Privacy Policy — CalendarVault

Effective: July 11, 2026

The short version

CalendarVault is a local-first macOS application. Your calendar data is processed only on your computer. We operate no backend, collect no analytics and store none of your data on any server.

What data the app accesses

With your macOS Calendar permission, CalendarVault reads and writes events in the calendars available on your Mac through macOS (iCloud, and any Google or Microsoft 365 accounts you have added in System Settings → Internet Accounts). The app uses this access solely to display your calendars and to create, update and delete the events and availability (“Busy”) blocks you ask it to manage. Calendar synchronization to the cloud is performed by macOS using your own system accounts — not by a CalendarVault server.

Where your data lives

Events are cached in files inside CalendarVault's data folder on your Mac. OAuth tokens and any app-specific passwords are stored in the macOS Keychain (Data Protection). No CalendarVault server ever receives, stores or processes your data. Any network traffic is sent directly from your Mac to your own calendar providers over TLS, using your own account authorization — to Apple's iCloud servers, and to Google's and Microsoft's APIs — never to us.

Optional iCloud calendar sharing

CalendarVault includes an optional feature that copies selected events (for example, meeting invitations from your work calendars) into your own iCloud calendars, so they also show up on your other Apple devices. This feature is off by default and becomes active only after you explicitly enter an Apple ID and an app-specific password in the app's menu. When enabled, the app sends the relevant event data (such as titles, times and participant addresses) directly to Apple's iCloud servers over TLS (CalDAV), authenticated with the credentials you provided. Those credentials are kept only in the macOS Keychain (Data Protection) and are never sent to us or to anyone other than Apple. If you never set up this login, no such traffic ever takes place.

What we do NOT do

Google API Services — Limited Use disclosure

CalendarVault's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access

Remove an account in the app (which also deletes its blocks), and additionally revoke the grant at myaccount.google.com/permissions or account.live.com/consent/Manage. Deleting the CalendarVault app does not by itself erase the data it stored on your Mac. To remove that data, delete the folder ~/Library/Application Support/CalendarVault and clear any CalendarVault entries via Keychain Access.

Disclaimer

CalendarVault is a professional/business tool provided “as is”, without warranty, and used at your own risk. It modifies your calendar data — you are responsible for verifying results and keeping backups. The full limitation of liability is in the Terms of Use.

Contact

Data controller: the CalendarVault team. Questions: hello@calendarvault.app.