Calendar Mesh is a small, invitation-only service operated by an individual, not a company. This policy sets out exactly what it collects, why, who it is shared with, how long it is kept, and what you can ask for. It is written to be accurate rather than reassuring — where something is a genuine limitation, it says so.
Calendar Mesh is operated privately by the individual who invited you, acting as the data controller. There is no company, no staff and no support desk. Contact that person for anything in this policy.
No advertising identifiers, no analytics or tracking scripts, no behavioral profiling, no location data beyond whatever appears inside the calendar feeds you choose to add, and no access to your Google or Microsoft email.
| Data | Purpose | Basis |
|---|---|---|
| Email, name, picture | Identify your account; show who you are signed in as | Necessary to provide the service you requested |
| Feeds and settings | Fetch and display your calendars | Necessary to provide the service |
| Event content | Detect changes and write them into your linked calendars | Necessary to provide the service |
| Provider tokens | Keep calendars updated in the background | Necessary to provide the service |
| Change journal | Produce your Daily Brief | Necessary to provide the service; emailed delivery only with your consent |
| Session token | Keep you signed in securely | Necessary to provide the service |
The emailed Daily Brief is off by default and is sent only if you turn it on. You can turn it off at any time; the in-app view is unaffected.
Your data is not sold, rented, or used for advertising, and it is not shared with anyone beyond the providers needed to run the service:
| Provider | What they receive |
|---|---|
| Cloudflare | Hosting and storage — technically all stored data passes through and rests on their infrastructure |
| Sign-in verification; if you link a Google calendar, the event content written to it | |
| Microsoft | The event content written into the Outlook account you connect |
| Resend | Your email address and the contents of your Daily Brief — only if you enable emailed briefs |
| Feed publishers | They see requests for their feed, including the originating network address |
Each provider handles data under its own privacy policy. Data may also be disclosed if required by law.
Each account's calendars, provider connections, sync history and Daily Brief are stored separately and keyed to that account. Another user cannot see your calendars or your event content.
When someone shares a calendar with you, they send only the feed's address, name and color. Accepting creates an independent copy owned by you: they cannot see it, change it, or see whether you kept it. The reverse is equally true of calendars you share.
You can ask the operator to:
Depending on where you live, you may have additional statutory rights, including data portability and the right to complain to a data protection authority.
You can act directly at any time: remove a calendar, disconnect Outlook or Google from the Connected Calendars screen, turn off the emailed brief, or sign out. Deleting an account removes the profile, feeds, tokens, sync history and journal.
All traffic runs over HTTPS. Sign-in uses Google's and Microsoft's own authentication, so this service never handles your passwords. Session tokens are cryptographically signed and expire. Access is invitation-only, and administrative functions are restricted.
Being honest about the limits: this is a personal project maintained by one person. It has not undergone an independent security audit, and it carries no formal certification or uptime guarantee. Please weigh that when deciding what to add.
No advertising or tracking cookies are used. The app stores a small amount of data in your browser's local storage — your session token, sign-in details and a cached copy of your calendars for offline viewing. Signing out clears it. Google's sign-in library may set cookies of its own under Google's policies.
The service is not directed at children and accounts are issued only to invited adults. If a feed you add contains information about children, you are responsible for having the right to use it.
The service runs on Cloudflare's global network, and the providers listed above operate internationally, so data may be processed in countries other than yours, including the United States. Using the service means accepting that transfer.
Material changes will be reflected in the date at the top of this page. Continuing to use the service after a change means the revised policy applies. Significant changes will, where practical, be mentioned in the app.