Privacy Policy

Effective Date: February 2026

Introduction

CalenDash is an AI personal assistant service that operates as a Telegram bot and web dashboard. This service is operated by an individual developer based in Israel, not a registered company. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our service.

By using CalenDash, you consent to the data practices described in this policy. If you do not agree with our practices, please do not use our service.

What We Collect

Account Information

When you create an account or use our service, we collect:

  • Your name (from Google OAuth)
  • Your email address (from Google OAuth)
  • Your profile picture (from Google OAuth, if provided)
  • Account creation and last login dates

Calendar and Task Data

If you choose to connect your Google Calendar (optional), we access:

  • Calendar event titles, descriptions, dates, and times
  • Event participants and organizers
  • Calendar metadata (calendar names, colors, settings)

We also store any calendar events, tasks, or reminders you create directly through CalenDash.

Conversation Data

Our AI assistant maintains conversation history with you to provide context and improve responses. This includes:

  • Messages sent to and from the Telegram bot
  • Voice messages (transcribed using ElevenLabs)
  • Commands and responses exchanged through the bot
  • Conversation context for the memory feature

Payment Information

For paid subscriptions, we process payments through PayPal. We do not store your payment card details - PayPal handles all payment processing securely. We only store:

  • PayPal transaction IDs
  • Subscription status (active/cancelled)
  • Subscription start and end dates
  • Payment amounts and dates

Usage and Technical Data

  • IP addresses (for security and analytics)
  • Browser type and version
  • Device type and operating system
  • Pages visited and features used
  • Time spent using the service
  • Error logs and crash reports

How We Use It

Core Service Functionality

We use your data to:

  • Provide AI assistant responses through the Telegram bot
  • Display and manage your calendar events in the web dashboard
  • Maintain conversation context and memory between sessions
  • Process voice messages and convert them to text
  • Send you reminders and notifications
  • Generate summaries and insights from your calendar data

Account Management

  • Authenticate your identity and maintain your session
  • Process subscription payments and manage billing
  • Provide customer support when requested
  • Send important service notifications via email

Service Improvement

  • Monitor system performance and identify technical issues
  • Analyze usage patterns to improve features (aggregated data only)
  • Detect and prevent abuse or fraudulent activity

Where It's Stored

Primary Storage

  • Database: Supabase (hosted in US West region)
  • Application servers: Hetzner VPS (located in Germany)
  • Files and media: Supabase storage buckets

Data Protection Measures

  • All data is encrypted in transit using TLS 1.3
  • Database contents are encrypted at rest
  • Access controls limit data access to essential operations only
  • Regular automated backups with encryption
  • Server access protected by SSH keys and firewall rules

Data Retention

  • Active user data is retained while your account is active
  • Conversation history is maintained for the memory feature
  • After account deletion, all data is permanently removed within 30 days
  • Backup copies are purged within 90 days of deletion

Third Parties

We work with the following third-party services to operate CalenDash:

Essential Service Providers

ServicePurposeData Shared
Google OAuthAccount authenticationName, email, profile picture
Google Calendar APICalendar integration (optional)Calendar events and metadata
SupabaseDatabase and file storageAll user data (encrypted)
PayPalPayment processingPayment information
Moonshot AI (Kimi K2.5)AI conversation processingMessages, names, schedule data, and any information shared in conversation
ElevenLabsVoice message transcriptionVoice recordings (temporarily)
Telegram Bot APIBot messaging serviceMessages and user interactions
HetznerServer hostingServer logs and access data

Data Sharing Limitations

We do NOT:

  • • Sell your personal data to any third party
  • • Share your data with advertisers or marketers
  • • Use your data for purposes other than providing CalenDash services
  • • Access your Google Calendar without explicit permission
  • • Store payment card details (handled entirely by PayPal)
  • • Share conversation content with other users

Your Rights

Access and Portability

  • Request a complete copy of all your personal data
  • Export your calendar events and conversation history
  • View what information we have about your account

Correction and Control

  • Update your account information through the dashboard
  • Correct inaccurate personal information
  • Control which calendar data is synchronized
  • Manage conversation memory and clear chat history

