Safety, consent & destructive actions
Ask the sky — the calendar's AI assistant — works inside the suite's safety layer, Zenith Guard. How Guard screens asks and replies is the same in every Zenith app, and is explained on AI safety. This page covers the calendar's own side: what the sky may undo, the question it asks before your words leave, and the safety page.
What the sky may undo
Most of what the sky does is placing, changing and arranging. A few things are harder to take back. These are the destructive actions:
- burning a commitment — deleting an event or thing to do;
- dropping an almanac — deleting one of your calendars and everything in it;
- stopping a phone calendar from feeding an almanac;
- removing a file from an almanac's material — the files its commitments share;
- taking an almanac off Drive, or stopping its travel;
- forgetting journal entries;
- letting items go from the Shuttle — the suite's shared tray for passing text and files between Zenith apps — or clearing it;
- withdrawing a yes, removing a key, or erasing remembered talks.
All of these sit behind one switch: Settings › ask the sky › allow destructive actions. It shows only while "zenith ai in this app" is on, and it starts off.
- Off (recommended). The sky can place, change and arrange. If you ask it to burn, drop, remove, withdraw or clear, it refuses and tells you where the switch is. Other Zenith apps' assistants meet the same refusal here.
- On. The sky may do these things, but it still stops each time with "‹being› wants to run “‹tool›” — allow it?". Tap "allow" to go ahead, or "not this" to run nothing.
Only you can switch it on. The sky can switch it off, never on. Everything else runs without asking.
The question before your words leave
The first time the sky would send your words to an AI company, the calendar asks "send to ‹service›?". It says your words go to that service, under your own key, only to answer you. Zenith, Black Syntax and Friend Castle never receive or keep them. What the service keeps is up to its own policy and your key's terms.
Along with your words, the question lists what can go too:
- your commitments, and the names of people who join them;
- what other Zenith apps hand back, and memory they share;
- a description of the screen, when "⌗ screen" is on;
- your remembered talks, when chat memory keeps them;
- words you say, share, select or pass through the Shuttle to make a commitment.
Tap "send to ‹service›" to agree, for that company, on this phone. Tap "not now", back, or outside the sheet, and nothing is sent or recorded. Your question comes back to you, and a form is filled by the phone's own reading instead.
It asks once per company. It asks again for every company if the calendar's list of what can go ever changes. The on-device model never asks, because nothing leaves the phone.
To take a yes back, open Settings › ask the sky › SENT WITH YOUR YES. Tap "withdraw" beside a company, or "withdraw all". The next send asks again. The sky can withdraw a yes for you, but it can never give one.
Knowing what's AI
Every reply carries a ⚑, and so does a form or a "what you fill in" section the sky made. Tap the ⚑ once to report it; it reads "reported". The report is logged on the phone and makes the on-device screening stricter. Nothing is sent.
The safety page
Settings › safety shows how many blocks and reports are on this device. "↗ export the log" shares the safety log through the phone's share sheet. Under "POLICIES" you find "acceptable use ↗", "ai safety ↗" and "privacy ↗".
Your keys and your data
Your key goes only to the one service the calendar uses, never another company. Keys are stored encrypted on the phone. Chat memory is off by default and is Gold; erasing it is free. "⌗ screen" starts off.
See also. AI safety · Ask the sky — the calendar's assistant · Privacy & permissions · Privacy across the suite