Privacy Policy

Sensory Budget · Last updated 22 September 2026

Sensory Budget works out how demanding your day is likely to be. To do that it reads your calendar and, if you let it, health and noise data. Almost all of that stays on your iPhone.

This policy describes what the app actually does. Where something only happens if you agree to it, it says so, and none of it happens until you have said yes, on a new iPhone and on one you already had. An earlier version of the app had personalised notes on without asking; that grant has been withdrawn, once, on every phone holding it, because a setting nobody was asked for is not a setting anybody agreed to.

The short version

What stays on your iPhone

These never leave your device, whatever your settings:

Your account

Sensory Budget does not require an account. Every part of it works without one, and there is no sign-in step anywhere in front of the app. If you want your history to survive a new phone, or to reach a second device, you can sign in with Apple or with Google at any time. It is offered and never required.

Our authentication provider stores the stable user ID that Apple or Google gives us, and the email address they return. If you use Sign in with Apple and choose “Hide My Email”, that address is Apple’s private relay, and we never see your real one. Nothing else about your identity is kept. There is no name or email column in our own database.

Signing in does not turn on syncing. With syncing off, your account holds a user record, a random salt used for scrambling identifiers, your time zone and your privacy choices. Three other things can reach it without syncing, and only if you allowed AI features: a daily note our server phrased for you; a one-way fingerprint of a redacted event title, so the same title is not paid for twice; and a daily count of how many requests those two made. All three are described below.

What you choose

AI features: one question

While you set the app up, it asks you once whether it may use AI features: sorting events it cannot place by itself, and phrasing your daily note. It is one switch, shown on, with a sentence beside it saying what is sent (event titles with names taken out, the kind of event and its time; never a Health reading, never who you are) and that an AI service on our servers does the sorting. That service is OpenAI’s language model, reached through our server. Turn the switch off before you continue and nothing in the two sections below leaves your phone. You can change your answer at any time under You › Privacy & data › AI features. If you installed an earlier version and never answered, the app asks once, never at launch; a setting you had turned off stays off.

Syncing

When you turn syncing on, a derived version of your budget is stored so a new phone can restore it: event times, categories and costs, your ratings, your model’s learned numbers and your settings, and, for each day, the sleep, heart-rate-variability and resting-heart-rate points the morning figure was built from (points on the app’s own scale, never the raw readings or their timestamps). Identifiers are scrambled with a key unique to you (HMAC-SHA256), and no event title, name or free text is included.

Smarter event classification

Some events are hard to categorise from their shape alone. If you allowed AI features, a redacted title may be sent to OpenAI’s language model, through our server, to be classified. Before it leaves the phone, email addresses, web links, phone numbers and digits are removed, and every word that is not a known calendar or everyday word is replaced with [name] or [word], so names are taken out: “Joseph : Oshin meeting” is sent as “[name]: [name] meeting”. The one exception is a name that is also an ordinary word when nothing marks it as a name: “Will review roadmap” keeps “Will”. The model never produces a score. It only suggests a category, and your own answers always outrank it.

Apple’s on-device model

On an iPhone with Apple Intelligence switched on, a title the app cannot place from its own word lists may be read by Apple’s on-device model, which suggests a category. This happens entirely on the phone: nothing is sent to us or to anyone else, so there is no setting for it. Like the server model, it only suggests a category, and your own answers always outrank it.

Personalised daily notes

Only if you allowed AI features. Then the one-line note on the Today screen is phrased by OpenAI’s language model, through our server. What it is given is your phone's own figures for the day, the kind of each event rather than its name, and up to three of the patterns the app has noticed about you. Your event titles are not among them. The note is built so that it cannot carry one, whatever your other settings say. It cannot invent a number either: anything it writes is checked against the figures your device sent (and, if you allowed location, the one temperature our server looked up) and thrown away if it does not match.

No Health reading is among them either, and this is the distinction worth being exact about. The model is never given a heart rate, a decibel figure, a sleep duration or a timestamp for any of them. It is given your morning figure, which your phone worked out partly from how you slept and from your resting heart rate; and a pattern it is given may be one the app learned from sound levels, such as “noise seems to add to your load”. So what the model sees is shaped by your health without containing any of it.

