Privacy Policy
Last updated: 22 September 2026
This policy explains how Then: Voice to Calendar processes information in its mobile app, backend, and connected services. Questions and requests about your data can be sent to join@mitacore.co.
Information used to provide Then
Then processes account identifiers, app settings, calendar items, email actions, voice recordings, and information you choose to provide in typed or spoken requests. Connected-service credentials and tokens are stored using secure storage; they are not analytics data. We do not use Google user data for advertising or sell it.
Google Calendar and Gmail
If you separately connect Google services, Then requests access to read calendars you can access and to send email on your behalf. Calendar information is used to show your schedule and help interpret requested actions. Gmail send access is used to deliver only messages you explicitly authorize, including messages you choose to schedule. Then does not request Gmail inbox-reading access. We do not share Google user data with OpenAI unless you separately authorize an AI request and the minimum calendar context is necessary to interpret it.
You can disconnect Google services in Then or revoke Then's access in your Google Account. This stops future access, subject to information already needed for a confirmed scheduled action or legal obligations.
OpenAI processing
Before the first AI request, Then presents a separate notice. If you agree, a selected typed request or submitted audio and the minimum context needed to interpret it are sent securely through our backend to OpenAI for transcription or planning. Canceling the notice sends nothing. OpenAI returns a proposed operation; it does not directly edit a calendar or send email.
Diagnostics
Then may collect technical events needed to operate, secure, and improve the service, such as app version, device/OS category, feature usage, permission outcomes, errors, crashes, and performance. Diagnostics must not include raw audio, commands, event titles or notes, email or message bodies, contact records, precise calendar content, authentication tokens, or provider secrets.
Storage and retention
Information is transmitted using encrypted connections. Access is limited to people and systems that need it to operate and protect the service. Account and action data are retained while needed for the service and applicable security or legal obligations. You may request access, correction, or deletion by emailing join@mitacore.co. You may revoke connected-provider permissions in the app or provider settings.
Children and international processing
Then is not directed to children below the minimum age required in their distribution region. Service providers may process information in other countries, subject to applicable safeguards.
Changes
Material changes to data use will be disclosed in the app and may require renewed consent.