Skip to content
CCalnel
PrivacyTermsCZ

Calnel Privacy Policy

Effective date: 1 October 2026 Version: 1.0

Operator: Double Brew s.r.o. Registered office: Ruprechticka 485/151, Liberec, 46014 Company ID: 05228280 VAT ID: CZ05228280 Contact: support@calnel.app Country of establishment: Czech republic

1. Who we are

Calnel is a calendar aggregation and routing service. It connects calendars selected by the user, creates privacy-filtered views called channels, and publishes read-only calendar feeds that users may subscribe to in third-party calendar applications.

For data-protection purposes, the controller of personal data processed by Calnel is Double Brew s.r.o., with the details stated above.

2. What this Policy covers

This Policy explains what personal data Calnel processes, why we process it, how long we keep it, who may receive it, and the choices and rights available to you.

It covers the Calnel website, application, authentication, calendar integrations, channel feeds, billing and support.

3. Data we process

3.1 Account and profile data

Depending on how you sign in, we may process:

  • email address;
  • display name and profile identifier provided by your identity provider;
  • linked authentication identities, such as Google or Microsoft;
  • account creation and last-activity timestamps;
  • locale, time zone and product preferences.

Authentication is provided using Supabase Auth.

3.2 Calendar connection data

When you connect a calendar provider, we process the identifiers and authorization data required to maintain that connection. This may include OAuth access/refresh tokens for Google or Microsoft, iCloud/CalDAV credentials, or a private ICS URL.

These credentials are used only to connect and synchronize the calendars you select.

3.3 Calendar and event data

Depending on the source and the fields available, Calnel may process:

  • calendar names and provider identifiers;
  • event start and end times;
  • event title;
  • description or notes;
  • location;
  • recurrence information;
  • meeting links;
  • attendee information where returned by the provider;
  • availability status and other metadata needed to build the Today view and channels.

Calendar content may contain personal data about you or third parties. You should connect only calendars you are authorized to use with Calnel.

Calnel is designed for read-only calendar access and does not write changes back to connected calendars as part of the current core product.

3.4 Channel and sharing data

We process your channel names, selected source calendars, privacy rules, custom labels and private feed tokens. A feed token enables anyone who has the link to retrieve the information intentionally exposed by that channel.

3.5 Billing data

If you purchase a paid plan, we process subscription status, plan, market/currency, billing period and payment-provider identifiers. Stripe processes payment-card and payment-method data. Calnel does not need to store your full card number.

3.6 Technical, security and usage data

We may process IP address, browser/device information, authentication logs, error logs, synchronization status, request timing, security events and limited product analytics such as feature usage or onboarding completion.

We do not use calendar content for advertising.

3.7 Support communications

If you contact us, we process your message, contact details and information you choose to provide so that we can respond and troubleshoot.

4. Why we process data and legal bases

Where the GDPR or similar law applies, we rely on the following legal bases:

  • Performance of a contract: account creation, calendar synchronization, channels, feeds, subscription management and support necessary to provide Calnel.
  • Legitimate interests: security, fraud prevention, abuse prevention, service reliability, diagnostics and limited product analytics, balanced against user privacy.
  • Consent: where required, for optional marketing communications, optional analytics/cookies, or access that legally requires consent.
  • Legal obligation: accounting, tax, compliance and lawful requests.

If you do not provide data necessary to connect a calendar or operate your account, the relevant feature may not work.

5. How Calnel uses connected calendar data

We use connected calendar data only to provide and improve user-facing Calnel features, including:

  • displaying your combined calendar view;
  • synchronizing selected sources;
  • applying your channel privacy rules;
  • generating read-only channel feeds;
  • showing sync and connection status;
  • diagnosing errors and preventing abuse.

We do not sell calendar data. We do not use calendar content for targeted advertising. We do not use connected calendar content to determine creditworthiness. We do not use connected calendar content to train generalized AI or machine-learning models.

Human access to connected calendar content is not part of normal administration. Our admin tooling is designed to show operational metadata such as counts, subscription status and sync health rather than meeting details. Human access to specific connected data should occur only where you expressly request or authorize support access, where necessary to investigate security/abuse, where required by law, or where data has been aggregated so that it no longer identifies an individual.

6. Google API user data

If you connect Google Calendar, Calnel requests the minimum Google Calendar permissions required for the features you choose, with read-only access used for the core product where possible.

Calnel's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is used only to provide or improve prominent user-facing Calnel features. We do not sell Google user data, use it for advertising, or transfer it to data brokers. We do not permit humans to read Google user data except with the user's affirmative permission for specific support, for security/abuse investigation, to comply with applicable law, or for appropriately aggregated internal operations as permitted by Google's policies.

You can disconnect Google Calendar from Calnel. You may also revoke Calnel's Google access through your Google Account security settings.

