Privacy Policy
Last updated: July 11, 2026
Performative Work (“we”, “the app”) helps you create and manage events on your own Google Calendar. This policy explains what we do — and mostly don’t — with your data.
We do not store your calendar data
We never store the contents of your calendar. When you ask the app to add or remove events, those actions happen directly against the Google Calendar API in real time. We do not copy, save, log, or retain any of your calendar events, their titles, times, attendees, or any other calendar information on our servers.
What we do store
To sign you in and keep the app working, we store only the minimum required:
- Your basic Google account profile: name, email, and avatar.
- Authentication tokens from Google that let the app act on your calendar while you are using it.
That is the full extent of it. We do not sell or share your data, and we do not use it for advertising.
How we protect your data
The limited data we hold — your basic profile and the Google authentication tokens described above — is treated as sensitive and protected with industry-standard security mechanisms:
- Encryption in transit. All communication between your browser and our servers, and between our servers and Google APIs, is encrypted using HTTPS/TLS. We never transmit your data over unencrypted connections.
- Encryption at rest. Google authentication tokens are encrypted with an authenticated cipher (XChaCha20-Poly1305) before they are written to our database, so they are never stored in plaintext.
- Protected storage. The database itself is not reachable from the public internet. It runs on an isolated private network, accepts connections only from the application itself, and requires authenticated access.
- Access controls. Database and API credentials are kept in server-side configuration, never in client-side code or version control. No third party is given access to your tokens, and they are used exclusively to perform the calendar actions you request.
- Data minimization. Our strongest safeguard is storing as little as possible: we request only the narrowest Google scopes the app needs, and we never persist your calendar contents at all, so there is no calendar data to breach.
- Incident response. In the unlikely event of a security breach affecting your data, we will promptly notify affected users and revoke compromised credentials.
Google API access
We request access to your Google Calendar (the calendar and calendar.events scopes) solely to create and manage the events you choose to generate. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access and deleting data
You can revoke the app’s access to your Google account at any time from your Google Account permissions page. To have the limited account data above deleted, contact us and we will remove it.
Contact
Questions about this policy? Email [email protected].