sync
Kelbra

Privacy Policy

Last updated: 2026-09-01

What Kelbra does

Kelbra connects calendars you own (Google, Apple/iCloud, Microsoft/Outlook, and other CalDAV servers) and keeps events synchronized between them. To do that, it needs to read and write calendar event data on your behalf, and it stores the account credentials needed to keep doing so automatically.

What we collect

  • Account info: your email address and a hashed (never plaintext) password, if you sign up directly rather than through a calendar provider's OAuth flow.
  • Calendar connection credentials: OAuth access/refresh tokens (Google, Microsoft) or app-specific passwords (Apple/iCloud, other CalDAV servers), encrypted at rest with AES-256. We never see or store your real account password for Google or Microsoft, only the token their own OAuth flow issues us, which you can revoke at any time from that provider's own account settings.
  • Calendar event content: titles, times, locations, descriptions, and attendee lists of events on the calendars you connect. This is the data being synchronized. A short-lived fingerprint of each event's content is kept to detect genuine edits and conflicts; deleted events are backed up temporarily so an accidental delete can be recovered.
  • Usage/operational data: a log of sync actions (created/updated/deleted, and which calendar each change came from and went to), so you can see your own sync history and so we can detect and surface conflicts and connection errors to you.
  • Billing data, if you subscribe: handled by our payment processor (Paddle). We store a subscription status and Paddle's own customer/subscription identifiers, not your card details, which Paddle handles directly.

Third parties we share data with

  • The calendar providers you connect (Google, Apple/iCloud, Microsoft, or a CalDAV server you specify), necessarily, since syncing means reading from and writing to them directly on your behalf.
  • Resend, to deliver account emails (password resets, sync-error and reconnect-needed notifications). We send only your email address and the message content, not your calendar data.
  • Paddle, our payment processor, if you subscribe to a paid plan. They handle your payment details directly; we never receive or store your card number.
  • Anthropic, only if you use the optional "parse event from text" feature. The text you paste in is sent to Anthropic's API to extract a structured event, and nothing else.

We do not sell your data, and we do not share your calendar content with anyone else.

Data retention and deletion

Disconnecting a calendar stops Kelbra from syncing it further; you can permanently delete your account and its data from Settings, which removes your stored credentials, connections, and synced event data associated with your account.

Security

OAuth tokens and app-specific passwords are encrypted at rest (AES-256). All connections to Kelbra and to the calendar providers it talks to use HTTPS. Session tokens are random, single-purpose, and expire.

Children's privacy

Kelbra is not directed at children under 13, and we do not knowingly collect data from them.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page.

Contact

Questions about this policy or your data can be sent to the contact address listed on our Google Cloud OAuth consent screen.