CallSheet

Privacy Policy

Effective September 12, 2026

What stays local

In the iPhone, iPad and Mac apps, you can create and edit local call sheets without an account. Local drafts stay in the app container on that device until you explicitly publish them. The browser app uses a signed-in cloud workspace: saving there uploads the call sheet, including the people you added, before you send anything.

What is uploaded

In the native apps, the searchable Contacts picker reads the contacts available through your device's Contacts permission so you can find people. CallSheet retains only the people you select. If you decline that permission, Apple's system picker can provide the people you choose instead. You can also enter people manually or review a CSV or vCard file you select. CallSheet does not upload your entire address book or file library.

When you explicitly Publish in the native app, CallSheet uploads the selected sheet snapshot: names, email addresses, phone numbers, roles, call times, locations, schedules, notes, generated PDF and the PDF, JPEG or PNG files you attached. Publication uploads this information even if you choose no email recipients. Local Crew Directory records and editable Site Map marks remain on their source device; selected sheet details and the rendered map image can be published.

The browser app has no contact picker: it never asks for your address book and never receives one. You add people by typing or pasting a crew spreadsheet. Save uploads the sheet and its included contact details to CallSheet before Send. Choosing a file also saves its details and uploads the file; generating a PDF stores that output on the service. Call-sheet emails contain a private recipient link, with the published PDF and attached files available on the recipient page. Those files are not email attachments.

Wrap sheets and invoicing details

CallSheet Pro can send a wrap sheet when a job ends: a closing email to people you select. The native apps can gather people across selected shoot days; the browser uses the current call sheet and requires an email address for each selected recipient. You choose every recipient; nothing is sent to anyone else. The email carries a thank-you message, the job code you enter for the invoice, and the invoicing details saved on your Account page: legal entity name, remit-to address, remit-to email, payment methods, terms, and a file-naming note. Fields you leave blank are left out of the email, which is delivered by the same transactional-email provider that delivers call sheets, with your account email as the reply-to address.

The invoicing details, a default thank-you message and any saved logo are stored with your account so they are entered once and reused. Each wrap sheet keeps its job code, message, chosen recipients, and per-recipient delivery status as part of your account's records. Wrap sheets follow the same retention and deletion rules as cloud call sheets: they remain until you delete the call sheet or your account, and the invoicing details are deleted with your account.

Ready to Wrap evidence and decisions

Call sheets can contain Ready to Wrap planning fields and previously created evidence records. Saving or publishing a sheet containing those records stores its deliverables, coverage requirements, selected media evidence and named reviews. Retained proof metadata can include original MHL filenames, a digest of each imported manifest, manifest dates, import times, entry counts, supported hash algorithms, and the selected file's safe relative path, display name, size, hash algorithm, and hash value. CallSheet does not upload the raw MHL XML, unselected manifest entries, or the camera media itself.

For an issued private wrap-exception link, CallSheet stores the expected representative's name and role, the frozen missing-coverage snapshot, link status, and any submitted choice, typed name, typed role, decision time, operation identifier, and evidence digest. This is retained as an operational production record and is not represented as a legal electronic signature.

Account and delivery data

Sign in with Apple provides an account identifier and may provide your name and email. A browser email account stores your email address, optional name and a password hash. The service records recipient-page opens, email delivery status, explicit confirmations, declines, and subscription entitlement needed to operate the product. A page open is not treated as confirmation.

Site and subscription analytics

CallSheet sends selected product events to PostHog. Public marketing events include the page path and type, referring domain, campaign parameters and the position of an App Store link you tap. Browser product events include account and call-sheet creation, subscription checkout, a send refused for missing Pro access, PDF branding, subscription activation and delivery outcomes. A checkout or trial-start event is not a completed paid charge, and a refused send is not every time a plan offer was shown.

