Privacy Policy
This Privacy Policy describes how Calendar Connector ("the Service") handles your data when you use it to synchronize calendars between Google Calendar and Apple iCloud Calendar.
1. What data the Service accesses
To perform calendar synchronization, the Service accesses:
- Google Calendar data — via Google's OAuth 2.0 flow, limited to the scopes you approve:
https://www.googleapis.com/auth/calendar.events— read, create, update, and delete events on calendars you choose to sync.https://www.googleapis.com/auth/calendar.calendarlist.readonly— list your calendars so you can pick which ones to pair.
- Apple iCloud Calendar data — via CalDAV using an app-specific password you provide: events on the Apple calendars you choose to sync.
- Credentials — your Google OAuth tokens and Apple app-specific password, required to access the above on your behalf.
The Service accesses only the specific calendars you pair. It does not read your email, contacts, files, or any other Google or Apple data.
2. How your data is used
Your calendar data is used solely to synchronize events between the Google and Apple calendars you have paired:
- Mirroring event creations, updates, and deletions in both directions.
- Preserving recurrence rules across both calendar systems.
- Detecting changes efficiently so only modified events are transferred.
Your data is not used for advertising, analytics, profiling, marketing, or any purpose other than the synchronization you configured.
3. Where your data is stored
The Service is self-hosted on a private server. Your calendar event data, OAuth tokens, and Apple credentials are stored locally on that server and are never transmitted to any third party except Google's and Apple's own APIs as required to perform the synchronization.
4. Data sharing
We do not sell, rent, or share your personal or calendar data with any third party. The only external transmissions are:
- To Google's Calendar API — the calendar changes being synced, using the OAuth scopes above.
- To Apple's iCloud CalDAV servers — the calendar changes being synced.
5. Data retention and deletion
- Synced calendar data is retained on the private server for as long as the calendar pairing exists, to support ongoing synchronization.
- When you delete a calendar pairing, the Service stops syncing it. You may request complete deletion of all stored data for your account by contacting us (see §8).
- OAuth tokens remain valid until you revoke them or they expire per Google's policies.
6. Your rights and choices
- Revoke Google access at any time from your Google Account permissions page. The Service will stop syncing your Google calendars immediately.
- Revoke Apple access by revoking the app-specific password at appleid.apple.com.
- Request data deletion by contacting us (see §8) — we will delete your stored credentials and synced data.
7. Security
The Service runs on a private, access-controlled server. Credentials are stored with restricted file permissions and are never logged or exposed. All communication with Google and Apple uses encrypted HTTPS connections. While no system is perfectly secure, we take reasonable measures to protect your data.
8. Contact
For questions about this Privacy Policy, to request data deletion, or for any privacy-related concern, contact:
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.