Dense Calendar Privacy Policy
Space City Software, L.L.C.
Effective date: June 5, 2026
Last updated: October 6, 2026
This Privacy Policy explains how Space City Software, L.L.C. (“Space City Software,” “we,” “us,” or “our”) handles personal information in connection with our products and services, including our consumer mobile applications, our Odoo modules and business-software extensions, and our websites (collectively, the “Services”).
This copy of the policy is published at https://densecalendar.app/privacy/. The same policy, word for word, is published by Space City Software at https://spacecitysoftware.com/privacy and by each of our apps on its own website; only Section 5.6, App-Specific Details, differs from app to app.
We have written this policy to be accurate to how our Services actually work. In many cases — particularly for our mobile applications and our Odoo modules — we do not collect your personal information at all, and we explain below exactly where that is the case.
Mobile app users: Our consumer mobile applications do not collect your personal data. The information you create stays on your device and in your own private Apple iCloud account, where we have no access. If you only use one of our apps, the sections most relevant to you are Section 5 (Our Mobile Applications), that app’s App-Specific Details (Section 5.6), and Sections 14–18. The remaining sections describe our websites and our Odoo business-software modules.
1. Who We Are and How to Contact Us
Space City Software, L.L.C. is a software company based in Houston, Texas, USA.
- Privacy contact email: support@spacecitysoftware.com
For any privacy question or request, the fastest way to reach us is by email at the address above.
2. Scope of This Policy
This policy applies to:
- Our mobile applications — consumer apps we publish, primarily for Apple’s App Store.
- Our Odoo modules and business-software extensions — modules and add-ons we distribute (for example, through the Odoo Apps Store) that run inside our customers’ own Odoo instances.
- Our websites and services — our marketing and informational websites and related online services.
Different parts of this policy apply to different Services. Where a section applies only to one category of Service, we say so.
This policy does not apply to:
- Third-party products, websites, or services that we do not operate (for example, Apple’s iCloud or App Store, or a vendor’s website), which are governed by their own privacy policies.
- Personal data that our business customers process inside their own systems using our Odoo modules, for which the customer — not Space City Software — is the data controller (see Section 4).
3. Our Role: Controller vs. Processor
Privacy law distinguishes between the party that decides why and how personal data is processed (the controller) and a party that processes data on a controller’s behalf (the processor).
-
Our websites and certain communications. We act as the controller for personal information you submit directly to us through our websites (for example, a contact-form message) and for our own business and marketing communications.
-
Our mobile applications. Our mobile applications are designed to keep your data on your device and within your own personal cloud account. As described in Section 5, we do not receive, access, or control the data you create in our mobile apps, so in practice there is no controller relationship between you and us for that data.
-
Our Odoo modules and business-software extensions. These run entirely inside the customer’s own Odoo instance. The customer — as the owner of the database — is the data controller for any personal data processed by the module. Our modules do not transmit data to Space City Software and do not “phone home.” Because no end-user data flows to us, we are not a processor of that data; we are solely the software vendor that supplies code which executes on the customer’s own infrastructure. Customers remain in full control of, and retain ownership of, their data at all times.
4. Our Odoo Modules and Business-Software Extensions
Our Odoo modules run inside the customer’s own Odoo database and instance — specifically on a customer’s on-premise deployment or on Odoo.sh. (Third-party modules that contain Python code cannot run on the Odoo Online (SaaS) platform, so that environment is not a supported target.) The modules do not connect to Space City Software, do not send usage statistics or telemetry to us, and do not call external services controlled by us.
We do not collect, transmit, or store any personal or usage data from these modules outside the customer’s own Odoo instance. The customer, as the owner of the database, is the sole data controller for all data the module processes. Because no data ever flows to us, we are not a processor of that data, and the standard module does not create a processor relationship between us and the customer.
