Privacy Policy

Privacy Policy — Agenda

Agenda · com.bullatschool.agenda · Version 1.0

Effective date: 12 September 2026 · Last updated: 12 September 2026

This Privacy Policy describes how Bull at School (“Developer,” “we,” “us,” or “our”) handles information in connection with the Agenda mobile application (package name com.bullatschool.agenda, the “App”). Replace the highlighted contact fields before publishing.

This policy is written to satisfy the disclosure requirements of the Solana Mobile dApp Store Publisher Policy and the Google Play User Data policy, including the need for a publicly accessible privacy policy that names the developer, explains data practices, describes security, retention and deletion, and provides a privacy contact.

1. Who we are

The App is published by:

  • Listing name: Bull at School
  • Privacy contact: bull@bullatschool.com

If you contact us, we will use the details you send (typically your email address and message) only to respond to your request.

2. Scope

This policy applies to the Agenda Android application distributed on the Solana Mobile dApp Store and, when listed, on Google Play. It does not apply to:

  • the Solana dApp Store, Google Play, or the Android operating system, which are governed by those providers’ own policies;
  • third-party websites, articles, or RSS feeds you open or subscribe to from the App;
  • device backups created by Google, your device manufacturer, or other backup tools.

3. What the App does

Agenda is a personal productivity app. It lets you:

  • create and manage calendar events, including repeating events and optional reminder notifications;
  • create text notes and checklists, including optional PIN-protected private notes;
  • read cryptocurrency and other news headlines from RSS or Atom feeds that you enable, including default feeds shipped with the App;
  • adjust language, theme, and which sections appear on the Home screen.

The App does not create user accounts, does not include in-app purchases or advertising SDKs, does not connect to a Developer-operated backend, and is not a cryptocurrency wallet, exchange, or brokerage. It does not ask you to connect a Solana wallet or submit seed phrases, private keys, or recovery phrases.

4. Information we collect — summary

We do not operate servers that receive your calendar events, notes, checklists, PIN, or reading history. Content you enter is stored on your device. The only network activity initiated by the App is fetching RSS/Atom feeds that you (or the default configuration) request, and opening article links you tap.

DataStored whereSent to Developer?Shared with others?
Calendar events (title, notes, date/time, recurrence, reminder offset, color)On device (local database)NoNo, except as may appear in Android notifications you enable
Notes and checklists (title, body, items, private flag)On device (local database)NoNo
Private-note PIN (salt and hash only; not the PIN itself)On device (local preferences)NoNo
App settings (theme, language, calendar view, Home layout, enabled RSS sources)On deviceNoNo
Cached news headlines and summaries from feedsTemporarily on deviceNoNo
Technical network data generated when a feed is fetched (IP address, user-agent, requested URL)Seen by the feed host; not stored by usNoYes — automatically received by the RSS publisher or host you contact
Support emails you send usOur email inboxYes, only if you write to usEmail provider as needed to deliver mail

5. Information stored on your device

5.1 Calendar and notes

When you create events or notes, the App stores that content locally using an on-device database (Android Room / SQLite). This can include event titles and descriptions, dates and times, recurrence rules, reminder offsets, note titles and bodies, checklist items and completion state, and whether a note is marked private.

This content is processed only to display it to you, schedule reminders you request, and persist it between sessions. We do not upload it.

5.2 Private notes and PIN

If you create a private note or private checklist, the App asks you to set a 4-digit PIN. The App stores a salt and a hash of the PIN in local preferences (private_pin_hash and private_pin_salt) so it can verify later attempts. The App is designed not to store the PIN in clear text. A 4-digit PIN is a convenience lock, not a substitute for full-disk encryption or a password manager. Anyone with physical access to an unlocked device, a device backup, or forensic access may still be able to read local data.

If you forget the PIN, we cannot recover it because we never receive it.

5.3 Settings

The App stores your theme, language, calendar display mode, Home-section order and visibility, and the list of RSS sources you add or enable.

5.4 Notifications

If you grant notification permission and enable a reminder on an event, Android may display the event title and timing on the lock screen or notification shade, depending on your system settings. Reminders are scheduled with the Android AlarmManager (including exact alarms) and can be restored after reboot using the App’s boot receiver.

5.5 Device backups

The App’s Android manifest allows standard device backup (android:allowBackup="true"). If you use Google Backup, a manufacturer backup, or another backup tool, copies of local App data (events, notes, settings, and the PIN hash) may be included in that backup according to your device and account settings. Those backups are controlled by you and the backup provider, not by us.

6. Information processed over the network

6.1 RSS and Atom feeds

The App uses the device internet connection (permissions INTERNET and ACCESS_NETWORK_STATE) and the OkHttp library to download feeds you enable. Default sources shipped in version 1.0 include:

  • Cointelegraph — https://cointelegraph.com/rss
  • CoinDesk — https://www.coindesk.com/arc/outboundfeeds/rss
  • Decrypt — https://decrypt.co/feed

You may add other feed URLs. When the App fetches a feed, the feed host typically receives your device’s IP address, a user-agent string, the time of the request, and the feed URL. That is standard web-request metadata. Those publishers have their own privacy policies. We do not receive a copy of that request.

The App stores titles, short summaries, source names, and article links so it can show the news cards. Full articles remain on the publisher’s site. Headlines remain copyright of their publishers.

6.2 Opening articles

If you tap a headline, the destination site (or your browser) may collect information under that site’s policy. We do not control those sites.

