Privacy Policy
CalendarSync · last updated 7 October 2026
CalendarSync is a private, self-hosted calendar synchronisation service operated by Kristian Henriksen for his own personal use. It has one user. This policy describes what data the service handles, why, and where it goes.
Who operates this service
Kristian Henriksen, Denmark. Contact: kristian.hatte@gmail.com. The service runs on a server controlled solely by the operator. It is not a commercial product and is not offered to other people.
What data is accessed
When a Google account is connected, the service requests these permissions and no others:
- See the list of Google calendars you are subscribed to
(
calendar.calendarlist.readonly) — used to let the operator choose which calendar should receive synchronised events. - View and edit events on your calendars
(
calendar.events) — used to create, update and delete the copied events that the service itself manages. - See your primary Google Account email address
(
userinfo.email) — used to label the connected account in the interface.
The service does not request or receive access to Gmail, Google Drive, Google Contacts, Google Photos, location data, or any other Google service.
What is stored, and where
- OAuth tokens for connected accounts, and credentials for non-Google calendar sources such as CalDAV application-specific passwords. These are encrypted at rest in the service's own database.
- Calendar event data — titles, times, descriptions and locations — for the events being synchronised, together with the identifiers needed to match a source event to its copy in the destination calendar.
- Operational logs recording synchronisation runs and errors.
All of this is stored in a database on the operator's own server. No data is stored by any third party beyond the calendar providers the operator has deliberately connected.
What the data is used for
Only to perform the synchronisation the operator has configured: reading events from a source calendar and writing the corresponding events to a destination calendar. The data is not analysed, profiled, sold, rented, shared, or used for advertising, and it is not used to train machine-learning models.
Disclosure to others
None. Data is not disclosed to any third party. The only parties that see it are the calendar providers the operator has connected, acting on the operator's own instructions.
Retention and deletion
Synchronised event data and stored credentials are retained for as long as the corresponding connection exists. Removing a connection deletes its stored credentials and the associated event-mapping records. Shutting down the service deletes everything.
Revoking access
Access granted to this service can be withdrawn at any time from Google Account permissions. Revoking it immediately prevents the service from reading or writing calendar data, whether or not the service is still running.
Compliance with Google API Services User Data Policy
CalendarSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
If this policy changes, the revised version will be published at this address with an updated date.