← bravely.dev

Privacy Policy — Calebar

Last updated: September 26, 2026 · Effective: September 26, 2026

Bravely Studios LLC (“we,” “our,” or “us”) makes Calebar, a Mac app that puts a calendar in your menu bar and shows the events on the day you pick. Calebar reads your calendars on your Mac, and your events stay there. This policy explains what Calebar reads, where it keeps it, and what leaves your Mac, when, and why.

The Short Version

Calebar reads your calendars so it can show your events in the menu bar. It only reads them: it never creates, changes, or deletes an event. Your events stay on your Mac, and we never receive them, whether they come from the calendars on your Mac or from a Google Calendar you connect. What leaves your Mac is your Bravely Account sign-in, your purchase state, the check for updates, and, if you connect Google Calendar, Calebar's requests to Google for your events. Calebar does not send usage analytics, crash reports, or diagnostic reports.

Calendars on Your Mac

Calebar shows events from the calendars in your Mac's Calendar app, including the accounts you have added to macOS, such as iCloud, Google, or Exchange, and calendars shared with you. It asks macOS for access to your calendars when you choose to show your events. macOS calls this full calendar access, but Calebar only reads. You can turn it off at any time in System Settings, under Privacy & Security › Calendars. For each event on the day you pick, Calebar uses the title, the start time, whether it lasts all day, the calendar's color, and the identifiers it needs to avoid showing the same event twice. It ignores notes, locations, attendees, and attachments. Settings lists your calendars by name and color so you can choose which ones to show, and Calebar saves those choices on your Mac. None of this is sent anywhere.

Google Calendar

Calebar 0.5.0 and later can also show events from your Google Calendar, if you choose to connect it. Earlier versions show only the calendars on your Mac. Signing in to your Bravely Account with Google is a separate thing: it does not give Calebar access to your calendar. Connecting. You connect Google Calendar in Calebar's Settings. Google's own page opens in your browser and asks whether to let Calebar see your calendars and events. Calebar asks for read-only access to your Google Calendar, and for your Google account's email address so that Settings can show which account is connected. It never asks for permission to change your calendar. What Calebar reads. First, your list of calendars: each calendar's identifier, name, and color, and whether it is your primary calendar or one you have chosen to show in Google Calendar. Then, from your primary calendar and the calendars you show, the events in the month you are looking at, plus two weeks on either side. For each event, Calebar reads the title, the start and end times, whether the event was cancelled, and its identifiers. It does not read descriptions, locations, attendees, attachments, or video-call links. How Calebar uses it. Only to show your events in the menu-bar calendar, merged with the events from your Mac's calendars so that an event that appears in both is shown once. Calebar never creates, changes, or deletes anything in your Google Calendar. Where it is kept. Calebar talks to Google directly from your Mac. Your Google sign-in, meaning the tokens Google issues to Calebar and your Google account's email address, is saved only in your Mac's login Keychain. It is never sent to us, and it is not synced to your other devices. Calebar keeps your Google events in memory while it runs, and fetches them again when you look at a day and they are more than five minutes old. It does not save them in files of its own. It fetches them through the web loading system built into macOS, which can keep a copy of Google's replies in Calebar's cache folder on your Mac (in your home folder, under Library › Caches › dev.bravely.calebar) until macOS clears it or you delete that folder. That copy stays on your Mac too. Sharing. Calebar does not send your Google data to us or to anyone else, and we never receive it, so no one at Bravely Studios can see your calendars or events. We do not sell it, use it for advertising, or use it to train AI models. Disconnecting. Disconnect, in Calebar's Settings, deletes your saved Google sign-in from the Keychain, clears the Google events Calebar holds in memory, and asks Google to revoke Calebar's access. You can also remove Calebar's access at any time from your Google Account at myaccount.google.com/permissions; Calebar then asks you to reconnect before it shows your Google events again. If you delete Calebar without disconnecting first, the saved sign-in stays in your Keychain until you delete it there, and removing Calebar's access in your Google Account makes it useless.

Google API Services User Data Policy

Calebar's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Calebar uses information from Google Calendar only to show you your own events in the app, and does not transfer it to anyone.

