Privacy Policy
This policy explains how CalendAIr H.I. UG (haftungsbeschränkt) (“CalendAIr”, “we”) processes personal data when you use the CalendAIr app and the website calendair.de.
It follows the steps you actually take in the app, from the invitation to deleting your account. Every step answers the same questions – what we process, what for, on which legal basis, who receives it, how long we keep it, and whether you have to provide it.
A1 · Who we are and how to reach us
CalendAIr H.I. UG (haftungsbeschränkt)Fährstraße 217
40221 Düsseldorf
Germany
Email: support@calendair.de. Further details are in the Imprint.
Our supervisory authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). You may also contact the authority in your country of residence.
A2 · The short version
- Our servers are in the EU (Frankfurt am Main). Some features run through Google, Apple and Microsoft and are also processed outside the EU – see C3.
- From events already in your calendar we only use when they start and end. We do not store titles, notes, locations or attendee lists, and we never show them to anyone.
- Meetings you create in CalendAIr are stored – we have to show them to the people you invite and write them to the calendars.
- The AI only receives the sentence you type. Not your calendar, not your contacts.
- We do not sell data. Ads appear only in the free version, and only personalised if you allow it.
- You can delete your account at any time – in the app or via this page.
A3 · Contents
A4 · Where all of this runs
Every processing activity described in Part B runs on our infrastructure at Amazon Web Services in Frankfurt am Main (region eu-central-1), unless an individual step says otherwise. Each step therefore only names the recipients that come in addition to that. The full list is in C2.
The tag next to each heading shows where that step's data is processed: EU stays in the EU, EU + non-EU goes beyond it – details in C3.
What you have to provide. Only two things are required: an email address for your account, and a connected calendar so we can work out free times. Without the first there is no account; without the second there is no scheduling. Everything else is optional and the app works without it. There is no legal obligation to give us any data.
B0 · You were invited EU + non-EU
For many people this is the first contact with CalendAIr: someone sends you an invite link before you even have the app. The code in it does not come from you but from the person inviting you (Art. 14(2)(f) GDPR). The link can contain a name. The website does not store it.
- What we process
- Only the invite code. It sits in the link, is shown in your browser, and is picked up by the app after you install it, so you do not have to type it.
- Legal basis
- Art. 6(1)(f) GDPR. Our legitimate interest is that an invitation arrives without detours.
- Recipients
- The code is part of the link's address. When you open the link, that address appears in the server logs of GitHub, where our website is hosted.
- How long
- We store nothing at this point. The code itself expires in our system after about 25 hours.
B1 · You install and open the app EU + non-EU
On first launch the app sets itself up and asks for your consent for analytics and ads. For anything stored on or read from your device, § 25 TDDDG (the German ePrivacy implementation) applies first, and the GDPR after that.
- What we process
-
- On your device: a copy of your profile (name, email, picture URL, subscription status), your calendar connection status, your language, your consent choices, and a pending invite code.
- Crash reports (Firebase Crashlytics): device model, operating system version, app version, timestamp and the technical stack trace.
- An app installation identifier that Firebase creates on first launch.
- Usage statistics (Firebase Analytics): only if you consent.
- What for
- So the app starts without reloading everything, so we can find and fix crashes, and – with your consent – to understand which features are used.
- Legal basis
- Profile cache, language, consent store and pending invite code: § 25(2)(2) TDDDG, because they are strictly necessary for the feature you asked for, together with Art. 6(1)(b) GDPR. Analytics and crash reports: § 25(1) TDDDG and Art. 6(1)(a) GDPR – your consent, which you can withdraw at any time in the app settings.
- Recipients
- Google (Firebase Crashlytics, Firebase Analytics).
- How long
- Data on your device stays until you delete the app. Crash and analytics data at Firebase according to its retention periods, at most 14 months.
- Do you have to provide this?
- Analytics and crash reports are optional. If you decline, the app works in full – we simply will not learn what it crashed on. Local storage is technically necessary; without it you would have to sign in on every launch.
B2 · You create an account EU + non-EU
Sign-in runs through AWS Cognito, using your Google or Apple account. There is no separate CalendAIr password.
- What we process
- Email address, name, the address of your profile picture, your language setting, a user ID and the identifier of your Google or Apple account. If you sign in with Apple and choose “Hide My Email”, we only receive Apple's relay address.
- What for
- To create your account, recognise you, show the app in your language, and present you to people who invite you. New accounts also get a timestamp we use to manage the 30 days of Premium you receive at the start.
