Privacy Policy

Last updated: August 11, 2026

This Privacy Policy describes how the UniCalen Android application ("UniCalen", "the app") handles information. UniCalen is a calendar and task management app that displays and edits data from the calendar services you choose to connect.

1. Data stored on your device

UniCalen stores calendars, events, tasks, task lists, sync statuses, settings and an in-app diagnostics log locally on your device in the app's private storage. This local data is used only to provide the app's features and is not uploaded to any server operated by the developer.

2. Accounts and credentials

When you connect an external calendar source, UniCalen stores the required credentials on your device only: OAuth tokens are kept in Android EncryptedSharedPreferences, and passwords for CalDAV connections (such as Yandex or Mail.ru app passwords) are stored in the same encrypted storage. Credentials are never sent anywhere except to the corresponding service you connected, and only to authenticate your requests.

3. Google user data

If you choose to connect a Google account directly, UniCalen requests the following Google OAuth scopes:

Google user data is used solely to provide these user-facing calendar and task features. UniCalen does not use Google user data for advertising, does not sell it, and does not share it with third parties. Google data is transferred only between your device and Google API servers.

UniCalen's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke UniCalen's access to your Google account at any time in your Google account permissions.

4. Security safeguards

UniCalen protects sensitive data with technical safeguards appropriate to the data it handles. OAuth access and refresh tokens, CalDAV passwords and Bitrix24 webhook credentials are encrypted at rest in Android EncryptedSharedPreferences. The storage uses AES-256-GCM encryption for values and an AES-256-GCM master key held by Android Keystore; preference keys use AES-256-SIV encryption. Calendar, event and task data is stored in the app's private Android storage, which is not accessible to other apps under normal Android app sandboxing.

Google OAuth, Google Calendar API and Google Tasks API communications use HTTPS with TLS. Authenticated CalDAV and Bitrix24 connections also use HTTPS with TLS. Sensitive credentials are sent only to the service you choose to connect and only to authenticate or complete your requested calendar or task operation. UniCalen does not operate a server that receives, stores or processes your Google user data, calendar data, tasks, OAuth tokens or passwords.

5. Other connected services

Depending on the sources you connect, UniCalen communicates directly from your device with the corresponding service: Google (Calendar API, Tasks API or iCal links), Yandex and Mail.ru (CalDAV or iCal), and Bitrix24 (API or webhook/iCal). The app exchanges only the calendar, event and task data needed for the features you use. Each service's own privacy policy applies to the data it processes.

6. Diagnostics and crash reports

UniCalen keeps a local diagnostics log and locally stored crash reports on your device to help troubleshoot synchronization, reminders and widgets. This information leaves your device only if you explicitly share it yourself (for example, through the system share sheet when contacting support). The app does not include third-party analytics, advertising SDKs or automatic crash-reporting services.

7. Data sharing

The developer does not receive, collect, sell or share your personal data. Information is exchanged only between your device and the calendar services you explicitly connect. If you email support, the contents of that email are used only to respond to your request.

8. Data retention and deletion

All app data resides on your device. You can delete individual events and tasks in the app, disconnect an account in the app settings, or uninstall the app to remove all local data. Revoking access at a connected service (for example, in Google account permissions) stops any further synchronization.

9. Children

UniCalen is not directed at children and does not knowingly collect personal information from children.

10. Changes to this policy

If this Privacy Policy changes, the updated version will be published at this URL with a revised "Last updated" date.

11. Contact

For questions about this policy or the app, contact: shumkiiv@gmail.com.