Privacy policy
Last updated October 8, 2026
Calendar Hub is made by Eniac Labs (“we”). It is available as a macOS app, a Windows app and as a browser extension for Chrome and Firefox. This policy explains what data the app handles and what happens to it. The short version: we do not collect any of your data. Everything stays on your device.
Data the app accesses
When you connect a Google account, you grant Calendar Hub these Google permissions:
- View your calendars (
https://www.googleapis.com/auth/calendar.readonly): the list of your calendars and the events on them, including titles, times, locations, descriptions, attendees and meeting links. - Your email address and basic profile (name and profile picture), used to label the connected account in the app.
Calendar Hub cannot create, edit or delete anything in your Google account.
How the data is used
The data is used only to show your events to you in the app, combine events from your different accounts into one view, show your next meeting, and open event and meeting links in the right Google account. Nothing else.
Calendar links
You can also add a calendar by its iCal address (an .ics or webcal link). Calendar Hub downloads that address directly from your device and reads it on your device; nothing about it passes through us. The address and the name you give it are stored on your device, and a copy of the calendar is kept for a short while so it is not downloaded again every time you change weeks (the browser extension keeps the last copy in its storage so the toolbar badge does not re-download it every minute). Removing the calendar deletes the address and the copy. The only thing sent to the calendar's host is the request to read it.
Where the data is stored
- Calendar events are fetched from Google when you view them and kept in memory only. They are not written to disk. A calendar added by link is kept as described above.
- Account details and settings (email address, name, the list of your calendars and which ones you've hidden) are stored on your device: in the app's own folder on your Mac or PC, or in the extension's storage in your browser.
- Google access tokens are stored on your device. The Mac and Windows apps store them in a file in your user profile. The browser extension keeps them in memory only, and they are discarded when the browser closes.
How your data is protected
Your Google data, including your calendar events and the tokens that give Calendar Hub access to them, is sensitive. These are the measures that protect it:
- It never leaves your device. There is no Calendar Hub server, so your calendar data and tokens are never uploaded, stored or backed up anywhere outside your own device. Nobody at Eniac Labs can see or access them.
- Encrypted in transit. Every connection to Google (sign-in, reading your calendars, revoking access) is made directly from your device over HTTPS with TLS encryption. The app does not use unencrypted connections to Google.
- Secure sign-in. You sign in on Google's own page in your browser; Calendar Hub never sees your Google password. The Mac and Windows apps use OAuth with PKCE, which binds each sign-in to the app that started it so an intercepted sign-in code cannot be used by anyone else.
- Least privilege. Calendar Hub asks only for read-only calendar access and your basic profile. It cannot create, change or delete anything in your Google account.
- Restricted storage on your device. In the Mac and Windows apps, account details and tokens are kept in a file inside a folder that only your operating system user account can read (on a Mac the folder and file are created with owner-only permissions). They are protected by your device's login and, where you have it turned on, its disk encryption (FileVault on Mac, BitLocker or Device Encryption on Windows). In the browser extension, data is kept in the extension's own storage, which the browser isolates from websites and other extensions; access tokens are held in memory only and are never written to disk, and the extension keeps no long-lived refresh tokens.
- Calendar events are not stored. Events from your Google calendars are held in memory while the app is open and are not written to disk.
- Access is easy to end. Disconnecting an account deletes its tokens from your device and asks Google to revoke them, so they stop working everywhere. You can also revoke access from your Google account at any time (see “Removing your data” below).
- Reporting a problem. If you believe you have found a security issue in Calendar Hub, email selva@eniaclabs.dev. We will investigate and ship a fix in an app update; because we hold none of your data, a problem cannot expose data from our side.
Update check (Mac and Windows apps)
Once a day the desktop app asks GitHub, where new versions are published, which version is the latest, so it can tell you when a newer one is available. That request carries the app's version number and nothing about you or your calendars; GitHub sees your IP address, as any website you visit does. The app does not download or install anything on its own. You can turn the check off under Display in the app's sidebar. The browser extensions are updated by the Chrome Web Store and Firefox Add-ons instead.
Sharing
We do not run any server for Calendar Hub. Your calendar data is never sent to us or to any third party. The app communicates only with Google, to sign you in and to read your calendars, with the host of any calendar link you add, to read it, with GitHub for the daily update check described above, and once with Polar when you activate a license key (see below). We do not sell data, use it for advertising, or use it to train AI or machine-learning models. The app contains no analytics or tracking.
Buying a license
Licenses are sold through Polar, which acts as the merchant of record and handles payment, receipts and tax. Polar receives the details you enter at checkout (such as your email address and payment information) under Polar's privacy policy; we never see your card details. When you enter your license key in Calendar Hub, the app sends the key and the name of the device type (for example “Calendar Hub for Mac”) to Polar once, to activate it. Nothing about your calendars is included, and no further checks are made afterwards. Removing the key from a device sends one more request to free that activation.
This website
This section is about the eniaclabs.dev website only, not the app or the extensions. The website counts page views with Vercel Web Analytics, so we can see how many people visit and which pages they read. It uses no cookies and does not identify you or follow you across other websites or across days; it records the page address, the referring site, and your browser, operating system, device type and country. Your IP address is not stored. None of this is linked to your license or your use of the app.
Google API Services User Data Policy
Calendar Hub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Removing your data
Disconnecting an account in Calendar Hub deletes its stored details and token from your device and asks Google to revoke the app's access. You can also revoke access at any time from your Google account permissions page. Uninstalling the extension deletes all of its stored data. On a Mac or PC, deleting the app's data folder removes everything it stored.
Children
Calendar Hub is not directed at children under 13 and does not knowingly handle their data.
Changes
If this policy changes, the new version will be posted on this page with a new date.