Privacy policy
What CalMonkey collects, why, where it is kept and for how long. Written to be read: if something here is unclear, that is our mistake, and we would like to hear about it.
Last updated 8 October 2026
1. Who we are
CalMonkey is operated by Swixy Pty Ltd (ABN 78 663 420 086), Level 1, 1-3 Albert Street, Blackburn VIC 3130, Australia. In this policy “CalMonkey”, “we” and “us” mean that company.
CalMonkey is a service for software companies. A company (our “customer”) uses CalMonkey so that the people who use its product (“end users”) can connect a Google, Microsoft or Apple iCloud calendar to that product.
2. Three kinds of people, two roles
- Visitors and customers. If you visit this site, send us a contact request or hold a CalMonkey account, we decide how your information is used. This policy is the main statement of that.
- End users of a customer’s product. If you connected your calendar to an app that uses CalMonkey, we handle your calendar information on that app’s behalf and on its instructions. The app’s own privacy policy tells you how it uses your information. This policy tells you what CalMonkey does with it along the way.
- People invited to an event. If you are a guest on an event in a connected calendar, or an app that uses CalMonkey added you to an event, we handle your name, email address and reply as part of that event, on that app’s behalf and on its instructions. The invitation you receive is sent by the organiser’s calendar provider (Google or Microsoft), not by CalMonkey.
3. What we collect
When you send a contact request
Your email address, your company or product name, and what you tell us you are building. Nothing else is stored with the request: no IP address and no browser details.
When you use this site
The site sets no advertising or analytics cookies and loads no third-party trackers. Our servers keep standard request logs (time, address requested, IP address, browser type) to keep the service secure and working. These logs are kept for a short period and rotated, so older entries are overwritten as new requests arrive.
When you are a customer
- Account details: the name and email address your Google or Microsoft account shares when you sign in to the dashboard (we ask for nothing else, and never for access to your own calendar), the organisations you belong to and your role in them, and a record of changes made in the dashboard.
- Billing details: your billing contact, plan, invoices and the number of connected accounts. Payments are handled by our payment provider, Stripe. We do not see or store full card numbers.
- Your application’s settings: its name, redirect addresses, webhook addresses and credentials (secrets are stored encrypted).
- A log of your application’s API requests, with tokens, credentials, event text, guests’ names and email addresses, and meeting links removed, kept for 30 days (7 days on the Developer plan).
When an end user connects a calendar
- The calendar account’s identifier and email address, so the connection can be shown and recognised.
- The access credentials the provider issues (OAuth tokens), or for Apple iCloud the Apple ID email address and an app-specific password. These are stored encrypted.
- The list of the account’s calendars: names, identifiers, and whether each is read-only or the primary calendar.
- Events in those calendars from 42 days in the past to 201 days in the future: start and end, whether the time counts as busy, status, and the title, description and location. The title, description and location are stored encrypted.
- The people on those events: the names and email addresses of the organiser and of the guests, each guest’s reply to the invitation (accepted, declined, tentative or no answer), and the calendar owner’s own reply. The organiser and the guest list, with the replies, are stored encrypted.
- The meeting link of an event that has one (for example a Google Meet or Microsoft Teams address), stored encrypted.
- For events the customer’s app writes through CalMonkey: the content of those events, including the guests the app adds (names and email addresses), how the event repeats and whether it has a meeting link, and the identifiers that link them to the provider’s copy. This is stored encrypted like other event content.
We do not store attachments, email, contacts or files, and we do not ask the providers for access to them. Guests’ names and email addresses come only from the events themselves, never from an address book.
4. How we use it
We use calendar information only to provide the calendar connection the end user asked for:
- to show the customer’s app which calendars exist and when the user is busy;
- to create, change and delete the events the customer’s app asks us to write, including events that repeat;
- to put the guests the customer’s app names on those events, so that the user’s own calendar provider sends them the invitation, later updates and the cancellation, and to show the app who is invited to an event and how they replied;
- to ask the calendar provider to add its meeting link to an event when the customer’s app asks for one, and to pass that link to the app;
- to tell the customer’s app when something in a connected calendar has changed;
- to keep the connection working (refreshing access, retrying failed writes) and to find and fix faults.
We use customer and visitor information to run accounts, answer requests, send service notices, bill for the service, and keep the service secure.
Attendee names, email addresses and replies, and meeting links, are used only to provide that service. CalMonkey does not email guests itself, and does not use their details for marketing, contact lists or anything else.
We do not sell personal information. We do not use calendar information for advertising, for profiling, or to train machine-learning or AI models.
