Smart Calendars AI is now on Mac — capture from anywhere from your menu bar calendar app.Download

Privacy Policy

Our Privacy Commitment

  • At Smart Calendars AI, privacy is a core feature.
  • We never sell, rent, or trade your personal information.
  • We collect only the data we truly need to deliver our scheduling services.
  • We do not use your content to train AI models. Your chosen assistant’s use of data is governed separately by its provider’s privacy policy and your account settings.
  • We design our systems to keep your information secure and retain it only as needed for the service you choose.

Smart Calendars AI, Berlin, Germany, is the controller responsible for the processing described in this policy. For privacy questions or to exercise your rights, contact [email protected]. This Privacy Policy explains what we collect, why we collect it, how it's used, and the choices you have.

1. Information We Collect and Why

  • Account Details – Your email and name to set up and sign in to your account (via Apple, Google, or email). This is used for subscription management and our business logic (free tier vs subscription access). Without providing this minimal data, our services cannot be used.
  • Google Calendar Connection – If you connect your Google account (OAuth), we store access tokens so we can read calendar data and create, update, reschedule, or delete events in your Google Calendar when you ask us to or enable a write action in the product. We do not use that access for any other purpose.
  • Subscriptions & Payments – Payment details are handled by our trusted partners (Apple for iOS, Stripe for web). We receive subscription status updates (active, canceled, etc.) to control access.
  • Assistant conversions – We temporarily store the text or images you send us so we can extract events or reminders for you.
  • Saved web calendars – The rules in section 7a apply to calendars you save as web feeds, whether on our website or through a connected assistant. They are separate from temporary Assistant conversions.
  • Security & Reliability Logs – Minimal technical details (like IP address) to detect abuse and keep the service stable. These logs are automatically deleted after a short period.
  • Website Analytics – Basic, privacy-friendly analytics through Plausible, a self-hosted, cookie-free analytics tool. It helps us understand overall usage trends without tracking you across the web or storing any personal data.

2. How Your Data Moves Through Our Service

  • AI Processing – We send the content you submit (such as text and images) to OpenAI and Google Gemini to process your request. Voice input is transcribed on your device using Apple's Speech framework (iOS); your audio is never stored or transmitted externally — only the resulting text is sent for processing. Our service providers do not use your data to train their models. This processing is not automated decision-making under GDPR Article 22, as it requires your active input and you control the results.
  • Google Calendar – When you connect your Google account, we use the Google Calendar API to read and write events (titles, dates, locations, attendees) only to fulfill your request, preview changes, or carry out a write action you enabled. Depending on the feature, that can include creating, updating, rescheduling, or deleting events. Calendar data is processed in memory for the specific operation and not retained beyond what is needed to complete your request. You can disconnect or revoke access at any time.
  • Availability Feeds (Share my availability) – When you create an availability feed, we call the Google Calendar API, Microsoft Graph API, or Apple's CalDAV endpoint (caldav.icloud.com) on a short cadence. For Google and Microsoft we use strict field masks that request ONLY the start time, end time, and free/busy status of your events. Apple's CalDAV protocol does not support a server-side field mask, so the full event body is briefly returned to our process; we discard the sensitive fields (titles, descriptions, locations, attendees, organisers) immediately on parse and they are NEVER persisted to our database. The resulting public feed URL contains only anonymised busy blocks (optionally rounded for additional privacy) labelled with a generic term you choose (e.g. 'Busy'). For Apple connections, your app-specific password is encrypted at rest with AES-256-GCM and used only to query CalDAV; it is never logged and never shared. If you disconnect your calendar (or your Apple ID password change silently revokes our app-specific password), the feed is automatically paused and subscribers see a notice asking you to reconnect; no stale data is served.
  • Temporary Conversion Results – Conversion results are stored temporarily until accessed by the user and deleted within the retention period described below. Persistent calendar feeds are described separately.
  • Security Logs – Automatically deleted after a short retention period (about 72 hours).
  • Connected assistants (MCP) – If you connect ChatGPT, Claude, Codex or another assistant to your saved web calendars, the data sharing and storage rules in section 7a apply. This is separate from using our Assistant for a one-off conversion.

3. Cookies & Similar Tools

  • Essential Cookies – Needed for sign-in and security.
  • Analytics – We use Plausible Analytics, which is cookie-free and collects no personal data. No analytics cookies are set. You can opt out by setting localStorage key plausible_ignore to "true" in your browser.

4. Legal Bases for Processing (EU/EEA/UK)

  • Contract – To deliver the service you request (e.g., process your calendar data, manage your account).
  • Legitimate Interests – To maintain security, prevent abuse, and understand service performance. You may object to processing based on legitimate interests; see section 8.
  • Consent – For any optional analytics or marketing (if applicable). You may withdraw consent at any time.

5. Sharing with Trusted Partners

We work with a small number of trusted providers who process information for us, including:

• OpenAI – AI text/image processing.

• Google (Gemini) – AI text/image processing.

• Google (Calendar API) – For Google Calendar integration; we read and write events in your connected calendar when you instruct us to.

• Stripe – Web payment processing.

• Apple – In-app purchases.

• Hosting & Email Providers – To run our infrastructure and support.

• Plausible Analytics – Self-hosted, cookie-free website analytics.

