Skip to main content

Privacy Policy

Takeaway

We do not host your calendar or contact databases. Our apps store them on your device and sync directly with the services you choose. Optional features, licensing, diagnostics, and information you choose to share with support use the connections described below.

Regulatory Compliance​

Our apps are designed to align with various global privacy and security regulations. Calendar and contact synchronization does not pass through our servers. We follow best practices that support compliance with:

  • GDPR (General Data Protection Regulation) – Your calendar and contact databases remain on your device or with the services you choose to sync with.
  • HIPAA (Health Insurance Portability and Accountability Act) – Your organization controls which service stores synced calendar and contact content. If you use our apps in a healthcare setting, you must ensure that your chosen sync service meets HIPAA compliance requirements.
  • CCPA (California Consumer Privacy Act) – We do not sell your personal data.
important

Our apps have not undergone formal certification for these regulatory frameworks. This information is for general guidance and transparency purposes only. Compliance is based on self-assessment and industry best practices. If you are required to meet specific legal or industry standards and use our software with a third-party service (such as a CalDAV or WebDAV server), it is your responsibility to ensure that the service complies with GDPR requirements, as these services are ultimately responsible for storing and handling your private data on their systems.

GDPR Compliance​

Your calendar and contact databases remain on your device or with the services you choose to sync with, such as iCloud, Google, or Microsoft 365. We do not host those databases or act as an intermediary for their synchronization. The feature requests, notification metadata, licensing information, and support information we handle are described below.

As a result, our operations do not involve large-scale processing or monitoring of personal data, which means we are not required to appoint a Data Protection Officer (DPO) under GDPR. However, we remain fully committed to ensuring all interactions comply with GDPR regulations, prioritizing secure and direct communication between the app and the services you choose to use.

HIPAA Compliance​

Calendar and contact synchronization occurs directly between your device and the service you choose, such as iCloud, Google, Microsoft, or a self-hosted service. It is the responsibility of the user and their organization to ensure that the chosen third-party service provider is HIPAA-compliant when handling sensitive data.

SOC 2 Applicability​

SOC 2 is a security and privacy compliance framework designed for service providers that store, process, or transmit user data via cloud infrastructure. BusyCal and BusyContacts are native clients, and we do not host your calendar or contact databases. The app's direct synchronization and the optional services described on this page are distinct parts of that architecture.

Our apps are native, sandboxed macOS and iOS applications. Calendar and contact content is stored locally and synchronized directly with the services you connect, including Microsoft 365. Optional push notifications use a relay to tell the app when to refresh; calendar and contact content is still retrieved directly from your provider.

When connecting to Microsoft 365 or Exchange accounts:

  • BusyCal uses Microsoft's official Exchange Web Services (EWS), Microsoft Graph protocol or OAuth authentication, depending on your configuration.
  • Calendar and contact synchronization occurs directly between your device and Microsoft's servers over secure channels.
  • Passwords and OAuth tokens are stored in the system Keychain and used to authenticate with your provider.
  • Application logs remain on your device unless you choose to share them with support.

Please contact us if your IT team needs more information about these data flows for a vendor review.

EULA​

Our End User Licensing Agreement is accessible here.

Contacts Access Permission​

When you launch our apps, they will request your permission to access your Contacts.

  • BusyCal: Access to your Contacts is required to display birthdays and anniversaries, schedule meetings, and autofill addresses when adding locations to events. Your name and email addresses from your "Me Card" are used for sending invitations, managing shared calendars, and tracking changes to events (e.g., last modified details). BusyCal does not collect or upload your contact details to its servers. Contacts are only uploaded to the CalDAV server you sync with if you explicitly attach them to events.

  • BusyContacts: Access to your Contacts is required to autofill addresses, names, and numbers as needed. It also uses your "Me Card" to accurately identify you and allow changes to your contact card. Like BusyCal, BusyContacts does not collect or upload your contact details to its servers.

Login Credentials​

BusyCal and BusyContacts use your login credentials (e.g., username and password) to synchronize, manage, and display your calendars, events, reminders, and contacts.

