Legal

Privacy Policy

Linkside Group Ltd  ·  Effective 17 June 2026

This Privacy Policy ("Policy") describes how Linkside Group Ltd ("we", "us", or "our") collects, uses, and protects your personal information when you use the Calendar Athlete mobile application and any related services, including this website (collectively, the "App"). Please read this Policy carefully. By downloading or using the App, you agree to the practices described here.

Our core commitment: Calendar Athlete is built on a privacy-first architecture. The vast majority of your data — including your calendar events, training history, and personalisation signals — is processed and stored exclusively on your device. Calendar Athlete cannot see it, and neither can anyone else. This is not a policy choice we can unilaterally reverse; it is how the product is engineered.

1. Scope

This Policy applies to all users of the Calendar Athlete iOS application as well as any web-based interfaces we provide, including this website. It does not apply to third-party services or platforms you choose to connect to Calendar Athlete; those services are governed by their own privacy policies.

Linkside Group Ltd acts as the data controller for the personal information processed under this Policy. Our registered address is in the United Kingdom.

2. How Calendar Athlete Handles Your Data — The On-Device Architecture

Privacy is structural at Calendar Athlete, not cosmetic. The app is designed so that your most sensitive data never needs to leave your device — and in most cases it is technically impossible for us to access it even if we wanted to.

What stays entirely on your device

The following data is stored exclusively in the app's local database on your iPhone, processed on-device, and never transmitted to Calendar Athlete's servers or any third party:

Why we can't see your calendar

Calendar Athlete reads your calendar using Apple's EventKit framework and Google Calendar's read-only OAuth API. This access happens on your device. Event titles and details are stored locally so they can be displayed as busy blocks in the app's calendar view — exactly as any consumer calendar app works. They are not transmitted to us, not stored in any backend database we operate, and are never written into the behavioural data store used for personalisation.

Private calendar events (marked private in your calendar provider) are shown only as "Private event" by default, without surfacing the real title even locally in the app. You can also toggle "Hide event names" in Settings to mask all event titles within the Calendar Athlete interface.

What we do receive

A small, defined set of information does reach our servers — specifically account credentials, subscription status, and the operational data necessary to run the service. This is described in full in Section 3 below.

In plain terms: we know you have a subscription. We do not know what is in your calendar, how you train, or what your schedule looks like. That information exists only on your device.

3. Information We Collect

Information You Provide

Information Collected Automatically

What We Deliberately Do Not Collect

The following data is explicitly out of scope for Calendar Athlete's data collection:

4. How We Use Your Information

To provide and operate the App

To analyse and improve the App

We do not use your calendar data, training history, or personalisation signals for any analytical purpose. Those remain on-device only.

To communicate with you

To comply with legal obligations

We process data where required by law, in response to legal process, or to protect the rights and safety of our users and the public.

5. Apple, the App Store, and Their Role in Your Privacy

Calendar Athlete is distributed exclusively through the Apple App Store. Apple has its own data practices that are separate from ours. This section explains where Apple's role begins and ours ends.

What Apple handles independently

What Calendar Athlete handles

Everything described in Sections 3 and 4 above — account management, subscription verification, and in-app scheduling — is our responsibility. Apple is not a data controller for your Calendar Athlete account data.

Google Calendar

If you connect Google Calendar, the OAuth flow is handled through Google Sign-In. We request only the calendar.readonly scope — the minimum permission necessary to read your events. We do not request write access, and we cannot modify or delete your Google Calendar events. The OAuth token is stored in your device's Keychain and not transmitted to our servers. You can revoke Google Calendar access at any time in your Google Account settings at myaccount.google.com/permissions.

6. Cookies and Tracking Technologies

The Calendar Athlete iOS app does not use cookies. The app does not embed advertising networks, cross-site trackers, or fingerprinting technologies.

The Calendar Athlete website (calendarathlete.co.uk) may use essential cookies to support website functionality and, with your consent, basic analytics to understand traffic patterns. You can manage cookie preferences via your browser settings.

We do not use advertising cookies or cross-site tracking on the website.

7. How We Share Your Information

We do not sell your personal data. We do not share your calendar data, training history, or personalisation signals with any third party.

We may share the limited account-level data described in Section 3 as follows:

8. Data Retention

On-device data

Data stored on your device — calendar events, training history, check-in responses, behavioural signals, and personalisation models — persists until you delete the app or use the in-app data controls described in Section 11. Calendar Athlete automatically prunes behavioural data older than 12 months as part of a daily maintenance routine.

Account data (server-side)

We retain your account data for as long as your account is active or as needed to provide the App. When you delete your account, we will delete or anonymise your account data within 30 days, unless we are required by law to retain certain records for longer (e.g. financial records for tax purposes, typically up to 7 years in the UK).

Aggregated or de-identified data derived from your information may be retained indefinitely as it can no longer be linked to you.

9. Data Security

We implement administrative, technical, and physical safeguards to protect your data:

Because the vast majority of your data never leaves your device, the attack surface is substantially smaller than for a server-side data model. No system is completely secure. If you suspect unauthorised access to your account, please contact us immediately at the address in Section 17.

