Privacy policy
Effective September 24, 2026
Calendar Sync is a free, invite-only service operated by Dave Dozier as an individual. It is not run by, or on behalf of, any employer. This policy says what it reads, what it keeps, and who can see it. Contact: dozier.dave@gmail.com.
What it reads from Microsoft
Through Microsoft Graph, with the delegated permission
Calendars.Read (plus offline_access, so syncing
continues without you signing in each time). Access is read-only: Calendar
Sync never creates, changes or deletes anything in your Microsoft calendar.
For each event in the sync window it reads the title, start and end time and
time zone, whether it is all-day, its recurrence pattern, location, the short
description preview Microsoft provides, the organizer's email address, your
response (accepted, declined and so on), and whether it was cancelled.
What it does in Google
Through the Google Calendar API, with the scope
https://www.googleapis.com/auth/calendar.events. It creates,
updates and deletes the copies it makes in the one calendar you choose. It
lists events in that calendar only to find its own copies; it does not keep or
change anything else there.
What it stores
- The sign-in tokens Microsoft and Google issue, so syncing can run unattended.
- For each synced event: its identifiers in both calendars, its title, times and organizer email, and the last version written to Google, so changes can be detected.
- Your sync settings, and a log of sync activity (event identifiers, actions taken, errors).
It stores no event attendees and no full event descriptions. Data is held in Cloudflare's D1 database, encrypted at rest, and sent only over HTTPS.
How it is used
Only to keep your Google copy of your calendar in sync. Your data is never sold, never used for advertising, never shared with anyone else, and never used to train AI or machine-learning models.
Who can see it
You. As with any hosted service, the operator can technically access the database. In the operator's console your event titles are hidden by default; revealing them is a deliberate, per-person action that is logged, and is done only to diagnose a problem you have reported.
Cloudflare hosts the service and its database. Microsoft and Google handle your data under their own terms when Calendar Sync calls their APIs. No one else receives it.
Keeping and deleting it
Data is kept while your calendars are linked. Email dozier.dave@gmail.com to stop syncing and everything stored about you, including sign-in tokens, is deleted within 30 days. On request, the copies in your Google Calendar can be removed too. You can also revoke access at any time yourself: in your Google Account under Third-party apps & services, and in Microsoft under My Apps.
Google API Services User Data Policy
Calendar Sync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
If this policy changes in a way that matters, everyone using Calendar Sync will be emailed before the change takes effect. The date at the top shows the current version.