  • When adding accounts such as Office 365 or Google, our apps use industry-standard authentication methods like OAuth for secure login.
  • Passwords and OAuth tokens are securely stored in the system Keychain on macOS or iOS. Account names and settings are stored locally by the app.
  • Authentication and synchronization take place directly with the provider you choose. Passwords and OAuth tokens are not sent to our push-notification relays.

Zoom Meeting Accounts​

BusyCal supports connecting to Zoom accounts to enable users to add Zoom meetings to events within BusyCal or remove existing meetings that were created using BusyCal. The app has no access to any other Zoom meetings, or workflows beyond those specifically created or managed through BusyCal. All communication occurs directly between your device and Zoom's servers using OAuth authentication.

Google Accounts​

BusyCal and BusyContacts connect to Google accounts using OAuth 2.0 authentication via Google's sign-in flow. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1. Data Accessed

When you connect a Google account, our apps access the following Google user data through Google's official APIs:

  • BusyCal: Calendar events and their properties (titles, dates, times, locations, attendees, descriptions, reminders), calendar metadata (names, colors, time zones), tasks and their properties (titles, due dates, notes), and free/busy availability information via the Google Workspace API.
  • BusyContacts: Contact records and their properties (names, email addresses, phone numbers, physical addresses, organizations, notes, photos) and contact group memberships.
  • Both apps: Your Google account email address, used to identify and display the connected account. Google calendar identifiers used for push notifications can also contain an email address, as described below.

2. Data Usage

Your Google data is used exclusively to synchronize, display, and manage your calendars, tasks, and contacts within BusyCal and BusyContacts on your device. Specifically:

  • Calendar and task data is displayed in the BusyCal interface and synced bidirectionally so that changes you make in the app are reflected in Google Calendar and vice versa.
  • Contact data is displayed in the BusyContacts interface and synced bidirectionally with Google Contacts.
  • Free/busy data is used in the Availability Viewer to help you find available meeting times.
  • Your Google data is not used for advertising, analytics, market research, or any purpose unrelated to providing calendar and contact management functionality.

3. Data Sharing

We do not sell or rent your Google data. Calendar and contact synchronization occurs directly between your device and Google. Optional Google Calendar push notifications pass notification metadata through our relay so the app knows when to refresh.

4. Data Storage and Protection

Our apps are sandboxed, native macOS and iOS applications. Google calendar and contact content is stored locally on your device within the app's sandboxed container and in the system's Core Data store. Your OAuth 2.0 tokens are stored in the system Keychain. We do not host your Google calendar or contact databases. All network communication with Google's APIs occurs over TLS-encrypted HTTPS connections.

5. Data Retention and Deletion

Your Google data is retained on your device only for as long as the Google account remains connected in the app. To delete all locally stored Google data, simply remove the Google account from BusyCal or BusyContacts in the app's account settings. This immediately removes all locally cached calendar events, tasks, contacts, and credentials associated with that account. You can also delete your data directly through Google's services at any time. Uninstalling the app removes all locally stored data, including any cached Google data and OAuth tokens.

Office 365 / Exchange Web Services​

BusyCal and BusyContacts connect to Office 365 and Exchange accounts using Microsoft Graph or Exchange Web Services (EWS), depending on the account type. ActiveSync is not supported.

  • Calendar and contact synchronization occurs directly between your device and the server associated with your account.
  • Optional Microsoft Graph push notifications use the relay described below.
  1. Delegate and Shared Calendars

BusyCal and BusyContacts offer a full replacement of Outlook in their own rights and so in order to sync with Exchange / O365, our apps need to be able to see delegate and shared calendars and address books (only related to the connected account) so that the user is able to manage calendars they own, including ones shared them.

  1. Basic profiles

Our applications do not probe, discover, or access the profiles of others within your organization. They only request the email addresses of users from the server when adding an "attendee" to an event or when setting up a shared calendar. This is also necessary when using the Availability Viewer to conduct Free/Busy lookups.

  1. Full Access to User Calendars/Address Books

Our apps are designed to serve as replacements for native apps like Apple Calendar or Microsoft Outlook, and therefore require full access to perform actions such as creating, editing, or deleting events and contacts on your behalf.

important

Full access is required for our apps to read, write, or delete events and contacts as directed by you. This access is limited to your calendars and address books and does not include any other organizational data.