5. Google user data and Limited Use
Limited Use disclosure. CalMonkey’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, for data from a connected Google account:
- What we access. With your consent we request these permissions: view and edit events on your calendars (
calendar.events), see the list of your calendars (calendar.calendarlist.readonly), and your Google account’s identifier and email address (openid,email). Through the events permission we read and write your events with their times, text, guests (names, email addresses and replies) and meeting links. We request no other permissions. - What we use it for. Only to provide the calendar features of the app you connected: reading when you are busy, reading who is invited to your events and how they replied, writing that app’s events to your calendar (with the guests the app adds, whom Google then invites, and a Google Meet link when the app asks for one), and noticing changes.
- Who it goes to. Only the app you connected your calendar to, and the service provider that hosts CalMonkey (see sub-processors). We do not transfer or sell it to anyone else, including advertising platforms, data brokers or information resellers.
- Advertising. We never use it to serve advertisements, including retargeted, personalised or interest-based advertising.
- AI. We do not use it to develop, improve or train generalised or non-personalised artificial intelligence or machine-learning models.
- People. Nobody at CalMonkey reads it, unless we have your clear agreement for specific events, it is needed for security purposes such as investigating abuse, or it is needed to comply with applicable law. Event text, guest lists and meeting links are stored encrypted and are kept out of our logs.
- Removing it. Disconnecting the calendar in the app, or removing CalMonkey’s access in your Google Account, stops access. Disconnecting deletes the stored events and credentials as described under “How long we keep it”.
6. Microsoft and Apple data
We hold information from connected Microsoft and Apple iCloud accounts to the same rules as Google data above: used only to provide the calendar connection, never for advertising or model training, and shared only with the app you connected.
For Apple iCloud, Apple offers no permission screen for calendars, so the connection uses an app-specific password that you create in your Apple account. Apple does not limit such a password to calendars. CalMonkey uses it only to reach your calendars, stores it encrypted, and deletes it when you disconnect. You can revoke it at any time in your Apple account.
8. Where it is stored and how it is protected
CalMonkey’s servers, database and backups are in Amazon Web Services’ Sydney region, in Australia. Calendar information stays there. Our payment provider, Stripe, is based in the United States and receives customers’ billing details only; the sub-processors page describes what each provider receives.
Provider credentials, application secrets and event content (text, guest lists and meeting links) are encrypted at rest. API tokens are stored only as hashes. Each customer’s data is kept separate from every other customer’s. More detail is on the security page.
9. How long we keep it
| Information | Kept for |
|---|---|
| Events from connected calendars, with their guests, replies and meeting links | While the calendar is connected, and only within the window of 42 days back to 201 days ahead. Events that move out of the window are removed, and their guests, replies and meeting links with them. |
| Provider credentials, calendars and connection records | Until the connection is revoked. Stored events, with their guests, replies and meeting links, are deleted at once; credentials, calendars and the provider’s permission are removed within 24 hours. |
| API request log | 30 days (7 days on the Developer plan), then deleted automatically. |
| Webhook delivery records | 30 days. |
| Contact requests | Until you ask us to delete them, or 12 months after we receive them, whichever comes first. |
| Customer account and billing records | While the account is open, then as long as Australian tax and company law requires (7 years for billing records). |
| Server request logs | A short period: the logs are rotated and older entries are overwritten. |
| Backups | Backups are encrypted and kept for 30 days, so deleted data leaves the backups within 30 days. |
10. Your choices and rights
- Disconnect. End users can disconnect a calendar in the app they connected it to, or withdraw access at the provider (Google Account, Microsoft account or Apple account settings).
- See, correct or delete. You can ask for a copy of the personal information we hold about you, or for it to be corrected or deleted. If you are an end user, the quickest route is the app you connected; we will also help directly and involve that app where we need to.
- Guests. If your name and email address are on an event because you were invited to it, they are kept only as part of that event and for as long as the event is kept (see “How long we keep it”). You can ask the organiser, the app the event came from, or us, to see, correct or remove them.
- Contact requests. Email us and we will delete yours.
Write to privacy@calmonkey.com. We answer within 30 days. We handle personal information in line with the Australian Privacy Principles. If you are in the European Economic Area or the United Kingdom you also have the rights the GDPR gives you, including to object, to restrict processing and to data portability. To use any of these rights, write to the address above.
12. Children
CalMonkey is a service for businesses. It is not directed at children, and we do not knowingly collect information from them.
13. Changes to this policy
We will post changes here and change the date at the top. If a change materially affects how calendar information is used, we will tell customers by email before it takes effect.
14. Contact and complaints
Privacy questions and requests: privacy@calmonkey.com. Post: Swixy Pty Ltd, Level 1, 1-3 Albert Street, Blackburn VIC 3130, Australia.
If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to the data protection authority where you live.
