October 9, 2026practice

I can’t see your agenda. Here is exactly what I can see.

By Jensen Bernard

5 min read

A few people I know, people I’d asked to try Livnly, hesitated. They were worried that because I build the app, I could see their agenda: who they meet, where they go, what’s in the notes of that one appointment.

It’s a fair thing to wonder about someone you know. So here is the answer, written down where I can be held to it: I can’t see your agenda. And because a promise like that is only worth something if the rest is said too, here is everything I can see.

What I can’t see

Your calendar. Livnly reads the calendars that are already on your iPhone, through the permission you give it in iOS, and it never uploads them. There is no copy of your week on our servers, and the titles and notes of your events never reach me.

What you type to plan. “Dinner with Sam on Thursday at 8” is read on your iPhone, by a parser inside the app. Neither the sentence nor the events around it leave the phone.

Your address book. It is read on the phone and never uploaded as it is. If you verify your own number or email, Livnly can help mutual contacts find each other, using scrambled versions (hashes) of their numbers and emails, and you can turn that off in Settings. Livnly never messages your contacts, and never sells them to anyone.

Anything you didn’t choose to share. A plan leaves your phone only when you send it to someone, and then only that plan. The person you send it to sees that plan and nothing else of your week.

What I can see

If you sign in (you don’t have to), this is what sits with your account, and as the person running Livnly I can access it.

  • Your account: your name, your email address and your subscription.
  • How you use the app: which screens get opened and how often, linked to your email address. Never what is in your calendar. If something breaks for you, I can look at your activity to understand it.
  • Plans you shared: when you send a plan by link, that one event (its title, time and place, your name) and the name you have for the person you sent it to, so the page they open can show it.
  • Places you pick: when you pick a place for an event, its name and its spot on the map are saved to your account, so it follows you to your other devices.
  • Your settings and people: your calendars’ names (often an email address), so your colours follow you; the few choices you make about an event, like its category or a new time you moved it to, stored against a code for that event rather than its title; and the names of the people in your people list, including the ones Livnly suggests from your events’ guest lists.
  • Tasks you type in Livnly: their titles, notes and due dates, so they sync between your devices.

There is one place where AI comes in. If you share a screenshot into Livnly and say yes, that picture goes through our server to OpenAI to be read, with the names of your people so they are spelled right. We keep nothing of it.

What I changed today

Writing this list meant checking every line of it against what the app and our servers actually do. Not every line held, so before publishing this I fixed what didn’t.

  • Typed plans no longer go to any AI. Until today, if you had said yes to AI, a typed plan and that day’s event titles were sent to OpenAI to be read. Now the phone reads it on its own. A phone that hasn’t had the next update yet may still send it to our server, which throws it away unread and passes nothing on.
  • Shared plan links are really deleted. The policy said a plan link is deleted 30 days after the event. The clean-up that does it was never switched on, and a few links had outlived that. It ran today and now runs every night. A couple of other copies of a shared plan aren’t covered by it yet; those are next.
  • Crash reports lose your name and email. They now carry an account number instead, and the names, emails and places that could ride along are scrubbed out. That’s live on the server, and reaches the app with the next update.
  • Sign-in tokens are deleted after use. The short-lived codes that finish a sign-in used to be kept. They are now removed the moment they’re used.
  • The privacy policy says exactly what the app does. I rewrote it today, including the less flattering lines, like the fact that I can access what syncs to your account.

Why it works this way

Livnly is paid for by the people who use it. There are no ads, I don’t sell your data, and there is no second business model behind the first. You are the customer.

The privacy policy has every detail, every company involved and what each one gets. If something in it, or in here, doesn’t sit right with you, I want to hear it. You can reach me on the contact page, and I read every message myself.

Who made this
Written by
Jensen Bernard

Founder. Builds the apps, and the company around them.

EmailLinkedInGitHub