6.3 Cleartext (HTTP) feeds

The App currently allows cleartext traffic, so an HTTP (non-HTTPS) feed URL you add is not encrypted in transit. Prefer official HTTPS feed URLs. Traffic to the default sources listed above uses HTTPS.

6.4 What we do not collect

The App does not include advertising SDKs, analytics SDKs, crash-reporting SDKs, or social-login SDKs. Based on analysis of version 1.0, it does not collect name, email, phone number, precise or approximate location, contacts, photos, files, payment info, government IDs, health data, or advertising IDs for our use. It does not access the device calendar or contacts providers; events you create live only inside Agenda unless you copy them elsewhere yourself.

7. Permissions

PermissionWhy it is used
INTERNETDownload RSS/Atom feeds and load linked articles
ACCESS_NETWORK_STATECheck connectivity before refresh
POST_NOTIFICATIONSShow event reminders you enable (Android 13+ runtime prompt)
SCHEDULE_EXACT_ALARM / USE_EXACT_ALARMFire reminders at the time you chose
RECEIVE_BOOT_COMPLETEDReschedule reminders after reboot or app update
VIBRATENotification vibration where the system allows it

You can deny notifications. The calendar, notes, and (if already cached) some news still work. Without internet, new headlines cannot be fetched.

8. Why we process information (legal bases)

Where data-protection laws such as the EU/UK GDPR apply to us, we rely on:

  • Performance of a contract — providing the App features you request (storing your notes and events on device, fetching feeds you enable, sending reminders you schedule).
  • Legitimate interests — securing the App, responding to support mail, and improving the product based on feedback you send us, balanced against your rights.
  • Consent — optional OS permissions (notifications) and any optional communication you start. You may withdraw OS permissions in Android settings.
  • Legal obligation — if we must retain or disclose support correspondence because the law requires it.

If you are in California or another U.S. state with a consumer privacy law, we do not “sell” or “share” personal information for cross-context behavioral advertising. The App has no ads and no advertising identifiers collection by us.

9. Sharing

We do not sell your information. We do not share calendar or note content with third parties because we do not receive it.

Independent third parties that may process technical data because of how the App works:

  • RSS publishers and feed hosts you subscribe to (including the default crypto-news sources and any URL you add);
  • Websites you open from a headline;
  • Google, Solana Mobile, device OEMs, and your mobile carrier as operators of the store, OS, device, and network;
  • Our email provider, if you write to us.

We do not use those parties as analytics or advertising partners for the App. If we later add a hosted backend, analytics, or crash reporting, we will update this policy before that version is published and, where required, obtain additional consent.

10. Retention and deletion

  • On-device events, notes, settings, PIN hash, and cached headlines are kept until you delete the item, clear App storage, or uninstall the App.
  • Deleting an event, note, or RSS source in the App removes it from the local database.
  • Uninstalling the App deletes local App data on that device, except copies that may remain in a device backup until that backup is deleted or expires under the backup provider’s rules.
  • Support emails are kept only as long as needed to handle your request and any related legal requirement, then deleted or minimized.

Because there is no account, “delete my account” under the Solana Mobile Publisher Policy is satisfied by uninstalling the App and, if you wish, writing to our privacy contact to ask us to delete any email you previously sent. We cannot remotely wipe a device we do not control.

11. Security

We use standard on-device storage, HTTPS for the default news feeds, and a salted PIN hash for the private-notes lock. No method of storage or transmission is perfectly secure. In particular:

  • local data can be included in device backups;
  • a 4-digit PIN is not strong authentication;
  • HTTP feed URLs are not encrypted;
  • notification content may be visible on the lock screen.

Protect your device with a system lock screen. Do not store secrets such as seed phrases, banking passwords, or government ID numbers in notes.

12. Children

The App is a general-audience productivity tool. Default news sources include cryptocurrency publications that are not directed at children. We do not knowingly collect personal information from children under 13 (or under 16 in the EEA/UK) on our servers. We do not market the App to children and it is not designed as a “Designed for Families” / children’s app under Google Play Families Policy.

If you are a parent or guardian and believe a child provided personal information to us by email, contact us and we will delete it. If you allow a minor to use the App on a shared device, you are responsible for that use and for any content they enter or feeds they add. Do not use the App to store a child’s sensitive data.

13. International users

The App stores your content on your device wherever you use it. If you fetch feeds or open articles, the publisher may be located in another country (including the United States). Those transfers occur because you requested that source, not because we run a global user database.

14. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data, and to data portability and complaint to a supervisory authority. Because most App data never leaves your device, the practical way to access or delete it is inside the App or by clearing App storage / uninstalling.

To exercise rights regarding emails you sent us, write to the privacy contact above. We may need to verify that the request comes from the email account that contacted us. You may also lodge a complaint with your local data-protection authority.

EEA users may contact their lead supervisory authority; UK users may contact the ICO; California residents may contact using the privacy email and will not receive discriminatory treatment for exercising their rights.

15. Automated decision-making

The App does not use profiling or automated decision-making that produces legal or similarly significant effects.

16. Changes

We may update this policy when the App’s behavior, third-party integrations, or the law changes. The “Last updated” date will change. Material changes will be posted at this URL and, where required, notified in the App or store listing. Continued use after the effective date means you accept the updated policy.

17. Contact

Privacy questions: bull@bullatschool.com

Please include “Agenda privacy” in the subject line. Agenda is published by Bull at School. This page is a privacy policy for the Agenda app (com.bullatschool.agenda). Store operators (Solana Mobile, Google) are not responsible for this App’s data practices.