Depending on the module and how the customer configures it, the module may store personal data within the customer’s own instance on the customer’s behalf — for example: email addresses of subscribers; signer names, email addresses, and company names; employee or user identifiers for internal policy attestations; hashed verification or unsubscribe tokens (we store SHA-256 hashes rather than raw tokens); the IP address recorded at the time a person signs up or submits a request; comments and votes tied to a logged-in portal user; customer-reference profiles and related free-text fields; and related audit-trail or event-log entries. All such data resides only in the customer’s database. Several of our modules also include data-erasure (“forget”) actions to help the customer honor data-subject deletion requests while preserving any required tamper-evident audit hashes.
Because the customer is the controller, the customer is responsible for its own privacy notices, lawful basis, consent, retention, and regulatory compliance (including GDPR and similar laws) for the personal data processed in its instance.
5. Our Mobile Applications
Our consumer mobile applications are designed to be privacy-light and to keep your information on your own device and in your own personal cloud account.
Our stance is the same for every app. We do not collect information we do not need. We do not sell it. We do not share it with third parties, other than the providers of the platform services an app’s features use, and then only what the feature needs. For example, an app that shows maps or travel times sends the place you look up to Apple Maps, because that is how the feature works. Different apps use different services, so the exact information involved differs from app to app; each app lists its own in Section 5.6 (App-Specific Details).
5.1 Data that stays on your device
The content you create and your in-app preferences are stored on your device, in the app’s own storage. What that content is depends on the app (for example timers, tasks, notes or calendar additions, and your settings); Section 5.6 lists it for each app. Where an app reads information already on your device to do its job (for example your calendars, or a contact you choose), that information is used on your device for that feature and is not sent to us. Our mobile apps do not collect personal identifiers, account data, or an advertising identifier.
This information is processed only on your device. It is generally not treated as “collected” under Apple’s App Store privacy definitions because it is not transmitted off your device to us for our access. We do not have access to this data.
5.2 Sync and backup through your own Apple or Google account
If you use Apple iCloud, our apps may synchronize your own content across your devices using Apple’s iCloud (for example the CloudKit private database or iCloud Drive), stored in your personal iCloud account. This sync keeps your data within your own Apple account. Space City Software has no access to your iCloud data, and we cannot read, retrieve, or manage it. Apple’s handling of iCloud data is governed by Apple’s privacy policy. On Android, your device’s own backup service (such as Google’s) may back up app data to your Google account under Google’s privacy policy; we have no access to it either.
If iCloud is unavailable, the app keeps working with local-only storage. Where an app lets you export or import your own backup data, any such backup is created at your direction and stays under your control.
5.3 In-app purchases and subscriptions
If an app offers in-app purchases or subscriptions (such as tips, unlocking features, or a free trial), those purchases are processed entirely by the app store: Apple through StoreKit and the App Store, or Google Play on Android. The store handles all payment information. The app only receives the store’s verified transaction result and may keep a simple local record of it; we do not receive your payment card details or other payment account information.
5.4 No accounts, no ads, no third-party analytics
Our mobile applications do not require an account or login, do not display advertising, do not use an advertising identifier, do not track you across other apps or websites, and do not include third-party analytics. The app makes no network calls of its own to Space City Software. If an app uses push notifications, it is only for the app’s own function (for example, iCloud telling the app that your synced data changed); we do not receive or store push or messaging tokens, and we do not send marketing notifications.
5.5 Crash and diagnostic data
Our mobile applications may include a third-party crash-reporting and diagnostics service to help us detect, diagnose, and fix crashes and performance problems. Where this is active, it may collect crash data and performance/diagnostic data — for example, the device model, operating-system version, app version, and the state of the app at the time of a crash.
This information is technical and is used only to keep the app stable and functional. It is not used to identify you, and it is not used for advertising or for tracking you across other apps or websites. Where the service is active, the provider acts as our service provider and processes the data on our behalf; we require it to provide the same or equal protection of your data as described in this policy and as required by applicable app-store guidelines.
This shared policy does not name a crash-reporting provider; an app that uses one names it, and what it receives, in its App-Specific Details (Section 5.6). Whenever crash reporting is active in a released build, we keep this policy and our App Store / app-marketplace privacy disclosures and privacy manifests consistent with what that build actually collects. If crash reporting is active for a build you use, you may email support@spacecitysoftware.com to request deletion of crash diagnostics associated with your reports; such reports are not linked to your identity.
