not use third-party analytics or crash reporting SDKs.
Feedback and customer support
When you submit feedback through the app, we collect the text you write along with contextual metadata: app version, iOS version, number of alarms, and days since installation. If you provide your email address, we store it to respond to your feedback. This data is tied to your user ID.
Timezone and language
We collect your device’s timezone setting (e.g., “Europe/Warsaw”) to calculate quiet hours, and your app language preference to render Live Activity content in the correct language. Both are stored on our server alongside your user ID.
Alarm sounds
Alarm tone selection is stored locally on your device. It is not sent to our server.
Data stored on our server — summary
Your user identifier, Google account email, encrypted OAuth tokens, webhook channel registrations, calendar metadata (names, colors, sync status), subscription status, the title of your next alarm, push tokens, timezone, language preference, diagnostic events, and feedback. That is all.
Analytics
In the app: we do not use third-party analytics SDKs. We do not serve advertisements. We do not collect the Apple advertising identifier (IDFA).
On this website: pealo.app runs Cloudflare Web Analytics, which counts page views without cookies, without a device fingerprint and without tracking you across other sites. It is separate from the app and collects nothing that identifies you.
Third-party services
Pealo uses the following third-party services, each governed by their own privacy policy:
Google Calendar API — to sync your calendar events.
Apple Push Notification service (APNs) — to trigger alarm sync, deliver rescue notifications, and update Live Activities. No calendar content is included in push payloads.
Apple StoreKit — to verify subscriptions.
Railway — server hosting. Our infrastructure processes event metadata in transit to schedule alarms.
Data security
OAuth tokens are encrypted at rest using AES-256-GCM. All communication between the app, our server, and third-party services uses HTTPS/TLS. Bearer tokens and your user ID are stored in the iOS Keychain on your device.
Data retention and deletion
When you disconnect a calendar, the associated tokens and metadata are permanently removed from our server. You can request full data deletion at any time by contacting us at the address below. Diagnostic events and feedback are retained until you request deletion.
Data sharing and disclosure
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
Google Calendar data received through the Google API is used solely for the purpose of providing Pealo’s alarm scheduling functionality. No Google user data is shared with, transferred to, or disclosed to any third party, except:
Apple Push Notification service (APNs) — receives a silent push to trigger alarm scheduling on your device. No calendar content is included in the push payload.
Railway (server hosting) — our server infrastructure processes event metadata in transit to schedule alarms.
Google API Limited Use Disclosure
Pealo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Google user data is used only to provide and improve the user-facing alarm scheduling features described in this policy.
Google user data is not used to train, improve, or build generalized or foundational artificial intelligence or machine learning models.
The use of raw or derived user data received from Google Workspace APIs adheres to the Limited Use restrictions.
Your rights (GDPR)
If you are in the European Economic Area, you have the right to access, rectify, or delete your personal data, and to restrict or object to its processing. To exercise these rights, delete your account in the app or contact us. Our legal basis for processing is legitimate interest (providing the service you requested) and, for the newsletter, your consent.
Children
Pealo is not directed at children under 13. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. We will notify you of material changes through the app or by updating the “Last updated” date above.
Contact
Privacy questions: privacy@pealo.app
Grzegorz Mróz Ventures, Krajewskiego 1/29, 01-520 Warszawa, Poland