RapidCal Logo RapidCal Privacy Policy
Home Privacy Policy Terms of Service GitHub
On This Page
  1. 1. Introduction & Scope
  2. 2. Data Collection & Access
  3. 3. How We Use Google User Data
  4. 4. Limited Use & Prohibited Uses
  5. 5. Data Sharing, Transfer & Disclosure
  6. 6. Data Protection & Encryption
  7. 7. Data Retention & Deletion
  8. 8. Your Privacy Rights
  9. 9. Website, Cookies & Children
  10. 10. Policy Updates & Contact

Privacy Policy

Effective Date: October 8, 2026 Last Updated: October 8, 2026 Application: RapidCal (rapidcal.codestacx.com)
Privacy Commitment & Google API Compliance Summary

RapidCal (developed and operated by CodeStacx at rapidcal.codestacx.com) is a privacy-first desktop calendar application for macOS, Windows, and Linux. When you sign in with your Google Account or Microsoft Account, RapidCal collects and accesses your account profile and calendar data solely to provide two-way calendar synchronization, event scheduling, offline search, and meeting management on your device. Security procedures and encryption are in place to protect the confidentiality of your data, and we never sell, share for advertising, or use Google Workspace API data to train artificial intelligence (AI) or machine learning (ML) models.

1. Introduction & Scope of This Privacy Policy

This Privacy Policy describes how RapidCal ("RapidCal", "we", "us", or "our"), developed and operated by CodeStacx, collects, accesses, uses, stores, protects, retains, and deletes your personal information and Google user data when you use the RapidCal desktop application or visit our official website at https://rapidcal.codestacx.com.

By downloading, installing, or using RapidCal, or by connecting your Google Account or Microsoft Account to RapidCal via OAuth 2.0, you acknowledge that you have read and understood the data collection, usage, protection, and retention practices detailed in this Privacy Policy.

2. What Personal Information and Google User Data We Collect and Access

When you sign up for and open an account with us, or when you connect a calendar account in RapidCal using Google Sign-In (OAuth 2.0) or Microsoft Sign-In, we ask you to provide us with certain personal information such as your name and email address, and to authorize RapidCal to collect and access your calendar data from Google APIs or Microsoft Graph APIs.

RapidCal only collects and accesses Google user data after you explicitly grant consent on Google's official OAuth 2.0 authorization screen. Below is the complete list of personal information and Google user data that RapidCal collects and accesses:

2.1 Google Account Identity & Profile Information

  • OAuth Scopes Requested: openid, email, profile (accessed via https://www.googleapis.com/oauth2/v2/userinfo).
  • Personal Data Collected: Your Google Account email address, full name / display name, unique Google account identifier (sub / user ID), and profile picture URL.
  • How It Is Collected: Retrieved directly over HTTPS when you authenticate your Google Account via OAuth 2.0 with PKCE (`S256`) and stored locally in the RapidCal application database so you can identify and switch between multiple connected calendar accounts.

2.2 Google Calendar Data (Sensitive Scopes)

  • OAuth Scopes Requested: https://www.googleapis.com/auth/calendar (which encompasses read and write access to your calendars and calendar events, equivalent to https://www.googleapis.com/auth/calendar.readonly and https://www.googleapis.com/auth/calendar.events).
  • Calendar Metadata Collected: Your Google Calendar list, including calendar IDs, calendar summary titles, descriptions, color codes, primary calendar flags, timezones, and your access role (`owner`, `writer`, `reader`, `freeBusyReader`).
  • Calendar Event Data Collected: For calendars you synchronize in RapidCal, we collect and store event records locally on your device, including:
    • Event identifiers (id, iCalUID, etag) and status (confirmed, tentative, cancelled);
    • Event titles (summaries) and text/HTML descriptions or meeting notes;
    • Start times, end times, all-day date flags, and IANA timezone identifiers;
    • Recurrence rules (RRULE, EXDATE, RDATE) and recurring event series linkage;
    • Physical event locations and virtual video conference join URLs (such as Google Meet, Zoom, Microsoft Teams, or Webex links);
    • Event organizer and attendee details (display names, email addresses, optional/required flags, and RSVP response statuses: accepted, declined, tentative, needsAction);
    • Visibility, transparency (busy vs. free), and reminder settings.

