Calo Privacy Policy
Last updated: September 20, 2026
Mind Stone Inc. ("Mind Stone," "we," "us," or "our") provides Calo, an AI-powered family calendar and household-coordination service available as a mobile app and related cloud services (the "Service"). The in-app AI assistant is also called "Calo."
This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have. By creating an account or using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
Because Calo is built for families, you will often provide information about other people — your partner, children, parents, other household members, and guests. Section 5 explains your responsibilities when you do.
1. Who We Are
Mind Stone Inc. 800 N King Street, Suite 304-2084, Wilmington, DE 19801, USA New Castle County, Delaware
Privacy contact: privacy@ourcalo.com General support: support@ourcalo.com
2. Information We Collect
We collect information you provide, information generated as you use the Service, and information we receive from third parties you connect.
2.1 Information you provide
- Account & identity. When you register with email/password or sign in with Apple or Google, we collect your email address, a securely hashed password (for email accounts), Apple/Google account identifiers, and email-verification codes.
- Family & member profiles. Family name, your home address (entered manually or captured via GPS during setup), and a profile for each family member you add — which may include name, photo, role/identity, birthday, and "life status." Members may include children, elderly relatives, and pets.
- Calendar & event content. Events, tasks, reminders, lists (shopping, to-do, chores), recipes and meal plans, rewards and points, and any notes, comments, or attachments you add.
- Dietary & health-related details. Dietary preferences and restrictions (including allergies), and reminders you set that may reveal health information (e.g., medication refills, doctor or hospital appointments). We treat this as sensitive information.
- Content you submit for processing. Photos of documents (e.g., a paper schedule or appointment letter) that you ask Calo to scan; emails you forward to your dedicated Calo forwarding address; and links/URLs you share for Calo to summarize.
- Conversations with Calo. The messages you exchange with the Calo AI assistant, including voice input you provide (which is converted to text), and, where you use the AI phone assistant, the purpose of the call and its transcript.
- Contact details for others. Email addresses or phone numbers you provide so Calo can send event invitations to guests, or send daily summaries by email/SMS to family members who don't use the app.
- Payments. If you subscribe to a paid plan, the purchase is processed by the Apple App Store / Google Play and RevenueCat; we receive subscription status and transaction identifiers but do not collect or store your full payment-card number.
2.2 Information collected automatically
- Usage & device data. App interactions and feature usage (analytics events), device and app version, language, and similar technical data.
- Diagnostics. Crash and error reports, performance data, and logs used to keep the Service reliable.
- Push & session data. Push-notification tokens and session/authentication tokens.
2.3 Information from connected services
If you connect an external calendar, mailbox, or account, we access data only as the permissions you grant allow. Section 3 sets out the Google and Microsoft connections in full — the exact access we request, what we read, what we store, and what we never do with it.
- Connected calendars. Google Calendar, Microsoft Outlook, Apple Calendar, and CalDAV, up to a limited number of accounts per member per provider. Read access is used to bring your existing events into your family's combined schedule and to detect conflicts. Write access is used only to apply back to the source calendar a change you make in Calo to an event that was imported from it, and to maintain Calo's own "Calo Events" calendar.
- Connected mailboxes. Gmail and Outlook mail, read-only, so the assistant can surface mail your household needs to act on and turn confirmations into calendar events. We store message headers; we do not store message bodies.
- Sign-in providers. Apple and Google identity, when you use them to sign in.
Disconnecting an account. You can disconnect any connected account at any time in the app. Section 3 explains what happens to that account's data when you do, and Section 11 describes your further rights.
3. Google and Microsoft Account Data
Calo connects to Google and Microsoft accounts in two separate, independent ways: a calendar connection and a mailbox connection. Connecting one does not connect the other, and you can grant, review, or withdraw each one on its own.
Limited Use. Calo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We apply the same limits to data we receive from Microsoft Graph.
3.1 Calendar connection
What we ask for. Read and write access to the calendars you select — calendar.readonly and calendar.events at Google, Calendars.ReadWrite at Microsoft — together with the primary email address of the account you connect (userinfo.email at Google, User.Read at Microsoft). We use that address to label the connected account in the app and to confirm that a later re-authorization attaches the same account, rather than silently attaching a different one.
What we read. From the calendars you select: event title, start and end time, location, description, recurrence rule, and the event's identifiers.
