Smirk is a calendar for iPhone made by Vennory LLC. This policy explains what we collect, why, who sees it, and how to delete it. It is written to be read.
Vennory LLC ("Vennory," "we," "us") is the controller of the personal data described here. This policy covers the Smirk app for iPhone and iPad, the smirk.co website, public booking pages at smirk.co/<username>/<link>, time-offer links at smirk.co/t/<code>, and the servers behind them (together, "Smirk"). Vennory's other websites and products have their own policy.
Smirk is a Google Calendar client. When you grant access we use these Google APIs:
| Google data | What we access | What we do with it |
|---|---|---|
| Google Calendar | Your calendar list, events (titles, times, attendees, locations, descriptions, conferencing links), and free/busy times. | Show your calendar in Smirk; create, edit, and delete the events you manage in Smirk; write confirmations for meetings booked through your booking links and time offers; compute which times are free on your booking pages. |
| Google Contacts (read-only) | Names, emails, phone numbers, photos, addresses, birthdays. | Read once, only when you tap Import, to create people entries in Smirk. Never read in the background. |
| Google Tasks (read-only) | Task titles, notes, due dates, completion status. | Read once, only when you tap Import, to create todos. Never read in the background. |
Smirk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the features you see in Smirk. We do not sell it, do not use it for advertising, do not let humans read it except with your permission, for security, or as required by law, and do not transfer it to third parties except as needed to run Smirk (Section 4) or as the law requires. You can revoke Smirk's access at any time at myaccount.google.com/permissions.
Server-side calendar access. Booking pages need to stay accurate while the app is closed. When you turn on "Keep availability fresh" for a booking link, Smirk stores a Google Calendar credential for that account on our servers, reads that account's free/busy times server-side, and keeps a cache of busy intervals so your public page can show open slots. Our servers also write confirmed bookings and time-offer confirmations to your Google Calendar. If you never turn this on, calendar access happens only on your device.
You can change any of these in iOS Settings at any time. Smirk does not request your device location.
Guests who use a booking page give us their first and last name, email address, the time they chose, their time zone, and an optional note. Recipients of a time-offer link give us their email address. We use this to create the calendar event, send the invitation, and show the booking to the host. Guests do not need a Smirk account, and this policy applies to their data too.
Smirk contains no advertising SDKs, does not use the Apple advertising identifier (IDFA), and does not track you across other companies' apps or websites.
For people in the EU, UK, and similar jurisdictions, our legal bases are: performance of our contract with you (running the service), your consent (Google and device permissions, notifications), our legitimate interests (security, analytics, improving the product), and legal obligations.
We do not sell personal information and never have. We do not share it for advertising. We share it only with:
Smirk is sold as an auto-renewable subscription through Apple's App Store. Apple processes the payment; we never see your card or billing details. To keep your subscription working on every device you sign in on, we verify it server-side with Apple's App Store Server API and App Store Server Notifications, and we store the product purchased, the paid-until date, Apple's transaction identifier, and a record of each verified notification. Manage or cancel the subscription in your Apple Account settings.
Your account data lives on Google Cloud servers in the United States. If you are outside the United States, your data is transferred there; for EU and UK users we rely on Standard Contractual Clauses and our providers' data-protection commitments. Data is encrypted in transit (TLS) and at rest. Server-side calendar credentials are stored in a restricted collection that only our functions can read.
You can also ask us to delete or export your data by contacting us (Section 11). We verify requests before acting on them.
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, to withdraw consent, and to complain to a data-protection authority. You can exercise most of these directly in the app; for anything else, contact us. We respond within the time the law requires and never discriminate against you for exercising a right.
California residents. The CCPA gives you the right to know what personal information we collect and how we use and share it (this policy), to delete it, to correct it, and to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. We do not knowingly collect personal information of consumers under 16.
Smirk is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us data, contact us and we will delete it.
When we change this policy we update the date at the top and, for material changes, tell you in the app or by email before they take effect. The current version is always at smirk.co/privacy.
Vennory LLC
United States
vennory.com/contact