- Legal basis
- Art. 6(1)(b) GDPR – without an account we cannot provide the service.
- Recipients
- Google or Apple as the sign-in provider. Both learn, as controllers in their own right, that and when you sign in to CalendAIr, and process that under their own privacy policies.
- How long
- As long as your account exists. After deletion see B10.
B3 · You connect a calendar EU + non-EU
This is the core of the product. Please read this section before you connect a calendar.
Access runs through the provider's servers, not through the calendar app on your phone. We use neither the iOS calendar permission (EventKit) nor the Android system calendar permission.
- What we process
-
- From existing events: start, end and status – whether an event is cancelled, marked as free, or declined by you. We do not store titles, descriptions, locations or attendee lists. They are processed in memory to work out when you are free, then discarded. We never show them to other users or to advertising partners.
- Credentials: for Google and Outlook an access token, for iCloud your Apple ID username and the app-specific password you enter. Both are stored with an additional layer of encryption.
- Your selection of which calendars should be taken into account.
- What for
- To work out when you are free, and to write accepted meetings into your calendar. The token keeps the connection alive so you do not have to reconnect on every launch.
- Legal basis
- Art. 6(1)(a) GDPR – the consent you give in the provider's own authorisation dialog. You can withdraw it at any time by disconnecting the calendar in the app; this does not affect the lawfulness of processing before withdrawal. Disconnecting a calendar is not the same as deleting your account.
- Recipients
- Depending on what you connect: Google (Google Calendar), Microsoft (Outlook via Microsoft Graph) or Apple (iCloud via CalDAV). With Google we also request the contacts permissions – what for is explained in B4.
- How long
- Until you disconnect the calendar or delete your account. We then remove tokens and credentials immediately, and our access ends at that moment.
- Do you have to provide this?
- No, that is your decision. Without a connected calendar, however, we cannot work out when you are free – that is the app's central feature.
You can also revoke access directly at Google or Microsoft, or delete the app-specific password in your Apple ID settings. Events already written to your calendar stay there – even if you disconnect the calendar.
B4 · You connect with friends EU + non-EU
Connections are only ever made through invite codes. We do not read your address book, and we do not process phone numbers.
- What we process
- A six-character invite code and the information about who is connected to whom. If either person has connected Google Calendar, we may also look up or create a contact with an email address and display name in a group called “CalendAIr Connections” in that Google account.
- What for
- So you can invite each other to meetings. The contact entry stops CalendAIr invitations from landing in spam as an unknown sender. This works both ways: when someone accepts your invitation, your email address and display name may likewise be added as a contact in their Google account. We do not use contact data for advertising.
- Legal basis
- Art. 6(1)(b) GDPR for the connection itself. Art. 6(1)(a) GDPR for the contact entry, which is only possible if you granted the contacts permission in Google's dialog.
- Recipients
- Google, where a contact entry is looked up or created.
- How long
- Invite codes about 25 hours. The connection, until either person removes it in the app or deletes their account. The contact entry in your Google account is yours to manage; we do not delete it automatically.
B5 · You find a time and create a meeting EU + non-EU
Two things happen here in sequence, and we describe them separately: the AI turns your text into time windows, and then the meeting itself is created.
The AI suggestion
- What we process
- The sentence you type (for example “friday afternoon next week”), plus your time zone and the app language. We do not send your calendar, your event titles, your name, or the names of the people you invite to the AI. We also count how many requests you have made in the current month.
- What for
- To turn everyday language into concrete time windows. The counter is what applies the limits of the free tier.
- Legal basis
- Art. 6(1)(b) GDPR for the conversion and the counter. For the logging, Art. 6(1)(f) GDPR; our legitimate interest is spotting misreadings and improving the hit rate.
- Recipients
- Google, as the provider of the Gemini model. We use a paid tier: under its terms, Google does not use the submitted input and output to train its own models.
- How long
- We log your request and the time windows it produced for about 30 days, without your user ID – so we cannot trace it back to you. We do not use this for advertising and do not build a profile from it.
The meeting
- What we process
- The meeting's title, description, start and end, the people you invite, and their acceptance or decline.
- What for
- To create the meeting, show it to the invited people, and write it into the connected calendars once accepted. Title, description, times and the attendees' email addresses are transmitted to Google, Outlook or iCloud in the process – as with any calendar invitation.
- Legal basis
- Art. 6(1)(b) GDPR. If you put special categories of personal data into a title or description – such as “rehab” or a religious service – we process those on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you give by entering them voluntarily. We recommend leaving such details out; a neutral title is enough.
