Effective 8 October 2026
Privacy Policy
FamCal (“family-calendar”) is made by Servaas Tilkin (POCITO). This policy explains what data the app accesses and how it is handled — the short version: it reads calendars you choose to connect, shows them on a screen inside one house, and stores nothing anywhere else.
Read-only · local-only · no analytics · no trackingWhat the app does
The app displays calendar events on a screen inside the operator’s home. It reads calendar data from accounts that family members deliberately connect, and shows a combined weekly overview. It is read-only: the app can never create, modify, or delete events, emails, files, or any other data in connected accounts.
What data we access
When you connect an account, the app requests read-only access to your calendars. Via the provider’s API (Google Calendar API / Microsoft Graph) the app can read:
- Calendar names and settings
- Event details: title, date and time, location, description, attendees, and busy/free status — only within a limited window (roughly the recent past up to ~60 days ahead)
The app does not request, and cannot access, email, contacts, files, photos, or any other account data.
What we store, and where
- OAuth tokensthe credentials that keep the calendar readable — on the home server, never in any cloud
- A local cache of eventsthe events inside the limited window, in a local database on that same server, pruned automatically
The home server is a Raspberry Pi inside the operator’s house. Older events are pruned automatically as the window moves forward, so the display works without hammering the providers’ APIs.
There is no external hosting, no analytics, no advertising, no tracking, and no cookies. Data never leaves the household network, and it is never sold, shared, or transferred to any third party beyond the Google/Microsoft APIs themselves.
How long we keep it
Cached events are deleted automatically once they fall outside the display window. OAuth tokens are kept until you revoke them (below) or ask the operator to remove them.
Your choices
- Revoke access at any time: Google — myaccount.google.com/permissions; Microsoft — account.live.com/consent/Manage (or your work account’s consent settings). Revoking immediately prevents any further reading.
- Delete cached data: contact the operator (below); the local cache is purged on request or when access is revoked.
- Questions: contact servaas.tilkin@gmail.com.
Google API Services — Limited Use
The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Changes
This is a hobby app for one household; if the policy ever changes in a way that matters, connected family members will be told directly and this page will be updated with a new effective date.
Contact
Operator: Servaas Tilkin (POCITO), Belgium. Questions about this policy: servaas.tilkin@gmail.com.