Privacy Policy
Effective date: July 28, 2026
CallCal helps users turn call schedules into reviewed Google Calendar events. This policy explains what information CallCal collects, how it is used, with whom it is shared, how it is protected, and the choices you have.
Information We Collect
When you use CallCal, we may collect your account email and profile name from Firebase Authentication / Google Sign-In, uploaded schedule files, extracted schedule entries, generated calendar event drafts, billing and subscription status, and basic technical logs needed to operate and debug the service.
If you connect Google Calendar, CallCal accesses Google user data needed to provide the service, including your Google account identity (such as email and name), the list of calendars you can write to, and calendar event data CallCal creates or updates at your request. CallCal stores Google OAuth tokens server-side so it can list writable calendars and create or delete events only when you request those actions.
How We Use Information
We use uploaded schedules to extract dates, names, and shift information, generate event drafts, and create Google Calendar events after you review and approve them. We use Google Calendar access only to list calendars, create approved events, and delete events created by CallCal if you use the undo feature.
We use Google user data only to provide or improve user-facing CallCal features that are visible in the product. We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use Google user data (including Google Workspace / Calendar API data) to develop, improve, or train generalized or non-personalized AI / ML models.
Google API Data
CallCal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. CallCal does not sell Google user data, use Google user data for advertising, or allow humans to read Google user data except when necessary for security, legal compliance, or user-requested support.
Sharing, Transfer, And Disclosure Of Google User Data
CallCal does not sell Google user data. We do not transfer or disclose Google user data to third parties for advertising, data brokerage, credit, lending, or unrelated commercial purposes. We share, transfer, or disclose Google user data only as follows:
- Google (Calendar and identity APIs): We send calendar create, update, and delete requests to Google on your behalf after you review and approve them, using the Google account and calendars you connect.
- Google Cloud / Firebase (our processors): Account data, OAuth tokens, schedule imports, drafts, and related service data are stored and processed on Google Cloud / Firebase infrastructure that hosts CallCal (including Authentication, Firestore, and Cloud Storage).
- Service providers that help operate CallCal: We may share limited account or operational data with vendors that provide hosting, email delivery, payments (for example Stripe for billing), or similar infrastructure, solely to provide or improve CallCal. We do not send Google Calendar contents or Google OAuth tokens to advertising platforms.
- Legal and safety: We may disclose information if required by law, legal process, or to protect the rights, safety, or security of users, CallCal, or others.
- Business transfers: If CallCal is involved in a merger, acquisition, or sale of assets, Google user data may be transferred as part of that transaction, subject to this policy and applicable law.
Uploaded schedule files that you provide (PDFs, photos, pasted text, or email forwards) may be processed by our AI extraction provider to generate event drafts. That processing uses the schedule content you upload; it is not a transfer of your Google Calendar contents for advertising or model training unrelated to providing CallCal.
Data Protection And Security
We use administrative, technical, and organizational safeguards to protect Google user data and other sensitive account information. These include:
- Encryption in transit using HTTPS / TLS for data exchanged between your device, CallCal, and Google APIs.
- Encryption at rest for data stored in Google Cloud / Firebase services used by CallCal.
- Server-side storage of Google OAuth tokens, with access limited to authenticated backend processes needed to perform calendar actions you request.
- Access controls, authentication, and least-privilege practices so that human access to Google user data is restricted to cases needed for security, legal compliance, or user-requested support.
- Security procedures intended to protect the confidentiality and integrity of your information and to reduce unauthorized access, use, or disclosure.
No method of transmission or storage is completely secure. If we become aware of a security incident that affects your personal information, we will take steps consistent with applicable law.
Retention And Deletion
We retain uploaded schedules, extracted entries, drafts, created-event records, and related account data for as long as needed to provide CallCal, maintain your account, meet legal obligations, or resolve disputes. When data is no longer needed for those purposes, we delete or destroy it, or de-identify it where appropriate.
You may request deletion of your CallCal account data by contacting us at the email below. You can also revoke Google Calendar access from your Google Account permissions at any time.
Your Choices
You can choose not to connect Google Calendar. You can revoke Google Calendar access from your Google Account permissions at any time. You may request deletion of your CallCal account data by contacting us.
Important Safety Note
CallCal is for schedules only. Do not upload patient information, clinical notes, medical records, or documents containing protected health information.
Contact
For privacy questions or data deletion requests, contact bryan@benchmark.care.