Legal
Privacy Policy
Effective and last updated: August 9, 2026
1. Overview
Calendar FreeSync ("we", "us", or "our") is a calendar synchronization service for Google Calendar, Microsoft Outlook, and iCloud Calendar. It also provides scheduling pages using Google and Microsoft calendars. This Privacy Policy explains what information we collect, how we use it, and how you can control it.
2. Information We Collect
- Account information: Your email address and name when you sign up.
- Connected account email addresses: The email addresses of the Google, Microsoft, and Apple Accounts you connect to the service.
- OAuth tokens: Access and refresh tokens granted when you authorize Calendar FreeSync to access your Google Calendar or Microsoft Outlook. These tokens allow us to read and write events on your behalf.
- iCloud Calendar credentials: Your Apple Account email and an encrypted, revocable app-specific password that you provide for iCloud Calendar synchronization. Two-factor authentication is required to create an app-specific password. Calendar FreeSync never asks for or receives your primary Apple Account password.
- Calendar event data: Event titles, dates, and times from your source calendar, solely for the purpose of replicating them to your target calendar. We do not store event content beyond what is necessary to perform the sync.
- Public booking page information: If you create a booking page, we store its URL and the page details you configure. An active booking page is public to anyone with its URL and may display details such as the host name, meeting name, duration, location, custom question, branding, and available times.
- Booking information: When someone books through a public booking page, we collect the booker's first and last name, email address, selected date and time, and any answer they choose to provide to an optional custom question. We also store booking status, meeting and location snapshots, technical identifiers, and a unique cancellation token.
- Usage data: Sync activity logs (e.g., which events were synced and when) to help us operate and debug the service.
3. How We Use Your Information
- To authenticate you and maintain your account.
- To connect to your Google Calendar, Microsoft Outlook, and iCloud Calendar accounts and perform the synchronization you configure.
- To operate public booking pages, check availability, process bookings, and create an event on the host's selected destination calendar. The event includes the booker's name and email address and may include the custom question and answer.
- To provide booking information to the host, including the booker's name, email address, meeting details, and any optional custom answer.
- To send transactional emails, including account emails, booking confirmations to bookers, new-booking notifications to hosts, booking reminders to bookers, and cancellation notices.
- To operate, maintain, and improve the service.
We do not sell your personal information. We do not use your calendar data for advertising. We disclose information only as needed to provide the service, including to the booking host, the host's authorized calendar provider, and the service providers listed below.
4. Third-Party API Usage
Calendar FreeSync uses the Google Calendar API, Microsoft Graph API, and Apple's iCloud Calendar service to read events from a source calendar and create or manage events in a target calendar. Scheduling availability checks and booking-event creation use Google and Microsoft calendars only. A booking event may contain the booker's name, email address, and optional custom answer so the host can identify and prepare for the booking. Our use of your data is limited to the functionality you configure or request.
Calendar FreeSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft APIs complies with the Microsoft API Terms of Use.
5. Revoking Access
You can revoke Calendar FreeSync's access to your connected accounts at any time:
- Within the app: Disconnect a calendar from the Connectors page. This removes the stored authorization material for that connected calendar, including an iCloud Calendar app-specific password. Deleting only a sync connection does not disconnect its calendars.
- Via Google: Visit Google Account Permissions and remove Calendar FreeSync from the list of connected apps.
- Via Microsoft: Visit Microsoft Account Permissions and remove Calendar FreeSync from the list of connected apps.
- Via Apple: Visit Apple Account settings and revoke the app-specific password used for Calendar FreeSync. Apple-side revocation stops future iCloud Calendar access but does not remove the encrypted credential from FreeSync; disconnect the calendar in FreeSync to delete it from our systems.
Disconnecting a calendar stops future synchronization but does not delete events that were already copied to a target calendar. Those events remain under the controls and retention practices of that calendar provider.
6. Data Retention
We retain connected-calendar metadata and authorization material while the calendar remains connected. Disconnecting a calendar deletes its stored OAuth tokens or encrypted iCloud Calendar app-specific password from our systems. Deleting your Calendar FreeSync account also deletes stored connected-calendar authorization material and stops future syncs. Deleting a sync connection alone does not disconnect its source or target calendars. You can delete your account from the dashboard settings.
Our daily anonymization process removes booking personally identifiable information after the booking start time is more than 90 days old. It replaces the booker's first name, last name, and email address with anonymized values and deletes the booker's custom answer from our booking record.
Historical and non-personal booking records may remain after anonymization, including the booking date and time, status, meeting name, location, custom-question text, operational timestamps, and technical identifiers. Anonymizing our booking record does not delete an event already created in the host's destination calendar. That calendar event remains under the host's and calendar provider's controls and retention practices.
7. Data Security
OAuth tokens, encrypted iCloud Calendar app-specific passwords, and account data are protected with access controls appropriate to their use. We use HTTPS for data in transit. Calendar FreeSync never stores or receives your primary Apple Account password.
Booking cancellation links contain a unique token and work like a capability: anyone who has the link can access the cancellation flow and cancel that booking. Keep cancellation links private and do not share them with anyone who should not be able to cancel the booking.
8. Third-Party Services
We use the following third-party services to operate Calendar FreeSync:
- Google Calendar API: Google calendar access, sync, availability, and booking-event creation
- Microsoft Graph API: Outlook calendar access, sync, availability, and booking-event creation
- Apple iCloud Calendar: iCloud Calendar access and synchronization only, not scheduling or booking-event creation
- Supabase: database and authentication
- Vercel: hosting and deployment
- Resend: transactional email delivery, including booking emails
- Stripe: payment processing (paid plans)
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice within the app. Continued use of the service after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at support@calendarfreesync.com.