What we write. Write access is used for two purposes only. First, when you edit, reschedule, or delete an event inside Calo that was imported from a connected calendar, we apply that change back to the calendar it came from. Second, if you turn the feature on, we create and maintain a separate calendar named "Calo Events" in your Google or Outlook account, mirroring events that originate in Calo so they appear alongside the rest of your schedule. We do not create, change, or delete anything in your calendars that you did not act on in Calo. For Apple Calendar we publish a read-only subscription feed instead of writing to your account.
Disconnecting. When you disconnect a calendar account in Calo, we delete every event copy Calo synchronized from that account — past as well as future, not only upcoming events — and we erase the credentials we stored for it. For Google we also revoke Calo's token with Google at that moment. You can withdraw access yourself at any time in your Google Account or Microsoft account security settings.
3.2 Mailbox connection
If you connect a mailbox, Calo reads your incoming mail so the assistant can tell you what needs your attention and turn things like appointment confirmations into calendar events. This access is read-only: Calo cannot send, reply to, delete, label, or otherwise change anything in your mailbox.
What we ask for. Read-only mail access — gmail.readonly at Google, Mail.Read at Microsoft — and the account's primary email address. At Google, gmail.readonly reaches archived messages as well as what is currently in your inbox.
What we store. For recent mail — the last 30 days when you first connect, and new mail from then on — we store message headers only: sender address, subject, time received, the short preview snippet the provider supplies, the message and thread identifiers, the mailbox it arrived in, and Calo's own assessment of whether the message looks like something your household needs to act on.
What we do not store. Message bodies are never written to our database. When you ask Calo to summarize a particular message, or when Calo needs more than the header to assess it, we fetch that body from the provider, use it in memory, and discard it. Body excerpts are limited in length, and no more than three messages are fetched in a single request. We do not store attachments.
Automated assessment. So that Calo can answer "is there anything I need to handle?", it assesses recent mail automatically rather than only when you ask. Headers — and, where the header alone is not enough, a bounded excerpt of the body — are sent to our AI provider for that assessment (see Section 4 and Section 7). Only the resulting assessment is kept.
Disconnecting. When you disconnect a mailbox in Calo, we delete the message headers we stored from that mailbox, erase the credentials we held for it, and revoke Calo's access token with the provider. You can also withdraw Calo's access yourself at any time in your Google Account or Microsoft account security settings.
3.3 What we never do with this data
- We do not sell Google or Microsoft user data.
- We do not use it for advertising, or to build advertising or marketing profiles.
- We do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. It is used only to produce the schedule, answer, or summary you asked for.
- We do not transfer it to anyone except the service providers listed in Section 7, which process it on our behalf under contract in order to run features you are using; to comply with applicable law; or in connection with a merger or acquisition as described in Section 7.
- We do not let our staff read it, except with your explicit permission for a specific request (for example, when you ask support to look into a problem), where strictly necessary for security purposes such as investigating abuse, or where required by law.
4. How We Use Your Information
We use the information above to:
- Provide the core Service — run your family calendar, aggregate events across connected calendars, detect conflicts, and keep household lists, tasks, meals, and rewards in sync across members.
- Power Calo's AI features — generate proactive summaries (e.g., the home "NowCard" and morning briefing), suggest events and tasks for your confirmation, parse scanned documents, forwarded emails, and mail in a connected mailbox into calendar entries, flag mail your household may need to act on, estimate travel/commute time, and operate the AI phone assistant.
- Personalize — tailor reminders, meal suggestions, and content to your family's profiles and preferences.
- Communicate — send service-related notices and reminders; deliver event invitations and daily summaries to the recipients you designate (including by email/SMS to non-app members).
- Maintain, secure, and improve — authenticate users, prevent fraud and abuse, debug, analyze usage in aggregate, and develop new features.
- Comply with law — meet legal, tax, and regulatory obligations and respond to lawful requests.
We do not sell your personal information, and we do not use the content of your family's calendars, mail, or conversations to serve third-party advertising.
4.1 Legal bases (EEA/UK users)
Where the GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service); consent (for optional features such as connecting external accounts, location use, or processing sensitive data — withdrawable at any time); legitimate interests (to secure and improve the Service); and legal obligation.
5. Information About Other People
Calo is a shared family tool. When you add a family member, invite a guest, or provide someone's email or phone number, you confirm that you are entitled to share that information and, where required, that you have their consent (or, for a child, that you are the parent/guardian — see Section 6). The family administrator who creates a family may be able to view and manage information added by members. Please only add information you are authorized to share, and tell other members that their information is in Calo.
