Privacy Policy
Last updated: August 6, 2026
Summary
CalendarCalls reads your upcoming calendar events so it can remind you about them in Slack and call your phone if you don't react. We only use your data to deliver those reminders. We do not sell it, and we do not use it for advertising.
Data we collect
- Account data: your name, email address, and profile picture from Google sign-in.
- Calendar data: upcoming events from your primary Google Calendar — title, start and end time, attendee count, RSVP status, event colour, and any Google Meet link. We read events in a short window around the present time in order to schedule reminders.
- Slack data: your Slack user ID, workspace ID, display name, and the email used to look you up, plus the workspace bot token needed to send you direct messages.
- Contact data: the phone number you save for escalation calls.
- Reminder history: which reminders were sent, whether you reacted, and whether a call was placed and its outcome.
- Technical data: basic logs and error reports needed to keep the Service running securely.
How we use it
- To detect upcoming meetings and send you a Slack reminder.
- To place a phone call when you have not reacted before the meeting starts.
- To show your upcoming meetings and reminder history in the app.
- To apply your settings, such as pausing notifications or priority event colours.
- To debug problems, prevent abuse, and keep the Service secure.
We do not sell your data, share it with advertisers, or use your calendar content to train models.
Google user data
CalendarCalls' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request read-only calendar access, use it solely to provide the reminder features described here, and do not transfer it to others except as needed to provide the Service, comply with the law, or as part of a merger or acquisition. You can revoke access at any time in your Google account settings or by disconnecting your calendar in Settings.
Service providers
We rely on a small number of processors to run the Service:
- Google — sign-in and calendar data.
- Slack — delivering reminder messages to your workspace.
- Our telephony provider — placing the escalation phone calls.
- Our cloud hosting and database provider — running the app and storing your data.
Each processor only receives the data required for its part of the reminder flow, for example the phone number and meeting title needed to place a call.
How we protect your data
We treat Google user data, Slack tokens, and phone numbers as sensitive data and apply the following safeguards:
- Encryption in transit: all traffic between your browser, our servers, Google, Slack, and our telephony provider uses TLS 1.2+ (HTTPS). We do not accept unencrypted connections.
- Encryption at rest: our managed cloud database and its backups are encrypted at rest with AES-256.
- Credential isolation: Google OAuth access and refresh tokens and Slack bot tokens are stored server-side only, are never sent to the browser, and are never written to logs or analytics. Provider secrets are held in a managed secret store, not in source code.
- Access control: every table enforces row-level security so a signed-in user can only read and write their own rows. Privileged database access is limited to a small number of named administrators using multi-factor authentication, and is used only for maintenance and support.
- Least privilege: we request only read-only Google Calendar access (
calendar.readonly) plus basic profile and email for sign-in. We cannot create, edit, or delete your calendar events. - Data minimisation: we read only events in a short upcoming window, store just the fields needed to send a reminder, and never copy your full calendar history. Phone numbers are only shared with our telephony provider at the moment a call is placed.
- Secure development: changes go through code review, automated dependency and security scanning, and OAuth callbacks are protected with single-use, user-bound state tokens to prevent cross-site request forgery.
- Vendor diligence: our processors (Google, Slack, our telephony provider, and our cloud hosting and database provider) are established providers bound by data processing agreements and receive only the data needed for their part of the reminder flow.
No system can be guaranteed perfectly secure, but we review these controls as the Service evolves.
Data retention and deletion
We keep your settings and tokens for as long as your account exists, and reminder history for as long as it is useful for showing you your history.
- Disconnecting Google Calendar in Settings immediately deletes the stored Google access and refresh tokens and stops all calendar reads.
- Disconnecting Slack removes your stored Slack identity and the workspace bot token used to message you.
- Deleting your account removes your profile, settings, phone number, tokens, and reminder history from our production database within 30 days, and from encrypted backups within 90 days as backups age out.
- You can also revoke our access at any time from your Google account permissions page.
International transfers
Our providers may process data in the United States and the European Union. Where personal data is transferred out of the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent approved mechanism.
Your choices and rights
- Pause all notifications at any time from the dashboard.
- Remove your phone number to stop all calls.
- Disconnect Google Calendar or Slack from Settings.
- Delete your account and associated data from Settings.
- Request access to, correction of, or deletion of your data by contacting us. Depending on where you live, you may also have the right to object to or restrict processing and to lodge a complaint with your local data protection authority.
Cookies
We use only the cookies and local storage needed to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies.
Children
The Service is not directed at children and we do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected in the "last updated" date above.
Contact
Privacy questions or requests: support@calendarcalls.com.
See also our Terms of Service.