Privacy Policy for Dash Calendar
Last updated: September 2026
Dash Calendar is an Android Automotive OS app that shows your Google and Microsoft (Outlook/Office 365) calendars, and calendars you subscribe to by URL (an iCalendar feed such as a Google, Outlook, or iCloud link), in your car. This policy explains what data is used and how. Dash Calendar is a personal project (not a company).
What data
- Your calendar data (events: title, time, location, attendees), read only.
- OAuth tokens that grant access to your Google/Microsoft calendar.
- For calendars you subscribe to by URL: the calendar's address (URL) you enter.
Where and how
- On your device: tokens and subscription URLs are stored encrypted on the car system. Calendar data is fetched directly from Google/Microsoft (or from the iCalendar URL you subscribed to) and only shown on screen.
- No server storage: calendar data and tokens are never stored on our servers.
- Pairing relay (digitalmountain.nl/dashcalendar): during pairing only a temporary authorization code (for Google/Microsoft) or the calendar URL you enter (for a subscription) is briefly passed through to link your phone back to the car. This value contains no calendar data, is deleted after a single use, and expires within 5 minutes. No tokens or calendar data are stored on the relay.
- No analytics, no ads, no sharing with third parties.
Data sharing, transfer, and disclosure
We do not sell, rent, share, transfer, or disclose your Google user data (or Microsoft data) to any third party.
- Your Google user data is transmitted only between your car and Google's own APIs, over an encrypted HTTPS connection, for the sole purpose of displaying your calendar to you.
- The pairing relay (digitalmountain.nl/dashcalendar) never receives, stores, or transmits any Google user data. It briefly passes a single-use OAuth authorization code (which contains no calendar content) to connect the phone sign-in back to the car.
- No advertising networks, analytics providers, data brokers, or other recipients receive your data. Data is not used to train any AI or machine-learning models.
- We may disclose data only if strictly required by law, or as needed to detect and prevent fraud, security, or technical issues.
Data protection and security
- In transit: all calendar requests and OAuth token exchanges use TLS/HTTPS encryption.
- At rest: OAuth tokens are stored encrypted on the car using Android's EncryptedSharedPreferences (AES-256), with encryption keys held in the Android Keystore.
- Minimal retention: calendar events are never persisted. They are held only in memory while shown on screen and discarded afterwards. No calendar data or tokens are stored on our servers.
- Pairing code: the temporary authorization code is single-use and expires within 5 minutes.
- Access control: access is strictly read-only, and you can revoke it at any time (see below).
Limited Use
Dash Calendar's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Access (scopes)
Dash Calendar requests read-only calendar access only (Google calendar.readonly, Microsoft Graph Calendars.Read). Calendars added by URL are public iCalendar feeds that are only read, never signed in to. Nothing is created, changed, or deleted in your calendar.
Revoking access
- In the app: Settings → Disconnect all removes the locally stored tokens.
- You can also revoke access anytime from your account: Google account access / Microsoft account access.