Privacy Policy
Hora Calendar is a native macOS application for Google Calendar with optional Zoom and Microsoft Teams integration. Your privacy matters, so below is exactly what we access and how we use it.
Who We Are
Hora Calendar is provided by NA SERIO Maciej Szamowski, the controller responsible for the personal data described in this policy. For privacy-related inquiries, contact support@horacal.app.
Data We Access
- Google Calendar: events and calendars (read & write)
- Google Other Contacts: names and emails (read only, for guest autocomplete)
- Google account email address
- Zoom account profile basics (user info needed to identify connected account)
- Zoom meeting data for meetings created or managed from Hora (metadata such as meeting ID, join link, start link, passcode, schedule/status)
- Microsoft account profile basics (user info needed to identify connected account)
- Microsoft Teams meeting data for online meetings created or managed from Hora (metadata such as meeting ID, join link, schedule/status, and related online meeting details)
How We Use It
- Display and manage your calendar events
- Provide autocomplete suggestions when adding guests to events
- Synchronize changes with Google Calendar
- If you connect Zoom: create, update, read, and delete Zoom meetings when you choose Zoom as the conference provider
- Show Zoom meeting details in the app UI (join URL, meeting ID, passcode) for your own events
- If you connect Microsoft: create, update, read, and delete Microsoft Teams meetings when you choose Microsoft Teams as the conference provider
- Show Microsoft Teams meeting details in the app UI (join URL and meeting metadata) for your own events
Zoom OAuth Scopes and Purpose
For v1, Hora uses a minimal Zoom scope set required for meeting lifecycle only:
meeting:write:meeting: create Zoom meetings for events.meeting:update:meeting: update meeting details when event title/time changes.meeting:delete:meeting: delete/cancel Zoom meetings when events are removed.meeting:read:meeting: read meeting metadata needed to render and sync meeting details.user:read:user: read the authorized Zoom user profile to identify the connected Zoom account.
Hora does not request webinar scopes and does not use Zoom data for ad targeting, profiling, or model training.
Microsoft API Access and Purpose
Hora uses Microsoft APIs only when you connect a Microsoft account and choose Microsoft Teams as the conference provider. Requested permissions are limited to the meeting lifecycle and connected-account identification needed to create, update, read, and delete online meetings on your behalf.
Hora does not use Microsoft account, calendar, or Teams data for ad targeting, profiling, or model training.
Calendar Push Notifications
To keep your calendar current without polling Google every minute, Hora combines Google Calendar push notifications with Apple Push Notification service (APNs).
- Google's push notification carries no calendar data. The webhook receives an empty body and a header stating that something on a given resource changed.
- Our worker then wakes your Mac over APNs, and the app fetches the changed data directly from Google.
- No event, title, attendee, or description ever passes through our infrastructure.
What the worker does store, and we would rather say so plainly:
- Your Google account email address and OpenID subject identifier
- The APNs device token for your Mac
- The application bundle identifier
That is just enough to know which Mac to wake, and it is used for nothing else. Signing out in Hora Settings unregisters the device with the worker.
Data Storage
- App data is stored locally on your Mac using SwiftData
- OAuth tokens are stored in the macOS Keychain
- Hora does not operate a general-purpose backend that stores your calendar/meeting content
- OAuth callback infrastructure may transiently process authorization flow parameters required to complete sign-in securely
- This website uses Plausible Analytics, Google Analytics 4, and Google Ads conversion tracking as described below
Support Requests
When you submit the support form, PostHog Support processes the request as our support intake and triage provider. We use it to receive, investigate, and respond to support requests.
- The support request may contain your name, email address, message content, selected category, app and macOS version, troubleshooting steps, and—when you ask about a direct-purchase refund—an optional Paddle transaction ID and requested refund outcome.
- The browser stores a session and current support-ticket identifier in localStorage so a later request from the same browser can continue an active ticket or start a new one after resolution.
- The purpose is support handling, product diagnostics, and processing direct-purchase refund requests. We retain support data only for as long as needed to handle the request and meet legal, accounting, or claims obligations, then delete or anonymize it where appropriate.
- We also use PostHog Analytics for product and website measurement. This is separate from the support request workflow and may process the analytics events described in our product telemetry.
- To request access to or deletion of support data, contact support@horacal.app. We manually reply to support requests from this mailbox; replies are not synchronized back into the PostHog ticket.
Website Cookies & Advertising
The Hora Calendar macOS application does not set cookies or use advertising tracking. The marketing website at horacal.app uses a limited set of third-party technologies:
- Google Ads conversion tracking: when you arrive from a Google Ads click, Google's gtag.js may set first-party cookies (
_gcl_auand related) to measure whether you later complete newsletter signup. - Google Analytics 4 (GA4): aggregate site usage measurement (pageviews, referrers, device type). Consent Mode v2 is enabled.
You can opt out of Google Ads personalization at adssettings.google.com, or block these cookies in your browser.
Data Protection
- All communication with Google, Zoom, and Microsoft APIs is encrypted in transit via HTTPS (TLS)
- OAuth authentication tokens are stored in macOS Keychain (hardware-backed encryption, protected by your system login)
- Local cached data remains inside the macOS app sandbox
- Hora requests the minimum practical scopes required for enabled features
- Hora does not sell personal data and does not share user data with data brokers
- Hora does not use your calendar, Zoom, or Microsoft Teams data for advertising personalization
Data Sharing
- We do not sell your data
- We do not share your calendar, Zoom, or Microsoft Teams content with third parties, except API processors required to provide the service (Google, Zoom, and Microsoft)
- We do not use your app data for advertising or profiling
Data Retention & Deletion
- Data is retained locally on your device for as long as you use the application
- Sign out in Hora Settings to remove locally stored tokens and cached data
- You can disconnect providers at any time:
- Uninstalling Hora removes application data from your Mac
Contact
For privacy-related inquiries: support@horacal.app