CalendarConnect is designed from the ground up to protect your privacy. We access the absolute minimum data required — free/busy status only — and nothing else.
CalendarConnect accesses the lowest permission level available on any calendar system — free/busy status only. We never see, store, or transmit meeting titles, descriptions, attendee lists, locations, or attachments. There is literally nothing sensitive to protect because we never access it.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. User authentication is handled via Google OAuth, Microsoft OAuth, or email/password with industry-standard session management.
Participants can revoke calendar access at any time from their own Google or Microsoft account settings. Project owners can remove participants instantly. When a participant is removed or revokes access, their calendar data is immediately deleted from our systems.
CalendarConnect data is hosted on secure cloud infrastructure in the United States. We do not sell, share, or provide access to user data to any third party.
CalendarConnect is designed with enterprise security requirements in mind. SOC 2 Type II certification is on our roadmap. For security inquiries, contact security@calendarconnect.net.
CalendarConnect requires only free/busy read access — no full calendar, no mail, no contacts, no admin permissions. This is the lowest risk calendar integration possible, making approval straightforward for IT security teams. No data is extracted, stored long-term, or shared between organizations. Each participant controls their own authorization and can revoke it at any time.
Exactly what CalendarConnect can and cannot see.
| Data | Access |
|---|---|
| Free/busy status | Yes (read only) |
| Meeting titles | Never accessed |
| Meeting descriptions | Never accessed |
| Attendee lists | Never accessed |
| Meeting locations | Never accessed |
| Attachments | Never accessed |
| Email or contacts | Never accessed |
| Admin/directory access | Never requested |