2.3 OAuth 2.0 Authentication Credentials

  • Authentication Tokens Collected: OAuth 2.0 access tokens, refresh tokens, token scopes, and token expiration timestamps issued by Google (https://oauth2.googleapis.com/token) or Microsoft (https://login.microsoftonline.com/common/oauth2/v2.0/token).
  • How Tokens Are Collected & Stored: Tokens are exchanged directly between your desktop device and the identity provider using RFC 8252 loopback redirection (http://127.0.0.1) with Proof Key for Code Exchange (PKCE) and stored encrypted on your device.

2.4 Microsoft Outlook / Microsoft 365 Account Data (Optional)

  • OAuth Scopes Requested: openid, profile, email, User.Read, Calendars.ReadWrite, and offline_access via Microsoft Graph (https://graph.microsoft.com/v1.0).
  • Data Collected: Your Microsoft display name, email address / user principal name, calendar metadata, and calendar events for two-way synchronization within RapidCal.

2.5 Application Preferences & Voluntary Support Communications

  • Local Application Settings: User interface preferences such as your default calendar view (Week, Month, Agenda), timezone preferences, working hours, theme settings, and cross-account busy block rules.
  • Support Communications: If you contact us via email at support@codestacx.com or submit a GitHub issue, we collect your name, email address, and any message or diagnostic information you voluntarily include so we can respond to your inquiry.

3. How We Use Google User Data and Personal Information

We use the Google user data and personal information we collect and access solely to provide, operate, and maintain the user-facing calendar management features of RapidCal that you explicitly request:

Data Category / Scope Specific Purpose & How RapidCal Uses the Data
Google Account Profile & Email
openid, email, profile
Used to authenticate your session, display your connected email address, name, and avatar in the RapidCal sidebar and Settings view, distinguish between multiple connected accounts, and determine your RSVP identity within calendar event attendee lists.
Google Calendar Metadata & Events
https://www.googleapis.com/auth/calendar
Used to synchronize and render your calendars and events in RapidCal's Day, Week, Multi-Day, Month, and Agenda views; index event titles, descriptions, attendees, and locations in a local SQLite FTS5 database for instant offline search; create, edit, reschedule, and delete events on your Google Calendar when you perform those actions in RapidCal; update your RSVP status (Yes / Maybe / No) on meeting invitations; extract video conference join URLs for one-key meeting launch; and create user-configured [Busy] availability blocks across your connected accounts.
OAuth 2.0 Access & Refresh Tokens Used exclusively to authenticate direct HTTPS API requests from your computer to Google Calendar APIs and Microsoft Graph APIs for background delta synchronization (nextSyncToken / @odata.deltaLink) and offline outbox mutation replay without requiring you to sign in repeatedly.

Specifically, your data is used for the following core application functions:

  • Account Authentication & Multi-Account Management: Identifying your connected Google and Microsoft accounts within the desktop client and associating each calendar and event with its owning account.
  • Two-Way Calendar Synchronization: Fetching incremental changes from Google Calendar API v3 using sync tokens (nextSyncToken) and pushing events you create, modify, move, or delete in RapidCal back to Google Calendar.
  • Local Offline Caching & Instant Search: Storing your synchronized calendar list and event instances in a local SQLite database on your workstation so you can view your schedule and run full-text searches even when disconnected from the internet.
  • Meeting RSVP & Conferencing Integration: Updating your attendee response status on invitations and parsing conference metadata (such as Google Meet links) so you can join upcoming calls directly from the application.
  • User-Configured Cross-Account Busy Blocking: When you explicitly enable cross-account busy blocking between two of your connected accounts, RapidCal reads the start and end time of an event on your source calendar and writes a redacted [Busy] placeholder event to your target calendar so your availability remains accurate across work and personal schedules.

