Calibri Calendar Assistant
Privacy policy
This policy explains how shermantan.xyz handles information when the authorized user operates Calibri, a private, single-user Telegram assistant for Google Calendar.
Information Calibri accesses
Calibri requests the Google Calendar events permission (https://www.googleapis.com/auth/calendar.events). This allows it to view and search event information, check for time overlaps, and create, reschedule, recolour, or delete events. Calibri accesses this information solely to fulfil calendar requests made by its authorized user.
Information collected or stored
To operate, Calibri may collect or store:
- Google OAuth credentials and an authorization token used to access the authorized user's calendar;
- the Telegram chat identifier used to restrict access to the configured user;
- a pending action or limited conversational context, such as an event title and time, needed to clarify or confirm a request; and
- operational logs used to maintain and troubleshoot the service, avoiding message contents where practical.
OAuth credentials and tokens are never published on this website.
How information is used and processed
Information is used only to interpret the authorized user's request, show a proposed calendar action, carry out confirmed actions, and maintain the service. The following service providers process information as part of that operation:
- Google Calendar API processes calendar reads and confirmed writes.
- Google Gemini API may process user messages and the minimum context needed to interpret a request. See Google's Privacy Policy.
- Telegram processes messages sent through Telegram. See Telegram's Privacy Policy.
- DigitalOcean hosts the private assistant. See DigitalOcean's Privacy Policy.
- Cloudflare delivers this public informational website. The website itself has no forms, login, analytics, advertising, or application cookies. See Cloudflare's Privacy Policy.
shermantan.xyz does not sell personal data and does not use Google Calendar data for advertising or targeted advertising.
Google user data
Calibri's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Security
Access to Calibri is limited to one configured Telegram chat identifier. The OAuth token is kept on a private server with restricted file permissions. Before any calendar change is applied, Calibri presents a preview and requires user confirmation. No method of storage or transmission can be guaranteed completely secure.
Retention
OAuth credentials and the authorization token are retained while the Google Calendar integration is active. Limited task state is kept only as needed for the bot workflow and is replaced or cleared as the conversation progresses. Operational logs are retained only as reasonably needed to operate and troubleshoot the private service.
Your choices and control
The authorized user can stop using Calibri at any time. Google access can be revoked from the Google Account third-party connections page. The user can also contact shermantan.xyz to request deletion of locally held credentials and limited task state.
Contact and changes
Questions or deletion requests can be sent to [email protected].
This policy may be updated when Calibri's practices change. Any revision will be posted on this page with an updated effective date.