Privacy Policy
Last updated 20 August 2026
Holt reads the school, sports, and activity email a parent already receives so they can ask what is happening this week and get an answer, instead of searching their inbox for it. To do that it has to read your mail, so this policy is specific about what Holt reads, what it keeps, who it shares it with, and how you get rid of it.
Holt is operated by the developer of Holt. Questions, requests, and complaints: privacy@checkholt.com.
1. What we collect
Information you give us
- Your email address, used as your account identifier and to send you sign-in codes and your brief.
- Household details you enter: your children's first names, their schools, teams, and activities, and which organisations belong to which child. You choose what to enter; a nickname works as well as a legal name.
- Settings: brief timing, notification preferences, which senders to capture or ignore.
Information from mailboxes and calendars you connect
When you connect a mailbox, Holt reads incoming messages in order to find school and activity mail. It reads broadly and keeps narrowly. From a message that matches a sender you have confirmed, Holt keeps:
- the extracted item — a title, date, time, location, amount, and whether something is due from you;
- the sender address and the message's identifier, so an update to the same event can replace it rather than duplicate it;
- a short opening excerpt of the message an item came from, so you can see why Holt thinks practice moved.
Holt does not store the full text of your messages, and does not store attachments. A message that matches no confirmed sender leaves behind at most the sender address, the subject, and a short snippet, in a review list so you can decide whether that sender matters. If you ignore a sender there, Holt sets it aside and stops asking about it — it does not process that sender's mail, and it keeps the noted sender, subject, and snippet only so it does not raise the same sender with you again. Those records are removed when you delete your data.
Information collected automatically
- Session cookies that keep you signed in.
- Operational logs — timestamps, error messages, and counts of messages processed — used to keep the service working. Logs are not used to build a profile of you.
- First-party product analytics. Holt records its own app-activity events — which route pattern was hit, the response status, how long it took, and the account and household it belonged to — in our own database, to keep the service working and understand how it is used. These events are scrubbed of email content: they never carry a message body, subject, sender, name, or credential. Nothing is sent to a third-party analytics or advertising service, and these records are erased when you delete your account.
2. Google user data
Connecting a Google account is optional. If you do, Holt requests exactly two permissions, and uses each one for a single purpose:
| Permission | Scope | What Holt does with it |
|---|---|---|
| Read your email messages and settings | gmail.readonly |
Reads incoming mail to identify school, sports, and activity messages and extract the dates, deadlines, payments, and forms in them. Also reads your Gmail address once, at connection time, so the app can show you which mailbox is connected. Holt never sends, replies to, modifies, labels, archives, or deletes anything in your mailbox. |
| Manage events on your Google Calendars | calendar.app.created |
Lets Holt create its own “Holt” calendar in your Google account and add, update, or cancel events on that calendar only. This scope grants access solely to calendars Holt itself created, so Holt is structurally unable to read, change, or delete events on your other calendars, and it cannot see or change your calendar settings or sharing. You can hide or delete the Holt calendar anytime. |
Holt requests read-only access to Gmail because it needs the body of a message to find a time, a place, and a deadline. Metadata-only access — sender, subject, and date — cannot answer "what time is the bus", which is the entire point of the product.
Limited Use
Holt's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means Holt does not:
- sell, rent, or trade your Google data;
- use it for advertising, retargeting, or ad personalisation;
- use it to develop, train, or improve generalised or general-purpose AI or machine learning models;
- transfer it to anyone other than the service providers listed below, and then only as needed to run Holt for you, or where you direct it, or where the law requires it.
No human at Holt reads your messages, with these narrow exceptions permitted by the policy: where you have given explicit consent for a specific message (for example, when you send us a support request about something Holt got wrong); where it is necessary for security purposes, such as investigating abuse; where the law requires it; or where the data has been aggregated and de-identified so that it no longer relates to you.
3. Automated processing, and the model behind it
Holt uses a large language model to turn a message into a structured item. This is the only place your message content leaves Holt's own infrastructure, so it is worth being exact about it.
Your email is never used to train an AI model
Extraction runs on Anthropic's commercial API. Under Anthropic's Commercial Terms of Service, inputs and outputs submitted through the API are not used to train Anthropic's models. That is a contractual commitment we rely on, not a setting we hope is switched on. Holt does not use consumer AI products, does not paste your mail into a chat interface, and does not have — or want — any arrangement that would let a model learn from your family's mail. Holt does not train models of its own.
What actually gets sent
- In ongoing processing, only messages from a sender you have confirmed as a school, team, club, or activity. Everything else is matched in memory and never sent anywhere. (The one exception is the optional discovery scan described just below, which you start yourself.)
- The subject line, the message's own text, and the text of any attachments on that confirmed message.