4. Google API Services User Data Policy, Limited Use & Prohibited Uses

Google API Services User Data Policy — Limited Use Disclosure

RapidCal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.1 Explicit AI / ML Model Training Prohibition (Google Workspace APIs)

RapidCal explicitly affirms that Google Workspace APIs and Google user data are NOT used to develop, improve, or train generalized or non-personalized artificial intelligence (AI) and/or machine learning (ML) models. We never feed your Google Calendar events, descriptions, summaries, attendee lists, or account profile information into any foundation model, large language model (LLM), or third-party AI training pipeline.

4.2 Strict Verification Against Unauthorized Uses

In strict compliance with Google's Limited Use requirements, RapidCal verifies and guarantees that we do not use, transfer, sell, or disclose Google user data for any of the following unauthorized purposes:

  • Targeted advertising: We never use Google user data for targeted advertising.
  • Selling to data brokers: We never sell, license, or trade Google user data to data brokers.
  • Providing to information resellers: We never provide or disclose Google user data to information resellers.
  • Determining credit-worthiness: We never use Google user data to determine credit-worthiness.
  • Lending purposes: We never use Google user data for lending decisions or financial underwriting.
  • User advertisements: We never serve user advertisements based on Google user data.
  • Personalized advertisements: We never use Google user data for personalized advertisements.
  • Retargeted advertisements: We never use Google user data for retargeted advertisements.
  • Interest-based advertisements: We never use Google user data for interest-based advertising or behavioral profiling.
  • Creating external databases: We never aggregate or export Google user data to create external, commercial, or third-party databases.
  • Training non-personalized or generalized AI and/or ML models: We never use Google user data or Google Workspace APIs to train, fine-tune, or improve non-personalized or generalized AI and/or ML models.

4.3 Restrictions on Human Access to Google User Data

No human at CodeStacx reads or views your Google user data unless: (a) we first obtain your explicit, affirmative consent to inspect specific diagnostic information to troubleshoot a support issue you reported; (b) it is strictly necessary for security purposes such as investigating a security vulnerability or abuse; or (c) it is required to comply with applicable law. Because RapidCal stores your calendar data locally on your own computer rather than on CodeStacx servers, CodeStacx personnel have no technical access to your calendar database or OAuth tokens during normal operation.

5. How We Share, Transfer, or Disclose Google User Data

We do not transfer or disclose your information to third parties for purposes other than the ones provided in this Privacy Policy. We do not sell, rent, or trade your personal information or Google user data to any third party.

Your data is transmitted or disclosed only in the following strictly limited, user-authorized circumstances:

  • Direct Communication with Google APIs and Microsoft Graph APIs: When you create, edit, reschedule, RSVP to, or delete a calendar event in RapidCal, the application transmits those updates directly from your device over encrypted HTTPS to Google (www.googleapis.com) or Microsoft (graph.microsoft.com) to synchronize the changes with your own calendar account and notify meeting attendees you have invited.
  • User-Initiated Cross-Account Busy Blocking: If you connect multiple calendar accounts to RapidCal (for example, a personal Google Calendar and a work Google or Microsoft Calendar) and explicitly trigger RapidCal's Busy Block feature, RapidCal writes a redacted [Busy] block containing only the event start and end times (excluding private event descriptions and attendee lists) to the destination calendar account you selected.
  • Legal Requirements & Protection of Rights: We may disclose information if required to do so by law or in the good-faith belief that such action is necessary to comply with a valid legal obligation, court order, or governmental request, or to protect the security, rights, or property of CodeStacx, our users, or the public. Note that because calendar events and OAuth tokens are stored exclusively on your local device and not on CodeStacx servers, CodeStacx does not possess copies of your calendar contents.

