CallSheet

Privacy Policy

Effective July 31, 2026

What stays local

You can create and edit call sheets without an account. Local drafts stay in the app container on your device unless you explicitly publish or send them.

What is uploaded

When you explicitly publish or send, CallSheet uploads that call sheet and the names, email addresses, phone numbers, roles, call times, locations, schedules, notes, generated PDF, and any PDF, JPEG, or PNG production files you chose to attach. Only contacts and files you select are imported; CallSheet does not upload your entire address book or file library.

Ready to Wrap evidence and decisions

When you use Ready to Wrap and sync the call sheet, CallSheet uploads the deliverables and coverage requirements you enter, the selected media evidence, and the named review attached to that evidence. Retained proof metadata can include original MHL filenames, a digest of each imported manifest, manifest dates, import times, entry counts, supported hash algorithms, and the selected file's safe relative path, display name, size, hash algorithm, and hash value. CallSheet does not upload the raw MHL XML, unselected manifest entries, or the camera media itself.

If you create a private wrap-exception link, CallSheet stores the expected representative's name and role, the frozen missing-coverage snapshot, link status, and any submitted choice, typed name, typed role, decision time, operation identifier, and evidence digest. This is retained as an operational production record and is not represented as a legal electronic signature.

Account and delivery data

Sign in with Apple provides an account identifier and may provide your name and email. The service records recipient-page opens, email delivery status, explicit confirmations, declines, and subscription entitlement needed to operate the product. A page open is not treated as confirmation.

Site and subscription analytics

CallSheet records privacy-limited events on its public marketing pages: the page type and path, campaign parameters, referring domain, and taps that hand off to the App Store. A random browser identifier keeps those events together; CallSheet does not send names, email addresses, phone numbers, call-sheet data, full URLs, or private recipient-link paths to analytics. After Apple verifies a new CallSheet Pro entitlement, CallSheet records the plan, listed price, and App Store environment against a one-way identifier. Apple's campaign reporting separately measures eligible App Store views, downloads, usage, sales, and subscriptions.

How data is used

Data is used only to authenticate you, store and restore call sheets, deliver private links, show personal call times, track delivery and confirmations, evaluate Ready to Wrap evidence, retain named wrap decisions, measure public-page and subscription performance, operate the optional creator program, secure the service, and provide support. CallSheet does not sell personal data, run advertising, or track people across apps and websites.

Service providers

Apple processes sign-in, subscriptions, creator-offer attribution, and production addresses you explicitly submit to Apple Maps or Apple Weather for hospital and forecast lookups. Stripe processes creator identity, tax, bank, connected-balance, and bank-delivery information only when a creator explicitly sets up payouts. PostHog processes the privacy-limited analytics events described above. CallSheet never requests your device location. Hosting, database, analytics, and transactional-email providers process data only to operate and improve CallSheet. Recipient and creator-portal links are capability links and should be treated as private.

Founding Partner invitations

The optional creator program uses owner-issued private invitations and creator-specific Apple offers. An invited creator explicitly submits a name, email address, and one public channel URL and accepts the versioned partner terms and disclosure duty. Unused invitation capability links expire 30 days after issuance.

Invitation and creator-portal capabilities stay in URL fragments. CallSheet does not copy them into cookies, local browser storage, query strings, referrers, or analytics, but a fragment URL may remain in browser history. Creators should use a private device and treat that history as private.

CallSheet stores the creator's name, channel URL, acceptance times, assigned Apple offer, native commission statement, payout readiness, transfer state, and a versioned keyed digest of the normalized email. CallSheet never stores the raw creator email. It transmits the raw creator email to Stripe only when the creator explicitly initiates payout setup and the keyed digest matches. The creator enters identity, tax, and bank details on Stripe-hosted pages; CallSheet stores only normalized readiness states and the opaque Stripe account identifier.

Customer email, contacts, app account tokens, signed Apple payloads, and customer Apple transaction IDs are not sent to Stripe. CallSheet uses complete verified Apple transaction history to decide whether the first paid annual charge earns one $21 commission and whether a refund reverses that exact commission. Trials, clicks, generic links, monthly subscriptions, and renewals earn no commission.

Retention and deletion

Recipient links expire after the configured sharing period. Cloud call sheets, delivery history, retained Ready to Wrap evidence metadata, and wrap-exception request and decision history remain until you delete the call sheet or your account. Expired, revoked, or superseded private-link records may remain during that period so the production record is not silently rewritten. Settings includes permanent account deletion. Local drafts remain on your device until you delete them or remove the app. If a local library becomes unreadable, CallSheet preserves an exportable recovery copy before allowing a new library; you can delete that recovery file in Settings after confirming your drafts.

CallSheet retains affiliate creator/agreement, Apple transaction, attribution, commission, tax-review, transfer, and audit records for seven years after the final financial event or dispute. After that period, CallSheet deletes or anonymizes those records where legally permitted. Account deletion does not shorten this period when CallSheet must preserve financial or dispute records.

Your choices

You can use local drafting without signing in, decline Contacts access and enter people manually, delete individual cloud call sheets, or delete your entire cloud account. Account deletion does not cancel an App Store subscription; subscriptions are managed through Apple.

Contact

CallSheet is operated by Joey Arcisz. Privacy and support questions can be sent to joey@production-engine.com or (214) 233-5925.