Skip to policy
Calbraid
PrivacyTermsRefunds
Open Calbraid
Trust / 01
Privacy policyTerms of serviceRefund policyData processingSubprocessors

Your schedule is not an ad profile

Privacy,
in plain sight.

Calbraid needs calendar data to synchronize calendars. It does not sell it, advertise against it, or use it to train artificial intelligence models.

Version
2026-08-05
Last updated
5 August 2026

Who is responsible

Calbraid is offered and billed by Applifyer, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Product operations and support are performed with affiliated operating company Applifyer SH.P.K., Rruga Vëllezërit Gërvalla, B2. 12, Prishtinë, Kosovo, NUI 811946089, VAT 330561995 (together, “Applifyer”, “we”, “us”).

Applifyer, LLC is controller for account, billing, security, support, and direct customer-relationship data. When an organization controls a workspace and its calendar content, Applifyer, LLC generally processes that content for the organization under the Data Processing Addendum.

Data Calbraid processes

  • Account and team data: workspace name and URL slug, email, display name, saved IANA time zone, role, membership, legal-policy acceptance versions and timestamp, hashed browser and app credentials, hashed one-time verification and recovery tokens, browser session metadata, account status, and timestamps.
  • Connected-source data: provider, account identifier and email, granted scopes, encrypted OAuth tokens, CalDAV credentials, secret ICS subscription URLs, uploaded ICS snapshots, connection status, and synchronization timestamps.
  • Calendar data: calendar names, identifiers, permissions, colors, event identifiers, titles, descriptions, locations, times, recurrence, attendees, organizer, responses, conference links, status, and provider revision data.
  • Device and feed data: CalDAV requests, collection permissions, synchronization tokens, app-password metadata, and private-feed configuration.
  • Billing data: selected plan and interval, purchaser email, Stripe customer, Checkout and subscription identifiers, status, period dates, and webhook event identifiers. Stripe, not Calbraid, handles full card details.
  • Security and support data: limited request metadata, redacted errors, role-change audit records, and information you send when asking for help or exercising a right.

Google Calendar data

Calbraid requests calendar.events to read, create, update, and delete events; calendar.calendarlist.readonly to discover calendars and their permissions; and openid plus email to identify the connected Google account. Access begins only after you grant permission on Google’s OAuth screen.

Google calendar and event data is used only for user-facing connection, synchronization, CalDAV, private-feed, routing, team-access, and support features. Our use and transfer of data received from Google APIs follows the Google API Services User Data Policy, including Limited Use requirements.

We do not sell Google user data, use it for advertising, determine creditworthiness, or use it to train generalized AI or machine-learning models. Human access is limited to your request, security or abuse investigation, legal necessity, or aggregated internal operations permitted by Google’s policy.

You can disconnect Google in Calbraid and revoke the grant at Google Account permissions. Revoking access stops future provider collection; contact us for deletion of data already held by Calbraid.

Microsoft data

For Outlook and Microsoft 365, Calbraid requests delegated Calendars.ReadWrite, User.Read, identity, and offline-access permissions. Connected providers remain the authoritative source for their calendars.

Why we process data

  • Contract: connect providers, maintain the calendar gateway, route changes to the original provider, manage teams, provide support, enforce plans, and bill paid service.
  • Legitimate interests: secure credentials and tenant access, prevent abuse, troubleshoot failures, keep minimal audit evidence, and improve reliability without analyzing calendar content for advertising.
  • Legal obligations: preserve required accounting, tax, fraud, dispute, and legal records and respond to valid legal requests.
  • Your direction: connect or disconnect a provider, choose a destination calendar, share a collection, publish a private feed, or ask support to inspect a specific problem.

Sharing and transfers

We share data only with operating affiliates and providers needed to deliver the service, with people you authorize through workspace roles or private feed credentials, when you direct a provider operation, during a protected business transfer, or when law requires it. Current providers, purposes, data categories, and locations appear on the Subprocessors page.

Primary service processing occurs on Microsoft Azure in Germany West Central. Cloudflare carries encrypted network traffic and stores protected backup copies on global infrastructure. Resend delivers account verification and recovery email. Applifyer’s operating affiliate is in Kosovo, and providers such as Google, Microsoft, Cloudflare, Resend, and Stripe may process data internationally. We use contractual and technical safeguards, including applicable Standard Contractual Clauses, where required.

