Privacy
Last updated October 8, 2026
OpenCal (opencal.link) shows your free time from your calendars on one link. Compound Labs runs it. Compound Labs is Isaiah Kim's independent product R&D lab. Email support@thecompound.tech with any question about your data.
What OpenCal reads from your calendars
OpenCal reads only whether your calendars are busy. It asks Google for free/busy times and asks Microsoft for each event's start, end and free/busy status. It asks iCloud for each event's start, end, repeat rule, status and free/busy setting. It never asks for event titles, descriptions, locations or guests. If iCloud sends more than OpenCal asked for, the server ignores it and stores none of it.
Busy times from Google, Microsoft and iCloud are read when someone opens your link or you open your own page. The server caches each read in memory and reuses it for at most one minute. After that minute it reads your calendars again. Each server instance keeps at most 500 cached reads and drops the oldest first. These busy times are never written to the database.
Busy times from Other calendars in Settings are stored in the database: from the browser extension, from a calendar read from your screen, and from a feed link. For each busy block, OpenCal stores only the start and end time, with no title or other details. These times are encrypted with AES-256-GCM before they are stored. A feed link is read when your page or link is opened, at most every 10 minutes. A screen read happens in your browser. The screenshot never leaves your browser and is never stored.
OpenCal reads busy times only to show your free times and to check that a time is still free before it is booked.
Your link and the shared view show only free time, never busy blocks.
What OpenCal stores
When you book someone's time
You must sign in to book. The person whose link you booked receives your name and the confirmed email address of the account you signed in with. The booking is stored with their account. It also records your OpenCal account and where the booking went on your side: your OpenCal bookings only, their invite, or an event on the calendar you chose. If you delete your account, the booking stays in their records without your account. If they add bookings to their calendar, Google or Microsoft sends you the invite from their calendar. OpenCal sends no email.
When you see times for both of you
If you sign in on someone else's link, the server compares both calendars and sends each person only the times you are both free. Neither person receives the other's busy times or events.
Who processes the data
- Cloudflare hosts the site and runs the server.
- Supabase hosts the database.
- Resend delivers messages from the contact form to our inbox.
- Google and Microsoft provide sign-in and the calendar data you allow.
- Apple provides the iCloud calendar data you allow.
- When you add a feed link, the server that hosts the feed receives a request from OpenCal's server each time the feed is read.
OpenCal does not sell your data, show ads, or use analytics or tracking cookies. It does not use your calendar data to train AI models.
Cookies and browser storage
opencal_sessionkeeps you signed in for up to 30 days.opencal_oauthholds the encrypted state of a sign-in for up to 10 minutes.- Your browser keeps three display choices in local storage:
opencal.dur(the meeting length),opencal.view(Week, 2 weeks or Month) andchipStep(the start-time step in the time menu). - The site's service worker keeps a copy of the site's styles, scripts, fonts and icons in your browser's Cache Storage, so the app opens when you are offline. It never stores pages, your calendar data or any other personal data.
Browser extension
OpenCal Sync is the Chrome and Edge extension. It adds busy times from Outlook on the web to your link.
- It reads your calendar only on outlook.office.com, outlook.office365.com and outlook.live.com, in your signed-in browser. It never asks for your Microsoft password.
- It keeps four things in the extension's local storage on your computer: your sync code, the server address, whether auto-sync is on, and the result of the last sync (its time, the number of busy times, the Outlook address and date range it read, and any error).
- It sends OpenCal only the start and end time of each busy block in the next 21 days, the date range it read, a name for the calendar (Outlook on the web, work or personal), and your sync code to identify you. Titles, people, places and notes stay in your browser.
- It sends nothing to anyone other than OpenCal.
- OpenCal stores those busy times as described under Other calendars above.
Google user data
OpenCal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. OpenCal uses Google calendar data only to show your free time, compare it with a signed-in visitor's free time, and add bookings to the calendar you choose. People never read your Google data, except when you ask for help and agree, for security purposes, or when the law requires it.
Removing access and deleting your data
- Disconnecting a Google account in Settings revokes OpenCal's access at Google and deletes the stored tokens.
- Microsoft has no way for an app to revoke its own access. Disconnecting a Microsoft account deletes the stored tokens. To remove OpenCal's access at Microsoft, open account.live.com/consent/Manage (personal accounts) or myapps.microsoft.com (work accounts).
- Disconnecting iCloud deletes the stored app-specific password. To turn the password off at Apple too, revoke it at account.apple.com.
- Deleting your account in Settings first cancels the Google or Outlook events of future bookings on your link, and that calendar tells the guests the meeting is canceled. It revokes OpenCal's access at Google. For Microsoft and iCloud, it deletes the stored tokens and password and shows you where to remove access. It then permanently deletes your account, connected accounts, tokens, sessions, sync code, synced calendars and their busy times, one-time links, profile, photo, old handles and the bookings on your link.
- Download your data in Settings to get a JSON file of your account and settings, connected accounts, synced calendars, bookings on your link, meetings you booked on other links, one-time links, the dates of your sync code, old handles and photo. It leaves out tokens, the app-specific password, the sync code, one-time link tokens and their hashes, and the full address of a feed link (it keeps the host).
- You can also email support@thecompound.tech to ask for a copy or for deletion.
Changes
If this policy changes, this page shows the new date.