Privacy

Privacy policy

Last updated: 11 August 2026

This policy explains how Caluminate uses personal information, including Google Calendar data, to provide Lilly’s personal timing and calendar-reading features.

Who is responsible

Caluminate, based in Ireland, is responsible for the application’s handling of your data. For privacy requests, use the email address at the end of this policy.

Google access and scopes

Caluminate currently requests https://www.googleapis.com/auth/calendar.readonly and https://www.googleapis.com/auth/calendar.app.created. The read-only scope lets Lilly retrieve the connected primary calendar, keep event timing fresh and produce diary-native personal readings. The app-created-calendar scope lets Caluminate create and manage a separate Google calendar called Caluminate for Lilly’s readings and approved moments.

Google authorisation does not let Caluminate change, move or delete events on your source calendar. You can hide or remove the separate Caluminate calendar in Google Calendar, and you can revoke access from Caluminate or your Google Account.

What Google Calendar data is read

Caluminate currently synchronises the primary Google calendar attached during connection and creates a separate Caluminate calendar for its own outputs. For ordinary diary intelligence, it retains only the minimum source-event identity, a sanitised title, start and end timing, all-day status, recurrence occurrence identity, status and timezone data needed for freshness and availability.

Caluminate does not retain Google event descriptions, attendee lists or event locations for ordinary diary intelligence. Declined and cancelled events are excluded. Private-event titles are replaced with a private-event label.

How the data is used

Event timing and sanitised titles are used to build bounded diary snapshots, understand the practical context around a date, generate personal astrological readings and prevent stale calendar context from being presented as current.

Deterministic code owns calendar identity, freshness, sanitisation, astronomical calculation and persistence. Calendar text is treated as untrusted data and cannot change system instructions or permissions.

AI processing and sharing

To compose a personal judgement, Caluminate processes a bounded task-specific projection containing the relevant calculated astrology, your active chart context and the sanitised calendar titles and times needed for that reading. Raw Google descriptions, attendee lists, Google credentials and unrestricted calendar history are not used for the reading payload.

Caluminate does not use Google Calendar data to train a shared model or to improve models for other users. Calendar context is used only to provide the visible Lilly reading and timing features you request.

Service providers used to operate Caluminate receive only the data needed for hosting, storage, account delivery, payment processing or requested reading generation. Payment processors do not receive Google Calendar content from Caluminate.

Human access

Humans do not routinely read your calendar content. If support or case review would require a person to inspect calendar content, Caluminate will first obtain your documented, specific consent. Access necessary for security, abuse investigation, legal obligations or maintaining the service is restricted to authorised operators and logged where applicable.

Storage and security

Application data is held in secure hosted infrastructure. Google access and refresh tokens are encrypted by the application using authenticated encryption before database storage. Access is restricted by application permissions and database row-level security, with privileged operational access limited to server-side functions and authorised administration.

No internet service can promise absolute security. Caluminate minimises retained calendar fields and separates provider context, personal chart data, issued judgements and operational credentials.

Retention

The Google event mirror is windowed around the period needed for current and forward readings. Bounded diary snapshots are configured to expire after 90 days. Issued readings retain minimal snapshot provenance and cited evidence rather than a permanent unrestricted copy of your diary.

Operational records may be retained for reliability, security, billing and legal obligations. Provider credentials are removed when the integration is revoked. Account deletion reaches calendar records, snapshots, personal readings and personal derived caches, subject to backup and legal-retention schedules.

Disconnecting and deletion

You can revoke the Google integration from the signed-in account area or from your Google Account permissions. Revocation clears stored Google access and refresh tokens and stops future synchronisation.

You may request account deletion or a copy of your data using the contact address below. Account deletion removes user-linked Google calendar data from the active application database. Deletion from time-limited backups follows the backup retention schedule.

Other account data

Caluminate may hold your email address, birth date, birth time, birth location, timezone, chart versions, subscription state, issued readings and operational logs needed to provide and secure the service. Payment providers process card details; Caluminate does not store complete card numbers.

Google API Services User Data Policy

Caluminate’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contact

For privacy, access or deletion requests, email info@caluminate.com.