Your calendars. Your control.
Security & Privacy
Keep your calendars in sync, and your personal details in the right places. You choose what crosses. We protect the connection.
Private busy blocks, encrypted access tokens, and limited permissions. Event details are never saved in our database.
How your data is handledYour personal calendar
Dentist appointment
10:00 – 11:00 AM
Appointment notes stay off the copy
Your work calendar
Busy
10:00 – 11:00 AM
Availability protected
We never store your event details
Event details pass through to create copies. They never enter our database.
Encrypted access tokens
Calendar access tokens are encrypted at rest with AES-256-GCM.
Least-privilege access
Calendar access for syncing and read-only Outlook settings for timezone discovery. You can disconnect anytime.
Encrypted in transit
HTTPS protects every connection, with HSTS enforced.
Behind each sync
What passes through. What stays private.
A sync needs access to your events to do its job. Here is exactly how we use that access.
We never store your event details
A busy block writes a time span and your chosen label — never the title, description, attendees, or notes. Details do pass through our servers to decide what syncs and to build the copy, in both modes, and are never written to our database. If you turn on a title or attendee filter, those fields are read for that decision and then discarded.
Encrypted access tokens
The tokens that let us sync your calendars are encrypted at rest with AES-256-GCM. They're only decrypted in memory for the moment a sync runs.
Least-privilege access
We request calendar permissions to read and write events. For Outlook, we also request read-only mailbox settings access to discover your default calendar's time zone. We read the time zone without changing your mailbox settings. Disconnect a Google account and we revoke our access immediately. Microsoft doesn't give a connected app a way to do that on its own, so disconnecting stops the sync and drops our copy of the token, and we'll point you to where you can remove the grant yourself.
Encrypted in transit
Every connection uses HTTPS with HSTS enforced. Security headers (frame-deny, no-sniff, strict referrer policy) are set on every response.
The path of an event
- 1
Your source calendar
The original event stays with Google or Microsoft.
- 2
Processed for your rule
We read the event, apply your filters, and build the copy. Event details are never saved in our database.
- 3
The copy you chose
A busy block shares a time span and your label. A full copy can include the title, description, and location. Attendees are never copied.
A clear purpose
Your data is for your sync.
Google & Microsoft Limited Use
Sync My Cal's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use calendar data only to provide the sync features you set up — never to train models, never for advertising, and we never sell it. The same principles apply to Microsoft Graph data.
The infrastructure
Subprocessors
The services that help us run Sync My Cal, and the role each one plays.
Includes analytics, monitoring, and what each provider can actually see.
- Vercel
- Application hosting, serverless functions & private backups (US)
- Supabase
- Managed Postgres database (US East)
- Google Calendar API (with your authorization)
- Microsoft
- Microsoft Graph / Outlook Calendar (with your authorization)
- Resend
- Transactional and opted-in product email, plus delivery-status webhooks
- Stripe
- Payment processing — we never see your card number
The details, in writing
Documents for your review
For security reviews and procurement, the paperwork is right here. No sales call in between.
We're listening
Report a security issue
Found something that needs our attention? Get in touch directly and we'll respond promptly.