Privacy Policy
Sensory Budget · Last updated 22 September 2026
Sensory Budget works out how demanding your day is likely to be. To do that it reads your calendar and, if you let it, health and noise data. Almost all of that stays on your iPhone.
This policy describes what the app actually does. Where something only happens if you agree to it, it says so, and none of it happens until you have said yes, on a new iPhone and on one you already had. An earlier version of the app had personalised notes on without asking; that grant has been withdrawn, once, on every phone holding it, because a setting nobody was asked for is not a setting anybody agreed to.
The short version
- Your scores, learning and reminders are worked out on your iPhone, not on a server.
- No Health reading of any kind leaves the device, including heart rate, sound levels and sleep. Nor does what you tell us about yourself. Event titles stay too, unless you allow AI features, which send a copy with names taken out.
- You are never asked to sign in. An account is optional, and signing in does not switch syncing on.
- We do not sell your data, show advertising, or track you across other apps or websites.
- You can export everything, and delete everything, from inside the app.
What stays on your iPhone
These never leave your device, whatever your settings:
- Every Health reading. Sleep, heart rate, heart-rate variability, environmental sound levels, steps (or wheelchair pushes) and
workouts are read from Apple Health, used on the device, and never uploaded: no value, no timestamp, no sample,
under any setting. You choose which of those four groups the app may read. Health is only ever read. The app never
writes anything back to Apple Health. Live readings are deleted after 48 hours. The database that holds what the
app has read is kept out of iCloud and computer backups, so it does not leave the phone that way either. That
also means a phone restored from a backup starts without your history unless you signed in and switched syncing on.
What the app works out from them is a different thing, and it can leave. Your morning figure moves with how you slept and with your resting heart rate, so with syncing on that figure is stored on your account, and with AI features allowed it is one of the numbers given to the language model. So is a pattern like “noise seems to add to your load”, which the app learned from sound levels a wearable measured. A conclusion drawn from a reading is not the reading, but it is not nothing either, and you should know it travels. - Event notes, locations and attendee names, and event titles unless you allow AI features (below), the one thing that sends a title, and only with names taken out. The app reads them to work out what kind of event something is, then keeps only the category, the times and a few anonymous details.
- How you describe yourself. If you tell the app you are autistic, ADHD, burnt out or sensitive to noise, that stays on the phone. It is never sent anywhere, and it never sets a cost by itself. It changes how soon the app trusts your own answers, and when it offers you a break.
- The name you are greeted by, and any words you write yourself.
Your account
Sensory Budget does not require an account. Every part of it works without one, and there is no sign-in step anywhere in front of the app. If you want your history to survive a new phone, or to reach a second device, you can sign in with Apple or with Google at any time. It is offered and never required.
Our authentication provider stores the stable user ID that Apple or Google gives us, and the email address they return. If you use Sign in with Apple and choose “Hide My Email”, that address is Apple’s private relay, and we never see your real one. Nothing else about your identity is kept. There is no name or email column in our own database.
Signing in does not turn on syncing. With syncing off, your account holds a user record, a random salt used for scrambling identifiers, your time zone and your privacy choices. Three other things can reach it without syncing, and only if you allowed AI features: a daily note our server phrased for you; a one-way fingerprint of a redacted event title, so the same title is not paid for twice; and a daily count of how many requests those two made. All three are described below.
What you choose
AI features: one question
While you set the app up, it asks you once whether it may use AI features: sorting events it cannot place by itself, and phrasing your daily note. It is one switch, shown on, with a sentence beside it saying what is sent (event titles with names taken out, the kind of event and its time; never a Health reading, never who you are) and that an AI service on our servers does the sorting. That service is OpenAI’s language model, reached through our server. Turn the switch off before you continue and nothing in the two sections below leaves your phone. You can change your answer at any time under You › Privacy & data › AI features. If you installed an earlier version and never answered, the app asks once, never at launch; a setting you had turned off stays off.
Syncing
When you turn syncing on, a derived version of your budget is stored so a new phone can restore it: event times, categories and costs, your ratings, your model’s learned numbers and your settings, and, for each day, the sleep, heart-rate-variability and resting-heart-rate points the morning figure was built from (points on the app’s own scale, never the raw readings or their timestamps). Identifiers are scrambled with a key unique to you (HMAC-SHA256), and no event title, name or free text is included.
Smarter event classification
Some events are hard to categorise from their shape alone. If you allowed AI features, a redacted title may be sent
to OpenAI’s language model, through our server, to be classified. Before it leaves the phone, email addresses, web
links, phone numbers and digits are removed, and every word that is not a known calendar or everyday word is replaced
with [name] or [word], so names are taken out: “Joseph : Oshin meeting” is sent
as “[name]: [name] meeting”. The one exception is a name that is also an ordinary word when nothing marks
it as a name: “Will review roadmap” keeps “Will”. The model never produces a score. It only
suggests a category, and your own answers always outrank it.
Apple’s on-device model
On an iPhone with Apple Intelligence switched on, a title the app cannot place from its own word lists may be read by Apple’s on-device model, which suggests a category. This happens entirely on the phone: nothing is sent to us or to anyone else, so there is no setting for it. Like the server model, it only suggests a category, and your own answers always outrank it.
Personalised daily notes
Only if you allowed AI features. Then the one-line note on the Today screen is phrased by OpenAI’s language model, through our server. What it is given is your phone's own figures for the day, the kind of each event rather than its name, and up to three of the patterns the app has noticed about you. Your event titles are not among them. The note is built so that it cannot carry one, whatever your other settings say. It cannot invent a number either: anything it writes is checked against the figures your device sent (and, if you allowed location, the one temperature our server looked up) and thrown away if it does not match.
