Security and privacy

Calendar availability without unnecessary exposure.

Synchronization needs access to the calendars you select, but it does not need to make their private details visible everywhere. ParallelCals is built around that boundary.

Security controls

You choose the connected calendars

Accounts and calendars are connected only after your provider authorization. You choose which calendars are included and can disconnect a provider account or request account deletion.

Private availability by default

The normal target event is a private busy block. Source notes and attendees are not copied. Limited title, location, or meeting-link context is an explicit per-rule choice.

Designed to avoid duplicate or looping events

ParallelCals records app-owned target events and sync-relevant hashes, so it can update or remove the right blocker and avoid treating its generated events as new sources.

Tokens remain server-side

Provider OAuth tokens are encrypted at rest and are not exposed to the browser. Server-side services use them only to provide the calendar features you configure.

Detailed policies and questions

The Privacy Policy explains the data categories, purposes, retention, deletion choices, and provider access in detail. The DPA describes the processor terms for business workspaces. This page describes product controls; it does not claim a certification or replace your own provider account-security practices.