5.6 App-Specific Details: Dense Calendar
Dense Calendar is a calendar for iPhone and iPad. This section lists exactly what it does with your information.
Your calendars. With your permission, Dense Calendar reads and edits the calendars on your device through iOS. Events stay in the calendar accounts you set up on your device (for example iCloud, Google or Exchange), which sync them under their own terms. Dense Calendar does not copy your events anywhere else.
Stored on your device. Hidden events, tags and people, day notes, the people directory, saved filters, a history of changes, and your settings. The home-screen widgets and the share extension use a container on your device that only Dense Calendar can read; the widgets’ copy leaves out notes, tags and people.
iCloud sync (optional). If you turn on Sync across your devices, hidden events, tags and people, day notes, the people directory and saved filters are stored in the CloudKit private database of your own iCloud account, as described in Section 5.2. While sync is on, iCloud sends the app a silent push when your data changes on another device, so it can fetch the change in the background. The push shows nothing, carries none of your data, and its token stays with Apple (Section 5.4).
Apple services the app’s features use. These are the only third parties involved, and each receives only what its feature needs:
- Apple Maps — when you search for a place or the app works out travel time, the location text and map coordinates are sent to Apple Maps. Dense Calendar does not ask for your device’s location.
- Apple speech recognition — when you add an event by voice, the microphone is used only while you speak, and Apple turns your words into text: on the device where it can, otherwise on Apple’s servers. Dense Calendar does not keep the recording.
- On-device text recognition and Apple’s on-device model — when you import from a photo, screenshot, PDF or file, text is recognised and events are extracted on your device. Images and documents are not uploaded.
- App Store — the rating prompt is Apple’s.
Importing from a web address. If you give the app a web address, it downloads that page or calendar file directly from that website, as a browser would. That website sees an ordinary request from your device, including your IP address. Nothing is sent to us.
Contacts. To link a person to a contact, the app opens the iOS contact picker. It does not ask for access to your contacts; it receives only the contact you pick and keeps a reference to it on your device.
Feedback email. Send feedback opens your own mail app with a message to support@spacecitysoftware.com that includes the app version, your device model and its iOS version. Nothing is sent unless you send it.
Crash reporting and purchases. Dense Calendar has no crash reporting and, for now, no in-app purchases.
Deleting your data. Deleting Dense Calendar removes everything it stored on your device; your events stay in your calendars. iCloud data: Settings → [your name] → iCloud → Manage Storage.
6. Our Websites
When you visit our websites or contact us through them, the following may apply.
6.1 Information you provide
If you submit a contact form, we collect the information you provide — typically your name, email address, an optional company name, and your message.
6.2 Information collected automatically
When you submit a contact form, and as part of standard web request logging, your IP address and standard request metadata are processed by our hosting provider. Our contact form also uses an anti-spam challenge to verify that submissions are not automated.
6.3 Cookies, SDKs, and similar technologies
Our websites do not use advertising or analytics cookies, and we do not use web analytics tools (such as Google Analytics, Plausible, Fathom, PostHog, or Segment). Our mobile apps use no tracking SDKs and collect no push-notification or messaging tokens. Because we do not sell or share personal information and do not run advertising or analytics, a Global Privacy Control (GPC) or “Do Not Track” signal has no processing for it to disable; if our practices ever change, we will honor valid opt-out preference signals as required by law.
6.4 How website information is handled
Our websites are served as static content through our hosting provider and do not maintain their own database of submissions. Contact-form submissions are delivered to us by email (including the name, email, optional company, message, and the submitter’s IP address) so that we can respond to you. IP address and request metadata persist in our hosting provider’s standard logs according to that provider’s retention practices.