Google API Services User Data Policy

Remove Calebar’s access in your Google Account

Your Account and Purchase

Calebar requires a Bravely Account, which is covered by its own policy at bravely.dev/privacy/bravely-account. It is sold only as part of the Mac Utility Bundle. The purchase is made through our website checkout and processed by the payment provider named under Sub-processors; we store the minimum record needed to know that your account owns the bundle. We do not collect or store payment card details. When you sign in, Calebar sends our account service the app version and an installation identifier that Calebar creates on your Mac. After that, Calebar asks our account service what your account owns when it starts and when you come back to it. Our account service records events such as these: that you signed in and with which method, that a session was renewed or ended, that a checkout was started, and that a purchase was completed or refunded. Each record carries your Bravely Account identifier, the app and its version, the user agent your app or browser sent, and the country your connection comes from. Our account service sends these records to the analytics provider named under Sub-processors, and it checks what your account owns with the purchase-records provider named there. None of these records contains anything from your calendars or your Google account.

Analytics and Diagnostics

Calebar does not send usage analytics, crash reports, or diagnostic reports, and it has no report button, so there is no analytics setting to turn off. The records described under Your Account and Purchase and under Updates are made by our servers when Calebar signs in, checks your purchase, or downloads an update. They do not track what you do in the app.

Updates

Calebar checks our servers for a new version once a day and when you choose Check for Updates. That check tells us the version you are on and the usual information any download involves, such as your IP address. It does not carry anything about your calendars or events. When Calebar downloads an update, we record that the download happened, with the country your connection comes from, the user agent, and an anonymous download identifier, and we send that record to the analytics provider named under Sub-processors. If you turn on Get early-access updates in Settings, the same check also offers beta versions.

Data Retention

We never store your calendars or events. On your Mac, Calebar reads the events from your Mac's calendars each time it shows a day, and holds your Google events in memory until it quits or you disconnect, apart from any copy of Google's replies that macOS keeps in Calebar's cache folder, as described above. Your Google sign-in stays in your Keychain until you disconnect, and your calendar choices stay in Calebar's settings on your Mac. Purchase records are kept for as long as your account exists, plus whatever the law requires us to keep for tax and accounting. Account and download records are kept for as long as they are useful for understanding how the product is used and keeping it reliable. They never contain your calendars or events. Deleting your Bravely Account works as described in the Bravely Account policy and has no effect on the calendars and settings on your Mac, which were never ours.

Children's Privacy

Calebar is intended for adults. We do not knowingly collect personal information from children under 13, or under 16 in places where 16 is the relevant age for information-society services.

Your Privacy Rights

Depending on where you live, you have rights over the personal data we hold about you. We honor these rights for everyone who asks, regardless of where you live. • Access — ask what personal data we hold about you and get a copy. • Correction — ask us to fix data that is wrong or incomplete. • Deletion — ask us to delete your personal data by emailing privacy@bravely.dev from the address on your account. Where a product has a built-in Delete Account control you can use that instead; bravely.dev/delete-account explains what applies to each product. • Portability — ask for your data in a portable, machine-readable format. • Objection and restriction — ask us to stop or limit certain processing. • Withdraw consent — where we rely on consent (marketing email, optional analytics), you can withdraw it at any time without affecting processing that already happened. • Non-discrimination — we will not degrade your service or charge you more for exercising any of these rights. EEA and UK residents also have the right to lodge a complaint with your local supervisory authority. California residents may use an authorized agent; we may verify the agent's authority and confirm the request with you first. Other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect) have equivalent rights, including a right to appeal a denied request — reply to our decision email with "Appeal" and we will respond in writing within the period the law requires. Canadian residents have access, correction, and consent-withdrawal rights under PIPEDA; Australian residents have access and correction rights under the Australian Privacy Principles. To exercise any right, email privacy@bravely.dev. We respond within the timeframe the applicable law requires — generally 30 days under GDPR and 45 days under the CCPA, with an extension where the law permits one. We may need to verify your identity before acting, usually by confirming control of the email address on the account.

Legal Basis for Processing

If you are in the EEA or UK, we rely on these lawful bases under the GDPR and UK GDPR: • Performance of a contract — creating and securing your account, delivering the features you paid for, syncing your content, processing purchases, and providing support. • Legitimate interests — keeping the service secure and reliable, preventing fraud and abuse, understanding aggregate product usage, and improving the product. We balance these against your rights and do not use them to justify intrusive tracking. • Consent — marketing email, and optional analytics where a client offers a toggle. You can withdraw consent at any time. • Legal obligation — keeping tax, accounting, and consent records, and responding to lawful requests.

