Calendar Mesh
Calendar Mesh
Your calendars, everywhere, within minutes.
← Back to Calendar Mesh

Privacy Policy

Last updated 27 July 2026 · Applies to calendar-mesh.com

Calendar Mesh is a small, invitation-only service operated by an individual, not a company. This policy sets out exactly what it collects, why, who it is shared with, how long it is kept, and what you can ask for. It is written to be accurate rather than reassuring — where something is a genuine limitation, it says so.

On this page:
Who runs this · What is collected · Why · Who it is shared with · How long it is kept · Your rights · Security · Local storage · Children · International · Changes

1. Who runs this service

Calendar Mesh is operated privately by the individual who invited you, acting as the data controller. There is no company, no staff and no support desk. Contact that person for anything in this policy.

2. What is collected

Information you give us

Information collected automatically to run the service

What is deliberately not collected

No advertising identifiers, no analytics or tracking scripts, no behavioral profiling, no location data beyond whatever appears inside the calendar feeds you choose to add, and no access to your Google or Microsoft email.

Please note: a calendar feed may contain personal information about other people — names of children on a team roster, home addresses used as venues, and so on. If you add such a feed, that content is processed and stored by this service on your instruction. Only add feeds you are entitled to use.

3. Why each item is processed

DataPurposeBasis
Email, name, pictureIdentify your account; show who you are signed in asNecessary to provide the service you requested
Feeds and settingsFetch and display your calendarsNecessary to provide the service
Event contentDetect changes and write them into your linked calendarsNecessary to provide the service
Provider tokensKeep calendars updated in the backgroundNecessary to provide the service
Change journalProduce your Daily BriefNecessary to provide the service; emailed delivery only with your consent
Session tokenKeep you signed in securelyNecessary to provide the service

The emailed Daily Brief is off by default and is sent only if you turn it on. You can turn it off at any time; the in-app view is unaffected.

4. Who your data is shared with

Your data is not sold, rented, or used for advertising, and it is not shared with anyone beyond the providers needed to run the service:

ProviderWhat they receive
CloudflareHosting and storage — technically all stored data passes through and rests on their infrastructure
GoogleSign-in verification; if you link a Google calendar, the event content written to it
MicrosoftThe event content written into the Outlook account you connect
ResendYour email address and the contents of your Daily Brief — only if you enable emailed briefs
Feed publishersThey see requests for their feed, including the originating network address

Each provider handles data under its own privacy policy. Data may also be disclosed if required by law.

Separation between users

Each account's calendars, provider connections, sync history and Daily Brief are stored separately and keyed to that account. Another user cannot see your calendars or your event content.

When someone shares a calendar with you, they send only the feed's address, name and color. Accepting creates an independent copy owned by you: they cannot see it, change it, or see whether you kept it. The reverse is equally true of calendars you share.

5. How long things are kept

6. Your rights and choices

You can ask the operator to:

Depending on where you live, you may have additional statutory rights, including data portability and the right to complain to a data protection authority.

You can act directly at any time: remove a calendar, disconnect Outlook or Google from the Connected Calendars screen, turn off the emailed brief, or sign out. Deleting an account removes the profile, feeds, tokens, sync history and journal.

Calendars already created inside your own Outlook or Google account belong to you, not to this service. Deleting your account here leaves them in place — they simply stop updating. Delete them in Outlook or Google if you no longer want them.

7. Security

All traffic runs over HTTPS. Sign-in uses Google's and Microsoft's own authentication, so this service never handles your passwords. Session tokens are cryptographically signed and expire. Access is invitation-only, and administrative functions are restricted.

Being honest about the limits: this is a personal project maintained by one person. It has not undergone an independent security audit, and it carries no formal certification or uptime guarantee. Please weigh that when deciding what to add.

8. Cookies and local storage

No advertising or tracking cookies are used. The app stores a small amount of data in your browser's local storage — your session token, sign-in details and a cached copy of your calendars for offline viewing. Signing out clears it. Google's sign-in library may set cookies of its own under Google's policies.

9. Children

The service is not directed at children and accounts are issued only to invited adults. If a feed you add contains information about children, you are responsible for having the right to use it.

10. Where data is processed

The service runs on Cloudflare's global network, and the providers listed above operate internationally, so data may be processed in countries other than yours, including the United States. Using the service means accepting that transfer.

11. Changes to this policy

Material changes will be reflected in the date at the top of this page. Continuing to use the service after a change means the revised policy applies. Significant changes will, where practical, be mentioned in the app.

Calendar Mesh is an independent personal project. It is not affiliated with, endorsed by, or sponsored by Microsoft, Google, Cloudflare or any calendar publisher.