Back to Home

Privacy Policy

Effective Date: May 7, 2026

1. Introduction

The Calm File ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using the Service, you consent to the practices described here.

Our core commitment: Your family's sensitive information belongs to you. We will never sell your personal data to third parties. We collect only what is necessary to provide the Service.

2. Information We Collect

2.1 Information You Provide

When you use the Service, you may provide:

  • Account information (name, email address)
  • Personal and family information you enter into the binder sections (emergency contacts, medical information, financial account references, legal document locations, etc.)
  • Documents and files you upload to the Service
  • Payment information (processed securely by Stripe we do not store full card numbers)
  • Communications you send to us

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

  • Log data (IP address, browser type, pages visited, timestamps)
  • Device information (device type, operating system)
  • Usage data (features used, session duration)
  • Cookies and similar tracking technologies for authentication and session management

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Authenticate your identity and manage your account
  • Process subscription payments through Stripe
  • Send you service-related notifications (account updates, security alerts)
  • Respond to your support requests and communications
  • Analyze usage patterns to improve the Service (using aggregated, anonymized data)
  • Comply with legal obligations

We do not use your personal binder content for advertising, marketing profiling, or AI model training without your explicit consent.

4. How We Share Your Information

We do not sell your personal information. We may share information only in the following circumstances:

  • Service providers: Third-party vendors who help us operate the Service (e.g., Stripe for payments, cloud storage providers), bound by confidentiality obligations
  • Family members you invite: Information you explicitly share with family members through the Family Access feature
  • Legal requirements: When required by law, court order, or governmental authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to you
  • Safety: To protect the rights, property, or safety of The Calm File, our users, or the public

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption in transit (TLS/HTTPS) for all data transmitted to and from the Service
  • Encrypted storage for sensitive fields (Social Security Numbers, account numbers)
  • Secure authentication via OAuth 2.0
  • Role-based access controls for family sharing features
  • Regular security reviews and monitoring

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes (such as resolving disputes or preventing fraud).

7. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal retention requirements)
  • Portability: Request your data in a portable format
  • Opt-out: Opt out of non-essential communications
  • California residents (CCPA): Additional rights including the right to know, delete, and opt out of sale of personal information
  • EU/UK residents (GDPR): Rights of access, rectification, erasure, restriction, and objection

To exercise these rights, contact us at [email protected].

8. Cookies

We use cookies and similar technologies for authentication (session cookies), security, and basic analytics. We do not use third-party advertising cookies. You can control cookie settings through your browser, but disabling essential cookies may affect the functionality of the Service.

9. Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at [email protected].

10. Third-Party Services

The Service integrates with third-party services including Stripe (payment processing) and OAuth providers (authentication). These services have their own privacy policies, and we encourage you to review them. We are not responsible for the privacy practices of third-party services.

11. AI Features

The Olivia AI assistant uses a large language model to provide preparedness guidance. Conversations with Olivia may be processed by our AI provider to generate responses. We do not use your personal binder data to train AI models. Olivia's responses are for informational and organizational purposes only and do not constitute professional advice of any kind.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. For significant changes, we will provide additional notice (such as an email notification). Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team at [email protected].