7. How We Use Information and Legal Bases (GDPR)
We use the limited personal information we actually receive (primarily contact-form submissions and, where active, app crash diagnostics) for the following purposes. Where the EU/UK General Data Protection Regulation (“GDPR”) applies, the legal basis for each purpose is noted.
| Purpose | Categories of data | Legal basis (GDPR) |
|---|---|---|
| Respond to your inquiries and provide support | Name, email, company, message content | Legitimate interests (responding to people who contact us); steps prior to a contract where relevant |
| Protect our websites against spam and abuse | IP address, request metadata, anti-spam challenge result | Legitimate interests (security and integrity of our Services) |
| Operate, maintain, and secure our websites | IP address, request/access logs | Legitimate interests (operating and securing our Services); legal obligation where applicable |
| Detect, diagnose, and fix app crashes and performance issues (only where crash reporting is active) | Crash data, performance/diagnostic data | Legitimate interests (maintaining a functional, reliable app) |
| Comply with legal obligations and enforce our rights | As relevant to the matter | Legal obligation; legitimate interests |
Providing your contact details is voluntary; if you choose not to provide them, we may be unable to respond to your inquiry. No other provision of personal data is required to use our apps or modules.
Where we rely on consent for any specific processing, you may withdraw it at any time (see Sections 11 and 12); withdrawal does not affect processing carried out before withdrawal.
8. How We Share Information — Third Parties and Sub-Processors
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your personal information for advertising or for tracking you across other companies’ apps or websites.
We rely on a small number of service providers and platforms, by category:
- Apple (iCloud / CloudKit and the App Store / StoreKit) and Google (Google Play and Android backup) — for our mobile apps: they store your synced or backed-up app data in your own account (we have no access) and process in-app purchases and payments. They act as independent parties under their own privacy policies.
- Platform services an app’s features use — for example Apple Maps for places and travel times, or Apple’s speech recognition for voice entry. They receive only what that feature needs, directly from your device, under their own privacy policies; we receive none of it. Each app lists the services it uses in its App-Specific Details (Section 5.6).
- Crash-reporting and diagnostics provider — where active, processes app crash and performance diagnostics on our behalf as a service provider, used only for app functionality (we do not name a specific provider here; see Section 5.5).
- Website hosting and edge/security provider — hosts our websites, runs our serverless functions, provides anti-spam challenge verification, and maintains standard request/access logs.
- Transactional email provider — delivers contact-form submissions to us by email (receiving the name, email, optional company, message, and submitter IP contained in that email).
- Professional advisors and authorities — we may disclose information where required by law, to comply with legal process, or to protect our rights, users, or the public.
We require our service providers to process personal information only as needed to provide their services to us, and we have confirmed that they provide the same or equal protection of personal information as described in this policy and as required by applicable app-store and legal requirements. For our Odoo modules, there are no sub-processors and no data sharing with us, because those modules do not transmit data outside the customer’s instance (see Section 4).
9. Data Retention
We keep personal information only as long as needed for the purposes described in this policy, or as required by law.
- Contact-form messages (name, email, company, message): retained in our email records for as long as needed to handle your inquiry and for a reasonable follow-up period, then deleted or archived.
- Website request/access logs (including IP address): retained by our hosting and email providers according to their standard retention periods.
- App crash/diagnostic data (where active): retained for the limited period needed to diagnose and fix issues, consistent with the provider’s retention defaults.
- On-device and iCloud app data: controlled entirely by you; it remains until you delete it from your device and your iCloud account. We do not retain it because we never receive it.
- Odoo-module data: retained within the customer’s own instance under the customer’s control; the customer determines retention.
10. International Data Transfers
We are based in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or another region with data-transfer rules, the limited information you provide to us (for example, a contact-form message) may be processed in the United States or in other countries where we or our service providers operate.
Where required, such transfers are protected by appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), or reliance on an adequacy decision, as applicable. You may contact us for more information about the safeguards we rely on.
For our mobile apps, your synced data is stored by Apple in your own iCloud account and is governed by Apple’s transfer practices. For our Odoo modules, data stays within the customer’s own infrastructure, so the customer controls where it resides.
11. Your Privacy Rights
11.1 EEA / UK (GDPR)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data (“right to be forgotten”);
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests;
- Data portability — receive certain data in a portable format;
- Withdraw consent at any time where processing is based on consent; and
- Lodge a complaint with your local supervisory authority (for example, your national Data Protection Authority, or the UK Information Commissioner’s Office). We would, however, appreciate the chance to address your concerns first.
