Privacy Policy
Last updated: March 3, 2026
1. Information We Collect
We collect information to provide our AI calendar services:
- Account Information: Email address, name, profile picture from Google OAuth
- Calendar Data: Event titles, descriptions, times, locations, attendees, and meeting links from your connected Google Calendar
- Zoom Account Data: When you connect Zoom for video conferencing, we collect your Zoom email address and OAuth tokens required to create and manage meetings on your behalf
- AI Interactions: Your messages to our AI assistant and the context needed to provide assistance
- Contact Information: Email addresses and names of attendees extracted from calendar events for contact management
- Usage Data: Service interactions, features used, and error logs for improving our service
2. How We Use Your Information
We use the information we collect to:
- Provide AI-powered calendar management and scheduling assistance
- Generate semantic embeddings of your events for intelligent search and recommendations
- Sync calendar data in real-time via webhooks when changes occur
- Process natural language queries to find and manage your events
- Send you technical notices, updates, and support messages
- Track credit usage for AI operations and manage subscription services
- Analyze anonymized and aggregated usage patterns to improve service reliability
3. Information Sharing
We do not sell, trade, or otherwise transfer your personal information to third parties. We may share your information only:
- With your explicit consent
- With these service providers under strict confidentiality:
- Supabase: Database hosting and authentication
- AI Services: AI assistant functionality and semantic search processing
- Google Calendar API: Calendar synchronization
- Zoom: Video conferencing integration (meeting creation and management only)
- Stripe: Payment processing (payment data only)
- Vercel: Application hosting
- To comply with legal obligations
- To protect our rights and prevent fraud
4. Data Security
We implement comprehensive security measures:
- All data encrypted in transit (TLS/SSL) and at rest
- Row Level Security (RLS) policies ensure users can only access their own data
- OAuth 2.0 for secure Google Calendar and Zoom authentication
- Automatic token refresh to maintain secure connections for all integrations
- Service role keys stored securely and never exposed to clients
- Real-time webhook validation to prevent unauthorized access
- Regular security audits and updates
5. Calendar Data Processing
Your calendar data is processed with these specific practices:
- Data Storage: Calendar events stored in Supabase PostgreSQL with full encryption
- Real-time Sync: Google Calendar webhooks update your data instantly when changes occur
- Semantic Processing: Event titles and descriptions converted to embeddings for intelligent search
- Attendee Extraction: Contact information from events stored separately for contact management
- Video Conferencing: Zoom and Google Meet links stored alongside associated calendar events
- Data Retention: Events synced from 4 years past to 4 years future, updated incrementally
- Deletion: When you disconnect, all calendar data and embeddings are permanently deleted
- AI Processing: Only event metadata sent to AI models, never shared with other users
6. Google API Data Usage
CalenAI affirms that our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We are committed to responsible data handling and full compliance with Google's policies.
Specifically, our use of Google Calendar data complies with the following Limited Use requirements:
- Limited Use: Google Calendar data is used solely to provide CalenAI's calendar management features and is not used for any other purpose
- No Sale: We never sell your Google Calendar data to third parties
- No Advertising: Your calendar data is not used for advertising purposes or to serve personalized ads
- Human Review: Google Calendar data is not reviewed by humans unless required for security, compliance, or to provide customer support
- AI Processing: Calendar data is processed using AI technology only to provide intelligent calendar management features such as natural language search and scheduling assistance
- Data Portability: You can export your calendar data at any time through CalenAI or directly from your Google Account
- Data Retention: We retain calendar data only as long as necessary to provide our services or as required by law
7. Zoom Data Usage
When you connect your Zoom account to CalenAI, the following practices apply:
- Limited Access: We only access Zoom APIs to create, update, and delete meetings on your behalf. We do not access your Zoom recordings, chat messages, phone calls, or any other Zoom data
- Token Storage: Zoom OAuth tokens are stored securely in our database with encryption at rest and protected by Row Level Security policies
- Meeting Data: We store only the meeting join URL, meeting ID, and passcode associated with your calendar events
- No Data Sharing: Your Zoom data is never shared with third parties or used for advertising
- Revocation: You can disconnect Zoom at any time in CalenAI Settings. Upon disconnection, all Zoom tokens are deleted immediately
- Deauthorization: If you remove CalenAI from your Zoom account, we automatically delete all stored Zoom tokens and data
- Data Compliance: We comply with Zoom's Marketplace data handling requirements and respond to all data deletion requests
8. Data Retention
We retain your data according to these policies:
- Active Accounts: Calendar data retained while your account is active
- Account Deletion: All data deleted within 30 days of account closure
- Backup Deletion: Backups and cached data removed within 90 days
- Google Disconnection: Calendar data deleted within 30 days if you revoke Google access
- Webhook Channels: Auto-renewed every 28 days while active
9. Your Rights
You have the right to:
- Access: View all your stored data through the dashboard
- Update: Modify your profile and preferences in settings
- Delete: Remove your account and all associated data permanently
- Export: Download your calendar data in standard formats
- Disconnect: Revoke Google Calendar access at any time through CalenAI settings or Google Account Settings
- Opt-out: Unsubscribe from marketing communications
- Complain: File a complaint with data protection authorities
10. Cookies and Tracking
We use minimal tracking for essential functionality:
- Authentication Cookies: Required for login sessions via Supabase
- Preference Storage: Local storage for UI preferences and settings
- Analytics: Basic usage metrics (no personal data)
- No Third-Party Tracking: We don't use advertising or tracking cookies
11. GDPR and International Data Rights
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, you have additional rights:
- Legal Basis: We process your data based on your consent (when connecting Google Calendar or Zoom) and legitimate interest (to provide and improve our services)
- Data Subject Rights: You have the right to access, rectify, erase, port, restrict, and object to processing of your personal data
- Right to Erasure: You can delete your account and all associated data (calendar events, Zoom tokens, AI interactions, contacts) at any time
- Data Portability: You can export your calendar data in standard formats or access it directly via Google Calendar or Zoom
- International Transfers: Your data is stored on US-based servers (Supabase, Vercel). Transfers from the EEA/UK are protected by Standard Contractual Clauses (SCCs) implemented by our service providers
- Data Protection Officer: For GDPR-related inquiries, contact our DPO at dpo@calenai.com
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
- Consent Withdrawal: You can withdraw consent at any time by disconnecting integrations or deleting your account, without affecting the lawfulness of prior processing
12. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last updated" date.
13. Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at:
Privacy Inquiries: privacy@calenai.com
Data Protection: dpo@calenai.com
Google API Issues: api-support@calenai.com
Response Time: Within 30 days
Questions about your data?
We're committed to transparency about how we handle your information. Contact us if you have any concerns.