Back to homeView pricing
Privacy

Privacy Policy

This page explains what Calendar Sync accesses, why it accesses it, how that data is used to provide calendar synchronization, how it is protected, and how you can request deletion.

Last updated: August 20, 2026

What Calendar Sync does

Calendar Sync is an automated calendar syncing service. You can connect supported calendar providers, choose calendars to sync, and let the service read calendar data and write synced changes between the calendars you explicitly configure.

Information we collect and process

Depending on the providers and features you use, Calendar Sync may collect or process:

  • Your email address for account identity, session association, and support/billing matching.
  • OAuth access and refresh tokens needed to keep connected provider accounts authorized. Google tokens are stored in Google Secret Manager rather than exposed in the browser.
  • Connected provider account identifiers and connected calendar metadata.
  • Calendar event data needed to operate synchronization, including event titles, descriptions, dates, times, recurrence details, status, and provider event identifiers.
  • Calendar sync configuration, sync status, compact sync mapping records, and short-lived run logs.
  • Subscription and billing metadata such as Stripe customer ID, subscription ID, plan, billing status, and current period end.
  • The `ks_user_id` session cookie used to keep you signed in.

Google data we access and why

When you connect Google, Calendar Sync currently requests the following Google scopes and uses them only for the service features you ask it to perform:

  • `https://www.googleapis.com/auth/calendar.events` to read existing events and create, update, or delete synced event copies.
  • `https://www.googleapis.com/auth/calendar.calendarlist.readonly` to list the calendars available on your Google account so you can choose which calendars to sync.
  • `https://www.googleapis.com/auth/userinfo.email` to identify your account and associate your Google connection with your Calendar Sync user record.

Calendar Sync does not sell Google user data, does not use Google user data for advertising, and does not use Google user data for anything unrelated to the calendar synchronization features you request.

Google user data is used only to provide and improve the user-facing functionality of Calendar Sync. Google user data is not transferred to third parties except as necessary to provide the service you requested, comply with applicable law, or protect against abuse or security issues.

If you configure a cross-provider sync, Calendar Sync transfers event details from the Google calendars you selected to the Microsoft or Apple calendars you selected. Event details can include titles, descriptions, dates, times, recurrence rules, status, and provider identifiers. Calendar Sync performs this transfer only to provide the sync direction and calendar pairing you configured.

Calendar Sync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use your data

  • To authenticate your connected accounts and keep your session associated with the right user.
  • To list calendars, read source events, and write synced event changes to target calendars.
  • To track which events have already been synced so duplicate copies can be avoided.
  • To enforce plan limits and show your current billing/subscription status.
  • To troubleshoot sync failures, abuse, and service reliability issues.

How data is shared

Calendar Sync does not sell your personal data. Data may be shared only in the following ways:

  • With Google, Microsoft, and Apple when you connect those providers and instruct Calendar Sync to read from or write to those calendars.
  • With Stripe to create checkout sessions, manage subscriptions, and operate customer billing.
  • If required to comply with law, enforce service terms, or protect the security of the service and its users.

Stripe and billing data

Billing for paid plans is handled through Stripe. Calendar Sync stores billing metadata needed to manage your plan, such as the Stripe customer ID, subscription ID, plan, subscription status, and billing period end date.

Payment card details are handled by Stripe checkout and customer portal flows rather than being stored directly in Calendar Sync.

Cookies and session use

Calendar Sync currently uses a session cookie named `ks_user_id` to keep you signed in and tie your browser session to your connected account records. This site does not currently describe any custom advertising cookie usage.

How we protect your data

Calendar Sync treats your calendar content and your OAuth credentials as sensitive data. The following safeguards protect that data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction.

Encryption in transit

Calendar Sync is served exclusively over HTTPS, and all traffic between your browser and the service is encrypted with TLS 1.2 or higher. Every call to the Google, Microsoft, Apple, Stripe, and Google Cloud APIs is likewise made over TLS. Calendar data is never transmitted over an unencrypted connection.

Encryption at rest

All stored data is encrypted at rest. Application data is held in Google Cloud Firestore, and OAuth access and refresh tokens are held separately in Google Cloud Secret Manager. Both services encrypt stored data with AES-256 using Google-managed encryption keys. Keeping tokens in Secret Manager isolates them from ordinary application records rather than storing them alongside your calendar data.

Credential handling

OAuth tokens are never exposed to the browser, never written to client-side storage, and never placed in URLs or client-side JavaScript. They are read server-side only, at the moment a sync run or an authenticated request needs them, and refreshed tokens replace prior versions in Secret Manager. Payment card details never reach Calendar Sync's servers; they are handled entirely by Stripe's hosted checkout and customer portal.

Access control and least privilege

Calendar Sync runs under a dedicated Google Cloud service account whose IAM permissions are scoped to only the Firestore data and Secret Manager secrets the service needs. Administrative access to the production Google Cloud project is limited to the service operator, requires Google account sign-in with two-step verification, and is granted on a least-privilege basis. Each user's records are partitioned under that user's own identifier, and API routes authorize the session against the requesting user before any record is read or modified.

Human access to your calendar content

People do not read your calendar event content. The only exceptions are when you give explicit permission for a specific support request, when access is strictly necessary to investigate a security incident or abuse, or when access is required by law. Routine operation, monitoring, and troubleshooting rely on identifiers and error information rather than event content.

Application and infrastructure security

The service runs on Google Cloud Run in a hardened container image that executes as a non-root user and is produced by an automated, reproducible build pipeline rather than by manual uploads. Session cookies are set with the HttpOnly, Secure, and SameSite attributes, so they cannot be read by page scripts or sent over plain HTTP. Dependencies and base images are kept current as security updates are released.

Data minimization and retention limits

Calendar Sync requests the narrowest scopes its features require and stores as little as it can. Sync processing is limited to events within roughly three months before and three months after each run rather than your full calendar history, compact sync mapping records expire roughly 90 days after an event ends, and short-lived sync run logs are pruned automatically after roughly 12 hours. Holding less data, for less time, limits the exposure of your calendar information.

Revocation, deletion, and incident response

You can disconnect a provider at any time from the admin area, which removes the stored provider account and its calendar records for that connection and stops further syncing. You can also revoke Calendar Sync's access at any time from your Google Account permissions page. When you request full deletion, your account data and the associated stored tokens are deleted. If Calendar Sync becomes aware of a security breach affecting your data, affected credentials are revoked, affected users are notified without undue delay, and applicable legal notification obligations are met.

Retention

Calendar Sync keeps account, calendar, authorization, and sync configuration data while the relevant connection remains in use. Current sync processing is limited to events within roughly three months before and three months after each run rather than unlimited calendar history.

Compact sync mapping records expire roughly 90 days after an event ends. Short-lived sync run logs are pruned automatically after roughly 12 hours.

Disconnecting providers and deletion

You can disconnect a connected provider from the admin area. The current disconnect flow removes the provider account and its stored calendar records from the app-managed user data for that connection and stops future syncing for that account.

Disconnecting a provider is not the same as requesting deletion of your entire account and all stored backend data. For a full deletion request, contact sync@lodehed.se.

Contact

For privacy, support, or deletion requests, contact sync@lodehed.se.

Calendar Sync

Automated calendar syncing for Google Calendar, Microsoft Outlook, and Apple Calendar.

HomePricingPrivacyTermsData deletion