- Recipients
- The attendees' calendar providers (Google, Microsoft, Apple) and the invited people themselves.
- How long
- Until about 21 days after the meeting ends, then deleted automatically.
Important: deleting a meeting in CalendAIr, disconnecting a calendar, or deleting your account does not remove events already written to Google, Outlook or iCloud. Those copies stay there until you or the organiser delete them in that calendar.
B6 · You receive notifications EU + non-EU
- What we process
- A device identifier for push messages, the platform and your language. The notification itself may contain a meeting title and names – and may therefore appear on your lock screen.
- What for
- To tell you about new meeting requests, acceptances and declines, and new connections.
- Legal basis
- Art. 6(1)(b) GDPR, because being told about a meeting request is part of the service. The system permission itself you grant to your operating system.
- Recipients
- Google (Firebase Cloud Messaging) and, on iPhones, Apple (push service).
- How long
- The device identifier until you sign out, delete the app, or delete your account.
B7 · You buy Premium EU + non-EU
- What we process
- Whether you have Premium, until when, through which store, and the transaction identifiers the App Store and Google Play need to verify and restore a purchase. We never see payment data – no card number, no billing address.
- What for
- To verify that the purchase is valid, unlock Premium, and restore it when you change devices.
- Legal basis
- Art. 6(1)(b) GDPR for unlocking, and Art. 6(1)(c) GDPR where we have to document transactions for tax purposes.
- Recipients
- Apple and Google as the store operators. Both also send us notifications on their own initiative when a subscription changes – renewal, cancellation or refund. We therefore do not collect this from you but receive it from the store.
- How long
- For the duration of the subscription, then until statutory commercial and tax retention periods expire.
B8 · You see ads in the free version EU + non-EU
- What we process
- Your device's advertising identifier (IDFA on iPhones, Advertising ID on Android), technical details of the ad request, and your consent choice. Calendar and meeting content is never sent to advertising services.
- What for
- To fund the free version and deliver ads – personalised only if you allow it.
- Legal basis
- § 25(1) TDDDG and Art. 6(1)(a) GDPR – your consent. On iPhones we also ask through Apple's App Tracking Transparency dialog. You can change your choice at any time in the app settings.
- Recipients
- Google (AdMob and the advertising partners it includes).
- How long
- According to Google's retention periods; your consent choice is stored on your device until you change it.
- Do you have to provide this?
- No. If you do not consent, you see non-personalised ads and the app remains fully usable. Premium removes ads entirely.
B9 · You write to us EU
- What we process
- Through the in-app form: the category, your text and your user ID. By email: your sender address and the content of your message. Please do not include data about other people that is not needed to handle your request.
- Legal basis
- Art. 6(1)(b) GDPR where it concerns your contract, otherwise (f) with our legitimate interest in working support. If you exercise a right from Part C, (c), because we are obliged to respond.
- Recipients
- The form stays on our own infrastructure. Emails additionally pass through the provider of our mailbox.
- How long
- Feedback from the form about six months. Emails until your matter is resolved, then within statutory retention periods.
B10 · You delete your account EU
You can delete your account in the app under “Profile”, or request deletion without the app via Delete your account.
- What happens
- Your profile is anonymised immediately: name, email address, profile picture and provider identifier are overwritten. Your calendar credentials are removed in full straight away, so our access to your calendar ends at that moment. Your connections and push identifiers are marked for deletion.
- Legal basis
- Art. 17 GDPR and Art. 6(1)(c) GDPR.
- How long
- The anonymised record is removed for good after about 90 days. Meetings you created stay visible to the other participants until they expire – at most 90 days.
- Your sign-in record
- Your sign-in is disabled immediately, so nobody can log in as you. The entry itself, with your email address and provider identifier, is deleted together with the rest of your account data.
- What we cannot delete
- Events already written to Google, Outlook or iCloud, and a running subscription. You have to end those in the respective calendar or store yourself.
C1 · The website calendair.de EU + non-EU
- What we process
- When you open the pages, our host processes your IP address, date and time, the address requested and technical details of your browser in server logs.
- What for
- To deliver the pages and defend against attacks.
- Legal basis
- Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website.
- Recipients
- GitHub, Inc. (GitHub Pages).
- How long
- According to GitHub's retention periods.
- Cookies and third-party content
- None. The website sets no cookies, neither its own nor anyone else's, and embeds no third-party content. Fonts, icons and every other file are served from our own domain. There is therefore no consent banner either.
C2 · Recipients at a glance
We use other companies to run CalendAIr. They process data on our instructions as processors or – for sign-in, stores and advertising – as controllers in their own right for their platform.
