Privacy Policy
Canary is a project and client management application operated by Canary. This policy explains what data Canary holds, why it holds it, and how to have it removed. It covers the Google Calendar integration in particular, because that feature accesses data held in your Google Account.
Who this policy is for
Canary is a business tool used by staff of the organisation that operates it and by client contacts invited into the support portal. Accounts are created by an administrator; Canary is not offered for public self-service sign-up.
What Canary stores about you
- Account details — your name, email address, and a hashed password. Passwords are stored only as Argon2 hashes and are never recoverable in plain text.
- Work content — the projects, tasks, clients, documents, tickets, and comments you create or are assigned to inside the application.
- Operational records — session records and an audit log of significant actions (sign-ins, record changes, integration changes), used for security and accountability.
Google Calendar integration
Connecting a Google account is entirely optional. Canary works fully without it, and you can disconnect at any time. Nothing below applies unless you complete the Google consent screen yourself.
Permissions Canary requests
- See and download any calendar you can access using your Google Calendar (
calendar.readonly) — used to show your existing Google events alongside your Canary work on the Calendar page. This permission is read-only: Canary cannot create, change, or delete anything on your own calendars. - Make secondary Google calendars, and see, create, change and delete events on them (
calendar.app.created) — used only if you switch on export. Canary creates one separate calendar named Canary and writes your Canary dates to it. This permission is deliberately narrow: it grants access only to calendars Canary itself created, so Canary is technically incapable of writing to or deleting your personal calendars. - Your email address and basic profile (
openid,email,profile) — used to label the connection in your profile so you can tell multiple connected accounts apart.
What is imported and stored
For each calendar you leave enabled, Canary caches the events in a rolling window of roughly 30 days in the past to 12 months ahead. For each event it stores the title, description, location, start and end times, all-day flag, and status, along with the original event record returned by Google, which may include organiser and attendee details. This cache exists so the Calendar page loads quickly without calling Google on every request; Google remains the source of truth, and Canary refreshes the cache roughly every 15 minutes.
You choose which calendars are imported. Every calendar on the account is enabled by default and can be switched off individually under Profile → Connected calendars. Switching one off deletes its cached events from Canary immediately.
What is exported
If you switch on Push my Canary dates to Google, Canary writes all-day events to the Canary calendar it created, covering the due dates of tasks assigned to you and the phases of projects you are a member of. Only your own items are exported. Switching the option off, or disconnecting, removes those events again.
How access tokens are protected
The OAuth access and refresh tokens Google issues are encrypted at rest with AES-256-GCM using a key held in the server's configuration, not in the database. They are used only to call the Google Calendar API on your behalf.
Limited Use
Canary's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google Calendar data is used only to provide the calendar features described above and is never sold, never used for advertising or profiling, never used to train machine learning or AI models, and never transferred to third parties except as needed to run the service or where required by law.
Who else sees your data
Canary does not sell personal data. Google Calendar data imported into Canary is visible only to you — it is not shared with your colleagues or shown on shared views. Data is processed by the hosting and infrastructure providers used to run this deployment, and by Google when calling the Calendar API at your request.
Retention and deletion
- Disconnect a calendar — go to Profile → Connected calendars and choose Disconnect. Canary removes the events it pushed to Google, revokes its tokens with Google, and deletes the stored tokens and all cached events for that account.
- Revoke from Google's side — you can also remove Canary's access at myaccount.google.com/permissions. Canary detects this on its next sync and stops holding usable tokens.
- Delete your account — contact your administrator or write to us at the address below. Removing an account deletes its calendar connections and cached events along with it.
Work content you created is retained by the operating organisation for as long as it is needed for its business records, independently of your account.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data, and to object to or restrict its processing. Write to us and we will respond.
Changes
If this policy changes in a way that materially affects how your data is handled, the updated date below will change and, where the change is significant, you will be notified in the application.
Contact
Questions or requests about this policy, or about data held by Canary, can be sent to antejunior2003@gmail.com.