Privacy Policy
Effective date: June 30, 2026
Unclash provides this Privacy Policy to explain how it handles information in the calendar sync service. Contact: unclash.co@gmail.com.
Information we collect
- Account information: email address, display name, email verification status, password authentication data, passkey public keys, session data, IP address, user agent, and profile icon data.
- Connected Google account information: Google account ID, email address, name, profile image URL, granted OAuth scopes, token status, and encrypted OAuth credentials.
- Calendar information: calendar IDs, names, descriptions, time zones, colors, access roles, sync cursors, watch channel metadata, calendar groups, and sync rule settings.
- Normalized event information needed for display and sync: event IDs, recurrence keys, title, description, location, event link, start and end time, all-day flag, status, transparency, the signed-in user's response status, visibility, color, etag, provider update time, fetch time, and deletion state.
- Operational information: sync jobs, event mappings, sync logs, error states, audit information for administrator actions, and support/debug information needed to operate the service.
- Analytics information: page views, referrers, browser/device information, IP-derived coarse location, cookies or similar identifiers, and interaction data collected through Google Analytics and Cloudflare Web Analytics when enabled.
Google Calendar data
Unclash requests Google Calendar permissions only to show connected calendars, understand availability, keep a normalized event cache, create, move, update, or delete calendar events when requested by the user or required by sync rules, detect relevant changes, and troubleshoot sync issues.
Unclash does not store raw Google Calendar event JSON, attachments, attendee lists, or conference data. Participants are not copied to target events because adding attendees in Google Calendar can send invitations and reveal guest lists.
- If a sync rule is Busy-only, target events use a busy block and the configured title.
- If a sync rule allows details, Unclash may copy selected fields such as title, description, and location to the target calendar. Conference information is not copied.
- When a user creates, moves, or deletes an event from the unified calendar, Unclash sends that change to the selected Google Calendar and updates the normalized event cache.
- Refresh tokens are encrypted at rest and used only to access calendars connected by the user.
- Google user data is not sold, used for advertising, used for credit or eligibility decisions, or used to train AI/ML models.
How we use information
- To create, maintain, and secure the user's Unclash account.
- To connect Google Calendar accounts and refresh calendar data.
- To display consolidated availability, conflicts, calendar freshness, and sync health.
- To apply sync rules and write target calendar events chosen by the user.
- To create, move, or delete Google Calendar events when the user performs those actions in Unclash.
- To send account, verification, password reset, and service emails.
- To measure basic product usage and improve reliability through analytics.
- To investigate abuse, security incidents, support requests, and service failures.
Sharing and processors
Unclash shares information only as needed to provide and operate the service, comply with law, protect rights and security, or with the user's direction.
- Google: to read and write Google Calendar data authorized by the user.
- Cloudflare: to host the Workers application, D1 database, KV, Queues, Durable Objects, R2 profile icons, email sending, security controls, and Cloudflare Web Analytics.
- Google Analytics: to measure production website and app usage when enabled.
- AI assistants and other MCP clients you connect: if you authorize a client such as Claude or ChatGPT on the OAuth consent screen, calendar data you request through that client (calendar lists, event details, and the results of create, update, and delete actions) is sent to it. This happens only at your direction, and you can disconnect the client at any time from its connector settings.
Storage and retention
- Calendar event details are cached only for display and sync windows. Current cleanup keeps detailed event cache around the recent 30 days and upcoming 120 days, and availability cache around the recent 30 days and upcoming 365 days.
- Old event mappings and completed sync jobs are cleaned up after about 30 days when no longer needed. Sync logs are cleaned up after about 90 days.
- Account, authentication, connected calendar, rule, and profile icon data are kept while the account is active or as needed for legal, security, and operational reasons.
Security
- Unclash uses encrypted transport, encrypted OAuth credentials, HTTP-only session cookies where applicable, passkey public-key authentication, rate limiting where configured, and administrator access controls.
- Administrator tools hide secrets such as tokens and are intended for support, security, and operational recovery.
Account deletion and user choices
- Users can disconnect a Google account. This deletes saved calendars and cached event data for that connected account from Unclash.
- Users can delete their Unclash account. This deletes the account-owned Unclash data, including sessions, passkeys, connected calendar records, sync rules, event cache, mappings, logs, and stored profile icon objects.
- Deleting an Unclash account does not delete original Google Calendar events. It also does not guarantee deletion of events already created in external calendars; those remain controlled by the external calendar account.
- For access, correction, deletion, or other privacy requests, contact unclash.co@gmail.com.
Children
Unclash is not directed to children. If we learn that we have collected information from a child in a way that requires deletion, we will delete it.
Changes
If Unclash changes how it accesses, uses, stores, or shares Google user data or other personal information, it will update this policy and, where required, ask users to consent before using data in a new way.