dsh-calendar — last updated 3 September 2026
dsh-calendar is a personal, single-user application operated by Nicolas Hafner. It is not a public service and has no other users. This policy describes what it accesses and where that data goes.
With the account holder's consent, the application accesses Google Calendar data for
the consenting account only, under the scope
https://www.googleapis.com/auth/calendar. This covers calendar events and
their contents: titles, descriptions, times, locations, and attendees. No other Google
data — mail, contacts, files, or profile information beyond the account identifier —
is requested or accessed.
Calendar data is read to answer the operator's own questions about their schedule, and written when the operator asks for an event to be created, changed, or deleted. It is used for no other purpose.
The only network traffic the application generates for this purpose is directly between the operator's machine and Google's own CalDAV endpoints.
The OAuth refresh token issued at sign-in is stored locally on the operator's machine, in a file readable only by the operator's user account. It is never transmitted anywhere except to Google, to obtain access tokens. No copy is kept elsewhere.
Calendar content is not retained after use: it is fetched on demand to answer a request, and no separate database or archive of calendar data is maintained.
Access can be withdrawn at any time from myaccount.google.com/permissions, by removing "dsh-calendar". Revocation immediately invalidates the stored token, after which the application can no longer read or write any calendar data. The locally stored token can additionally be deleted from the operator's machine.
The application is not directed at children and is not made available to any user other than its operator.
If this policy changes, the revised version will be published at this address with an updated date.
Questions about this policy: nicolas.hafner@gmail.com