Privacy Policy
Effective: 2026-12-01
Candelina is a birthday reminder app for iPhone. It is built so that the people you care about stay on your iPhone and, when you are signed into iCloud, in your own iCloud account and nowhere else. This policy explains exactly what the app does with data, in plain language. If anything here is unclear, write to us — the address is at the bottom.
The short version
- There is no Candelina account. You never create one, and we never see a login.
- Your people, dates, notes and history are stored on your device and, if you use iCloud, in your own private iCloud database. We cannot read them.
- AI drafts are switched off until you explicitly allow them. When on, a small, specific set of fields is sent to Anthropic to write the draft — never your contact list.
- We do not sell data, we do not run ads, and we do not track you across apps or websites. Candelina does not ask for tracking permission because it does not track.
Data that never leaves your device
The core of the app is local. The following is stored on your iPhone and, when you are signed into iCloud, in your own iCloud account (Apple's CloudKit private database), which is encrypted and tied to your Apple Account:
- Names, nicknames and photos of the people you add.
- Birthdays and other yearly dates, and the reminder plan for each.
- Your notes, gift ideas, gift log and the history of wishes you have sent.
- Your own name and birthday, if you enter them.
- App settings such as digest day and time, and the languages you choose.
Deleting the app removes the local copy. To remove the iCloud copy as well, use Settings inside the app before deleting, or delete Candelina's data from your iCloud settings.
Importing birthdays
Candelina can read birthdays from sources you choose. In every case the reading happens on your device, and only the birthdays you confirm are saved into the app.
Contacts and Calendar are read through Apple's system permissions; you can pick individual people instead of granting full access. Files you import (a Google Contacts CSV, a WhatsApp chat export, a calendar file, a PDF, a plain list) are parsed locally and never uploaded. Screenshots are read with Apple's on-device text recognition; the image is not sent anywhere and is not stored by the app.
If you ask Candelina to save a birthday back into your Contacts, it writes only the date, only to the contact you chose, and only when you tap the button.
AI drafts
Writing a wish is optional and works in three tiers. Templates that ship with the app work offline and send nothing. On newer iPhones, Apple's on-device model can write drafts without any network request. For the remaining languages and devices, drafts are written by Claude, a model by Anthropic, through our own server.
The cloud tier is off until you allow it in a screen that names Anthropic explicitly, and you can turn it off again at any time in Settings. There is no account and no identifier for the person you are writing to: the request carries the words needed to write the wish and nothing that ties two requests to the same friend. In full, one request contains:
- The recipient's first name (or the nickname you gave them).
- Your relation tag, such as family or work.
- Their gender, used only to get the grammar right, and the age they turn.
- The tone and language you picked, and whether it is a milestone birthday.
- The one-line note you typed or dictated, if any.
- The text you sent last year, so the model does not repeat it.
- Your own first name, if you set it as a signature.
- The current year, and whether you are catching up on a birthday that has passed.
Your contact list, phone numbers, photos and the rest of your people are never sent. Under Anthropic's commercial API terms, data sent through the API is not used to train their models. Our server does not store the text of requests or drafts; it keeps only a monthly counter tied to a pseudonymous device token so that the free allowance can be enforced. Dictation uses Apple's speech recognition, on device where your iPhone supports it.
The Collector link
You can share a link that asks friends for their own birthday. When someone opens it and submits the form, their name and date are stored briefly on our server so your app can pick them up, and are deleted after delivery or when the link expires. The page tells them this before they submit. Only you receive what they send. You can reset the link at any time, which invalidates the old one.
Analytics and diagnostics
Candelina uses TelemetryDeck, a privacy-focused analytics service based in Germany, to understand how the app is used — never who is in it. Each event is a name plus a few short details: an onboarding step completed, whether notifications were allowed, an import finished and how many birthdays it found, reminders rescheduled, a wish marked as sent, a card shared or saved, an export done, which paywall or locked feature was shown, a trial or purchase started and for which product, the source, tone and language of a draft, and the app's language.
Names, birthdays, notes, contacts, phone numbers, the text of your wishes and anything that identifies the people in your list are never sent. The app sends no device or user identifier; TelemetryDeck derives its own pseudonymous one from a salted hash on your device. This data is not linked to your identity, and it is never sold or passed to a data broker. There is no setting in the app to turn this off today, but you can always write to us about this data. Crash reports come from Apple's own system, and only if you have chosen to share them with developers in your iPhone settings.
Candelina does not use the Advertising Identifier and never shows the App Tracking Transparency prompt, because it does not track you across other companies' apps or websites.
Purchases
Subscriptions and the lifetime purchase are handled by Apple, and we never see your payment details. Whether you have Unlimited is checked on your device against Apple's own signed receipt — there is no third-party subscription service in between. When you use cloud drafts, that signed proof of purchase travels with the request so our server knows to lift the monthly limit. It proves a purchase, not an identity, and it is not stored.
Who processes data for us
We use a small number of providers, each for one clearly defined job:
- Apple — App Store purchases and subscriptions, iCloud sync, push notifications, App Attest device verification.
- Cloudflare — our AI proxy server, this website, and email forwarding for the support address.
- Upstash — the counters that enforce the free monthly allowance for AI drafts.
- Anthropic — writing AI drafts, only after you allow it.
- TelemetryDeck — privacy-focused product analytics: how the app is used, never the people in it.
How long things are kept
- On your iPhone, and in your iCloud when you are signed in: until you delete them.
- AI draft requests: not stored. Only a monthly counter per device, reset each month.
- Collector submissions: deleted after they reach your app, and in any case when the link expires.
- Analytics: usage events under a pseudonymous identifier, never your people. TelemetryDeck keeps them under its own retention rules; we only look at aggregated usage statistics.
Your rights
Because Candelina keeps your list on your own device, you are in control of it directly: you can edit, export or delete everything from inside the app at any time. Export gives you a CSV or JSON copy of your data.
For anything held on our side — the AI quota counter and any Collector submissions in flight — you can ask us to delete it, and the app also offers a one-tap deletion in Settings. If you are in the EU or UK, you have the right to access, correct, delete and port your data, and to complain to your local data protection authority. Write to the address below and we will answer within 30 days, usually much sooner.
Children
Candelina is not directed at children and does not knowingly collect data from them.
Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top always shows the current version.
Contact
Questions, requests, or something that looks wrong — write to privacy@candelina.app and a human will reply.