If you are in the EEA or UK and we do not have an establishment there, you may contact us at support@spacecitysoftware.com for the attention of our data-protection contact.
11.2 California (CCPA/CPRA) and similar U.S. state laws
Subject to applicable law, California residents (and residents of other U.S. states with comparable laws) have the right to:
- Know what personal information we have collected, used, and disclosed;
- Delete personal information we have collected from you;
- Correct inaccurate personal information;
- Opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information, so there is nothing to opt out of, but you have this right;
- Limit the use of sensitive personal information — we do not use sensitive personal information for purposes that would trigger this right; and
- Non-discrimination — we will not discriminate against you for exercising any of your rights.
We do not knowingly use automated decision-making or profiling that produces legal or similarly significant effects about you.
Notice at Collection (CCPA/CPRA)
In the past 12 months, we have collected the following categories of personal information through our websites (our mobile apps collect none). We do not sell or share any of these categories.
| Statutory category | Examples we collect | Source | Business purpose | Disclosed to (categories) | Sold / Shared |
|---|---|---|---|---|---|
| Identifiers | Name, email address, IP address | Directly from you (contact form); automatically (web request logs) | Respond to inquiries; secure the Services | Website hosting/edge provider; transactional email provider | No |
| Customer records information | Optional company name, message content | Directly from you (contact form) | Respond to inquiries | Transactional email provider | No |
| Internet or other network activity | Request/access log metadata, anti-spam challenge result | Automatically (web request logging) | Operate, secure, and protect the Services against abuse | Website hosting/edge provider | No |
We retain each category for the periods described in Section 9. A link to this full policy is provided at or before the point of collection on our website and from our App Store listing.
11.3 What we actually hold
Because our mobile apps keep your data on your device and in your own iCloud account, and because our Odoo modules keep data within the customer’s instance, the personal information we can act on directly is generally limited to contact-form submissions and related logs. For data on your device, in your iCloud account, or in a customer’s Odoo instance, you may need to use the controls in the app/device, your Apple account, or the relevant customer’s systems.
12. How to Exercise Your Rights
You can submit a privacy request in either of these ways, without creating an account:
- Email us at support@spacecitysoftware.com; or
- Use the contact form on our website.
To protect your privacy, we may need to verify your identity before acting on a request. You may use an authorized agent to submit a request on your behalf, subject to reasonable verification. We will respond within the timeframes required by applicable law (generally within 30 days under GDPR and 45 days under California law, each extendable where permitted).
To withdraw consent or stop receiving communications, contact us using the methods above.
13. Data Security
We use reasonable administrative, technical, and organizational measures appropriate to a small software vendor to protect personal information, including transmitting data over encrypted connections (HTTPS), using hashed tokens rather than raw tokens where applicable in our software, and limiting access to the limited information we receive. For our apps, keeping data on your device and in your own iCloud account reduces exposure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Children’s Privacy
Our Services are not directed to children under 13 (or the equivalent minimum age in your jurisdiction, such as 16 in parts of the EEA), and we do not knowingly collect personal information from children. Our mobile applications are general-audience productivity tools and do not include child-directed content, third-party advertising, or tracking. Our apps are not part of the App Store Kids Category and are not designed for or marketed to children. If you believe a child has provided us personal information, please contact us at support@spacecitysoftware.com and we will take appropriate steps to delete it.
15. Third-Party Links and Services
Our Services may reference or link to third-party products, websites, or services that we do not control (for example, Apple’s services or external sites). This policy does not apply to those third parties, and we encourage you to review their privacy policies.
16. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (for example, an in-app notice for app users or an email to business contacts). Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy, where permitted by law.
17. Governing Law
This policy and any related disputes are governed by the laws of the State of Texas, United States, without regard to conflict-of-laws principles, to the extent permitted by applicable law. Nothing in this section limits any non-waivable rights you may have under the laws of your place of residence.
18. Contact Us
Space City Software, L.L.C. Houston, Texas, USA Email: support@spacecitysoftware.com
If you have questions about this policy or wish to exercise your rights, please contact us using the details above. This policy applies to our mobile applications, our Odoo modules and business-software extensions, and our websites and services.