International Data Transfers

Bravely Studios LLC is a US company. We and our sub-processors process data in the United States and in other countries where they operate. For personal data originating in the EEA, UK, or Switzerland, we rely on appropriate transfer safeguards in our processor agreements — such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — where those safeguards are required. Email privacy@bravely.dev if you want more detail about the safeguards that apply to you.

California Notice at Collection

For California residents, the categories of personal information we collect for this product are: • Identifiers: your Bravely Account identifier, email address, and an installation identifier. • Commercial information: the record of your Mac Utility Bundle purchase and entitlement, and any refund. • Internet or other electronic network activity: records of sign-ins, purchase checks, checkouts, and update downloads, with the app version, the user agent, and an anonymous download identifier. • Coarse geolocation: a country-level signal derived from your network connection, used for consent rules and tax. We collect this from you, your device, and our own systems, and we use it to run the product, honor what you have bought, keep the service secure, and support you. We disclose it to the service providers listed under "Sub-processors," each for a business purpose under a written contract. We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA and CPRA, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for any purpose that would trigger the right to limit. If that ever changes we will update this policy and provide the required opt-out before the practice begins. Retention is described under "Data Retention" above and, for account-level data, in the Bravely Account privacy policy.

Sub-processors

We use the following service providers to run this product. They receive only what they need to perform their service for us, and each is bound by the data-processing terms that apply to our use of their service. Where a provider is not yet covered by a written data-processing agreement with us, its entry below says so. If you need a data-processing agreement in place before you use this product, email privacy@bravely.dev: • Cloudflare, Inc.: hosting for bravely.dev, the update and download service, and the account and purchase services the app talks to. See cloudflare.com/privacypolicy. • Google LLC: Firebase Authentication, which backs Bravely Account sign-in (including Sign in with Google). See policies.google.com/privacy. • Apple Inc.: Sign in with Apple, when you choose that sign-in method. See apple.com/legal/privacy. • Paddle.com Market Ltd: our merchant of record for the Mac Utility Bundle purchase. Paddle handles checkout, payment processing, invoicing, and sales tax/VAT. See paddle.com/legal/privacy. • RevenueCat, Inc.: holds our record of what each Bravely Account owns. When Calebar checks your purchase, our account service looks up your Bravely Account identifier there, and when you buy the bundle it records the purchase there with your account identifier, the app you bought it from, and the date of your first purchase. See revenuecat.com/privacy. • PostHog Inc.: product analytics, receiving the account, purchase, and update-download records described above. Calebar itself sends it nothing. See posthog.com/privacy. • Resend Inc.: sends our transactional email (sign-in links, email confirmations, password emails, and the download links we send after a purchase). See resend.com/legal/privacy-policy. • Google LLC, a second time: the Google Calendar API, only if you connect your Google Calendar in Calebar 0.5.0 or later. Here Google is not processing data for us. It is your own Google account, which Calebar reads directly from your Mac, and nothing from it passes through our servers. See policies.google.com/privacy. If we add or change a sub-processor in a way that materially changes how your data is processed, we will update this policy and give additional notice where the law or our data-processing commitments require it.

Security

We protect your data with authenticated accounts, encryption in transit, access controls on our backend systems, and a deliberately small number of people who can reach production. No system is perfectly secure, and we do not claim guarantees we have not built and verified. Where a product makes a specific security claim, that claim appears in the app-specific sections above and is limited to what we have actually shipped. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators as required by law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change — a new category of data, a new sub-processor, a new purpose, or a new legal basis — we will update the "Last updated" and "Effective" dates and give additional notice where the law requires it. Where a change requires fresh consent under the GDPR, UK GDPR, CASL, or a similar regime, we will ask for it before relying on the new purpose. Non-material changes (typos, clarifications, link fixes) are reflected by updating the "Last updated" date.

How to Contact Us

Bravely Studios LLC Privacy and data rights: privacy@bravely.dev Product support: support@bravely.dev Website: https://bravely.dev Postal address: available on request to privacy@bravely.dev.