Skip to content

Security & privacy

Sync My Cal is built for people who manage several clients' calendars — so keeping those worlds private and your data safe is the whole point, not an afterthought.

We never store your event details

In busy-block mode we only ever read an event's start and end times — never the title, description, attendees, or notes. Even in exact-copy mode, details pass through in transit to write the copy and are never persisted to our database.

Encrypted access tokens

The tokens that let us sync your calendars are encrypted at rest with AES-256-GCM. They're only decrypted in memory for the moment a sync runs.

Least-privilege access

We request only the calendar scope required to read and write events. You can disconnect any account in one click, which revokes our access immediately.

Encrypted in transit

Every connection uses HTTPS with HSTS enforced. Security headers (frame-deny, no-sniff, strict referrer policy) are set on every response.

Google & Microsoft Limited Use

Sync My Cal's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use calendar data only to provide the sync features you set up — never to train models, never for advertising, and we never sell it. The same principles apply to Microsoft Graph data.

Subprocessors

We rely on a short list of trusted infrastructure providers:

VercelApplication hosting & serverless functions (US)
NeonManaged Postgres database (US)
GoogleGoogle Calendar API (with your authorization)
MicrosoftMicrosoft Graph / Outlook Calendar (with your authorization)
ResendTransactional email (reconnect alerts, receipts)
StripePayment processing — we never see your card number

Report a security issue

Found something? Email security@syncmycal.app and we'll respond promptly. See our Privacy Policy for full data-handling details.