Doraemon Schedule
Privacy Policy
This policy explains how Doraemon Schedule Development Team (“we”) processes information when providing the Doraemon Schedule iOS app and related services, and how you can manage it. Please pay particular attention to cloud AI, subscription verification, and system permissions.
Your schedule library stays on your device. We do not upload or store that library on our servers, retain schedule, chat, or materials content, sell your information, or share it for advertising or purposes unrelated to the service. Only when you choose cloud AI is the content needed for that request forwarded through Cloudflare to DeepSeek. Account, subscription, and feedback information you choose to send is handled as described below.
1. Schedules, conversations, and materials
Schedule titles, dates and times, notes, locations, and tags that you create or import, together with conversations and the names, types, extracted text, references, and summaries of selected materials, are primarily stored on your device to record, display, find, and organize your plans. We do not proactively read files you have not selected.
Local creation, editing, and viewing do not upload your schedule or materials library to our servers, and we do not create server copies of those libraries. We currently provide neither our own schedule cloud sync nor in-app iCloud schedule sync. When you choose cloud AI, only content needed for that request is forwarded without retaining its body, as described in section 4; system calendar account sync is described in section 7.
Daily and weekly free schedule creation allowances and usage counts are recorded locally and are not uploaded to our servers. The allowance rules are described in the Terms of Use.
2. Device accounts, authentication, and security
The app generates a random 40-character hexadecimal CUID to identify a service account, authenticate requests, and provide membership or allowlist access. This is a device account identifier for our service, not an advertising identifier. The app also generates a device authentication credential, deviceSecret, and stores it in the iOS Keychain. It is not used for advertising tracking or attached to feedback emails. Keychain items may remain after the app is uninstalled.
Our servers process the CUID, account UUID, device authentication information, and session verification information. During authentication, the device credential is transmitted over HTTPS. The server stores only hashes of the device credential and session token, not their original values. Sessions last no more than one hour. Requests may also include common parameters such as system language, together with a signature, timestamp, and random nonce, for authentication, replay protection, and appropriate responses.
Network providers such as Cloudflare process IP addresses and necessary network information when establishing connections. We use necessary request status, rate-limit, and security records to prevent abuse, diagnose failures, and protect the service. We do not put schedule content, chat bodies, materials, or authentication secrets in business logs.
3. Apple purchases and subscription verification
Purchases are handled by Apple through the App Store and StoreKit. We do not read your bank card details, payment passwords, or Apple Account password. To verify purchase ownership and provide access, the app sends our Cloudflare service the product identifier, transaction identifier, original transaction identifier, expiration date, revocation status, appAccountToken, and Apple-signed transaction evidence (JWS).
Our servers verify transactions through Apple’s verification mechanisms and receive Apple subscription status notifications, with production and sandbox handled separately. Cloudflare D1 stores the minimum account records, subscription and transaction status, allowlist status and expiration, and necessary security or audit records needed for account and subscription services.
The app keeps different layers of UserInfo and entitlement cache in memory, UserDefaults, and the Keychain, separated by account owner and service environment. Persisted entitlement caches are encrypted with AES-GCM using a key derived from the device credential in the Keychain. If a network request fails, verified local access that has not expired can support the applicable local features. A purchase awaiting verification is not an active membership. Cloud AI access must still be checked by the server at the time of use.
4. When you choose cloud AI
When you choose to send a cloud AI request, the text you enter, extracted text from selected documents used in the request, and conversation context necessary for the task are forwarded through our Cloudflare Worker to DeepSeek to interpret content, generate a response, and help organize schedules. This may include schedules, locations, other people’s personal information, or sensitive materials. Review the content and remove unnecessary information before sending, and obtain any necessary authorization to process other people’s information.
This feature requires a network connection and eligible access. You can choose not to send a request and continue using available local schedule features. Speech recognition text first appears in the input area for you to decide whether to send it. Selecting a file or editing a local schedule does not itself sync your entire library to the cloud.
Our servers temporarily process necessary content only to complete the request. We do not write schedules, chat bodies, materials, attachments, or summaries to D1 or other persistent storage, and do not log request or response bodies. Cloudflare and DeepSeek still process request data to transmit it and perform inference. These restrictions do not mean the providers retain no data. Their processing, retention, and regional rules are described in the Cloudflare Privacy Policy and DeepSeek Privacy Policy.
Our Cloudflare service runs on its global network; a .cn domain does not mean the service is hosted in mainland China. Using cloud AI, account, or subscription services may involve transmission or processing outside your country or region. DeepSeek processes inference requests under its own policy. We do not promise that all network data is processed within China. Where separate notice or consent is required by applicable law, we will follow those requirements.
5. Microphone and speech recognition
For voice input, the app requests microphone and speech recognition permissions and uses Apple’s on-device speech recognition to convert speech into text, without falling back to cloud speech recognition. Voice input may be unavailable if your device or language does not support on-device recognition.
