Privacy Policy
Last updated: September 10, 2026
This policy explains what Aura Calendar ("Aura", "we", "us") collects, how we use it, and the choices you have. The short version: we store the data you give us so the calendar works, we don't sell your personal information, and you can delete your data any time.
1. What we collect
- Account information. When you sign up we store your name, email address, and a securely-hashed password (or your Google login identifier if you sign in with Google).
- Calendar data. Events, tags, notes, and schedule settings you create or import into Aura.
- Sharing data. The friends you connect to and the share permissions you give for calendars or individual events.
- Associate data. If you enable assistant actions, the messages you send the assistant and the actions it performs on your calendar.
- Google Calendar sync (only if you connect it). With your permission we securely store a token that lets Aura read your calendar and sync it into Aura. This is opt-in — we never access it unless you connect the sync.
- API keys (only if you create them). If you create an API key so an external agent (e.g. Claude, ChatGPT, Gemini) can access your calendar via MCP, we store a hashed reference to authenticate those requests.
2. How we use your data
- To operate and personalise the app — showing your calendar, events, tags, and shared calendars.
- To let the assistant read and update your calendar when you ask it to.
- To honour calendar and event sharing you set up between you and other Aura users.
- To sync your Google Calendar when you've connected it.
- To respond to support requests and keep the service secure.
3. What we don't do
- We do not sell or rent your personal data to anyone.
- We do not use your calendar contents for advertising.
- We do not read your Google Calendar or data unless you've connected the relevant feature.
- We do not show your calendar or events to other users except through shares you explicitly authorise.
4. Sharing with others
We only share your data when you choose to — for example, when you share a calendar or event with another Aura user. That person can only see what your chosen permission allows (view or edit), and only by exact-match — we never reveal partial matches or searchable listings of people to other users.
5. Where your data is stored
Aura runs on Cloudflare infrastructure and stores your data in a managed PostgreSQL database (Neon). Our infrastructure providers process data only to provide hosting, and we remain responsible for the security of the data you entrust to us. Your Google Calendar data stays within the scope of the permissions you grant and is not transferred beyond what the sync feature requires.
6. Security
- Passwords are stored as secure, salted hashes — never in plain text.
- API requests are authenticated with short-lived access tokens and refresh tokens.
- Google sync tokens are stored as secrets and used only to fetch your calendar.
- Connections are served over HTTPS.
7. Data retention & deletion
We keep your data only as long as your account exists, to provide the service. You can delete individual events at any time. If you want to delete your entire account and all associated data, contact us and we'll remove it, except where we're legally required to keep limited records. Deleting your account removes your events, tags, shares, and connected calendar tokens.
8. Cookies & local storage
Aura uses browser local storage to keep you signed in and to cache lightweight preferences. We don't use third-party advertising cookies.
9. Children
Aura is not directed to children under 13, and we do not knowingly collect information from them.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated date, and where appropriate we'll notify you in the app.
11. Contact
Questions about this policy or requests to delete your data? Contact us at support@sky-linking.com.