Effective: July 17, 2026
Facet turns your data into Home Screen and Lock Screen widgets. Privacy is the product's design constraint, not an afterthought.
| Data | Where it's processed | Why |
|---|---|---|
| Calendar events (EventKit) | On device; event fields your widget uses are sent to the Facet service only when a widget requests an AI summary or server-assembled snapshot | To fill widgets like "Morning Brief" |
| Reminders (EventKit) | Same as calendar | Task widgets |
| Location (while using the app, kilometer accuracy) | Coordinates are sent through the Facet service, processed in memory, and used to request weather from Open-Meteo; they are excluded from AI prompts. The last valid fix is cached on device. | Local weather widgets. You can decline; weather then uses a genuine last-known area when available, or asks for location instead of inventing one. |
| Health (steps, active energy, exercise minutes, distance; HealthKit) | Read on device; today's totals are sent to the Facet service only to fill a health widget's numbers, processed in memory, never stored. Health data is never included in AI text generation and never shared with AI providers. | Step/activity widgets you create |
| Connected apps (Gmail, Google Calendar, Notion and others) | You sign in through the provider's own page. A connection is either managed by Composio under an anonymous reference or, for supported direct connections, its tokens stay in the iOS Keychain and are relayed only when a selected widget fetches data. Fields your widget uses are processed in memory and never stored by Facet. | Widgets that show your email, events, or docs |
| Bank data | New bank linking is disabled in the launch build. Facet does not initiate bank connections or fetch, refresh, or use bank data. A dormant plan-neutral cleanup route remains only so a controlled test or migration grant can be revoked before its local credential is erased. | No launch widget feature |
| Anonymous install ID and crash summaries | A random ID (not tied to you or your device identity) accompanies requests for abuse prevention; anonymized crash summaries help fix bugs. | Service protection and reliability |
| Widget prompts and layouts | Sent to the Facet service and its AI provider | To generate/revise your widget design |
| Manual values, RSS/JSON URLs you add | Fetched/processed to fill your widgets | Custom widgets |
| Crash and hang diagnostics (Apple MetricKit) | A count-and-signal summary (no content, no identifiers beyond a random install id) is sent to the Facet service and kept in rotating logs | To find and fix crashes |
| Random install id | Sent with service requests; one-way hashed before the quota counter is stored, and the raw id is not persisted | To meter fair daily AI usage per install; not linked to you |
| Signed StoreKit entitlement proof (product, expiration/revocation status, and anonymous Apple transaction identifiers) | Sent to the Facet service, cryptographically verified against Apple's certificates, processed in memory, and not stored. Its anonymous quota subject is one-way hashed before metering. | To grant the paid plan's service quota and reject forged plan claims |
Widget generation and AI summaries use third-party large language models. A provider receives: your widget prompt, the widget's layout JSON, and the specific data fields the widget declares. Never your credentials, never your whole calendar or inbox, never health data.
Widget creation and revision (your prompts and layouts) run on established AI providers whose API terms exclude using requests for model training.
Per-refresh AI-written widget text (the short summaries an AI widget regenerates from its data) may use fallback endpoints. OpenRouter fallback requests enforce Zero Data Retention and deny provider data collection. Gemini is eligible only when its key is explicitly configured for Google's Paid Services data terms, under which prompts and responses are not used to improve Google's products. Only the data fields that widget declares are included; you can avoid this path entirely by leaving AI writing off on a widget.
Style reference photos you attach when creating a widget are sent to the Facet service and its AI provider once, to style that widget, processed in memory and not stored.
Each widget has a Lock Screen mode: show, redact (values become ••••), or hide.
Facet Pro and Power are auto-renewing subscriptions billed through your Apple ID. Apple processes the payment; Facet never sees your payment details. Facet sends Apple's signed entitlement proof to its service to verify the paid plan and meter its service quota; the proof is not stored. Manage or cancel in iOS Settings → Apple ID → Subscriptions.
Delete any widget and its snapshots in-app; use Disconnect to revoke a supported connected-app grant and remove its local reference or credentials; revoke calendar, reminders, or location access in iOS Settings; all remaining app data is removed when you delete the app. New bank linking is disabled for launch; the dormant bank cleanup path exists only to revoke a controlled test or migration grant before erasing its local credential.
Facet is not directed at children under 13 and does not knowingly collect their data.
facetwidgets@gmail.com
We will update this policy as the product adds accounts, sync, or new connectors, and note material changes in the App Store release notes.