Legal

Privacy policy

Last updated 1 August 2026

This policy explains what CalSync collects, why, and what we deliberately do not collect. It applies to the hosted service; if you self-host, you are the controller of your own data and this document is a starting template.

CalSync is open-source software. This document describes the managed service and is provided as a template for self-hosted deployments — it is not legal advice. Have a lawyer review it before publishing it as your own.

What we collect

We collect the minimum needed to run a calendar sync and a booking page.

  • Account details: your email address, name, timezone and a hashed password.
  • Calendar connections: the provider, an account identifier, OAuth tokens and the names and colours of your calendars.
  • Sync bookkeeping: for each mirrored event, the identifier of the source event, the identifier of the copy, its start and end time, and a fingerprint used to detect changes.
  • Booking data: the name, email address, chosen time and any note an invitee submits through your booking page.
  • Operational logs: security-relevant actions such as sign-ins, calendar connections and sync failures.

What we do not collect

We do not store the contents of your calendar events. Titles, descriptions, locations, attendee lists, attachments and meeting links are read from your provider at the moment a sync runs, used to create or update the copy, and then discarded. They are never written to our database.

We do not analyse your calendar data, build profiles from it, use it to train models, or sell it. There is no advertising on CalSync.

Legal basis and purpose

We process your data to perform the contract you enter into when you create an account (Article 6(1)(b) GDPR) and, for security logging, on the basis of our legitimate interest in keeping the service safe (Article 6(1)(f) GDPR).

Sharing

Your data is shared only with the infrastructure providers needed to run the service, listed on our subprocessors page. We do not share data with anyone else unless legally compelled, in which case we will tell you where we are permitted to.

Retention

Account data is kept while your account exists. Delete your account and everything associated with it is removed within 30 days, including OAuth tokens, which stop working immediately. Sync bookkeeping is removed as soon as the corresponding sync is deleted.

Your rights

You may request access to, correction of, or deletion of your data, and you may object to processing or request that it be restricted. Deletion is available directly in your account settings. For anything else, contact us and we will respond within 30 days. You also have the right to complain to your local data protection authority.

International transfers

The hosted service runs inside the European Union. Where a subprocessor operates outside the EU, transfers are covered by Standard Contractual Clauses.