Skip to content

Privacy Policy

Last updated: 2026-09-16

calit is open-source scheduling software you host yourself. It stores all data in a database you control. The maintainers of the project do not operate a central service, do not receive your data, and have no access to any deployment’s database.

  • Account data — your username, email address, display name, timezone, and an argon2id hash of your password (never the password itself).
  • Scheduling data — your meeting types, availability rules, and the bookings made by invitees (invitee name, email, and any answers to custom booking questions you configure).
  • Google account data — when the deployment has Google configured and you connect Google Calendar: the Google account’s email and stable subject identifier (from the OpenID id_token), and the OAuth access and refresh tokens. Tokens are encrypted at rest in the deployment’s database.

How Google user data is used (when Google is configured)

Section titled “How Google user data is used (when Google is configured)”

When you connect a Google account, calit requests the Google Calendar scope and uses it only to provide scheduling:

  • Read free/busy information from the calendars you select, to compute which time slots are available.
  • Create, update, and delete events on the single write-target calendar you choose, when bookings are made, rescheduled, or cancelled.

calit does not read the content of your calendar events beyond busy intervals, and does not use Google data for advertising, profiling, or any purpose other than the scheduling features you initiated.

calit’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, not transferred to third parties except as needed to provide the scheduling features, not used for advertising, and not read by humans except where required for security, to comply with law, or with your explicit consent.

calit does not sell or share your data. A deployment sends data only to the services its operator has configured, and its own /privacy page lists exactly which ones:

  • Google (when configured), for the calendar operations above.
  • A single sign-on identity provider (when configured), when you sign in with it.
  • The SMTP server the operator configures, which delivers booking and notification emails.
  • Chat or push services (when a host has configured notification channels, for example Telegram, Slack, Discord or ntfy). Messages already delivered there cannot be recalled.
  • Cloudflare Turnstile (when configured), which checks booking requests for abuse.
  • Disconnecting a Google account in Settings → Google (when Google is configured) deletes that account’s stored tokens and calendar selections. It does not withdraw the grant at Google — revoke calit’s access in your Google account to do that.
  • Deleting your account at Settings → Delete my account (/me/settings/delete) removes your account, settings, meeting types, availability, bookings, connected Google accounts and notification channels. It does not revoke the grant at Google either.
  • A hash of a deleted account’s username is kept permanently, so that name can never be re-registered and used to take over a stale login.
  • If you booked a meeting, the manage link in your confirmation email lets you download your data or erase it from that booking. Bookings are not linked to each other by email address, so erasure reaches only the booking whose manage link you used. An operator may turn self-service erasure off; the instance then tells you whom to contact instead.
  • Booking details are anonymised a set number of days after the meeting ends (when the operator or host has configured a retention window). Without one, bookings are kept until removed by the host or the operator.
  • Emails queued for sending are deleted about 30 days after they are sent (or after they were queued, if never sent). Password-reset, invitation and sign-in tokens are deleted about a day after they expire.

Passwords are hashed with argon2id; Google OAuth tokens are encrypted at rest. Production deployments run behind TLS with secure cookies. The operator is responsible for securing the host and database.

For questions about a specific deployment, contact that deployment’s operator. For questions about the calit software itself, open an issue at github.com/asm0dey/calit.