Restriction and Objection

  • Disconnect Google Calendar integration at any time
  • Revoke OAuth permissions through your Google Account settings
  • Opt out of non-essential communications
  • Restrict processing of your data for specific purposes

Data Deletion

Account Deletion Process

You can request complete deletion of your account and all associated data by:

  • Sending an email to support@calendash.app with "Delete My Account" in the subject line
  • Including your email address associated with the account
  • Confirming your identity (we may ask for verification)

What Gets Deleted

  • All personal information (name, email, profile data)
  • Complete conversation history with the AI assistant
  • All calendar events and tasks stored in CalenDash
  • Account settings and preferences
  • Payment history and subscription data
  • Usage logs and analytics data linked to your account

Deletion Timeline

  • Immediate: Account becomes inaccessible
  • Within 7 days: Active data removed from primary systems
  • Within 30 days: All data permanently deleted from all systems
  • Within 90 days: Data purged from encrypted backups

Legal Retention Requirements

Some information may be retained longer if required by law, such as:

  • Payment records (for tax and accounting purposes)
  • Security incident logs (for fraud prevention)
  • Legal compliance records (if subject to legal hold)

Cookies and Tracking

CalenDash uses minimal cookies and tracking:

  • Authentication session cookies (essential for login)
  • Temporary preference cookies (theme, language settings)
  • No advertising or third-party tracking cookies
  • No analytics cookies beyond basic usage statistics

You can disable cookies in your browser, but this may affect service functionality.

International Data Transfers

Your data may be processed in multiple jurisdictions:

  • Germany (Hetzner VPS hosting)
  • United States (Supabase database)
  • China (Moonshot AI — AI conversation processing)
  • Israel (service operator location)

AI Processing Disclosure

⚠️ Important: AI Data Processing

CalenDash uses Moonshot AI (Kimi K2.5), operated by Beijing Moonshot Technology Co., Ltd. (China), to power the AI assistant. When you interact with Calen (the AI assistant), your messages and conversation context are sent to Moonshot AI's servers for processing.

This means that any personal information you share in conversation — including names, schedules, health information, family details, financial data, or other sensitive information — is transmitted to and processed by Moonshot AI's infrastructure in China.

Moonshot AI's privacy policy states they do not use customer data for training and do not share it with third parties. However, data processed in China is subject to Chinese data protection laws, which may differ from those in your jurisdiction.

All transfers are protected by appropriate safeguards including encryption, contractual protections, and adherence to international data protection standards.

Children's Privacy

CalenDash is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information as quickly as possible.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@calendash.app.

Security Incidents

In the event of a data breach that affects your personal information, we will:

  • Notify you within 72 hours of discovering the breach
  • Describe what information was involved
  • Explain what we are doing to address the incident
  • Provide steps you can take to protect yourself
  • Offer assistance and support as needed

Service Changes and Limitations

Trial Period

New users receive a 3-day unlimited trial with full access to all features. During the trial, all privacy protections apply equally.

Paid Subscription

After the trial period, continued use requires a $29/month subscription processed through PayPal. Subscription data is subject to the same privacy protections as all other user data.

Service Discontinuation

If CalenDash is discontinued, we will:

  • Provide at least 30 days advance notice
  • Offer data export options
  • Delete all user data according to our deletion procedures
  • Process any remaining refunds according to our terms

Contact

For any privacy-related questions, concerns, or requests, please contact us:

Email: support@calendash.app

Response Time: Within 48 hours for general inquiries

Data Requests: Within 30 days for access, correction, or deletion requests

Subject Line: Include "Privacy Request" for faster processing

Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes:

  • We will notify you by email at least 30 days before changes take effect
  • We will display a prominent notice in the CalenDash dashboard
  • We will update the "Effective Date" at the top of this policy
  • We will maintain an archive of previous versions upon request

Your continued use of CalenDash after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you may delete your account before they take effect.

Google API Services Compliance

CalenDash's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, CalenDash:

  • Only accesses Google data that you explicitly authorize
  • Uses Google data solely to provide CalenDash services to you
  • Does not transfer Google data to third parties except as necessary for service operation
  • Does not use Google data for advertising purposes
  • Does not sell Google data to any third party
  • Stores Google data securely and deletes it when you request account deletion