Privacy
Last updated: September 30, 2026
Hold That is a place to keep your own things. Here is exactly how your information is treated — in plain words.
What we collect
Your email address, to sign you in, and your name if you give one. The things you put in the app — thoughts, tasks, events, lists, notes, goals, and the times you set. And, if you sync a calendar, the events from it, so they show on your days on every phone you sign into.
Where it lives
Your words are stored in a secured database (hosted by Supabase), scoped so that only your signed-in account can ever read your rows. Pictures and files you add are stored in your account, in a private folder only your signed-in account can read. They are never used for anything else, and they are deleted with your account. Videos stay on the phone that took them.
What we don’t do
No analytics. No tracking. No ads. No selling or sharing your data with anyone, ever. The app has no push notifications. Every reminder or alarm is created on your device, from a time you set. The one thing the app fetches on its own is the title of a link you share in, from that site. Add to calendar writes that one event to the calendar you chose, and nothing else.
Google Calendar
If you connect Google Calendar, Hold That asks Google for two permissions: to see your calendars and their events (calendar.readonly), and to add events (calendar.events). It also learns which Google account you connected (your email address), so Settings can show it.
How Google user data is used
The events from the calendars you switch on are shown on your days in the app, next to your own things, and kept in your Hold That account so they appear on every phone you sign into. Add to calendar writes the one event you chose to the one calendar you picked, and never edits or deletes anything else on your calendar. That is the whole use. Your Google data is never sold, never shared with anyone, never used for advertising, and never used to train AI or machine-learning models. It is used only for the features described here, which you can see in the app.
How Google user data is protected
The keys Google issues to Hold That are stored in your phone’s secure keychain, filed under your account, and never on our servers: the app talks to Google directly. The only Google data that reaches our servers is the synced events themselves (title, day, time, place, and Google’s id for the event). They travel over encrypted connections (HTTPS) and are stored encrypted at rest in a secured database (hosted by Supabase), protected by row-level security so that only your signed-in account can read your rows. No one at Hold That reads your data; there is no admin view of it. On a shared phone, each person’s Google connection is kept under their own account and is never used by anyone else.
Retention and deletion of Google user data
Synced events are shown only while Google Calendar is connected and that calendar is switched on. Disconnect Google in Settings asks Google to cancel Hold That’s access, deletes the keys from your phone, and takes its upcoming events off your days; what already happened, and what you answered, stays in your history. Switching a calendar off does the same for that calendar. A removed event’s record is kept in your account marked as deleted, so your phones agree on what left, until you delete your account. Delete my account in Settings erases your entire account, including every synced event and its history, right then; our database host’s routine backups expire on their own within days. Your phone’s own copy is gone when you delete the app. Events that Add to calendar put on your Google calendar stay there; they’re yours, and Hold That never deletes anything on Google. You can also remove Hold That’s access at any time from your Google Account’s third-party access page. Email us and any of this is done for you.
Hold That’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The Claude connector
If you add Hold That to Claude (Anthropic’s assistant), you sign in with your Hold That account on holdthatapp.com, and Claude can then read your account — your things, lists, days, counters and pictures — and hold, move, dress or mark things the way the app does. It works only for the account you signed in with, under the same rules as the app: your rows, no one else’s. The connector keeps nothing: each request is answered from your account and not stored. What Claude retains of what it reads is set by your Claude account, not by us. Remove the connector in Claude’s settings and its access ends. How to set it up is on the connector page.
Your data is yours
You can export everything you’ve written as a single file, anytime, from Settings in the app. Pictures aren’t in it — they’re in your account, and on your phone. If you want your account and everything in it deleted, Delete my account is in Settings in the app: two taps, and it’s gone from every phone, right then. Or email us and it’s done.
Questions
Write to [email protected].