Last updated: April 10, 2026
When you use CalendarPipe, we collect the following information:
Events synced between connected calendars are not stored. When CalendarPipe syncs events between two calendars you have connected (Google, Microsoft, or Apple/CalDAV), events are fetched from the source, processed through your pipe function in real-time, and written to the target. We do not maintain a copy of these events on our servers.
Hosted calendars are different. When you create a hosted calendar on CalendarPipe, CalendarPipe is the system of record for that calendar, so the events in it are stored in our EU-hosted database. They are deleted when you delete the hosted calendar or your account.
We use the data we collect for the following purposes:
Your data is not sold, rented, or shared with third parties for advertising purposes. We do not use your data to build advertising profiles or share it with data brokers.
CalendarPipe's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, CalendarPipe requests the following OAuth scopes:
https://www.googleapis.com/auth/calendar — read and write calendar events in order to perform syncshttps://www.googleapis.com/auth/userinfo.email — identify your Google account so we can associate it with your CalendarPipe accountGoogle data is used exclusively to sync calendar events according to your configured rules. Your Google data is:
When you connect a Microsoft account, CalendarPipe requests the following OAuth scopes:
Calendars.ReadWrite — read and write calendar events in order to perform syncsUser.Read — read your basic profile to identify your Microsoft accountoffline_access, openid, email, profile — standard OpenID Connect scopes for authentication and token refreshMicrosoft data is subject to the same handling commitments as Google data: not sold, not used for advertising, events are processed in real-time during sync and are not stored on CalendarPipe servers.
CalendarPipe offers an optional AI feature that generates pipe function code from a natural-language description. This feature uses OpenAI's API (gpt-4o-mini model).
When you use this feature, the following is sent to OpenAI:
The following is NOT sent to OpenAI: your calendar events, OAuth tokens, or any other calendar data.
OpenAI does not use data submitted via its API to train its models. API inputs and outputs may be retained by OpenAI for up to 30 days for safety and abuse monitoring, after which they are deleted. For more information, see OpenAI's API data usage policies.
This feature is entirely optional — you can write pipe functions manually or use pre-built templates instead.
CalendarPipe relies on the following third-party services to operate:
We also use standard infrastructure services for bot protection and transactional email delivery. These services do not process your calendar event content.
We take security seriously. Here is how we protect your data:
While we implement strong security measures, no method of electronic storage or transmission is 100% secure. If you discover a security issue, please contact us at privacy@calendarpipe.com.
Your data is retained for as long as your account is active and for the period necessary to provide the service. Sync logs are retained for operational monitoring and are periodically pruned.
When you delete your account, the following is removed from our systems:
Deletion is processed within 30 days of account removal.
Your core account data — profile, OAuth tokens, sync rules, and hosted calendar events — is stored with Supabase in the EU Central region (Frankfurt, Germany). Background job scheduling runs through Upstash in the same EU region (AWS eu-central-1).
International transfers: Product analytics events, error reports, and application logs are processed by PostHog in the United States. These transfers rely on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, as applicable. We do not send calendar event content, attendee personal data, or OAuth tokens to PostHog — only product events, error metadata, and diagnostic logs tied to your CalendarPipe user ID.
Under the General Data Protection Regulation (GDPR), EU residents have the following rights:
Our legal basis for processing your data is: contract performance (providing the sync service you signed up for) and legitimate interests (security monitoring and abuse prevention).
To exercise any of these rights, email us at privacy@calendarpipe.com. We will respond within 30 days.
You can delete your account at any time from your account Settings page. Deleting your account removes all personal data, OAuth tokens, sync rules, and sync history from our systems.
If you need help deleting your account, you can also email us at privacy@calendarpipe.com and we will take care of it for you.
Account deletion is irreversible. Once deleted, your data cannot be recovered.
If you have questions about this Privacy Policy or your data, contact us at:
CalendarPipe
privacy@calendarpipe.com