These selected events use counts, states and plan details rather than names, email addresses, phone numbers, call-sheet content, card details or recipient tokens. Marketing events use a random browser identifier; account events use a one-way identifier derived from your account. Native setup, plan-screen, purchase, restore and export events use a random per-install identifier. On sign-in, these identifiers can be linked to the account identifier so activity from the same producer can be understood together. Events may create pseudonymous analytics profiles; they are not all anonymous. Request user agents help distinguish people, crawlers and automated provider notifications.

The native apps also report named screens, application starts and stops, install/update events, device model, system version and app version. They do not automatically record taps on controls, whose labels may contain crew information, and native session replay is disabled. Builds with crash reporting enabled send the failure type, internal stack addresses and device/version details after a crash, and builds with freeze reporting enabled send the length of a freeze, internal stack addresses and the same details from Apple's system diagnostics; neither records the text entered into the interface. Apple's campaign reporting separately measures eligible App Store views, downloads, usage, sales and subscriptions. Verified Apple and Stripe subscription events record entitlement and renewal, cancellation, billing, expiry, refund or trial-conversion states without card details.

PostHog's browser SDK also records technical page-view, click, performance and error information on public marketing pages and the signed-in producer workspace. It records page addresses on those surfaces. Public marketing session replays show the page, scrolling, pointer movement and clicks, while masking form input before it leaves the browser. In the producer's library, call sheets, wrap sheets, account and billing pages, replay masks all text and form inputs. API response bodies and headers are not recorded. These recordings are kept for thirty days.

The PostHog browser SDK and session replay are disabled on recipient call-sheet and wrap-decision links, sign-in, signup, password recovery, email verification, invitations, private review access and creator portal routes. Its browser SDK respects Do Not Track. The separate first-party product-event requests and server delivery records do not use that SDK setting.

Vercel Web Analytics separately measures public marketing page views. CallSheet excludes private producer, authentication, recipient, invitation, review and creator routes from that provider. Vercel Web Analytics does not provide CallSheet's session replay. Recipient opens, delivery and confirmation records needed for the product are still processed by the CallSheet service; an aggregate event can be attributed to the producer without sending the recipient's identity or link token to PostHog.

How data is used

Data is used only to authenticate you, store and restore call sheets, deliver private links, show personal call times, track delivery and confirmations, send wrap sheets with the job code and invoicing details you provide, evaluate Ready to Wrap evidence, retain named wrap decisions, measure public-page and subscription performance, operate the optional creator program, secure the service, and provide support. CallSheet does not sell personal data, run advertising, or track people across apps and websites.

How data is protected

Traffic between the native apps, this site and the service uses HTTPS, and service responses carry HTTP Strict Transport Security. Call sheets stored on the server live in a managed PostgreSQL database whose storage is encrypted at rest. Native local drafts stay inside the app's sandbox. On iPhone and iPad, iOS Data Protection applies; on Mac, CallSheet does not add its own encryption to draft files. The native sign-in token is held in the system Keychain with device-only access and is not synced to iCloud.

CallSheet is not end-to-end encrypted. The service can read call-sheet content, because it renders recipient pages, generates PDFs, and answers support requests. Private recipient links carry a 192-bit random token, are excluded from search-engine indexing, and are sent with a no-referrer policy so the link is not disclosed to the next site a recipient visits. You can revoke a link or give it an expiration date. Anyone holding an unrevoked link can open the call sheet it points to, so treat it as a private document link.

Service providers

Apple processes sign-in, subscriptions bought in the native apps, creator-offer attribution, and production addresses you explicitly submit to Apple Maps or Apple Weather for hospital and forecast lookups. When Apple Weather cannot supply a forecast, the coordinates of that address — not the address itself — are sent to the United States National Weather Service, a federal agency, to fetch one. Stripe processes subscriptions bought on the web: CallSheet sends Stripe your email address and an opaque account identifier, you enter your card on Stripe's own checkout page, and Stripe collects the billing address it needs to calculate tax. CallSheet never receives or stores your card. Separately, Stripe processes creator identity, tax, bank, connected-balance, and bank-delivery information only when a creator explicitly sets up payouts. PostHog processes the privacy-limited analytics events and the session replays described above. CallSheet never requests your device location. Hosting, database, analytics, and transactional-email providers process data only to operate and improve CallSheet. Recipient and creator-portal links are capability links and should be treated as private.

