CalendHome collects only the data strictly necessary for the service to function:
Registration data: name (or nickname), emoji, chosen color, family role, administrator's email address
Authentication data: admin account password and family password (stored as hashes, never in plain text)
Usage data: calendar events (title, date, time, notes, participants)
Technical data: session tokens for authentication
We do not collect: geolocation data, contacts, photos, biometric data, payment data, or browsing/advertising tracking data.
3. Why We Collect Data
Personal data is processed exclusively for the following purposes:
Service provision: enabling the creation and management of the shared family calendar
Authentication: verifying user identity and protecting family access
Credential recovery: sending the family code to the registered email address
Service communications: technical notifications related to app functionality (admin alerts)
4. Legal Basis for Processing
The processing of personal data is based on:
Performance of a contract (Art. 6(1)(b) GDPR): processing is necessary to provide the service requested by the user
Consent (Art. 6(1)(a) GDPR): given by the user at the time of registration
5. How We Protect Your Data
We implement the following security measures:
Encrypted communications via HTTPS/TLS protocol
Passwords stored using bcrypt hashing (never in plain text)
Calendar events encrypted with XOR + SHA-256 algorithm before server transmission
Cryptographically generated session tokens with automatic expiration
Database access protected by credentials and limited to the application server only
6. Data Sharing
We do not share your data with third parties. Data is not sold, transferred, or shared with external parties for marketing, profiling, or any other purpose.
Data is stored on servers located in Italy (Aruba S.p.A. hosting) and is not transferred outside the European Economic Area (EEA).
7. Data Retention
Personal data is retained for as long as necessary to provide the service:
Account data: until the user deletes their account
Events: until deleted by the user or upon account deletion
Session tokens: 30 days from creation, then automatically removed
Upon account deletion, all personal data is permanently and irreversibly removed.
8. Your Rights (GDPR)
In accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Italian Privacy Code), you have the right to:
Access: obtain confirmation of whether your data exists and receive a copy
Rectification: correct inaccurate or incomplete data
Erasure: request deletion of your data ("right to be forgotten")
Restriction: request restriction of processing
Portability: receive your data in a structured, machine-readable format
Objection: object to the processing of your data
Withdraw consent: withdraw your consent at any time
Deletion is permanent and irreversible. The following will be removed: your member profile, all events you created, and if you are the last family member, the entire family and all associated data.
10. Minors
CalendHome is not intended for children under 13. We do not knowingly collect data from children under 13. If a parent or guardian discovers that a minor has provided data without consent, they can contact us to request its deletion.
11. Changes to This Policy
We reserve the right to update this Privacy Policy. In case of substantial changes, we will notify you through the app. The date of the last update is indicated at the top of this document.
12. Contacts and Complaints
For any questions regarding the processing of your data, contact us: