Privacy
Effective October 3, 2026
Sidekin is a private productivity app made by Damasqas, Corp. This policy covers Sidekin, including the calendar connection previously named Quiet Calendar.
Joining the waitlist
You can join by texting Sidekin or signing in with Google. Sidekin stores your encrypted registration and access decision. WorkOS handles Google sign-in and receives your account email. Registration or sign-in alone does not grant app access while you are waitlisted, and does not connect your calendar or email. After approval, you can authorize Calendar and optional read-only Gmail access. To leave the waitlist or request deletion, email deep@onepatch.dev.
Messages and phone sign-in
AgentPhone processes the messages you send to Sidekin and our replies. Sidekin uses the observed sender to verify your phone, manage signup, and send account-access links. Phone numbers, account profiles, and prepared replies are encrypted in Sidekin’s database and recovery backups. Sign-in links expire after ten minutes and can be used once; phone browser sessions last up to thirty days and can be revoked. Text STOP to pause replies or START to resume them. You can disconnect Messages in Sidekin after verifying your Google sign-in. People who have only registered a phone can contact us for help or deletion; we verify ownership before making account changes.
A limited AI assistant helps with setup over text, including while you are waitlisted. It receives your message, up to twelve recent conversation messages, and signup/connection status flags. It does not receive calendar or mailbox content through this onboarding flow. We remove sign-in URLs, obvious contact identifiers, and credential-like strings before inference. New registrations use inference through exe.dev; linked accounts use the provider selected in Sidekin, including verified encrypted Tinfoil inference. Recent conversation is encrypted with your phone record; messages older than thirty days are excluded when it is next read or updated. Disconnecting Messages clears this active conversation history. Delivery records and recovery backups are retained separately.
After approval and Google sign-in, messages from your verified phone go to the same private assistant as Sidekin’s web chat, with the tools and account access you have enabled. Linking your phone and Google account sends a short introduction; it does not change waitlist status. Voice notes are sent through exe.dev to OpenAI for transcription, even when your assistant uses Tinfoil. Sidekin temporarily decodes the recording and removes its local processing files afterwards. We retain the original transcription, message and time references, model name, and audio fingerprint in encrypted account storage and recovery backups for future use. Saved voice-note transcripts do not automatically expire and remain after you disconnect Messages; you can request deletion as described below. Ordinary message and delivery records expire after thirty days. Raw transcription tool results are omitted from saved agent sessions, while replies, summaries, and saved insights may contain information from your notes. The assistant can reply to your verified phone in the same conversation.
You can also send screenshots, links, documents, audio, video, contacts, locations and other files through iMessage or the native Share menu. Sidekin stores these original attachments and your accompanying note encrypted in your account. They are available for thirty days, then removed during the next daily cleanup; you can ask the assistant to remove a share sooner. Relevant file contents and image previews are sent to your selected assistant inference provider for the requested work; audio transcription uses the service described above. Temporary processing files are removed after inspection. Raw shared-file tool results are omitted from saved agent sessions, but replies, summaries, saved insights and recovery backups can retain derived information. Native Share extensions use the app’s device-only Keychain session; unsent drafts stay in memory and are discarded when the sheet closes. Signing out clears the shared device session.
Optional iPhone visits
If you enable Location visits, Sidekin records Apple's approximate visit coordinates, accuracy, and arrival and departure times in a protected index on your iPhone. This is not continuous route tracking. Visits are excluded from device and iCloud backups and kept for up to ninety days, with expired records removed the next time the app handles visits or opens the index. You can delete the local history in the app; signing out removes this account's local visits.
A separate sharing switch lets your cloud agent query limited date ranges while Sidekin is open on that iPhone. The requested visits pass temporarily through our server to the inference provider selected for your agent. We do not maintain a server visit database or retain raw visit tool responses in saved agent history. Your replies, derived summaries and saved patterns may contain location-related conclusions and remain in your account and its recovery backups. Turning sharing off stops future queries; deleting the phone history does not erase conclusions already saved by your agent. An unavailable phone cannot answer a query.
