Your data
Privacy policy
Last updated:
This policy describes the Tor Event Calendar web service and its calendar API and remote MCP connections. The service is operated by Yurii Tor. For privacy questions or requests, email yurii.tor@bofh.od.ua.
Information we handle
- Account and sign-in. If you sign in with Google, we receive your Google account identifier, verified email address, and available basic profile details such as your name and picture through the
openid email profilescopes. We do not request access to Google Calendar, Gmail, or Drive. If you use an email sign-in link, we use the address you enter to send that link. Authentication records can include provider account details, session tokens, IP address, user agent, and sign-in timestamps. - Your calendar. We store the events, dates, custom fields, publication planning details, and files you choose to save. File metadata is stored with your calendar records; file contents are stored separately in private storage.
- Connections and service activity. We store the client details, scopes, approvals, token records, and usage timestamps needed for API, local AI, and remote MCP connections. Technical logs and rate-limit records help operate and protect the service.
- Browser storage. A secure cookie keeps you signed in. Your browser can also keep your theme choice and temporary state used to recover an unfinished manual publication receipt.
How we use information
We use account information to sign you in and keep calendars separate; calendar information to show, edit, and retrieve the content you save; connection information to honor the permissions you grant and allow revocation; and technical information to maintain reliability and prevent abuse. Google sign-in is used for identity only. Calendar actions do not automatically publish or schedule social posts.
We do not sell personal information or use calendar content for advertising. If you authorize an AI client, it can receive your account identity and the calendar content it requests within the permissions you approve. The AI client is responsible for its own handling of information it receives.
Providers and disclosures
Cloudflare runs the Worker and provides the D1 database, private KV file storage, and operational logs. Google provides the optional sign-in flow. Resend delivers one-time email sign-in links. We share information with these providers as needed for those functions. We also disclose requested calendar information to an API or AI client only when you authorize that connection. Provider infrastructure may process information in more than one country; contact us for details relevant to your data.
Storage, retention, and deletion
Browser sessions are configured to expire after 30 days and email sign-in links after 15 minutes. Remote MCP access tokens expire after 15 minutes and refresh tokens after 30 days. Expiration or revocation prevents further use of a credential, but does not itself remove all related database or log records.
Calendar information remains while your account uses the service. Deleting an event hides it from normal access and starts cleanup of related files; the event record is marked deleted rather than immediately removed from the database. Operational records, backups, and provider logs may remain after a deletion or connection revocation. We do not currently offer an in-app account deletion button or promise a fixed deletion period for every record. Email us to request a copy, correction, or erasure of your account data, and we will review the request under applicable law.
Your choices
You can edit or delete your events in the calendar and revoke API or remote MCP connections in “Connections & tokens.” You can stop using Google sign-in or remove the app from your Google account; that does not automatically erase data already held by this service. Contact yurii.tor@bofh.od.ua to request access, correction, deletion, or information about other privacy rights that apply to you.
Security and changes
The service uses HTTPS, account-scoped access checks, secure session cookies, and private file storage. No online service can guarantee absolute security. If this policy changes, we will update this page and its “Last updated” date. Material changes to how Google account data is used will be disclosed before that new use.
This page covers the Tor Event Calendar service. A separate AI application or local client that you choose to connect may have its own privacy policy.