6. Data Protection Mechanisms for Sensitive Data

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information both in transit over the network and at rest on your local device. RapidCal implements defense-in-depth technical, cryptographic, and architectural safeguards designed specifically to protect sensitive Google Calendar and OAuth credential data:

  • Encryption in Transit (HTTPS / TLS 1.2 & TLS 1.3): All network communications between RapidCal and Google APIs (oauth2.googleapis.com, www.googleapis.com) or Microsoft APIs (login.microsoftonline.com, graph.microsoft.com) are encrypted in transit using industry-standard Transport Layer Security (TLS 1.2 / TLS 1.3) enforced via rustls with strict certificate validation. Plaintext HTTP connections to remote APIs are never permitted.
  • Encryption at Rest in Native OS Hardware-Backed Keychains: Sensitive OAuth 2.0 access tokens and refresh tokens are never stored in plaintext configuration files or unencrypted SQLite tables. RapidCal stores your credentials inside your operating system's native, encrypted credential manager under the service identifier dev.rapidcal.desktop:
    • macOS: Apple Keychain Services (protected by Secure Enclave / user login keychain encryption).
    • Windows: Windows Credential Manager (protected by Windows Data Protection API / DPAPI).
    • Linux: Freedesktop Secret Service API / libsecret (GNOME Keyring or KDE KWallet).
  • AES-256-GCM Authenticated Encryption Vault: In desktop or headless Linux environments where an OS D-Bus Secret Service keyring daemon is unavailable, RapidCal automatically encrypts all OAuth token payloads at rest using authenticated AES-256-GCM (256-bit Advanced Encryption Standard in Galois/Counter Mode) with a cryptographically random 96-bit nonce per encryption operation and strict owner-only file permissions.
  • OAuth 2.0 Loopback with PKCE (Proof Key for Code Exchange): RapidCal authenticates directly with Google and Microsoft using RFC 8252 loopback redirection (http://127.0.0.1) paired with cryptographic S256 PKCE code challenges and anti-CSRF state verification tokens, preventing authorization code interception attacks.
  • Zero-Server Local Isolation: Unlike cloud-intermediary calendar apps that store copies of every user's calendar in a centralized multi-tenant cloud database, RapidCal stores your synchronized calendar events exclusively within your local OS user profile's application data directory. This eliminates the risk of centralized server data breaches exposing your calendar events or OAuth tokens.

7. Data Retention and Deletion of Google User Data

We retain your personal information for the length of time needed to fulfill the purposes outlined in this privacy policy unless a longer retention period is required or permitted by law. When the data retention period expires for a given type of data, we will delete or destroy it.

7.1 Data Retention Schedule

Data Type Storage Location Retention Period & Expiration
Google & Microsoft OAuth Tokens OS Keychain / AES-256-GCM Encrypted Vault on your device Retained only while your account remains connected in RapidCal. Immediately and permanently deleted the moment you disconnect your account or uninstall RapidCal.
Google Account Profile & Calendar Events Local SQLite Database on your device Retained locally while your account is connected so you can view and search your calendar offline. Events deleted in Google Calendar are automatically removed during incremental sync, and all account records are immediately purged when you disconnect the account.
Support Emails & Inquiries CodeStacx Support Inbox (support@codestacx.com) Retained only for the duration necessary to resolve your support request and deleted upon your request or after resolution, unless required by applicable law.