7. Security and application-level encryption

Calnel uses security controls intended to reduce unauthorized access to personal data. These include HTTPS/TLS in transit, Supabase authorization controls such as Row Level Security, server-side access checks and protection of service credentials.

After the Calnel application-level encryption layer is deployed: sensitive calendar content is encrypted by Calnel's server-side application before it is written to Supabase. Calnel uses authenticated encryption (AES-256-GCM). Encryption keys are kept separately in Vercel Secrets and are not stored as readable values in Supabase database tables. User-specific encryption keys are derived server-side so that stored calendar payloads are not plaintext when viewed directly in the database.

Certain operational fields needed for efficient synchronization or querying, such as internal IDs, provider type, timestamps, sync state or event time boundaries, may remain unencrypted. Calendar titles, event titles, descriptions, locations, attendee details, meeting links and connection credentials should be encrypted according to the implementation specification.

Authorized Calnel server processes can decrypt data when necessary to provide the Service, such as generating a user view or channel feed. Application-level encryption therefore reduces exposure from direct database access but is not “zero-knowledge” encryption.

No security system can guarantee absolute protection. If we become aware of a personal-data breach requiring notification, we will act in accordance with applicable law.

8. Sharing and recipients

We do not sell personal data.

We may disclose limited data to service providers acting on our behalf where necessary to operate Calnel, including:

  • Supabase — authentication and database infrastructure;
  • Vercel — application hosting and server execution;
  • Stripe — subscription and payment processing;
  • Google, Microsoft, Apple/iCloud or other calendar providers — when you choose to connect those services;
  • professional advisers, security providers or authorities where necessary and lawful.

A person who receives a valid Calnel channel feed link can access the information you have intentionally exposed in that channel. Once information is synchronized into a recipient's third-party calendar, that recipient and calendar provider may independently retain it.

Service providers are permitted to process data only for appropriate service purposes and subject to applicable contractual and legal safeguards.

9. International data transfers

Some service providers may process data in countries outside your country or outside the EEA. Where required, we rely on appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses or another legally recognized transfer mechanism.

10. Data retention

We retain account and configuration data for as long as your Calnel account is active and as needed to provide the Service.

Calendar event data may be synchronized and cached for the periods necessary to provide the Today view and channel feeds. We aim to minimize stored calendar content to what is necessary for the product.

When you disconnect a calendar, we stop future synchronization and remove or age out data that is no longer required, subject to technical logs and backup retention.

When you delete your Calnel account, the product is designed to revoke active sharing tokens, stop synchronization, delete stored provider credentials and remove application data through the account-deletion process. Operational records that must be retained for legal, billing or security reasons may be kept for the required period.

Encrypted infrastructure backups may retain deleted data for up to 30 days before they age out. Backups are not intended to restore a deleted user account through normal product operations.

Payment providers may retain transaction records under their own legal obligations.

11. Data export and deletion

Calnel provides account data export and account deletion functionality through Data & privacy settings, where available.

A data export may include account information, connected-account metadata, calendar/source metadata, channels, rules, subscription metadata and retained event data. Authentication secrets, OAuth refresh tokens, iCloud app-specific passwords, private encryption keys and usable sharing tokens are not included in exports.

Account deletion is intended to be irreversible once completed. If you later register again with the same email address, Calnel creates a new account rather than restoring the old account.

12. Your rights

Depending on your location, you may have rights to:

  • access personal data we hold about you;
  • correct inaccurate data;
  • request deletion;
  • restrict or object to certain processing;
  • receive certain data in a portable format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a competent data-protection authority.

Where GDPR applies, you can exercise these rights by contacting support@calnel.app. We may need to verify your identity before fulfilling a request.

You also have direct controls inside Calnel to disconnect calendar providers, rotate sharing links, export data and delete your account.

13. Cookies and local storage

Calnel may use essential cookies or browser storage for authentication, security, language, pricing-market selection and product preferences. Optional analytics or marketing cookies, if introduced, will be handled in accordance with applicable consent requirements.

14. Children's privacy

Calnel is not intended for children who are below the minimum age at which they can lawfully use the Service or consent to the relevant data processing in their jurisdiction. If we learn that we have collected personal data from a child in violation of applicable law, we will take appropriate steps to remove it.

15. Changes to this Policy

We may update this Policy as Calnel changes or legal requirements evolve. We will publish the updated version with a new effective date. Where required, we will provide additional notice of material changes.

16. Contact

Privacy questions and requests may be sent to:

support@calnel.app

Operator: Double Brew s.r.o. Registered office: Ruprechticka 485/151, Liberec, 46014 Company ID: 05228280 VAT ID: CZ05228280 Contact: support@calnel.app Country of establishment: Czech republic