Privacy policy · July 14, 2026

Your work stays local.

HourSift does not operate an account or backend service. Optional Google Mobile Ads use SDK-required technical data after consent; Calendar contents and calculations stay local.

Calendar access

With your permission, HourSift reads only the device calendars you select. On iPhone and iPad it uses Apple EventKit with Calendar Full Access. On Android it uses the system Calendar Provider with the read-only READ_CALENDAR permission and queries concrete occurrences through CalendarContract.Instances.

HourSift uses the minimum facts needed to build and review a timesheet: Calendar identifier and display name; a temporary source or account label used only to distinguish same-name calendars; event/provider identifier; recurrence or occurrence anchor when available; title; start and end time; time zone; and all-day or cancellation state. It does not read event notes or descriptions, locations, or attendees. It never creates, edits, or deletes Calendar events. Temporary source or account labels are not included in exports or long-term history.

Data stored on your device

Client and project settings, rates, mapping rules, reviewable draft facts, export summaries, and event fingerprints are stored in the app container. The Apple app uses its local app data store. The Android app uses Room for business records and DataStore for lightweight preferences and selected Calendar identifiers. HourSift does not create a complete Calendar mirror or synchronize or migrate app data between devices or platforms. Sample data is temporary and separate from saved business data.

Export history keeps report summaries and occurrence fingerprints for duplicate and change warnings; it does not keep copies of exported PDF or CSV files or a long-term copy of complete Calendar event text.

Local processing and advertising

HourSift contains no account, authentication, backend, developer analytics, tracking, crash-reporting, AI, or cloud-sync SDK. The main app may use Google Mobile Ads and Google UMP after consent. Google may process SDK-required technical data for consent, ad delivery, frequency control, fraud prevention, and aggregated measurement; it does not receive Calendar contents, client names, project names, rates, drafts, or exports. App data remains inside the platform app sandbox unless you choose a save or share destination. A one-time US$1.99 purchase removes ads permanently.

Saving and sharing

PDF and CSV files are created locally from the report you reviewed. On Apple devices, a file leaves HourSift only when you choose a destination in the system Share Sheet. On Android, saving uses the system document picker and Storage Access Framework; sharing uses a narrowly scoped FileProvider content URI and the system Sharesheet. Only the destination you choose receives the file, and HourSift does not receive it. That destination’s privacy practices then apply. Temporary HourSift staging files are removed when the export flow ends; a copy saved outside HourSift is controlled by its destination.

Retention and your controls

Local clients, projects, rules, drafts, and export summaries remain until you delete the relevant record, use Delete All App Data, or uninstall HourSift. You may remove one history record, all history, a client and its related local records, or all app data. Uninstalling removes the app container but does not remove copies you previously saved elsewhere.

Revoking Calendar permission immediately hides event text, stops active reads, and invalidates the current export snapshot. Revocation does not itself delete local settings or drafts; use the in-app deletion controls if you also want to remove those records.

Contact

Questions can be sent to support@iagent7.com.