7.2 How to Delete Your Data and Revoke Access

You have full, immediate control to delete all Google user data collected by RapidCal and revoke OAuth permissions at any time using any of the following methods:

  • Method 1 — Instant In-App Account Disconnection & Data Purge: Open RapidCal, navigate to Settings → Accounts, and click Disconnect next to your Google or Microsoft account. RapidCal immediately:
    1. Deletes your OAuth 2.0 access token and refresh token from your OS Keychain and AES-256-GCM encrypted credential vault;
    2. Deletes your account profile (email address, display name, avatar) from the local SQLite database;
    3. Permanently deletes all synchronized calendars, calendar events, recurrence rules, attendee records, FTS5 full-text search index entries, and queued offline mutations associated with that account.
  • Method 2 — Uninstalling RapidCal & Removing Local Storage: Uninstalling the RapidCal desktop application and deleting its local application data directory (dev.rapidcal.desktop in your operating system's standard AppData / Application Support / XDG data directory) permanently destroys all locally stored databases, caches, and settings on your computer.
  • Method 3 — Revoking OAuth Access via Google or Microsoft Security Settings: You can directly revoke RapidCal's authorization to access your Google Account or Microsoft Account at any time from your provider's official security portal:
    • Google Third-Party App Permissions: https://myaccount.google.com/permissions
    • Microsoft Account Consent Management: https://account.live.com/consent/Manage
  • Method 4 — Requesting Data Deletion via Email: If you have corresponded with our support team or wish to request deletion of any personal information or support records held by CodeStacx, send an email to support@codestacx.com with the subject line "Data Deletion Request". We will process and confirm the permanent deletion of your information within 7 business days (and always within the timeframe required by applicable privacy laws).

8. Your Privacy Rights (GDPR, UK GDPR, CCPA/CPRA & Global Privacy Laws)

Depending on your jurisdiction, including the European Economic Area (EEA), the United Kingdom, Switzerland, California, and other US states, you have specific statutory rights regarding your personal information:

  • Right of Access & Portability: You can inspect all calendar and profile data stored by RapidCal directly within the application and its local SQLite database on your device.
  • Right to Rectification: You can edit or update your calendar events directly within RapidCal or in Google Calendar / Microsoft Outlook.
  • Right to Erasure ("Right to Be Forgotten"): You can immediately erase all collected Google user data by clicking Disconnect in RapidCal Settings or by contacting support@codestacx.com.
  • Right to Withdraw Consent: Since RapidCal processes your Google user data based on your explicit consent via Google OAuth 2.0, you may withdraw your consent at any time by disconnecting your account in RapidCal or revoking access at https://myaccount.google.com/permissions.
  • Right to Non-Discrimination & No Sale of Personal Information: We do not sell or share your personal information for cross-context behavioral advertising, and we never discriminate against users who exercise their privacy rights.

9. Website Privacy, Cookies & Children's Privacy

  • Static Website & No Tracking Cookies: Our public website at https://rapidcal.codestacx.com is an informational static site. We do not use advertising cookies, third-party analytics trackers, cross-site tracking pixels, or behavioral fingerprinting. Standard, short-lived web server access logs (such as IP address, request timestamp, and browser user-agent header) are processed solely to maintain network security, prevent denial-of-service abuse, and deliver static web pages.
  • Children's Privacy: RapidCal is not directed to children under the age of 13 (or the applicable minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us at support@codestacx.com and we will promptly delete such information.

10. Changes to This Privacy Policy & Contact Information

We may update this Privacy Policy from time to time to reflect changes in RapidCal's features, security practices, legal requirements, or Google and Microsoft API policies. When we make changes, we will revise the "Last Updated" date at the top of this page and publish the updated policy at https://rapidcal.codestacx.com/privacy. We will never materially expand the way we use or share your Google user data without first notifying you and obtaining your affirmative consent.

If you have any questions, concerns, or requests regarding this Privacy Policy, our data collection and usage practices, or our compliance with the Google API Services User Data Policy, please contact us:

  • Developer / Organization: CodeStacx (rapidcal.codestacx.com)
  • Privacy & Support Email: support@codestacx.com
  • GitHub Repository & Issue Tracker: https://github.com/Smit2553/RapidCal/issues
RapidCal by CodeStacx • Hosted at rapidcal.codestacx.com
Home Privacy Policy Terms of Service GitHub Contact Support