EditLog
Privacy Policy
How EditLog Calendar handles booking, reminder, and Google Calendar data.
Data We Process
- Telegram user identifiers, usernames, display names, and bot chat identifiers needed to operate the Mini App and bot notifications.
- Calendar schedules, booking links, booking requests, reminder requests, comments, and contact text submitted by users.
- Google user data described in the Google User Data Accessed section below when the owner connects Google Calendar.
Google User Data Accessed
- Google account email address from the Google identity response, used to show which account is connected.
- Google OAuth access token and refresh token, used by the backend to create and manage Google Calendar events requested by the user.
- Google Calendar event data for events created through EditLog, including event title, description, start time, end time, time zone, Google event ID, and Google event link.
- EditLog uses the Google Calendar Events permission to create events in the connected user's primary Google Calendar and to delete EditLog-created events when the user cancels or deletes them in EditLog.
- EditLog does not read, list, search, download, export, or store the user's existing Google Calendar events that were not created through EditLog.
Apple Calendar Data Accessed
- If the user connects Apple Calendar, EditLog stores the Apple ID email address entered by the user.
- EditLog stores an encrypted Apple app-specific password generated by the user for EditLog, not the user's primary Apple Account password.
- EditLog stores technical CalDAV URLs returned by iCloud Calendar, such as the calendar principal URL and calendar home URL, to keep the Apple Calendar connection working.
- Apple Calendar connection is used for calendar integration features requested by the user. EditLog does not ask users to enter their primary Apple Account password.
How We Use Data
- To create and manage bookings, reminders, and availability in the Telegram Mini App.
- To send Telegram notifications about booking and reminder actions.
- To create Google Calendar events for meetings and reminders explicitly created by the user.
How Google User Data Is Used
- Google account email is used only to display the connected calendar account to the user.
- Google OAuth tokens are used only by the EditLog backend to call Google Calendar APIs on behalf of the connected user.
- Google Calendar event IDs and links are stored only so EditLog can show the created event status and delete an EditLog-created event if the user cancels it.
- Google user data is not used for advertising, retargeting, credit decisions, data brokerage, AI model training, or any purpose unrelated to providing EditLog calendar features.
Sensitive Data Protection
- EditLog is served over HTTPS/TLS, including the OAuth callback, privacy policy, and Mini App pages.
- OAuth refresh tokens and access tokens are encrypted before being stored in the server database using application-level encryption with a server-side secret key.
- Apple app-specific passwords are encrypted before being stored in the server database using the same application-level encryption mechanism.
- OAuth state values are random, short-lived, and consumed once to reduce cross-site request forgery and replay risk during account connection.
- Server secrets, encryption keys, and OAuth client credentials are stored in environment configuration and are not exposed in the public Mini App frontend.
- Application logs are configured not to intentionally record Google OAuth access tokens, refresh tokens, or authorization codes.
- Database and server access are restricted to the application operator for maintenance, security, and support purposes.
Data Sharing
- EditLog does not sell user data.
- Data is shared with Telegram only as required to send bot messages and Mini App notifications.
- Google user data is shared with Google only through Google APIs when creating or deleting Google Calendar events requested by the user.
- EditLog does not transfer Google user data to third parties except when necessary to provide or improve user-facing EditLog features, comply with applicable law, or protect against security abuse.
- EditLog use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Retention And Deletion
- Booking, reminder, and calendar records are stored while needed to provide the service.
- Google OAuth tokens are stored while the Google Calendar integration remains connected and are deleted or made unusable when the integration is disconnected or access is revoked.
- Google Calendar event IDs and links for EditLog-created events are retained while related bookings, reminders, or manual events remain in EditLog.
- Users can request deletion using the instructions on the Data Deletion page.
- Users can also revoke EditLog's Google Calendar access at any time from their Google Account permissions page.
Contact
- For privacy questions, contact the EditLog owner through the Telegram bot @EditLog_bot.