- Amazon Web Services
- Hosting, database, sign-in service, logs. Processor. Location: Frankfurt am Main. Applies to every step in Part B.
- Sign-in, Google Calendar and Contacts, the Gemini AI model, Firebase (crash reports, analytics, push), AdMob and Google Play billing. Partly processor, partly controller in its own right. Applies to B1 through B8.
- The provider of our email mailbox
- Receiving and sending the messages to our contact addresses. Processor. Applies to B9.
- Apple
- Sign in with Apple, iCloud Calendar, push delivery, App Store billing and subscription notifications. Controller in its own right for its platform. Applies to B2, B3, B6, B7.
- Microsoft
- Outlook calendar via Microsoft Graph. Applies to B3 and B5.
- GitHub
- Hosting of the website calendair.de – not the app and not your account data. Applies to C1 and B0.
We do not sell personal data. Beyond the above we only disclose data where we are legally required to.
C3 · Processing outside the EU
Our own infrastructure is in the EU. Google, Apple and Microsoft may process data in the United States or other countries. Where required, we rely on an adequacy decision of the European Commission – including the EU-US Data Privacy Framework where the provider is certified under it – as well as the EU Standard Contractual Clauses and supplementary safeguards.
We will provide a copy of the relevant safeguards on request. Write to support@calendair.de.
C4 · Google API Services User Data Policy (Limited Use)
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve user-facing CalendAIr features: working out free times (B3), creating and updating CalendAIr meetings on your calendar (B5), and the contacts group (B4).
- We do not use Google Calendar or Contacts data to serve advertisements.
- We do not sell that data.
- We do not allow humans to read it unless you give affirmative consent, it is needed for security or to comply with law, or use is limited to internal operations such as debugging (aggregated or as needed to fix an issue you report).
Our use of Microsoft Graph data follows the Microsoft APIs Terms of Use and is limited to the Outlook features described in B3 and B5.
C5 · Operational and security logs
- What we process
- Technical logs across all steps: error messages, user ID, timestamps, the function called. We do not log calendar content, meeting titles, credentials or passwords. The only content we log is the scheduling request from B5.
- What for
- To run and secure the service, find faults and prevent abuse.
- Legal basis
- Art. 6(1)(f) GDPR. Our legitimate interest is a working and secure service. You can object – see C7.
- How long
- About 30 days. We do not build a profile of you from them.
C6 · Security
Traffic between the app and our servers is encrypted in transit (TLS). Our databases are in the EU and encrypted at rest. Calendar credentials receive an additional layer of encryption before they are stored. We limit access to production systems to the people who need it to run the service.
No system is perfectly secure. If a breach affects you, we will inform you as required by Art. 33 and 34 GDPR.
C7 · Your right to object
You have the right to object at any time to processing we base on a legitimate interest (Art. 21(1) GDPR) – on grounds relating to your particular situation. If you object, we will stop processing that data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims.
We currently rely on a legitimate interest for our operational and security logs (C5), the invite link (B0) and handling general enquiries (B9).
An informal message to support@calendair.de is enough to object. Telling us your reasons helps us weigh them up, but is not a requirement.
C8 · Your other rights
You can request access to your data (Art. 15), its rectification (Art. 16), its erasure (Art. 17), restriction of processing (Art. 18) and portability in a common format (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)).
In the app: disconnect calendars, change consent, delete your account. Without the app: via Delete your account or by email to support@calendair.de. We do not currently offer an automated data export; we handle access requests by hand. To make sure we do not hand data to the wrong person, we may ask for one detail to match your account – we will not ask for more than necessary.
You can also complain to a supervisory authority (Art. 77). Ours is the LDI NRW, see A1; you may also contact the authority in your country of residence.
C9 · No automated decisions
We do not use automated decision-making or profiling that produces legal effects for you or similarly significantly affects you (Art. 22 GDPR). The AI only converts your text into time windows; you always choose the slot yourself.
C10 · Children and young people
CalendAIr is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, write to support@calendair.de and we will delete it.
C11 · Changes to this policy
We update this policy when the app or the legal situation changes. The version published here is always the one that applies; the date at the top shows its status. We will tell you about material changes in the app or on the website.
If we ever intend to process your data for a purpose other than the one it was collected for, we will inform you about that purpose and its legal basis beforehand (Art. 13(3) GDPR).
C12 · Contact
CalendAIr H.I. UG (haftungsbeschränkt)support@calendair.de ↑ Back to top