Sillet Open app

Security

Last updated July 6, 2026. This page summarizes Sillet's current security posture for launch readiness.

Sillet is designed so your daily account rows belong to your signed-in account and calendar access remains read-only.

Account-scoped data

Signed-in account data is stored behind authenticated requests and account-scoped access rules. Your profile, categories, plans, preferences, and ledger rows are tied to your account.

Calendar connections

Google and Apple calendar integrations are used to read events for planning context. Imported events become Sillet plan rows that you can edit or remove. Sillet does not write changes back to your external calendar.

Shortcut tokens

iOS shortcut tokens are private credentials for timer actions. Treat them like passwords. Regenerating a token should revoke the old shortcut token for future use.

Responsible disclosure

If you believe you found a security issue, email hello@sillet.app with enough detail to reproduce the problem. Please do not access, change, or delete data that is not yours.

More from Sillet Privacy Terms