EditLog

Privacy Policy

How EditLog Calendar handles booking, reminder, and Google Calendar data.

Data We Process

  • Telegram user identifiers, usernames, display names, and bot chat identifiers needed to operate the Mini App and bot notifications.
  • Calendar schedules, booking links, booking requests, reminder requests, comments, and contact text submitted by users.
  • Google user data described in the Google User Data Accessed section below when the owner connects Google Calendar.

Google User Data Accessed

  • Google account email address from the Google identity response, used to show which account is connected.
  • Google OAuth access token and refresh token, used by the backend to create and manage Google Calendar events requested by the user.
  • Google Calendar event data for events created through EditLog, including event title, description, start time, end time, time zone, Google event ID, and Google event link.
  • EditLog uses the Google Calendar Events permission to create events in the connected user's primary Google Calendar and to delete EditLog-created events when the user cancels or deletes them in EditLog.
  • EditLog does not read, list, search, download, export, or store the user's existing Google Calendar events that were not created through EditLog.

Apple Calendar Data Accessed

  • If the user connects Apple Calendar, EditLog stores the Apple ID email address entered by the user.
  • EditLog stores an encrypted Apple app-specific password generated by the user for EditLog, not the user's primary Apple Account password.
  • EditLog stores technical CalDAV URLs returned by iCloud Calendar, such as the calendar principal URL and calendar home URL, to keep the Apple Calendar connection working.
  • Apple Calendar connection is used for calendar integration features requested by the user. EditLog does not ask users to enter their primary Apple Account password.

How We Use Data

  • To create and manage bookings, reminders, and availability in the Telegram Mini App.
  • To send Telegram notifications about booking and reminder actions.
  • To create Google Calendar events for meetings and reminders explicitly created by the user.

How Google User Data Is Used

  • Google account email is used only to display the connected calendar account to the user.
  • Google OAuth tokens are used only by the EditLog backend to call Google Calendar APIs on behalf of the connected user.
  • Google Calendar event IDs and links are stored only so EditLog can show the created event status and delete an EditLog-created event if the user cancels it.
  • Google user data is not used for advertising, retargeting, credit decisions, data brokerage, AI model training, or any purpose unrelated to providing EditLog calendar features.

Sensitive Data Protection

  • EditLog is served over HTTPS/TLS, including the OAuth callback, privacy policy, and Mini App pages.
  • OAuth refresh tokens and access tokens are encrypted before being stored in the server database using application-level encryption with a server-side secret key.
  • Apple app-specific passwords are encrypted before being stored in the server database using the same application-level encryption mechanism.
  • OAuth state values are random, short-lived, and consumed once to reduce cross-site request forgery and replay risk during account connection.
  • Server secrets, encryption keys, and OAuth client credentials are stored in environment configuration and are not exposed in the public Mini App frontend.
  • Application logs are configured not to intentionally record Google OAuth access tokens, refresh tokens, or authorization codes.
  • Database and server access are restricted to the application operator for maintenance, security, and support purposes.

Data Sharing

  • EditLog does not sell user data.
  • Data is shared with Telegram only as required to send bot messages and Mini App notifications.
  • Google user data is shared with Google only through Google APIs when creating or deleting Google Calendar events requested by the user.
  • EditLog does not transfer Google user data to third parties except when necessary to provide or improve user-facing EditLog features, comply with applicable law, or protect against security abuse.
  • EditLog use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention And Deletion

  • Booking, reminder, and calendar records are stored while needed to provide the service.
  • Google OAuth tokens are stored while the Google Calendar integration remains connected and are deleted or made unusable when the integration is disconnected or access is revoked.
  • Google Calendar event IDs and links for EditLog-created events are retained while related bookings, reminders, or manual events remain in EditLog.
  • Users can request deletion using the instructions on the Data Deletion page.
  • Users can also revoke EditLog's Google Calendar access at any time from their Google Account permissions page.

Contact

  • For privacy questions, contact the EditLog owner through the Telegram bot @EditLog_bot.