In some cases, granting access to work or university accounts may require prior approval from your organization. This is typically done through administrative settings within platforms like Office 365 or similar portals.

Push Notifications​

When Push is enabled for Google Calendar or Microsoft Graph, the provider sends change notifications to our AWS-hosted relay. The relay prompts your device to refresh through Apple Push Notification service. The app then retrieves the changed calendar or contact content directly from your provider.

These notifications use a device push token, account and calendar or resource identifiers, and subscription or change metadata. Microsoft Graph notifications include the connected account's email address. Google calendar identifiers can also contain an email address. The notifications do not include full event or contact content, passwords, or OAuth tokens.

You can choose a timed interval instead of Push under Settings > Accounts > Refresh calendars in BusyCal for Mac. Existing subscriptions are removed during a subsequent successful sync.

Licensing​

When you place an order or purchase a copy of our software, you are required to share your email address with us. This email is linked to the serial number generated to uniquely identify your installation(s). This information is stored and used exclusively for licensing and invoicing purposes. When you register your Mac for the first time, your Mac-ID, IP address, and serial number are sent to our servers to validate and activate your copy. This process is necessary solely for licensing purposes and to validate your installation.

Automatic Updates​

BusyCal and BusyContacts on macOS periodically check for updates by contacting our servers. This process involves sending anonymous information about your installation, including the version of BusyCal/BusyContacts and macOS, to determine if an update is available for your software.

Mailing List​

If you have subscribed to our mailing list, you will receive infrequent emails from us about important software updates, new product announcements (which may or may not be developed in association / collaboration with another company) or special offers. We will protect your privacy and not share / sell your email addresses to anyone. You may unsubscribe from our mailing list at any time.

Application Logs​

If you contact us and choose to share private logs for diagnostic purposes (with your consent), these logs are retained only as long as necessary to resolve the issue. No one outside our organization has access to this information. You have the right to request immediate deletion of logs at any time, even before the issue is resolved.

note

Our support staff is trained to handle diagnostic logs with extreme care. They see logs day in and day out and are highly skilled at honing in on only the information necessary to resolve your issue or identify the fault, ignoring any unrelated details. Additionally, we utilize tools that filter out noise and highlight specific details, helping us efficiently locate faults or potential resolutions.

The logs stored on your disk automatically roll over and are deleted every few days. When shared with us, only a snapshot of the data is captured, focusing on essential details like network request data or UI actions (e.g., editing) required to diagnose and assist in solving the issue.

Your logs are never shared with us automatically, and we cannot access your computer or installed apps. Our apps are sandboxed, native applications that securely store data locally on your device, giving you complete control over your logs, including the ability to delete them or adjust logging levels as needed from the app's Help menu.

tip

Please see instructions here on how to share the minimal set of logs if this is deemed necessary for troubleshooting purposes.

Non-Personal Information​

We use Google Firebase to receive crash reports and optional performance metrics. Reports can include stack traces, app and operating-system versions, and Firebase installation identifiers used to group diagnostics from an app installation. We use this information to identify bugs and improve performance.

Application logs shared with support are separate and may contain sensitive information. They are sent only when you choose to share them.

Crash reporting can be entirely disabled via the application's preferences, ensuring complete control over data sharing.

In non-beta BusyCal for Mac, disabling both analytics and crash reporting before launch prevents Firebase from starting in BusyCal and BusyCal Menu. Fully quit and reopen both after changing these settings. Connections for sync, licensing, updates, and enabled features are separate from diagnostic reporting.

Internet Access Policy​

The domains below support app updates, licensing, diagnostics, and optional features. The connections used depend on your app version, accounts, and settings. Your configured sync providers and their sign-in services require their own domains in addition to this list. Update checks and update downloads are separate requests, so a firewall needs to allow both.

