Legal
Privacy policy
Last updated: 23 September 2026
MT-CalSync is a calendar-synchronization service operated by Melsson Technology. This policy explains exactly what data we access, what we store, and what we never do with it. It's short because the answer is: as little as possible.
What we access
When you connect a Google or Microsoft account you grant MT-CalSync access to your calendars, plus the basic sign-in details that identify which account you connected:
- Google: calendar events (read/write) and your calendar list (read-only), via the
calendar.eventsandcalendar.calendarlist.readonlyscopes; and your account's email address and ID, viaopenidandemail. - Microsoft: calendar read/write (including calendars shared with you), via the
Calendars.ReadWriteandCalendars.ReadWrite.Sharedpermissions; your name and email address, viaopenid,profile,emailandUser.Read; andoffline_access, which lets the sync keep running while you are away.
We request no mail, file, contact, or drive access of any kind.
What we store
- OAuth tokens for the accounts you connect, encrypted at rest (AES-256-GCM). We never see or store your account passwords.
- Sync bookkeeping: which of your events maps to which mirrored copy (event identifiers, timestamps, and content hashes used to detect changes).
- Your MT-CalSync account: email address, name, a securely hashed password, and subscription state.
- Payment method references: card processing is handled by Stripe; we store only a reference token plus the card brand, last four digits, and expiry for display. Full card numbers never touch our systems.
Event details flow through the sync engine to create and update mirrored events, but we avoid retaining event bodies beyond what syncing requires, and we never write event contents, attendee emails, or tokens to our logs.
Limited Use disclosure (Google user data)
MT-CalSync's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- Google user data is used only to provide the calendar-sync features you see, never for advertising, profiling, or model training.
- We do not sell Google user data, and we do not transfer it to third parties except as necessary to provide the service (our hosting infrastructure), to comply with law, or as part of a merger or acquisition with equivalent privacy commitments.
- No humans read your calendar data except with your explicit permission for a support issue, where required for security purposes, or to comply with law.
Deleting your data
- Disconnect an account at any time from the Calendars page: we revoke the grant where the provider supports it (Google) and delete the stored tokens immediately. For Microsoft, deleting our stored tokens ends our access (any short-lived access token expires within the hour); you can additionally revoke MT-CalSync under your Microsoft account's app permissions.
- Removing a sync pair deletes the events it mirrored into the destination calendar. Your original events are never touched.
- Unconverted trials: if your trial ends and you don't subscribe, we automatically revoke and delete your stored calendar tokens after 30 days. We don't warehouse credentials we no longer need.
- Account deletion: delete your account yourself from the profile page (password- confirmed), or email us and we'll do it. Deletion erases your login, stored tokens, connections, sync pairs, and the events they mirrored where we can still reach them. Payment transaction records are retained as required for accounting; the card references at Stripe are removed.
Cookies
We use a single first-party session cookie to keep you signed in, and it is strictly necessary for the service to work at all. No analytics trackers, no advertising cookies, no third-party beacons, no session recording, which is why this site has no cookie banner to click through.
Contact
Privacy questions: see the support page. We answer personally.