Back to home

Privacy Policy

Effective September 2, 2026

Who we are

Stacy OS is a personal planning and decision-support application for students, parents, and shift workers. It is operated by the Stacy OS team and is not a medical record system, electronic health record, or clinical tool.

Information we collect

  • Account information — your email address and, if you sign in with Google or Apple, the basic profile details that provider returns (name, email, avatar URL).
  • Planning data you enter — courses, coursework, work shifts, sleep and study blocks, family events, children and caregiver names, and your own notes.
  • Calendar data you connect — if you import an .ics file or connect a calendar account, we store event titles, times, locations, and identifiers needed to keep the calendar in sync.
  • Operational records — audit entries for consequential changes, sync activity, and error logs used to keep the app working and recoverable.

Information we do not collect

Stacy OS is not intended for protected health information. Do not enter patient names, medical record numbers, chart data, clinical notes, or screenshots from an electronic health record. We do not knowingly collect or process this information, and the app warns you before free-text and file inputs.

How we use your information

  • To display your schedule and detect conflicts, coverage gaps, and sleep risk.
  • To generate suggestions you must explicitly confirm before anything changes.
  • To authenticate you and keep your account secure.
  • To diagnose errors and improve reliability.

We do not sell your data, and we do not use it for advertising or profiling.

Calendar access

Calendar connections are read-only by default. We request the narrowest scope needed to read events for planning. We never write to, delete, or share your calendars without a separate, explicit action by you. OAuth tokens are stored server-side, encrypted at rest, and are never exposed to the browser. You can pause or disconnect a calendar at any time from Settings, which stops syncing and removes stored tokens.

Stacy OS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Service providers

We use infrastructure providers to host the application, database, authentication, and file storage, and an AI provider to generate explanations and study material summaries from content you submit. Providers process data on our behalf under contract and are not permitted to use it for their own purposes.

Security

Data is protected with row-level access rules so that records are only readable by the household they belong to. Access is default-deny, secrets stay server-side, and consequential changes are recorded in an audit history so they can be reviewed and reversed.

Retention and deletion

We keep your data while your account is active. You can export everything you have entered as JSON or CSV from Settings at any time. You can request deletion of your account and associated data by emailing support@stacyos.app; we delete the account and its records within 30 days, excluding backups that expire on their normal schedule.

Your choices

You can review, edit, or delete individual records in the app, disconnect calendars, export your data, and request deletion. If you are in a region with data protection rights such as the EEA, UK, or California, you may also request access, correction, or restriction of processing by contacting us.

Children

The app is intended for adults. Household members may record their own children’s names and schedules for planning purposes; children do not have accounts.

Changes to this policy

If we make material changes, we will update the effective date above and notify you in the app.

Contact

Questions about privacy? Email support@stacyos.app.

See also our Terms of Service.