Founding Partner enrollment

The optional creator program uses self-serve email verification and creator-specific Apple offers. A creator submits a name, email address, and one public HTTPS channel URL. The private verification link expires after 30 minutes. The creator then accepts the versioned partner terms and disclosure duty before requesting a creator link. An Apple offer is assigned only after that verified action.

Verification and creator-portal capabilities stay in URL fragments. CallSheet does not copy them into cookies, local browser storage, query strings, referrers, or analytics, but a fragment URL may remain in browser history. Creators should use a private device and treat that history as private. An active creator can use the same enrollment form and verified email flow to recover private portal access without changing the public creator link.

CallSheet stores the creator's name, channel URL, acceptance times, assigned Apple offer, native commission statement, payout readiness, transfer state, and a versioned keyed digest of the normalized email. CallSheet never stores the raw creator email. CallSheet transmits the raw creator email to Resend only to deliver the verification or recovery message. CallSheet transmits the raw creator email to Stripe only when the creator explicitly initiates payout setup and the keyed digest matches. The creator enters identity, tax, and bank details on Stripe-hosted pages; CallSheet stores only normalized readiness states and the opaque Stripe account identifier.

This program sends Stripe nothing about a customer: no contacts, app account tokens, signed Apple payloads, Apple transaction IDs, or email. A web subscriber's own email reaches Stripe through their own subscription, described under Service providers, and never through this program. CallSheet uses complete verified Apple transaction history to decide whether the first paid annual charge earns one $21 commission and whether a refund reverses that exact commission. Trials, clicks, generic links, monthly subscriptions, and renewals earn no commission.

A pending enrollment record becomes cleanup-eligible after 24 hours. Protected hourly cleanup gives that record an operational retention ceiling of 25 hours while scheduled cleanup is running. Durable creator agreements and financial records follow the longer retention rule below.

Retention and deletion

Recipient links expire after the configured sharing period. Cloud call sheets, delivery history, wrap sheets and their delivery history, retained Ready to Wrap evidence metadata, and wrap-exception request and decision history remain until you delete the call sheet or your account. Expired, revoked, or superseded private-link records may remain during that period so the call-sheet record is not silently rewritten. Settings includes permanent account deletion, and the browser Account page supports deletion for accounts with an email password. Apple-only accounts are directed to native Settings for fresh Apple authorization. Local drafts remain on your device until you delete them or remove the app. If a local library becomes unreadable, CallSheet preserves an exportable recovery copy before allowing a new library; you can delete that recovery file in Settings after confirming your drafts.

CallSheet retains affiliate creator/agreement, Apple transaction, attribution, commission, tax-review, transfer, and audit records for seven years after the final financial event or dispute. After that period, CallSheet deletes or anonymizes those records where legally permitted. Account deletion does not shorten this period when CallSheet must preserve financial or dispute records.

Your choices

You can use native local drafting without signing in, decline Contacts access and enter people manually, delete individual cloud call sheets, or delete your cloud account. The Account page at calltimes.app/account exports a JSON file with account details, call sheets you own and their recorded recipient delivery and confirmation state. It excludes PDF and attachment files, saved logos, your invoice profile, wrap-sheet records and sheets owned by a partner. It is not a restorable backup. An Apple-only account must be deleted in the native app so Apple authorization can be revoked; the browser explains that step rather than deleting it.

Account deletion does not cancel an App Store subscription; subscriptions bought in the native apps are managed through Apple. A subscription bought on the web is cancelled when you delete your account, and if it cannot be cancelled at that moment the account is not deleted, so your card is never charged for an account that no longer exists.

Contact

CallSheet is operated by Joey Arcisz. Privacy and support questions can be sent to joey@production-engine.com or (214) 233-5925.