Where providers process information on our behalf, their use is governed by our service agreements. Your chosen MCP assistant provider also receives the feed data and results you request and processes them under its own terms, privacy policy and your account settings.

6. International Transfers

Your data may be processed in the EEA, US, or other countries where our partners operate. When required, we use legal safeguards such as Standard Contractual Clauses to protect your data.

7. How Long We Keep Information

  • Temporary conversion downloads – Stored for up to 15 minutes, then deleted. Saved web calendars have separate storage and deletion rules in section 7a.
  • Google OAuth tokens – Stored for as long as your Google account remains connected; deleted when you disconnect or revoke access.
  • Logs – Deleted after about 72 hours.
  • Minimal account/payment records – Kept as needed for legal or accounting purposes.

7a. Saved web calendars and connected assistants (MCP)

  • This section applies only to calendars saved as Smart Calendars AI web feeds. It covers feeds created on our website or through a connected assistant. It does not describe temporary content used for a one-off Assistant conversion.
  • Your saved calendars – We keep the feed, its events and editing history so it can stay available and you can restore removed events. Active and inactive feeds have no fixed expiry. An expired editing window does not delete them.
  • What your connected assistant shares – We receive the information your assistant sends to our calendar tools. This can include details from your conversation, but we do not automatically receive your full conversation history. We return the feed details and results you request to that assistant. Its provider handles those copies under its own privacy policy and your account settings. The MCP connection does not grant access to your inbox or other calendar accounts.
  • Subscription links – Anyone with a feed’s subscription link can read its published events. Share the link only with people you want to have access.
  • Disconnecting or deactivating – Disconnecting an assistant does not delete saved feeds. Deactivating a feed stops subscription access but keeps its events and history. Neither action deletes the feed or your account.
  • Deleting a feed – Deleting a private feed that is not in the public catalogue stops normal publication. Calendar apps may receive a deletion notice for 30 days. After that period, the next successful cleanup removes the feed, its events, linked history and calendar files kept to serve the subscription, including earlier versions. If cleanup fails, it is retried. Separate records and backups are explained below. Public or curated feeds and feeds with unresolved activation payments need separate review before removal.
  • Records of changes and charges – We keep separate records to prevent duplicate changes or charges. These include account and feed references, creation and editing results, and credit-payment references. They have no automatic deletion deadline and remain after a feed is deleted. You can request deletion at [email protected]. Records needed for unresolved payments or legal obligations require separate review.
  • Troubleshooting deleted links – A separate record may keep the feed title, your account reference and its subscription link identifier. It helps us investigate requests for deleted feeds. It becomes eligible for removal 90 days after its last update. Cleanup runs when a later deletion is recorded, so the record may remain longer.
  • Your assistant connection – We keep a record of the assistant you connected, its permissions and information used to secure the connection. Access can expire or be revoked without these records being deleted.
  • Deleting your account – This immediately revokes MCP access. Your sign-in account and its linked MCP connection records are scheduled for cleanup after 30 days. This does not automatically delete saved feeds or the separate records of changes and charges. Delete your feeds in the dashboard before closing your account, or ask [email protected] to remove remaining service records and backup copies. Your rights are explained in section 8.
  • Backups and copies elsewhere – Disconnecting an assistant or deactivating a feed does not erase our backups or copies already received by an assistant or calendar app. For copies held by another provider or on your devices, use that provider’s or app’s deletion controls.

8. Your Privacy Rights

Depending on your location, you may have the right to:

• Access your personal data

• Rectify (correct) inaccurate or incomplete data

• Delete your data

• Restrict or object to processing

• Data portability (receive your data in a machine-readable format)

• Withdraw consent at any time

• Lodge a complaint with your local data protection authority

To exercise any rights, email [email protected]. We aim to respond within one month.

EU/EEA & UK users – You may contact your local data protection authority if you feel we haven't addressed your concerns properly.

California residents – You have rights under the CCPA, including the right to know, delete, correct, opt out of sale/share (we do not sell/share), and non-discrimination.

Brazil residents – LGPD grants similar rights, plus review of automated decisions.

9. Children's Privacy

Our services are not intended for children under 13 (or the legal minimum in their country).

10. Security

We protect your data with encryption, secure authentication, and minimal retention.

11. Data Breach Notification

If a breach affects your personal data, we will notify you and relevant authorities as required by law.

12. Changes to this Policy

If we make material changes, we will notify you in-app or on our website before they take effect.

13. Google API Limited Use Compliance

Our use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use, transfer, or sell this data to create, train, or improve generalized AI or machine learning models.

Updated: September 9, 2026

AI Assistant Connections (MCP)

Your feeds. Your permissions.

With your approval, ChatGPT, Claude, Codex or another compatible assistant can read and manage your Smart Calendars AI feeds. We receive information supplied to our tools and return requested feed details to your chosen assistant. This connection does not grant access to your inbox or other calendar accounts.

Tracking Preferences

Plausible Analytics is cookie-free and collects no personal data. To opt out, open your browser console and run:

localStorage.setItem('plausible_ignore', 'true')

To re-enable, run: localStorage.removeItem('plausible_ignore')

Questions about privacy?

[email protected]

Last Updated

September 9, 2026

Related Information