Outgoing Connections

versioncheck.busymac.com

Direct-download Mac versions use this server to check for app updates and update eligibility.

register.busymac.com

Direct-download Mac versions use this server to activate and validate licenses. The serial number and device identifier are used to check license status and the number of activated devices.

www.busymac.com, downloads.busymac.com

The update feed links to release notes and downloads on www.busymac.com. App downloads redirect to downloads.busymac.com, so both hosts need to be allowed for the download to complete. These connections use HTTPS.

support.busymac.com

This is the domain used by our online support portal. Some help links or contact links within the app will open help pages under this domain.

news.busymac.com

Our apps connect to this server to check for essential app-updates and related announcements.

weatherkit.busymac.workers.dev, weather.busymac.workers.dev

BusyCal retrieves Apple Weather forecasts through weatherkit.busymac.workers.dev and uses weather.busymac.workers.dev for city lookups. Requests include the coordinates or city needed for the lookup. The Apple Weather attribution identifies the forecast provider; these proxy hosts are still used. Saved forecasts can remain visible after restarting the app. Weather requests may use HTTPS over TCP or HTTP/3 over UDP port 443.

ogpsakm3q7cp6qavyeymbtixze0mtmnv.lambda-url.us-east-1.on.aws

BusyCal uses this AWS endpoint to convert a What3Words address into coordinates. The three-word address is sent for that lookup. It is separate from the weather forecast hosts above.

url-us.link

Our apps connect to this URL shortening service when you explicitly use the link shortening feature to create shortened URLs for sharing events or other content. This connection only occurs when you manually invoke the URL shortening feature. Only the URL you choose to shorten is sent to the service. No personal information, event details, or other data is collected, stored, or tracked by us through this service.

icons.busymac.com

BusyCal connects to this server to look for icons online in the Graphics Panel. If you deny this connection, you will not be able to search for online icons in the Graphics Panel.

*.crashlytics.com, crashlyticsreports-pa.googleapis.com, firebaseinstallations.googleapis.com

Our apps use Firebase Crashlytics for crash reports and Firebase's installation service for the identifiers used in those diagnostics. Crash logs are automatically generated by macOS whenever an app unexpectedly closes or crashes due to issues such as user interactions, memory leaks, or other system errors. These stack traces provide critical insights, enabling developers to diagnose the root cause and improve the app's overall stability.

firebaselogging-pa.googleapis.com, firebaselogging.googleapis.com, app-measurement.com, *.app-measurement.com, app-analytics-services.com, *.app-analytics-services.com, app-analytics-services-att.com, *.app-analytics-services-att.com

Analytics are turned off by default. When manually enabled under app Settings, our apps occasionally send app-usage and licensing-related events to Firebase to correlate these with Crashlytics reports and to help identify general performance issues and usage trends. These analytics also help us identify areas that are under-utilized and need greater attention. Any data collected here strictly complies with the General Data Protection Regulation (GDPR). Data collection is also automatically purged periodically and contains absolutely no information related to events, calendars, and accounts, personal or otherwise.

*.googleapis.com

Google Calendar, Tasks, Contacts, and Workspace APIs use hosts under this domain when you connect a Google account. The Firebase diagnostic hosts listed above also use this domain and have separate reporting settings.

dns.google

This is Google's public DNS, used internally by all Google APIs (Calendar, Tasks, Contacts, Firebase, Crashlytics, etc.) for sending queries to authoritative servers from Core data centers and Google Cloud region locations.

Push notification relay hosts

dxp5xke4dn2hydzeeahrttal7y0rlvie.lambda-url.us-east-1.on.aws (Google Calendar)

m6fpsxmw3ad3k2hld4w7e6jnxe0gzsbq.lambda-url.us-east-1.on.aws (Microsoft Graph)

The app registers these callback addresses with Google or Microsoft. The provider contacts the relay, which prompts the device through Apple Push Notification service. These are provider-to-relay connections, not direct app requests to the relay. See Push Notifications for the metadata involved.

Cookies and Other Technologies​

Our website, services, apps, email communications, and advertisements may use "cookies" and other technologies such as "pixel tags" and "click-through URLs". We use the information we collect in this manner to better understand our users' interactions with our website and to optimize the user experience. You can disable cookies in your browser settings, but please note that certain features on our website may not be available as a result.

As you access our services, we gather some information automatically on our servers and store it in log files. This information includes your browser type, version, and language, your operating system, the referring and exit websites, IP address, a date/time stamp of the request, and the requested resource (file name and URL). We use this information in anonymized form for statistical analysis, to administer our site, and to improve our product and services, without directly associating this data with individual users.