No Health reading is among them either, and this is the distinction worth being exact about. The model is never given a heart rate, a decibel figure, a sleep duration or a timestamp for any of them. It is given your morning figure, which your phone worked out partly from how you slept and from your resting heart rate; and a pattern it is given may be one the app learned from sound levels, such as “noise seems to add to your load”. So what the model sees is shaped by your health without containing any of it.
Off means nothing leaves, not that we decline it on arrival. When AI features are off your phone never composes the request, so the day's categories, times and costs are not sent and then refused. They are not sent. The same is true when we turn the feature off from our end: your phone checks that before it builds anything, from a setting it already holds, without asking the network.
The note our server writes is kept on the server for 30 days, so the same day does not have to be phrased twice. The facts your phone sent to produce it are not kept. Only a fingerprint of them is, used to recognise the same day again.
Usage analytics
Off by default. When on, it records four things and no others: which screen came to the front, that the app launched, that it went to the background, and that a previous run ended without closing. Nothing else is recorded: no event, no rating, no health value, no budget number, no free text, and no device or advertising identifier.
Each row is stored with your account’s ID and the app version. That is what lets “Delete everything” remove them and an export include them, but it means they are tied to your account, not anonymous, and an earlier version of this page was wrong to call them that. They are never used for advertising and never shared.
Location and weather
If you allow it, the app asks for your approximate location (an area of a few kilometres, never a precise position) so the daily note can mention weather that may cost you, such as a heatwave or a storm.
- It is read once, when your day is planned. Never in the background.
- It is stored nowhere. It exists for the length of one request.
- Our server looks the forecast up on your behalf, so the weather service never sees you.
- If you decline, there is no fallback. No place of any kind is sent, and the note simply has no weather in it. We do not infer your location from your time zone or your IP address.
The weather never changes a number. It only changes wording.
Calendars
You can connect your calendar in two ways.
Apple Calendar is read on the device through iOS. Nothing about it crosses the network for that to work, including calendars from a Google account you have added to your iPhone in Settings.
Google Calendar, connected directly, is the one case where calendar data crosses the network: the app asks Google for your calendar list and your events over an encrypted connection, using read-only access. It can never write to, change or delete anything in your calendar. What comes back is turned into the same anonymous shape as everything else; titles are kept on your device only, in an offline cache that is erased when you disconnect Google, when a different account signs in, or when you delete everything.
Subscriptions
Subscriptions are sold by Apple and managed through your App Store account. We use RevenueCat to tell whether your subscription is active. They receive an identifier for your account and the purchase details Apple provides; they do not receive your health, calendar or budget data. Cancelling is done in your iPhone’s Settings, as Apple requires.
Who else handles your data
We do not sell or share your data for advertising, and nobody below may use it for their own purposes. Each is used only for the job named here, and each is bound by terms that protect your data at least as well as this policy does.
- Supabase runs our database, sign-in and server functions. Everything described above as reaching “our server” or “your account” is stored there.
- OpenAI, only while AI features are allowed. Our server sends it the redacted title or the day’s figures described above, and nothing that says who you are: no account ID, no email, no location. Under OpenAI’s API terms it does not train its models on what we send, and it may keep a request for up to 30 days to detect abuse before deleting it.
- RevenueCat checks whether your subscription is active (see Subscriptions).
- Apple and Google, only if you sign in with them or connect Google Calendar. They see that you signed in to Sensory Budget; they do not receive your budget, health or calendar data from us.
- Open-Meteo looks up the weather for the daily note, if you allowed location. Our server asks it for a rounded point and a time zone, so it never learns who is asking.
How long things are kept
| Data | On your iPhone | On our server |
|---|---|---|
| Live heart rate and noise readings | 48 hours | Never stored |
| Health daily summaries | 400 days | Never stored |
| Calendar events | 400 days after the event | Without titles, until you delete them |
| Notification history | 90 days | 90 days |
| Your ratings and learned model | Until you delete them* | Until you delete them |
| Daily notes written for you | Not stored | 30 days |
| Usage analytics rows | Not stored | 180 days |
* When you delete a single rating or logged break, it disappears from the app at once and stops affecting anything. If your phone has not yet managed to tell our server, because it has been offline or because the request keeps failing, a hidden copy of that entry stays on the phone until it can, because that copy is the only thing that can carry your deletion to the server. There is no time limit on that: we would rather hold something on your own phone, where nothing shows it and “Delete everything” wipes it, than leave a copy on a server you were told was gone.
Deleting and exporting
Delete everything is in the app, under Settings › Privacy & data. It removes every row we hold and your account itself, signs you out, cancels pending reminders, disconnects Google Calendar if you had connected it, and wipes the database on your phone. It also removes the breaks and events Sensory Budget itself added to your calendar, past and future, because that is the one place its data was ever visible to anyone else. Nothing else in your calendar is touched, and Apple Health is not touched at all.
If your phone cannot reach our server at that moment, nothing is deleted and the app tells you, so that you are never left believing a copy is gone when it is not. You can try again.
Export gives you a JSON file of everything held on the device, including the titles and the self-description that never left it, because it is yours. Three things are left out: the live heart-rate and noise readings that are deleted after 48 hours anyway, the queue of things still waiting to be sent, and the secret key the app uses to scramble identifiers. The last one is left out on purpose: it is not information about you, it is what stops the scrambled values in the file meaning anything to anyone else, and a file you may share is the wrong place for it.
Two things we cannot do for you: an Apple subscription must be cancelled in your iPhone’s Settings, and RevenueCat’s own customer record is removed on request.
Children
Sensory Budget is not directed at children and we do not knowingly collect data from anyone under 13.
Changes
If this policy changes in a way that affects what leaves your device, the app will say so before the change takes effect. The date at the top always reflects the current version.
Contact
Questions about this policy, or about your data: jbarbosa0427@gmail.com.