Cookies and analytics

Calbraid does not use advertising cookies, behavioral advertising, session replay, or heatmaps. We use our Applifyer-operated Umami service at insights.applifyer.com for anonymous page usage and performance measurement. It receives the page path, referrer, and coarse browser, device, and country information. The tracker uses no cookies or persistent user identifier, respects Do Not Track, strips query strings and fragments, and never sends account, calendar, form, or billing content. After sign-in, Calbraid sets a strictly necessary, first-party, HttpOnly browser-session cookie for up to 30 days. Registration, sign-in, activation, verification, and recovery forms also use a short-lived, first-party anti-forgery cookie. Google, Microsoft, and Stripe may set their own cookies after you deliberately follow an OAuth or Checkout link to their domain.

Retention and deletion

  • Connected credentials and synchronized calendar data remain while the connection or workspace is active. Disconnecting an account removes its provider credentials and materialized calendars from the live service. Owner workspace deletion removes every live connection and calendar.
  • Browser sessions remain until sign-out, member credential reset or removal, workspace deletion, or their 30-day expiry. Email-verification links expire after 24 hours and password-reset links after 60 minutes; replacing or using a link invalidates its token. Failed-authentication and recovery throttle records normally expire or are cleared after successful authentication.
  • Team and security audit records remain while the workspace is active. Self-service workspace deletion removes them from the live service. Separate evidence may be retained only where reasonably required for security, disputes, or law.
  • Billing and tax records remain for the period required by applicable accounting and tax law, commonly up to seven years.
  • Privacy-safe operational logs, traces, and metrics are retained for 14 days on Applifyer-operated Azure infrastructure in Germany. They contain route templates, methods, response status, timings, provider family, software release, random request and trace identifiers, and aggregate synchronization counts. Query strings, account or calendar identifiers, event content, credentials, request bodies, and provider responses are excluded.
  • Private error groups are retained for 30 days on separate Applifyer-operated Azure infrastructure in Germany. Calbraid sends a safe operation and exception class, not the original exception message, user identity, request body, provider response, or calendar content. Local container logs are size-limited and rotated.
  • Transactionally consistent Cloudflare R2 database copies use a 14-day rotation. Separately encrypted disaster-recovery snapshots may remain for up to 12 months. They are isolated from normal use; if a snapshot is restored, verified deletion requests must be reapplied before the service returns.

Your controls and rights

Members with permission can disconnect sources, revoke app passwords, and remove team access. Owners can use authenticated Data Control to cancel active billing, end provider access, and irreversibly erase the entire live Calbraid workspace for every member and device. This deletes Calbraid’s materialized data and encrypted source secrets; it does not delete events at their original Google, Microsoft, or CalDAV provider or at an ICS publisher.

You can also revoke Google or Microsoft access directly with that provider. To request access, correction, a portable copy, restriction, objection, or deletion without using Data Control, email info@applifyer.com from the account email. Do not send card numbers or calendar contents.

We may verify your identity. Depending on your location, you may complain to your local data-protection authority or appeal a privacy decision. Where GDPR applies, including the Article 17 right to erasure, we normally respond within one month and explain any lawful extension, exception, or refusal. Erasure does not override records that applicable law requires us or a payment processor to retain.

Security

Controls include TLS, authenticated encryption of provider tokens and standard-source secrets, private-network rejection and DNS pinning for user-supplied endpoints, Argon2id browser passwords, hashed app passwords and session tokens, server-side session revocation, login throttling, least-privilege roles, provider-bound OAuth state, private no-store feeds, signed Stripe webhooks, rotating logs, tested backups, and provider-preserving writes that are acknowledged only after the original provider accepts them. No system is perfectly secure; report suspected unauthorized access promptly.

Children and changes

Calbraid is intended for adults and business users and is not directed to children under 16. We do not knowingly collect their data. Material policy changes will update the version and date here and, where appropriate, be announced in the service or by email before new processing begins.

Privacy questions or requests: info@applifyer.com
Applifyer, LLC · 131 Continental Dr, Suite 305 · Newark, DE 19713 · United States