TrevOS Calendar

Google user data

Privacy Policy

Effective August 1, 2026

TrevOS Calendar is a private, single-owner, read-only calendar integration. This policy explains the narrow data boundary used to provide its approved planning views.

Data accessed

TrevOS requests only permission to read Google Calendar events and the list of calendars available to the authorized account. It does not request Gmail, Contacts, Drive, Calendar write, event creation, event editing, event deletion, RSVP, attendee-management, or calendar-sharing permission.

How data is used

Calendar data is used only to provide the authorized owner's TrevOS Calendar, Home calendar summary, Daily Brief day shape and preparation context, and limited Command Center scheduling context. Retrieved Calendar text is treated as untrusted data and cannot expand TrevOS permissions or authorize actions.

Storage and protection

OAuth client credentials and refresh tokens are stored locally in macOS Keychain. They are not embedded in browser code or public files. TrevOS keeps a minimized, protected local calendar projection needed for its approved views.

The browser does not receive Google credentials, raw Google Calendar identifiers, attendee email addresses, conference credentials, attachments, or unbounded provider payloads.

Retention and deletion

The live projection refreshes approximately every 10 minutes and is marked stale after 20 minutes without a successful refresh. A protected last-safe projection may remain available for no more than 48 hours and is always identified as stale with its as-of time.

Privacy-safe refresh audit metadata is retained locally for up to 30 days, bounded to 500 records, and does not contain event content. Revoking Google access stops future collection. The owner can remove the local token and separately delete protected local Calendar caches through the TrevOS administrative process.

Sharing and sale

Calendar content and Google user data are not sold, used for advertising, or shared with third parties. Data remains within the owner's protected local TrevOS environment except for the direct read-only requests necessary to retrieve it from Google Calendar.

Revocation

The owner can revoke access from Google Account permissions. TrevOS then fails closed: it does not silently represent old data as current and becomes unavailable after the limited last-safe retention window.

Contact

Privacy questions may be sent to the developer-contact address shown on the Google OAuth consent screen.