Velprium (the “Service”) collects and uses personal data as described below, and this policy applies when you use the Service. This policy is written to match the actual data flows of the Service.
1. Information We Collect
- Google account information: email, name, profile image, and Google account unique identifier (for login, identification, and display).
- Google Calendar data: the list, names, and colors of the calendars you select; and the title, start/end time, description, and recurrence of events.
- In-app data: Page, Area, Calendar mappings, Event Properties, filter/display settings, and theme/preferences.
- Service usage information: login history, sync history, error logs, access IP (stored as a hash), User-Agent, and usage timestamps.
- Analytics data: anonymous usage statistics via Google Analytics (page views, approximate region, device/browser type) to improve the Service. Not used for personal identification or advertising.
2. Purposes of Use
- Providing Google login and identifying users and displaying profiles.
- Reading selected Google Calendar events and displaying them in the app’s Page / Area structure.
- Reflecting create/update/delete actions in the app to Google Calendar, only for calendars with two-way sync enabled.
- Saving Page / Area / Property settings.
- Error analysis and service stabilization, customer support, and security and abuse prevention.
3. Google User Data Use and Protection (Limited Use)
The Service retrieves Google Calendar data with your explicit consent. The retrieved Google Calendar data is used only to provide the features you request, such as displaying the calendar view, syncing events, and Page/Area-based event management.
The Service’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Google user data for advertising purposes.
- We do not sell Google user data to third parties.
- Humans do not read Google user data except where permitted, such as to provide a feature you specifically requested, for security, or for legal compliance.
- When you disconnect Google or delete your account, we delete the stored Google OAuth tokens and related sync data.
- We do not use raw or derived data received from Google users to develop, train, or improve generalized AI/ML models.
- When you use the AI analysis feature (Ask), your question and the retrieved calendar-derived data are sent to a third-party AI provider (OpenAI) via its API to generate a response, and request/response traces may be sent to Langfuse, an observability provider, to monitor and improve the feature. Data sent to these providers is not used to train their models, and we do not use any self-hosted AI models. If you do not use the AI feature, no data is sent to these providers.
4. Data Security
- Encryption in transit: all communication between the client and our server, and between our server and Google APIs, is encrypted with TLS (HTTPS).
- Encryption at rest: the database is encrypted at rest, and Google OAuth refresh tokens are additionally encrypted at the application level with AES-256. Tokens are never returned to the client, stored in the browser (such as localStorage), or written to logs.
- Access control: Row Level Security isolates data per user so that no one other than the authenticated owner can access it. Operator access follows the principle of least privilege and is limited to permitted purposes such as security and customer support.
- Monitoring and incident response: we monitor error and security logs and, in the event of a personal data breach, notify affected users and relevant authorities without undue delay as required by applicable law. We regularly apply security updates to dependencies and infrastructure.
5. Retention Period
- Member account information: until account withdrawal (account deletion).
- Google OAuth tokens: until Google is disconnected or the account is withdrawn.
- Google Calendar sync data: deleted upon disconnection or account withdrawal.
- Service usage logs: retained for a period for security and operational purposes, then deleted.
- Customer support inquiries: retained for a period after resolution.
6. Disclosure to Third Parties
Collected data is used solely to provide the Service and is not disclosed or sold to third parties except as required by law.
We use Google Analytics (Google LLC) to analyze service usage. The anonymous usage data it collects is processed under Google’s privacy policy, and we never send Google Calendar event content or OAuth tokens to Google Analytics.
To provide the AI analysis feature (Ask), we use the following sub-processors: OpenAI (response generation) and Langfuse (request/response observability). Data sent to each provider is not used to train models and is processed under each provider’s privacy policy. If you do not use the AI feature, no data is sent to these providers.
7. Your Rights
You may exercise the following rights at any time.
- Request access to, correction, deletion, or suspension of processing of your personal data.
- Disconnect Google Calendar (Settings > Google Calendar).
- Delete your account (Settings > Account > Delete Account).
- Export your data (Settings > Data, JSON).
For details, see the Data Deletion Guide.
8. Data Protection Officer and Contact
9. Effective Date
This policy takes effect on June 30, 2026. Any changes will be announced on this page.