CalendarProject Privacy Policy
This Privacy Policy describes how CalendarProject ("we", "our", or "the Application"), a self-hosted household software project developed by Cornfield Codeworks, accesses, collects, uses, stores, and protects your information, with specific focus on data accessed through third-party services such as Google APIs.
1. Overview of CalendarProject
CalendarProject is an autonomous, self-hosted household calendar and wall dashboard designed for private family scheduling. It runs within a household's private local network infrastructure. CalendarProject is not a publicly hosted multi-tenant cloud service; each instance operates independently on hardware managed and controlled by the household operator.
2. Google User Data Accessed by CalendarProject
CalendarProject provides an optional integration with Google Calendar to allow household members to synchronize personal and family events. CalendarProject accesses Google user data strictly after explicit user authorization via the Google OAuth 2.0 consent screen.
The specific Google API scopes requested by CalendarProject are:
-
https://www.googleapis.com/auth/calendar(Full access to Google Calendar): Used to read calendar metadata and event schedules from user-selected calendars, and to create, update, or delete calendar events when the user performs corresponding synchronization actions within CalendarProject. -
https://www.googleapis.com/auth/userinfo.email(View user email address): Used solely to display the connected Google Account identifier within the application's administrative settings so users can identify which account is active.
3. How Google User Data Is Used
Google user data accessed by CalendarProject is used solely to provide the core calendar synchronization functionality explicitly requested by the user:
- Calendar & Event Discovery: To retrieve the list of available calendars in your Google account so you can designate which calendars should appear on your household display.
- Event Retrieval & Display: To fetch scheduled events from your designated calendars and display them on the household dashboard.
- Two-Way Synchronization: To push new events, modifications, or cancellations made within CalendarProject to your selected Google Calendar destination.
Limited Use Disclosure:
CalendarProject's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. What We Do NOT Do With Your Data
We hold a strict stance on user privacy and data ownership:
- No Selling of Data: Google user data is never sold, rented, leased, or monetized to third parties under any circumstances.
- No Advertising: Google user data is never used for advertising, behavioral profiling, personalized ads, or retargeting.
- No AI/ML Training: Google user data is never used to train, develop, or improve generalized machine learning or artificial intelligence models.
- No Third-Party Sharing: Google user data is never transferred or shared with external third parties, except strictly as required to fulfill the user's explicit synchronization instructions or where required by valid legal process.
5. Data Storage, Security & Encryption
CalendarProject is engineered to maintain high standards of security for sensitive credentials:
- Server-Side Storage Only: OAuth tokens (access tokens and refresh tokens) are managed entirely server-side. They are never transmitted to client browsers, wall display screens, or client-side storage.
- Encryption at Rest: All stored OAuth tokens and credentials are encrypted at rest in the application's private PostgreSQL database using authenticated AES-256-GCM encryption.
- Key Isolation: The master encryption key is maintained exclusively in the local host's secure environment configuration and is never accessible through public endpoints or shared across networks.
- Encrypted Transmission: All communications between CalendarProject and Google APIs occur over TLS/HTTPS (port 443) using modern, secure cipher suites.
6. Data Retention, Disconnection & Deletion
Because CalendarProject is self-hosted on your own hardware, you maintain complete custody of all synchronized event records:
- Disconnecting from within the Application: You may disconnect your Google account at any time by navigating to Settings → Google Calendar Sync and selecting Disconnect. Disconnecting immediately revokes the active session and permanently purges stored access tokens, refresh tokens, and calendar synchronization states from the database.
- Revoking Access via Google Account: You can revoke CalendarProject's authorization at any time directly through your Google Account security controls at https://myaccount.google.com/permissions. Once revoked, CalendarProject cannot access your Google account until explicitly re-authorized.
- Local Event Purge: When an account or calendar synchronization is removed, local replicas of synchronized events can be deleted immediately through the application settings or database management tools.
7. Other Third-Party Providers (Apple / iCloud)
CalendarProject also supports synchronization with Apple/iCloud Calendars via the standard CalDAV protocol. Any credentials provided for Apple/iCloud access (such as Apple ID and App-Specific Passwords) are subject to the same strict security standards: stored exclusively on the self-hosted server, encrypted at rest using AES-256-GCM, and used solely to synchronize user-selected calendars.
8. Children's Privacy
CalendarProject is designed for family household use on a shared display. The software does not collect personal information from individuals or track child users. All account authorizations and settings must be configured by an authorized household administrator.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect enhancements to CalendarProject or changes in applicable legal standards. Any revisions will be published at https://cornfieldcodeworks.com/calendarproject/privacy with an updated effective date.
10. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or CalendarProject's privacy practices, please contact:
Cornfield Codeworks
Email: support@cornfieldcodeworks.com
Website: https://cornfieldcodeworks.com