Calendar Airmail is optional. You start a Google OAuth connection, which requests only the https://www.googleapis.com/auth/calendar.events.readonly scope.
The app reads the title and start/end time of timed events from your primary calendar, expands recurring instances, and ignores all-day events. It uses this information only to create local reminders 10 minutes before an event and at its start. It cannot create, modify, delete, or share calendar events.
Event schedule data stays local in a rolling upcoming 30-day window and is refreshed every 10 minutes. OAuth sessions, tokens, and credentials are encrypted at rest in plugin-scoped secret storage.
Security procedures are in place to protect the confidentiality of your Google Calendar data: all communication with Google APIs is encrypted in transit (HTTPS/TLS); Calendar Airmail runs in the host sandbox with access gated by approved permissions; network requests are limited to Google OAuth and Google Calendar API endpoints; and Calendar error diagnostics redact token-like values and URLs.
The plugin contacts only Google OAuth and Google Calendar API endpoints; no Calendar data is sent to an OpenPets server or another third party. You can disconnect in the app to immediately clear the locally stored Calendar event schedule, delivery metadata, pending reminders, and Google session.
Google user data - whether raw, aggregated, anonymized, or derived - is not sold, is not used for advertising, is not transferred to data brokers, and is not used to develop, improve, or train generalized (non-personalized) AI and/or ML models, nor transferred to any third-party AI or ML tools. OpenPets' optional coding-tool integrations are separate features and never receive Google user data. OpenPets' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.