Holt reads text attachments — PDFs, plain-text, and HTML files — and sends their text along with the body,
because the schedule a parent needs often lives only in the PDF. Calendar (
.ics) invites are parsed on our side and not sent. Quoted reply chains are stripped first, and long requests are truncated. - Nothing about you is attached to it: no name, no email address, no child's name, no account identifier, not even your timezone. The request carries the subject, the message text, and the date the message was sent (so a phrase like “this Friday” can be turned into a real date) — and nothing more. Which child an item is for is worked out afterward on our side, not by the model.
Finding your senders: the discovery scan
To spare you typing every sender in by hand, Holt offers an optional scan, which you start, that suggests which senders already in your mailbox look school- or activity-related. It reads envelopes only — sender addresses, display names, and subject lines — and never fetches or stores message bodies. To categorise the shortlist it sends the model each candidate's address and a few sample subject lines; it does not send any message body, and it does not send a child's name. The scan produces a list of suggestions; a sender only enters the processing described above once you confirm it.
What happens to it afterwards
Anthropic processes the request and returns the extracted items. It acts as our processor, bound to use the content only to serve that request. Extraction results are cached on our side against a hash of the message text, so the same newsletter is not processed twice; the cache holds the extracted items — a title, a date, a place — never the original message, is not linked to any account, and is cleared after 90 days without use.
If you want to check any of this rather than take our word for it, ask us at privacy@checkholt.com. We will tell you exactly which model version ran, what was sent, and what came back.
4. Service providers
| Provider | Purpose | Data involved |
|---|---|---|
| Render | Application hosting and the database | All stored Holt data |
| Anthropic | Extracting items from message text | Message text, transiently |
| Resend | Sending sign-in codes and briefs | Your email address and brief content |
| The mailbox and calendar you connect | As described in section 2 | |
| Apple (APNs) | Delivering push notifications to the Holt iOS app | The notification text — currently a child's first name and the item's title |
Each is bound by contract to use the data only to provide their service to Holt. Beyond these providers Holt has no other recipients, and uses no third-party analytics, advertising, or tracking services — the only analytics is the first-party product analytics described in section 1.
Push notifications and Apple's APNs
If you use the Holt iOS app and turn on notifications, alerts are delivered through Apple's Push Notification service (APNs). To be useful at a glance, a Holt notification currently includes the child's first name and the item's title. Apple transmits notifications over an encrypted connection and, if your device is offline, may hold the most recent notification for up to 30 days before delivering it and then discards it. APNs is not end-to-end encrypted — Apple's servers relay the notification — and Apple does not publicly state how it handles notification content. You can turn this off in the iOS app's notification settings, so alerts carry no child's name or details and instead just prompt you to open Holt. Read Apple's APNs documentation.
5. How your data is protected
- All traffic is served over HTTPS.
- Mailbox credentials and OAuth refresh tokens are encrypted before they are written to the database, with a key held outside it.
- Data is separated by household at the database level, so one family's records cannot be read through another family's session.
- Sign-in is by emailed one-time code — there is no password for an attacker to guess or reuse.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator without undue delay.
6. How long we keep things
- Items and calendar dates — kept while your account is open, so past terms remain answerable. You can delete any item at any time.
- Unmatched senders in the review list — when you ignore one it is set aside and no longer processed or re-raised, with the noted sender, subject, and snippet kept only so you are not asked about it twice; all of it is removed when you delete your data.
- OAuth tokens and mailbox credentials — deleted the moment you disconnect that source.
- Everything else — deleted when you delete your account, as described below.
7. Your choices, and deleting your data
You can, at any time, from inside Holt:
- Disconnect a mailbox or calendar. Holt deletes the stored credentials and, for a Google account, tells Google to revoke the token so the access is withdrawn on Google's side too.
- Delete your account. This removes your household and everything in it — children, organisations, contacts, items, history, sources, and stored credentials — from the live database, and revokes any connected Google access. It cannot be undone. Residual copies in encrypted backups age out within 30 days.
You can also revoke Holt's access directly at myaccount.google.com/permissions. Doing it there stops the access but does not delete what Holt already holds — use the in-app deletion for that, or email privacy@checkholt.com and we will do it for you.
Depending on where you live you may also have the right to access, correct, export, or restrict the processing of your data, and to complain to your data protection authority. Write to the address above and we will respond within 30 days.
8. Children
Holt is a service for parents and carers. It is not directed to children, it does not have accounts for children, and it does not collect information from children. The only information about a child in Holt is what a parent chooses to enter — typically a first name — plus the school and activity dates that concern them, all of it entered and controlled by that parent.
9. Where data is held
Holt's servers and database are hosted in the United States. If you use Holt from elsewhere, your data is transferred to and processed in the United States.
10. Changes
If this policy changes in a way that materially affects how your data is used, we will email you before the change takes effect. The date at the top always reflects the current version.