Calsync privacy policy

Effective 6 September 2026

Calsync is a personal calendar-synchronization tool maintained by Andy Edmonds. It runs on a computer or server selected by its operator and copies supported event details between explicitly connected Google Calendar and Microsoft 365 calendars. It is not a public, multi-user calendar-hosting service.

Data accessed and purpose

With your authorization, Calsync reads calendar identifiers, event identifiers, titles, descriptions, locations, start and end times, time zones, reminders, recurrence information, and change/deletion metadata. It uses these data only to create, update, and remove corresponding mirrored events in your selected destination calendar and to recover safely from interruptions.

Provider responses may also contain organizer and attendee information. Calsync does not copy attendee lists to mirrors, send meeting invitations, or retain organizer, attendee, or attachment lists in its event cache.

Where data goes

Event details are transmitted over HTTPS between the selected host and Google Calendar or Microsoft Graph. Mirrored details become available to people and administrators who already have access to the destination calendar or account under its existing permissions. Google and Microsoft process data under their own terms and privacy policies.

Calsync does not sell calendar data, use it for advertising, or use it to train artificial-intelligence models. It does not send calendar contents to analytics services. This policy page contains no Calsync tracking scripts; the website host may process ordinary request and security logs.

Storage and protection

OAuth credentials are stored in the encrypted macOS Keychain or, on a configured headless host, in encrypted files whose key is supplied separately by that host's credential system. Calsync does not ask for your Google or Microsoft account password.

A local SQLite database stores event-cache data, provider cursors, and source-to-mirror mappings. That database is restricted to the operating-system user but is not encrypted by Calsync itself; the operator is responsible for host access controls, disk encryption, and secure backups. Operational logs contain counts, timing, and error categories rather than event contents or tokens.

Retention and your control

Cached event data is refreshed as the synchronization window advances. Mapping records and historical mirrors may remain until the source is deleted or the operator removes them. Revoking authorization stops future access but does not automatically erase existing mirrors, the local database, backups, or provider-held data.

You can stop the service, revoke its access in your Google Account or Microsoft account settings, delete the local caches and stored credentials, and remove mirrored events from the destination calendars. Stop synchronization before manual cleanup so mirrors are not recreated.

Google API data

Calsync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Calendar data is used to provide the synchronization function described here.

Contact and changes

For privacy questions or requests, contact [email protected]. Changes to Calsync's data practices will be reflected on this page with an updated effective date.