Privacy Policy

Last updated: July 26, 2026

This Privacy Policy explains how CalendarFlow ("CalendarFlow," "we," "us") collects, uses, and shares information when you use our website, our web dashboard, and our desktop application (together, the "Service").

If you have any questions about this policy, contact us at support@calendarflow.io.

1. Information we collect

Account information. When you sign up, we collect your name, email address, and profile picture from your Google or Microsoft account via Google Sign-In or Microsoft Sign-In.

Google user data. If you connect a Google account, we request the following Google API scopes to provide the Service's core functionality:

  • Google Calendar (calendar.events) — to view your existing events and create, reschedule, or cancel events on your behalf.
  • Google Tasks (tasks) — to create and manage to-do items you ask us to add.
  • Google Contacts (contacts.readonly, contacts.other.readonly) — to look up email addresses for people you mention by name (e.g. "schedule a call with Sarah"), so we can add them as event attendees without you having to type their email manually.

Microsoft user data. If you connect a Microsoft (Outlook) account instead, we request the equivalent Microsoft Graph permissions:

  • Calendars.ReadWrite — to view your existing events and create, reschedule, or cancel events on your behalf.
  • Tasks.ReadWrite — to create and manage to-do items (Microsoft To Do) you ask us to add.
  • People.Read and Contacts.Read — to look up email addresses for people you mention by name, the same way we do for Google Contacts.

We only use this data to perform the actions you explicitly request through the Service (by voice command or through the dashboard). We do not use your Google or Microsoft user data for advertising, and we do not sell it.

Voice recordings and transcripts. When you use the desktop app's voice feature, your recorded audio is sent to our transcription and language-understanding infrastructure (provided by OpenRouter, a third-party AI API provider) to convert speech to text and extract the structured details of your request (title, time, attendees, etc.). We store the resulting transcript and the structured data we extracted from it, associated with your account, so you can see a history of your commands and so we can debug misunderstood requests. We do not use your voice recordings or transcripts to train AI models.

Payment information. Subscription payments are processed by Lemon Squeezy, our payment processor. We do not collect or store your credit card number ourselves — Lemon Squeezy handles that directly and shares with us only what's needed to manage your subscription (e.g. plan, status, renewal date).

Device and log information. Like most web services, our servers automatically log standard technical information (IP address, browser type, timestamps) for security and troubleshooting purposes.

2. How we use your information

We use the information described above to:

  • Authenticate you and maintain your account
  • Carry out the calendar, task, and contact actions you request
  • Provide customer support and respond to your requests
  • Maintain the security and reliability of the Service
  • Comply with legal obligations

3. How we share your information

We share information only in the following circumstances:

  • With Google or Microsoft APIs, to read and write the calendar/task/contact data described above, as directed by your own actions.
  • With OpenRouter, to perform speech-to-text transcription and language understanding on your voice commands.
  • With Lemon Squeezy, to process subscription payments.
  • With infrastructure providers (our hosting and database providers) who process data on our behalf and are bound by confidentiality obligations.
  • If required by law, or to protect the rights, property, or safety of CalendarFlow, our users, or others.

We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.

Google API Services User Data Policy

CalendarFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data retention and deletion

We retain your account information and command history for as long as your account is active. You may request deletion of your account and associated data at any time by emailing support@calendarflow.io — we will delete your data within a reasonable time, except where we are required to retain certain records by law.

You can also revoke CalendarFlow's access at any time — for Google, from your Google Account permissions page; for Microsoft, from your Microsoft account app permissions page — which immediately stops us from accessing your data.

5. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us at support@calendarflow.io.

6. Security

We use reasonable technical and organizational measures designed to protect your information, including encrypted connections (HTTPS/TLS) between your devices and our servers. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children.

8. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you directly.

9. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at support@calendarflow.io.