Off means nothing leaves, not that we decline it on arrival. When AI features are off your phone never composes the request, so the day's categories, times and costs are not sent and then refused. They are not sent. The same is true when we turn the feature off from our end: your phone checks that before it builds anything, from a setting it already holds, without asking the network.

The note our server writes is kept on the server for 30 days, so the same day does not have to be phrased twice. The facts your phone sent to produce it are not kept. Only a fingerprint of them is, used to recognise the same day again.

Usage analytics

Off by default. When on, it records four things and no others: which screen came to the front, that the app launched, that it went to the background, and that a previous run ended without closing. Nothing else is recorded: no event, no rating, no health value, no budget number, no free text, and no device or advertising identifier.

Each row is stored with your account’s ID and the app version. That is what lets “Delete everything” remove them and an export include them, but it means they are tied to your account, not anonymous, and an earlier version of this page was wrong to call them that. They are never used for advertising and never shared.

Location and weather

If you allow it, the app asks for your approximate location (an area of a few kilometres, never a precise position) so the daily note can mention weather that may cost you, such as a heatwave or a storm.

The weather never changes a number. It only changes wording.

Calendars

You can connect your calendar in two ways.

Apple Calendar is read on the device through iOS. Nothing about it crosses the network for that to work, including calendars from a Google account you have added to your iPhone in Settings.

Google Calendar, connected directly, is the one case where calendar data crosses the network: the app asks Google for your calendar list and your events over an encrypted connection, using read-only access. It can never write to, change or delete anything in your calendar. What comes back is turned into the same anonymous shape as everything else; titles are kept on your device only, in an offline cache that is erased when you disconnect Google, when a different account signs in, or when you delete everything.

Subscriptions

Subscriptions are sold by Apple and managed through your App Store account. We use RevenueCat to tell whether your subscription is active. They receive an identifier for your account and the purchase details Apple provides; they do not receive your health, calendar or budget data. Cancelling is done in your iPhone’s Settings, as Apple requires.

Who else handles your data

We do not sell or share your data for advertising, and nobody below may use it for their own purposes. Each is used only for the job named here, and each is bound by terms that protect your data at least as well as this policy does.

How long things are kept

DataOn your iPhoneOn our server
Live heart rate and noise readings48 hoursNever stored
Health daily summaries400 daysNever stored
Calendar events400 days after the eventWithout titles, until you delete them
Notification history90 days90 days
Your ratings and learned modelUntil you delete them*Until you delete them
Daily notes written for youNot stored30 days
Usage analytics rowsNot stored180 days

* When you delete a single rating or logged break, it disappears from the app at once and stops affecting anything. If your phone has not yet managed to tell our server, because it has been offline or because the request keeps failing, a hidden copy of that entry stays on the phone until it can, because that copy is the only thing that can carry your deletion to the server. There is no time limit on that: we would rather hold something on your own phone, where nothing shows it and “Delete everything” wipes it, than leave a copy on a server you were told was gone.

Deleting and exporting

Delete everything is in the app, under Settings › Privacy & data. It removes every row we hold and your account itself, signs you out, cancels pending reminders, disconnects Google Calendar if you had connected it, and wipes the database on your phone. It also removes the breaks and events Sensory Budget itself added to your calendar, past and future, because that is the one place its data was ever visible to anyone else. Nothing else in your calendar is touched, and Apple Health is not touched at all.

If your phone cannot reach our server at that moment, nothing is deleted and the app tells you, so that you are never left believing a copy is gone when it is not. You can try again.

Export gives you a JSON file of everything held on the device, including the titles and the self-description that never left it, because it is yours. Three things are left out: the live heart-rate and noise readings that are deleted after 48 hours anyway, the queue of things still waiting to be sent, and the secret key the app uses to scramble identifiers. The last one is left out on purpose: it is not information about you, it is what stops the scrambled values in the file meaning anything to anyone else, and a file you may share is the wrong place for it.

Two things we cannot do for you: an Apple subscription must be cancelled in your iPhone’s Settings, and RevenueCat’s own customer record is removed on request.

Children

Sensory Budget is not directed at children and we do not knowingly collect data from anyone under 13.

Changes

If this policy changes in a way that affects what leaves your device, the app will say so before the change takes effect. The date at the top always reflects the current version.

Contact

Questions about this policy, or about your data: [email protected].