10. International Data Transfers

Linkside Group Ltd is based in the United Kingdom. Some of our service providers (for account management and infrastructure) operate outside the UK or EEA. Whenever we transfer personal data internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs), or adequacy decisions by the relevant authority.

Your on-device data — calendar events, training history, personalisation signals — is never transferred internationally because it never leaves your device.

You can request copies of the applicable transfer mechanisms by contacting us.

11. Your Privacy Rights and Choices

Depending on where you live, you may have the following rights. To exercise any of them, contact us at the details in Section 17. We will respond within 30 days.

RightWhat it means
Access & PortabilityRequest a copy of the personal data we hold about you (account-level data), and receive it in a portable format.
RectificationAsk us to correct inaccurate or incomplete personal data.
ErasureRequest deletion of your personal data ("right to be forgotten"), subject to legal exceptions.
RestrictionAsk us to pause processing of your data in certain circumstances.
ObjectionObject to processing based on legitimate interests or for direct marketing.
Withdraw ConsentWhere processing relies on your consent, withdraw it at any time. Withdrawal does not affect prior processing.
Lodge a ComplaintYou may complain to your local data protection authority, e.g. the UK Information Commissioner's Office (ICO) at ico.org.uk.

Managing your data directly in the app

Many privacy controls are available directly within Calendar Athlete, without needing to contact us:

12. Automated Decision-Making and On-Device Personalisation

All personalisation in Calendar Athlete happens on your device using your data, for your benefit. No behavioural data is sent to us. The models train on-device and run on-device. We cannot see, access, or influence your personal model.

Calendar Athlete uses automated processing to generate training recommendations, scheduling suggestions, and daily briefings. Here is how each layer works:

Rule-based scheduling engine

The core scheduling engine places your workouts based on your stated preferences (preferred times, working days, goal type) and the busy/free map derived from your calendar. This is deterministic and does not require any historical data from you. It is always active.

On-device personalisation (statistical layer)

After you have completed enough sessions (a minimum threshold is required before personalisation activates), the app analyses patterns in your completed sessions — which time slots you tend to complete versus reschedule, how your calendar density on a given day correlates with your training outcomes. This analysis runs locally using Apple's NaturalLanguage framework and a small statistical engine built into the app.

This layer adjusts scheduling weights by up to ±20% to nudge sessions toward time slots that work better for you. It never overrides your preferences; it refines within them.

When the personalisation layer has influenced a scheduling decision, a subtle note appears in the session detail view: "Placed at 7am — your training history shows this slot works well."

On-device machine learning model

Once you have completed 30 or more sessions, the app trains a personal machine learning model on your device using Apple's Create ML framework. This model runs entirely on-device. It is stored in your app's local Application Support directory and is never transmitted to Calendar Athlete's servers or any third party.

You can delete the model and all associated behavioural data at any time using Reset Learning in Settings → Privacy.

Coach Briefing (on-device language model)

The Coach Briefing feature generates a short daily summary of your training context using Apple's on-device language model (Apple Intelligence, available on supported devices). The input to the model is a set of derived signals — session counts, calendar density, check-in state — not raw calendar event titles or personal identifiers. On devices that do not support Apple Intelligence, a deterministic rule-based fallback generates the briefing instead.

In both cases, the content is generated on-device and is never transmitted to us.

On-Device AI Models — Disclosure

Calendar Athlete's AI and machine learning features run entirely on your device. We do not use any third-party or cloud-hosted AI service, and no data obtained from Google APIs is ever transmitted to an external AI provider. The models used are:

All of these models are self-hosted and run in an offline, on-device capacity. Any data obtained from Google APIs (your Google Calendar events) is processed exclusively on your device and is never sent to, shared with, or used by any model provider — including for training or improving any generalised AI model.

These automated systems are designed to be helpful scheduling suggestions. They do not produce decisions that have legal or similarly significant effects on you. You remain in full control: you can reschedule, skip, or delete any suggested session at any time.

13. Children's Privacy

Calendar Athlete is not directed at children under the age of 13 (or 16 in some jurisdictions). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact us immediately and we will take prompt steps to delete that data.

14. Third-Party Links and Services

The App may offer integrations with third-party calendar providers (Apple Calendar, Google Calendar). This Policy does not govern those third parties. We encourage you to review their privacy policies before connecting them to Calendar Athlete:

15. Notice for EEA, UK, and Switzerland Residents

Data Controller

Linkside Group Ltd is the data controller for personal information collected through Calendar Athlete. We are registered in the United Kingdom.

Legal Bases for Processing

Supervisory Authority

If you are in the UK, our lead supervisory authority is the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EEA, you may also contact the supervisory authority in your country of residence.

Data Protection Officer

You may contact our Data Protection Officer at privacy@linksidegroup.co.uk (subject line: "DPO Enquiry").

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this page. For material changes that significantly affect your rights, we will provide advance notice via the App or by email. Your continued use of the App after changes take effect constitutes acceptance of the updated Policy.

17. Contact Us

If you have questions, concerns, or requests relating to this Policy or your personal data, please reach out to us:

CompanyLinkside Group Ltd
Emailprivacy@linksidegroup.co.uk
Subject (DPO queries)"Privacy Enquiry" or "DPO Enquiry"
Response timeWithin 30 days