Effective date: 12 September 2026

DayCal is a Google Calendar extension for Raycast. Privacy and security are core design priorities: DayCal is built to work directly between Raycast on your Mac and Google Calendar, without a DayCal-operated backend service.

Summary

Google data DayCal accesses

DayCal currently requests these Google OAuth scopes:

Depending on the feature you use, DayCal may access Google Calendar information such as:

DayCal uses this information only to provide user-facing calendar features such as Schedule, Menu Bar, Quick Add, editing, copying, moving, deleting, calendar routing, meeting links, and permission-aware event actions.

How Google data is transmitted

Calendar API requests are made directly from the Raycast extension to the Google Calendar API at www.googleapis.com using the Google OAuth access token supplied by Raycast.

DayCal does not proxy those requests through a DayCal-owned server.

When you explicitly choose Open Event, Open in Google Calendar, or Open Calendar, DayCal opens the Google Calendar event or calendar link in your default browser for the connected Google account. Actions such as Open Location or Join Meeting may open the relevant maps, conferencing, or other event-provided URL using the system default handler. Those destinations then operate under their own privacy policies.

Local storage on your Mac

DayCal stores some information locally through Raycast so the extension can remember your choices and remain responsive.

This can include:

This local event cache can contain calendar event information returned by Google. It is used only for DayCal's local UI and refresh behaviour.

DayCal does not intentionally transmit this locally stored configuration or cache to the developer.

OAuth tokens

Google OAuth authentication is provided through Raycast's native OAuth support. DayCal does not contain a Google client secret, refresh token, or access token in its public source repository.

The public OAuth client ID is included in the source code because OAuth client IDs are application identifiers, not secrets.

DayCal does not log or intentionally transmit OAuth tokens to the developer.

Disconnecting and revoking access

The Disconnect Google Calendar command:

Disconnecting inside DayCal does not revoke the app's authorization in your Google Account. You can separately revoke Google access from your Google Account's third-party access/security settings.

A dedicated one-step command for clearing all remaining DayCal local configuration is planned before the full public release. Until then, DayCal is transparent that Disconnect preserves those settings rather than silently deleting them.

Analytics, advertising, and tracking

DayCal currently includes no DayCal-operated analytics, advertising SDK, behavioural tracking, telemetry service, or crash-reporting service that sends calendar data to the developer.

DayCal does not sell, rent, or trade Google user data or DayCal user data.

DayCal does not use Google user data for advertising, credit decisions, or training generalized AI or machine-learning models.

Human access to calendar data

The developer does not receive or routinely have access to your calendar data through DayCal.

If you choose to submit a GitHub issue, screenshot, screen recording, log, or other diagnostic information, that information is provided voluntarily by you. Please redact private event details, email addresses, private calendar links, OAuth tokens, and other credentials before posting publicly.

Security-sensitive reports should follow security policy instead of being posted publicly.

Google API Services User Data Policy

DayCal's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

DayCal requests Google data only for features that are visible to and initiated for the benefit of the user, and does not use that data for unrelated purposes.

Data sharing

DayCal does not share Google Calendar data with advertisers, data brokers, or unrelated third parties.

Data may be handled by the services required to provide the extension's functionality, principally:

Any additional external destination is opened only when you explicitly trigger an action such as opening a map, conference link, event source link, or calendar page.

Security

DayCal is open source so its Google API usage and local data handling can be inspected publicly.

The project aims to use the minimum Google scopes required for its current features, avoids embedding secrets in the repository, distinguishes writable/owned events from guest or read-only events, and runs automated regression and TypeScript checks on changes.

See security policy for vulnerability reporting guidance.

Changes to this policy

If DayCal's data handling changes materially, this policy will be updated before or alongside that change. The effective date at the top of this document will be revised when appropriate.

Contact

For privacy questions that do not contain sensitive information, email calflow.support@gmail.com, use the DayCal GitHub repository, or contact the maintainer through the GitHub profile.

For suspected vulnerabilities or anything involving credentials or private calendar data, follow the private reporting guidance in security policy.

This website

This static website is hosted on GitHub Pages. It has no added analytics, advertising, tracking scripts or cookies. GitHub processes visits under its privacy statement. The website does not connect to your Google Calendar.

Adapted from the project’s privacy policy with DayCal branding and the support contact. The extension’s data-handling policy is unchanged.