Report a vulnerability

If you discover a vulnerability that could expose another user’s calendar data or credentials, contact the maintainer privately at calflow.support@gmail.com, or through the contact information on the maintainer’s GitHub profile.

Please describe the affected feature and steps to reproduce the issue using redacted or example data. Do not publish exploit details in a public issue.

Keep sensitive information private

Please do not post OAuth tokens, refresh tokens, client-secret JSON files, private calendar URLs or other credentials in a public issue. Do not include working credentials in a report.

Ordinary bugs and feedback

For ordinary bugs, use GitHub Issues. Explain what you expected, what happened and which command you were using. Redact private calendar details from screenshots or recordings.

Privacy and data handling

For information about Google Calendar access, local storage and disconnecting your account, read the privacy policy.

Based on the project’s security policy. DayCal is maintained by Jonah Tweed.