6. Children's Information
Calo is intended to be set up and managed by an adult (a parent or legal guardian). A parent or guardian may add a child as a family member and may use features that involve the child (such as assigning chores or tracking reward points). Any information about a child in Calo is provided and controlled by the managing adult.
We handle children's information consistent with applicable law, including the U.S. Children's Online Privacy Protection Act (COPPA) and the GDPR's provisions on children's data (GDPR-K). A parent or guardian may review, update, or delete a child's information, and withdraw consent, through the app or by contacting privacy@ourcalo.com. We do not knowingly allow children to create their own accounts. If you believe a child has provided us information without proper authorization, please contact us and we will delete it.
7. How We Share Information
We share information only as described here:
- Service providers (sub-processors). We share what is necessary with vendors that process data on our behalf under contract, including:
- Cloud hosting & storage: Amazon Web Services (AWS), in the United States (including S3 for uploaded images/attachments).
- Real-time push: Ably.
- Telephony & SMS: third-party telephony and messaging providers used to power the AI phone assistant and to send SMS summaries to family members who don't use the app.
- AI processing: our AI service (calo-agents) and Google (Gemini), the large-language-model provider used to generate conversation, suggestions, and summaries, and to assess whether a message in a connected mailbox needs your attention. Data from your Google and Microsoft accounts is never used to train generalized AI models (see Section 3.3).
- Calendar: Google, Microsoft, Apple, and CalDAV providers (for the calendars you connect).
- Mail: Google (Gmail) and Microsoft (Outlook mail), for the mailboxes you connect — read-only (see Section 3.2).
- Maps, places & travel time: Google Maps / Google Routes & Places.
- Weather: Google.
- Food & recipes: Edamam (recipe/nutrition lookups).
- Payments: Apple App Store, Google Play, and RevenueCat.
- Error monitoring: Sentry.
- People you designate. Guests you invite to events, and family members (including non-app members) to whom you send summaries.
- Legal & safety. When required by law or legal process, or to protect the rights, safety, and security of users, the public, or Mind Stone.
- Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
Our sub-processors are contractually restricted from using your information for their own purposes. A current list of sub-processors is available on request.
8. Where Your Data Is Stored and International Transfers
Mind Stone is based in the United States, and we store and process all user data on Amazon Web Services (AWS) infrastructure located in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws different from those in your country. Where required for users in the EEA, the UK, or other regions, we use appropriate safeguards (such as the EU Standard Contractual Clauses) for such transfers.
9. Data Retention
We keep your information for as long as your account is active and as needed to provide the Service. We retain different categories for different periods based on why we hold them and applicable legal requirements. When information is no longer needed, we delete or de-identify it. If you delete specific content or your account, we delete the associated personal information within a reasonable period, except where we must retain limited records for legal, tax, security, or accounting purposes.
Connected accounts. Event copies synchronized from a connected calendar are deleted when you disconnect that calendar (see Section 3.1). Mail headers stored from a connected mailbox are deleted when you disconnect that mailbox (see Section 3.2); mail bodies are never stored at all.
10. Security
We use technical and organizational measures designed to protect your information, including encryption of data in transit (HTTPS/TLS), encryption of data at rest, access controls and least-privilege practices, token-based authentication, and monitoring. No method of transmission or storage is completely secure, but we work continuously to protect your information and to detect and respond to incidents.
11. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your information;
- Port your information to another service;
- Object to or restrict certain processing;
- Withdraw consent for optional features at any time; and
- Opt out of any "sale" or "sharing" of personal information — note that we do not sell or share your personal information for cross-context behavioral advertising.
Self-service controls. You can edit or delete events, members, and other content in the app, connect or disconnect each calendar and each mailbox independently, manage notification preferences, and delete your account directly in the app. When you delete your account, we also revoke linked sign-in tokens (e.g., Apple) as part of deletion.
California (CCPA/CPRA). California residents have the rights to know, delete, correct, and opt out, and the right not to be discriminated against for exercising them. We do not sell or share personal information as defined under California law.
How to exercise. Use in-app controls or contact privacy@ourcalo.com. We will verify your request before acting on it. If we decline, we will explain why, and you may appeal or complain to your local data-protection authority.
12. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you through the app or by other reasonable means before they take effect and update the "Last updated" date above. Your continued use of the Service after the effective date means you accept the updated Policy.
13. Contact Us
Mind Stone Inc. 800 N King Street, Suite 304-2084, Wilmington, DE 19801, USA Privacy: privacy@ourcalo.com · Support: support@ourcalo.com