SotiDo™ is the product name used for this service and is operated by a private individual based in Indonesia.
Introduction
SotiDo™ (the “Service”) is available on the web, as a Telegram Mini App, and through native iOS and Android apps. It lets people discover events, create and manage calendars and events, and share selected content. This Privacy Policy explains what information we collect, how we use it, how it is stored, and under what circumstances it may be shared.
By using the App, you agree to the collection and use of information in accordance with this Privacy Policy.
Data We Collect
We collect only the data necessary to operate the App and provide its features:
- Identity and Authentication Information. You may sign in with an email address and a one-time code, or through Google, Apple, or Telegram. Provider sign-ins may give us your name, display name, avatar/profile photo, email address, and a provider-specific user identifier. Email-code sign-in stores your normalized email address and does not require us to store an account password. If you create a passkey, your device or credential provider keeps the private credential; SotiDo stores only the public credential material and limited security metadata needed to authenticate you. We do not receive your biometric data or passkey private key. This information is used to create or link your account across platforms and to display your identity within the App.
- Calendars and User Content. The Service stores content you choose to create, including calendar and event titles, descriptions, dates, times, places, participants, private notes, saved contacts, reports, and moderation submissions. You may also attach photos or videos to supported event surfaces. If you choose to import your Google Calendar data (via Google OAuth with your permission), we access your Google Calendar events and related details only when you request the import. These event details may be stored in our database so that you can view and manage them in the App.
- Places and Optional Location Use. Places, addresses, and map pins that you manually add to calendars or events are stored as user-created content. The web version may ask for browser location access, and native apps may ask for device location access, when you explicitly choose nearby discovery, Globe centering, or automatic time-zone help. That location is used to service the active request or session and is not saved as persistent account or home coordinates.
- Usage Data and First-Party Analytics. We may record product interactions and operational information, such as page or event views, feature actions, timestamps, and login activity, to provide owner statistics, maintain the Service, prevent abuse, and troubleshoot issues. We do not use third-party advertising analytics or advertising pixels.
- Reports and Moderation Data. If you submit a content report or if content is reviewed for abuse-prevention purposes, we may store the report text, reason code, timestamps, your account identifier, internal review notes, and limited snapshots of the reported content.
The current first-release native apps do not offer digital-goods purchases and do not collect payment-card or banking information.
How We Use Your Data
We use the collected data solely to provide, maintain, and improve the core functionality of the App. Specifically:
- Providing Services. Identity information is used to authenticate you and allow you to securely access your calendar. Your display name and avatar may be shown to you and (only when you share events) to those specific people you share with. Calendar event data is used to display your schedule and enable sharing/collaboration when you request it.
- Synchronization. If you link Google Calendar, we use your OAuth authorization to fetch your calendar events and show them in the App. This data is used only to synchronize events when you ask us to.
- Operation and Improvements. We may use usage data and aggregated, non-personal information to debug issues, monitor performance, and improve features. This data is never used for advertising, promotional targeting, or behavioral profiling.
- Safety, Abuse Prevention, and Legal Compliance. We may use account data, event data, reports, and moderation logs to detect spam, investigate complaints, enforce our Terms, protect users and rights holders, and comply with legal obligations.
We do not use personal data for advertising, profiling, or promotional targeting. We do not sell or rent personal information.
Third-Party Service Providers
To operate the App, we rely on a few trusted third-party services. We share data with these providers only as needed:
- DigitalOcean-hosted infrastructure. We operate the Service on self-hosted infrastructure running on DigitalOcean. User data (including account information and calendar events) may be stored in our managed application databases and storage systems only as needed to provide the Service.
- Google APIs (OAuth & Calendar API). Used for Google Sign-In and (if you request it) importing calendar events. We do not use Google data beyond what is necessary for these features.
- Telegram Platform. If you use the App as a Telegram Mini App, Telegram provides your Telegram user ID and basic profile data. We use it to identify you. Telegram’s own privacy policy governs data Telegram collects.
- Apple Sign In (if used). Used to authenticate you. Apple may share your name and (optionally) email address, depending on your settings.
- Transactional email delivery. We currently use Postmark to deliver one-time sign-in codes and essential account messages. The provider receives the destination email address and message content needed to deliver that email; it does not receive your SotiDo session cookie or passkey private key.
- First-Party Analytics. The Service does not use third-party analytics tags or advertising pixels. We rely on first-party product analytics and internal reporting for service statistics.
We do not share your personal data with third parties beyond what is necessary to provide the Service.
Analytics
The Service does not use third-party analytics tags or advertising pixels. We use first-party product analytics and internal reporting to understand service usage, owner statistics, and operational trends.
If you use the Service as a Telegram Mini App, Telegram platform policies and Telegram Mini App environment analytics may still apply inside Telegram.
Data Sharing and Disclosure
We do not sell or share your personal information for advertising, profiling, promotional targeting, or unrelated purposes.
We may disclose data only in these cases:
- Service operation — to the providers listed above, only as needed.
- Legal requirements — if required by law, regulation, or valid legal process.
- Protection of rights — to prevent fraud/abuse, review reports, respond to rights-holder complaints, or protect users and the Service, in accordance with applicable laws.
If you share events with other users, event information you choose to share will be visible to those recipients. The App does not share your events with others by default.
Data Security
- Encryption in transit. Communications use HTTPS/TLS.
- Access controls. We apply authentication and access rules to prevent unauthorized access.
- No guarantee. No method of transmission or storage is 100% secure, but we work to protect your data.
Data Retention and Deletion
- Retention. We retain data as long as needed to provide the Service, unless deletion is requested.
- User-requested deletion. You can delete your account in the app settings when you are signed in, or use the public account deletion request page at /account/delete. You can also request deletion of your account and associated data by contacting us. We may need to verify your identity before processing the request.
- Google permissions. You can revoke Google access in your Google Account settings at any time. Revoking access stops future imports/sync; previously imported data may remain until you delete it or request deletion.
- Backups. Residual copies may persist in encrypted backups for a limited period before being purged.
Payment Processing
The current first-release native apps do not offer digital-goods purchases. If paid features are enabled in a future release, payment details will be entered through the applicable platform or payment provider rather than stored by SotiDo, and this policy and the relevant store disclosures will be updated before that feature is released.
Your Rights and Choices
- Access and update. You can manage your events in the App.
- Revoking permissions. You can revoke third-party access (Google/Apple/Telegram) in the respective account settings.
- Account deletion. You can delete your account in app settings, use /account/delete, or contact us (see below).
Children’s Privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information, contact us to request deletion.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the effective date at the top of this page. Continued use of the Service after changes means you accept the updated policy.
Contact Us
If you have questions or requests (including deletion), contact: [email protected] or [email protected]