What you connect
We receive your account email and sign-in information through WorkOS. When you connect Google Calendar, we request permission to read your calendar list and events: calendar names, event titles, times, descriptions, locations, and event links. Google account identity is used to distinguish connected accounts. With your additional consent, Sidekin can create personal events through Edit and create, reschedule, or cancel Sidekin bookings on Google calendars you own.
Gmail is optional and requires separate read-only consent. When enabled, Sidekin can search and read messages, threads, headers, labels, and attachments, and observe mailbox changes to help you and surface meaningful updates. This does not grant permission to send or change email.
You can also connect iCloud using an app-specific password or provide a private iCalendar feed URL. Treat these credentials as passwords. Private feeds are read-only. iCloud is read-only unless you separately enable calendar management.
If you connect an external agent through calendar MCP, it can read calendar data for your account. Updating or deleting source events requires both write-enabled agent access and separate provider management permission. Google management requests additional Calendar permission; iCloud management uses CalDAV and supports personal events without attendees or an organizer. Each edit requires a prepared change and the agent's stated user authorization.
What we use it for
Sidekin displays your calendars together and refreshes them in the background. The Unified view identifies duplicate events. To do that, overlapping event details and their calendar labels are sent to TypeSafe/Jev for automated comparison. Usual day boundaries are suggested from calendar history; this analysis uses observed times and supporting event details. Hidden calendars are excluded from these analyses.
Calendar data returned to an external agent is shared with the agent you connect. For calendar management, we store the prepared before-and-after change, its stated authorization, and the recorded outcome.
These features process your connected calendars and email for your own account. We do not sell this data, use it for advertising, or use it to train general-purpose AI models. We do not share your calendar or email with other Sidekin users.
Where it is processed
WorkOS provides sign-in and manages existing Pipes calendar connections. Our server processes calendar data, stores encrypted connection credentials and saved views, and uses TypeSafe/Jev for the features described above. Hosting and backup providers, including exe.dev and AWS, support this service. Cloudflare hosts this public website. These services receive the data needed for their role.
For Gmail, Google remains the mailbox and search provider. Sidekin fetches relevant content on demand and sends it to the agent model selected in your settings (through exe.dev, or verified encrypted inference through Tinfoil). Google Cloud Pub/Sub can deliver mailbox-change identifiers. Email content is not sent to TypeSafe/Jev for calendar deduplication.
We restrict access to the systems that hold your data. Human access to Google data is limited to your affirmative consent, necessary security investigations, or legal requirements. Sidekin uses Google API data only for the features described here, and its use and transfer of that data follows the Google API Services User Data Policy, including its Limited Use requirements.
Retention and deletion
Connection credentials are retained while the connection is active. Saved calendar views expire after seven days without a visit; saved duplicate decisions are bounded per account. Disconnecting removes that connection’s active credentials and clears saved calendar views and analysis results for your account. It does not delete events at Google or Apple.
Sidekin does not maintain a copy or search index of your mailbox. We retain encrypted connection credentials, change cursors, and pending change identifiers and review results needed for reliable processing. Raw Gmail tool responses are omitted from saved agent transcripts; user messages, agent replies, conversation summaries, and concise saved insights can contain email-derived information and remain in Sidekin. Disconnect Gmail stops future access and removes its active cursors and pending changes while preserving your calendar connection. Existing conversations and saved insights remain until removed.
Encrypted recovery backups can retain earlier copies after a disconnect. To request deletion of your account and retained data, including backup copies, email deep@onepatch.dev from your sign-in address. We verify ownership and handle requests directly. Data required for a security investigation or legal obligation may be retained for that purpose.
You can independently revoke Google access in your Google Account, revoke an Apple app-specific password, or reset a private feed URL. Disconnecting in Sidekin stops Sidekin from using that connection; revocation at the provider removes its authorization.
Website and updates
The public website has no advertising trackers or analytics scripts. The app uses cookies for sign-in and connection security, and browser storage for display preferences. Service providers may process technical request information to operate and protect their services.
We will update this page when our practices change and seek consent before using Google data for a new purpose. For privacy questions, contact deep@onepatch.dev.