Privacy

Privacy

Controller

Cal and this website are operated by Fritz Kürmayr. The legally required contact and postal details are available in the imprint. Privacy requests can be sent to privacy@frilabs.dev.

frilabs website

No analytics, advertising trackers, or cookies are used, and fonts are served from this site. If you switch between light and dark mode, that choice is stored in your browser's local storage and never leaves your device. Standard server and security logs may temporarily contain an IP address, request metadata, and error information to deliver and protect the site.

Other frilabs products

Orbit has its own privacy policy at orbit.frilabs.dev/privacy. The sections below cover Cal.

Data Cal processes

Cal processes the email address and account identifier needed for passwordless login; device identifiers and push tokens; locale, timezone, and submission time; and text, URLs, email or message content, screenshots, images, and calendar details that a user deliberately submits. It also stores structured event candidates, processing status, and limited operational records needed to prevent duplicates, enforce quotas, and keep the service reliable.

Purposes and legal basis

Account, security, submission, and calendar data are processed to provide the service requested by the user and to protect it from abuse. Shared content is transferred to OpenAI only after explicit consent. Consent can be withdrawn in Settings; Cal then stops accepting new AI-processed submissions until consent is given again. Google Calendar access is authorized separately by the user and can be disconnected at any time.

Calendar access

Cal requests the minimum Google authorization needed to create and manage a dedicated calendar named “Cal”. It does not use Google Calendar authorization as product login and does not add events to the primary calendar. Disconnecting removes locally stored refresh-token material and requests revocation from Google.

Service providers

International processing

Some providers may process data outside the user's country. Where applicable, the operator relies on the provider's contractual safeguards and other legally recognized transfer mechanisms. Provider privacy terms remain available from the respective provider.

Retention

Successful raw submissions and attachments are scheduled for deletion after 24 hours. Unresolved or failed inputs may be retained for up to seven days so the user can correct them. Structured event history remains until the user deletes it or the account. OAuth state expires after ten minutes. Security and delivery logs are kept only as long as operationally necessary.

Account deletion

Account deletion is available directly in Cal Settings. It removes stored attachments, deletes the Supabase user and associated database records, and attempts to revoke Google authorization. A user may also disconnect Google Calendar without deleting the Cal account.

Your rights

Depending on applicable law, users may request access, correction, deletion, restriction, portability, or objection and may withdraw consent without affecting prior lawful processing. EU and EEA users also have the right to lodge a complaint with their competent data-protection authority. Requests should be sent to privacy@frilabs.dev.

Children and changes

Cal is not directed to children under 13. This policy may be updated when the product, providers, or legal requirements change; the date below identifies the current version.

Last updated: 20 September 2026