The app does not save this recording as a materials attachment. Recognized text first appears in the input area, where you may edit it, delete it, or decide whether to send it to cloud AI. Denying or disabling these permissions affects voice input; text input remains available.
6. Location and maps
When you use a feature that needs your current location, the app requests location access while in use to help select or search for a schedule location. It does not continuously collect location in the background or build a background movement history. You can also enter a location manually.
Place search and map display use Apple Maps. Search terms, the map area you view, authorized coordinates, and necessary device and network information may be processed by Apple and its mapping partners. Apple Maps in China uses Amap’s mapping service. See Apple Maps & Privacy and Apple Location Services & Privacy for details.
7. System calendar, reminders, and widgets
Connecting the system calendar requires full calendar access to read information needed for calendar integration. The current reading window covers one year in the past through one year in the future. Event fields may include titles, start and end times, notes, locations, links, time zones, recurrence, alerts, and participants. The app creates, updates, or deletes system calendar events after you authorize access and perform the corresponding action.
System calendar accounts such as iCloud, Google, and Exchange, and their synchronization, are managed by iOS and the account providers you choose according to your system settings and their privacy rules. They are separate from a schedule cloud sync service provided by us.
Notification permission and, on supported system versions, AlarmKit permission are used only for the schedule reminders you set. Delivery depends on permissions and system settings. Schedule widgets and Live Activities display relevant titles, times, and similar information that may be seen by others who can view your Home Screen or Lock Screen. Use available app and system options to show, hide, or remove these displays. Local data needed by widgets is shared with the app through an App Group.
You can manage or revoke calendar, location, microphone, speech recognition, notification, and other permissions in iOS Settings. Disabling a permission affects its corresponding feature without affecting available features that do not depend on it.
8. Email feedback
When you choose to send feedback, an email draft may include your CUID, device model, iOS version, and app version to help diagnose the problem. You may review, edit, or remove them before sending through your email app. We do not automatically attach schedules, materials, authentication secrets, or purchase evidence.
We process the email address, description, and attachments you choose to send to respond and resolve the issue. Remove unnecessary personal information from screenshots or attachments first. Email services may involve international transfers and are subject to the privacy rules of your email provider and our receiving email provider. Contact: dorastudio.support@gmail.com.
9. Storage, protection, and third parties
Local files use iOS file protection, authentication credentials use the Keychain, and network services use HTTPS. We apply security measures appropriate to the processing purpose, but cannot guarantee absolute security for any device, network, or storage. The app does not track users for advertising, read advertising identifiers for ad delivery, or build advertising profiles.
Local schedules, conversations, and materials remain until you delete the relevant content or app data. Server records are retained only as needed for account, subscription, security, and support services and legal requirements. When no longer needed, we delete them or handle them appropriately; we do not promise an unverified fixed retention period. Purchase ownership records and legally necessary transaction or security audit information may need to be retained.
The main third parties involved are Apple (purchases, speech, calendar, maps, notifications, and other system capabilities; see the Apple Privacy Policy), Cloudflare (network access, server execution, and D1 storage; see the Cloudflare Privacy Policy), and DeepSeek (cloud inference you choose to use; see the DeepSeek Privacy Policy). Relevant information is processed for the corresponding feature or necessary service, and each provider’s own services are also governed by its rules.
10. Your choices and information rights
You can view, edit, or delete relevant schedules and conversations in the app and use the existing attachment cleanup option. Removing attachment files does not necessarily delete extracted text, references, or summaries; manage those within the corresponding records. There is currently no option to clear the entire workspace in one step.
Uninstalling the app does not automatically delete events already written to the system calendar, system or account backups, or Keychain information that may remain. It also does not cancel an Apple subscription. Manage calendars and backups in the relevant services and subscriptions in your Apple Account.
You may email dorastudio.support@gmail.com to request access to, copies of, correction of, or deletion of account-related information we process, withdraw consent, or ask us to explain our processing rules. You may also use this address to exercise other rights under applicable law. We will conduct necessary identity and account ownership checks to avoid deleting the wrong account or disclosing information to another person. Do not send device secrets, session tokens, Apple passwords, or bank card details.
The app currently has no one-step interface for deleting a server account. Please request account deletion by email. We will handle the request under applicable law. Minimum records that must remain for legal requirements, purchase ownership, security, or dispute handling will have restricted purposes and appropriate protection. Deleting an account does not replace canceling an Apple subscription.
11. Children
Minors should use the service with a guardian’s guidance and obtain guardian consent as required by applicable law. Where such consent is required for processing the personal information of children under 14, we will process it after obtaining that consent. If a guardian believes a child has provided information without necessary consent, please contact dorastudio.support@gmail.com so we can address it.
12. Policy changes and contact
This policy may change as features or legal requirements change. We will display the updated and effective dates on this page. Material changes to information processing will be communicated through an in-app notice or another appropriate channel, and we will obtain renewed consent where legally required.
Operator: Doraemon Schedule Development Team. For privacy, permissions, or information rights questions, contact dorastudio.support@gmail.com.