Privacy Policy

Last updated: 1 September 2026. Calenda (“Calenda”, “we”, “our”) publishes availability profiles at calenda.io. This policy explains what data we process, why, on what legal basis, and what we will never do with it.

The data controller is Senso SARL, 21 rue de Trévise, 75009 Paris, France — SIREN 948 888 003, SIRET 948 888 003 00019, registered in Paris. You can reach us at privacy@calenda.io.

The core promise

Calenda shows how much of your time is available — never what you are doing. The system is designed so that the content of your calendar events cannot be exposed, because we never store it.

Data we collect

Account data. When you sign in with Google: your name, email address and profile picture. When you sign in with an email link: your email address, and the name and photo you choose to add. In both cases, the optional profile details you fill in — company, website, bio, skills, social links.

Calendar data. With your explicit consent, we read the calendars you select — either through the Google Calendar read-only API, or from an iCalendar (ICS) feed URL you provide. From those events we store only bare time intervals: a start time and an end time, in UTC. Event titles, descriptions, locations and attendees are never stored on our servers. Events marked as “Free” (transparent) are ignored entirely.

Settings. Your working days and hours, your timezone, your display preferences, and an optional Google Analytics tracking code for your own profile page.

Network data. The people you follow, the private tags you apply to them, and the lists you choose to share — including who you shared them with.

Usage data. Server-side events recording how the product is used (pages viewed, invitations sent, profiles consulted), associated with a session identifier and, where applicable, your account.

Legal bases

How we use Google user data (Limited Use)

Calenda’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

How we protect your data

Calendar data is sensitive, and we protect it in five ways.

We minimise what exists. The strongest protection is not storing the data at all. From your calendars we extract only busy time intervals — a start time and an end time. Event titles, descriptions, locations and attendees are discarded during processing and never written to our database. Even in the event of a breach, there is no event content to expose.

Encryption in transit. All traffic to and from Calenda uses HTTPS/TLS, including the connections between our application and our database, and every call to the Google Calendar API.

Encryption at rest. Our database is hosted on infrastructure that encrypts stored data at rest. In addition, the most sensitive values — Google OAuth access and refresh tokens, and any iCalendar feed URL you provide — are encrypted by the application itself with AES-256-GCM before being written, using a key held outside the database. They are never stored, logged or displayed in clear text.

Restricted access. No human at Calenda reads your calendar data; it is processed automatically. Administrative tools are limited to a named list of authorised accounts and expose aggregate figures, not individual calendar content. Credentials and encryption keys are held as environment secrets, never committed to source code.

Limited retention. Availability intervals cover a rolling 12-month window and are continuously replaced. Disconnecting a calendar deletes the intervals it produced and revokes our access immediately. Accounts that never finish onboarding are deleted automatically after 48 hours, with their tokens revoked. Deleting your account permanently removes your data.

If a breach affecting your personal data occurs, we will notify the competent supervisory authority within 72 hours and inform you directly where the breach is likely to result in a high risk to your rights.

What is public

Your profile page (calenda.io/your-name) is public. It shows your name, photo, bio, skills, links and daily availability percentages. It never shows individual events, nor the hours of specific appointments.

Availability percentages are also served through a partner API to a small number of named business partners, for the accounts on an explicit allowlist. This shares only the same derived percentages that are already public on your profile page — never raw Google data, and never event content.

Who else processes your data

We use a small number of providers, all bound by data processing agreements:

ProviderPurposeLocation
SupabaseDatabaseEuropean Union (Paris)
VercelApplication hostingEuropean Union (Paris) for serverless functions
BrevoTransactional email (sign-in links, invitations, notifications)European Union

We do not sell your data, and we do not share it for advertising purposes.

Cookies

We use first-party cookies only:

CookiePurposeDuration
Session cookieKeeps you signed in. Strictly necessary.Session / sign-in duration
ca_sidAnonymous session identifier used to measure product usage.30 days
ca_attrRecords how you first arrived (referral or campaign link), so we can measure what brings people to Calenda.30 days

We do not use Google Analytics, and we set no third-party or advertising cookies. Usage measurement is entirely first-party: the events described above are recorded on our own servers, in the European Union, and never shared.

If you choose to add your own analytics tracking code to your profile page, you are responsible for obtaining your visitors’ consent where required.

Retention

Your rights

Under the GDPR you may access, rectify, export, restrict or erase your data, and object to processing based on legitimate interest. Most of this is available directly in your settings. For anything else, write to privacy@calenda.io; we answer within one month.

You can revoke Calenda’s access to your Google account at any time from your Google account permissions.

If you believe your rights are not respected, you may lodge a complaint with the CNIL (Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, 75007 Paris — cnil.fr) or with the supervisory authority of your country of residence.

Changes

We may update this policy as the product evolves. The date at the top always reflects the current version; significant changes will be announced by email.

HomePrivacy PolicyTerms of ServiceMentions légales