Security &privacy
CalenSync connects to Google with read-only permissions, encrypts your tokens at rest, and processes email in memory — so you get a unified schedule without giving up control.
Read-only OAuth
No write access to Gmail or Calendar
AES-256-GCM
Tokens encrypted at rest
Your controls
Disconnect or disable AI anytime
Read-only Google access
CalenSync only requests the minimum scopes needed to read your schedule — never to modify it or act on your behalf.
- calendar.readonly — view events, not create or delete them
- gmail.readonly — scan for commitments, not send mail
- tasks.readonly — sync task lists without editing them
We cannot send email or change your calendar
Our architecture is intentionally one-way. CalenSync pulls data in; it never pushes changes back to Google on your behalf.
- No write scopes on Gmail or Calendar
- No automated replies or invitations from CalenSync
- Disconnect any account instantly from Settings
Encrypted OAuth tokens
Google access and refresh tokens are encrypted at rest using AES-256-GCM before they are stored in our database.
- Industry-standard AES-256-GCM encryption before storage
- Decrypted only when a sync job or API call needs them
- Revoked automatically when you disconnect an account
Minimal email retention
Email is processed to find hidden events — not archived. We store extracted metadata and source references, not full inbox copies.
- AI parsing runs on relevant message context in memory
- Event rows store titles, dates, and source links — not full bodies
- AI email parsing can be disabled per account in Settings
AI with boundaries
The Assistant and Insights features use sanitized calendar context. You control whether AI features are enabled.
- RAG context limited to schedule-relevant metadata
- Anthropic API data is not used to train public models
- Query logs retained briefly for quality and abuse prevention
Trusted infrastructure
CalenSync runs on managed providers with industry-standard security practices. We do not sell your data.
- Supabase (PostgreSQL) for encrypted storage
- Vercel for application hosting
- Background sync workers on Fly.io with isolated credentials
Google OAuth scopes we request
When you sign in, Google shows exactly which permissions CalenSync needs. We keep the list short and read-only.
- openid email profile
- https://www.googleapis.com/auth/calendar.readonly
- https://www.googleapis.com/auth/gmail.readonly
- https://www.googleapis.com/auth/tasks.readonly
Your data, your call
Disconnect any linked Google account from the Accounts page to revoke access immediately. Disable AI email parsing or the morning digest from Settings. For full details on collection, retention, and third-party processors, see our privacy policy.
Privacy PolicyUnified schedule, without the trade-offs
Connect Google with read-only access and see your full timeline in minutes.