Privacy Policy
Monthly Calendar Widgets is built to keep your calendar data on your device. We do not operate a backend server for your event data.
Last updated: July 31, 2026
Google Calendar OAuth Data Disclosures
This section explains exactly what Google user data Monthly Calendar Widgets accesses, how that data is used, whether it is shared or disclosed, how it is protected, and how it is retained or deleted.
What Google user data is accessed
If you connect Google Calendar, the app accesses Google Calendar data using only the read-only OAuth scope https://www.googleapis.com/auth/calendar.readonly. The app may read event titles, start and end times, all-day status, event locations if present, calendar names, calendar color metadata, event color identifiers, event identifiers, and your primary calendar email address so the connected Google account can be shown in the app.
How Google user data is used
Google Calendar data is used only to display your schedule in Monthly Calendar Widgets, render Home Screen and Lock Screen widgets, show accurate Google Calendar colors, provide offline viewing after sync, and identify the Google account you connected. The app does not create, edit, or delete Google Calendar events.
With whom Google user data is shared, transferred, or disclosed
We do not sell, share, transfer, or disclose Google Calendar user data to advertisers, data brokers, analytics providers, AI/ML model providers, or any other third party. Google Calendar data is not sent to our servers. Your device communicates directly with Google's OAuth endpoints and Google Calendar API endpoints to sign in, refresh tokens, and fetch the calendar data requested by the app.
How Google user data is protected
Google OAuth tokens are stored in the iOS Keychain. Synced Google Calendar event data is stored locally on your device in app storage and the shared App Group container used by the widget extension. The OAuth flow uses PKCE with S256, and all network communication with Google uses HTTPS through iOS App Transport Security defaults.
Google user data retention and deletion
Google Calendar data is retained locally on your device only while your Google account remains connected or while cached widget/offline data remains in app storage. You can delete Google user data by disconnecting Google Calendar in the app, using Delete All My Data in app settings, revoking access from your Google Account, or uninstalling the app. Disconnecting Google removes OAuth tokens and cached Google Calendar events from local storage.
Quick Summary
| Data | What happens |
|---|---|
| Calendar events | Read from your device to display in app and widgets. Never uploaded to us. |
| Google Calendar sync | Your device communicates directly with Google APIs. We do not proxy calendar data. |
| Purchases | Handled by Apple StoreKit and RevenueCat for entitlement status. |
| Google OAuth tokens | Stored in iOS Keychain on your device and never sent to our servers. |
Permissions
Calendar access (required)
The app requests Full Access using Apple EventKit so it can read events, show them in widgets, and let you create or edit events when you choose.
- Reads title, start/end, all-day, calendar name/color, and location (if present).
- Creates and edits events when you initiate those actions.
- Writes lightweight snapshots to widget extension storage for reliable widget rendering.
If you grant Write Only access, the app can create events but cannot read existing events for in-app display or widgets.
Google sign-in (optional)
Google Calendar connection uses OAuth 2.0 in a secure in-app browser (ASWebAuthenticationSession) with PKCE (S256) and the read-only scope https://www.googleapis.com/auth/calendar.readonly.
- We request read-only access — the app only reads and displays your Google Calendar events and never creates, edits, or deletes them.
- We do not see or store your Google password.
- The OAuth flow runs between your device and Google.
- You can revoke access anytime from your Google Account permissions.
Data Used On Device
Apple Calendar data
With permission granted, event data is used locally for app views, editing flows, and widget rendering. Up to 4,000 events may be snapshotted for widgets across a 2-year history and 1-year future window.
Google Calendar data (optional)
When connected, the app fetches event details, calendar names, and color metadata from Google Calendar API and stores synced data locally for offline use.
- Tokens (access/refresh/expiry) are stored in iOS Keychain.
- Event snapshots are stored in App Group container for widgets.
- Connected account metadata (email/display name) is stored in UserDefaults.
Google User Data Disclosures
Google user data accessed
If you connect Google Calendar, Monthly Calendar Widgets accesses Google Calendar data using only the read-only scope https://www.googleapis.com/auth/calendar.readonly. The app may read calendar event titles, start and end times, all-day status, locations if present, calendar names, event color identifiers, calendar color metadata, event identifiers, and your primary calendar email address so the app can identify the connected Google account.
How Google user data is used
Google Calendar data is used only to display your schedule inside the app, render calendar widgets, show accurate Google Calendar event colors, support offline viewing after sync, and identify the Google account you connected. The app does not create, edit, or delete Google Calendar events.
Sharing, transfer, and disclosure of Google user data
We do not sell, share, transfer, or disclose Google Calendar user data to advertisers, data brokers, analytics providers, AI/ML model providers, or any other third party. Google Calendar data is not sent to our servers. Your device communicates directly with Google's OAuth and Calendar API endpoints to sign in, refresh tokens, and fetch calendar data requested by the app.
Protection of Google user data
OAuth tokens are stored in the iOS Keychain. Synced event data is stored locally on your device in app storage and the shared App Group container used by the widget extension. The OAuth flow uses PKCE with S256, and network communication with Google uses HTTPS through iOS App Transport Security defaults.
Retention and deletion of Google user data
Google Calendar data is retained locally on your device only while your Google account remains connected or while cached widget/offline data remains in app storage. You can delete it by disconnecting Google Calendar in the app, using Delete All My Data in app settings, revoking access from your Google Account, or uninstalling the app. Disconnecting Google removes OAuth tokens and cached Google Calendar events from local storage.
Third-Party Services
- Google (optional): OAuth and Calendar API calls are made directly from your device to Google.
- RevenueCat: purchase validation and entitlement status for subscriptions.
- Apple: StoreKit handles all app purchase transactions.
RevenueCat policy: revenuecat.com/privacy
Google policy: policies.google.com/privacy
Google API Services User Data Policy
Monthly Calendar Widgets' use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only access Google Calendar data using the read-only scope to display your events. We do not sell or transfer this data to others, and we never use it for advertising, analytics, cross-app tracking, or to train generalized AI/ML models.
What We Do Not Collect
- We do not collect or store your Google password.
- We do not sell your data.
- We do not include ads, analytics, or cross-app tracking SDKs.
- We do not build cross-app profiles about you.
Retention, Security, and Deletion
- Use Delete All My Data in app settings to permanently erase all events, connected accounts, and settings from your device and revoke connected Google access.
- Revoke calendar permission in iOS Settings > Privacy & Security > Calendars.
- Disconnect Google in app settings to remove tokens and cached Google events.
- Uninstalling the app removes local app data, App Group storage, and app-related keychain entries.
- Stale local cache entries are cleaned automatically (about 180 days).
- All network traffic uses HTTPS and iOS ATS defaults.
Children and Policy Changes
The app is not directed to children under 13. If you believe a child submitted personal information, contact us and we will address it promptly.
We may update this Privacy Policy to reflect legal or product changes. Updates will be posted on this page with a revised effective date.
Contact
Questions about this Privacy Policy or your data? Contact us at pyashwanthkrishna@gmail.com.