Security
Last updated: August 11, 2026
Your plans are personal, and we treat them that way. eudy is built on trusted, industry-standard infrastructure, and we keep the design deliberately simple: we collect little, and we never sell your data. This page explains the main measures that protect your information.
Encryption
All traffic between your device and eudy is encrypted in transit using HTTPS (TLS). Your account data and content are encrypted at rest within our cloud infrastructure provider's managed storage.
Trusted infrastructure
eudy runs on Google Cloud Platform via Firebase, including Firebase Authentication and the Cloud Firestore database. This means your data is hosted in Google's secure, professionally operated data centers, with the physical, network, and redundancy protections Google maintains for its cloud services.
Account access
You can sign in with Google or with Apple (each handled by that provider's own sign-in flow, so eudy never sees your Google or Apple password), or with an email address and password. Authentication is handled by Firebase Authentication. Access to your content is scoped to your account, and our database security rules are configured so that you can only read and write your own data, apart from anything you deliberately choose to share.
Shared days
If you share a day, eudy publishes a read-only copy of that one day, reachable only through a random link you choose to hand out. It is not a public page: whoever opens it must be signed in, and you must approve that specific person before they can see anything, so a link that goes astray shows nothing on its own. Links expire after 30 days, and expiry is enforced by our database rules rather than by the app, so an expired link cannot be read at all. Links cannot be guessed or found by searching, and you can stop sharing at any time, which deletes the shared copy.
Connected calendars
If you connect an external calendar, the private feed address you provide is treated as a credential: it is masked after you enter it, it is never recorded in our server logs, and it is removed when you disconnect the calendar or delete your account. Calendar events pass through our server to your device without being stored or logged on our servers, and the copy your device keeps is removed when you disconnect.
Secure payments
Purchases are handled by established payment providers: Stripe on the web, and the Apple App Store or Google Play within the mobile apps. Card details are entered and processed by these providers, which maintain PCI-DSS compliance; eudy never receives or stores your full payment card number.
Data reliability
Your content is stored in Google's managed Cloud Firestore, which replicates data across infrastructure to guard against loss. Because the planner also stores a copy on your device, your current week remains available even when you are offline.
Your controls
You can review and edit your data at any time within the app, and you can permanently delete your account and its associated content from the Settings screen. See our Privacy Policy for details on what we collect and how it is used.
Reporting a vulnerability
We welcome reports from the security community. If you believe you have found a security vulnerability in eudy, please email security@eudy.app with the details and steps to reproduce. Please give us a reasonable opportunity to investigate and address the issue before any public disclosure, and avoid accessing or modifying other users' data. We appreciate responsible disclosure.
Questions
For any security or privacy question, contact us at security@eudy.app.