← Back to Home
AttendMate ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our mobile application, specifically regarding the Google Calendar Sync feature.
1. Information We Collect
AttendMate operates as a client-side only utility. All data is stored locally on your device in a secure private database. We collect:
- Timetable Schedules: Subject names, acronyms, and slot times created or imported by you.
- Google Account Information: Your Google profile email address, used strictly to authenticate and link the correct Google Calendar account.
2. How We Use Your Google Calendar Data
To enable the synchronization of your timetable with Google Calendar, the App requests permissions for the following OAuth scope:
https://www.googleapis.com/auth/calendar (read, write, and delete events on your Google Calendar).
We use this access exclusively for the following purposes:
- Creating events for your classes, timetables, and special lectures inside your selected Google Calendar.
- Automatically modifying, rescheduling, or deleting events in your Google Calendar to match modifications you make to your schedule inside the App.
- Excluding specific holiday dates and cancellations using iCalendar recurrence exclusion rules (
EXDATE).
3. Data Sharing & Third-Party Access
Your data is private. We do not share, sell, or rent your personal information, calendar events, or email address with any third parties.
- Local-First Architecture: The App does not have a backend server. Authentication credentials (OAuth tokens) are stored locally in secure local storage and are transmitted directly to Google's API endpoints.
- No data is uploaded to our servers or stored on any third-party infrastructure besides your own Google Calendar account.
4. Data Protection Mechanisms
We implement industry-standard security measures to safeguard your Google user data and prevent unauthorized access, alteration, or disclosure:
- Encryption in Transit: All data transmitted between the App and Google API servers (such as OAuth access tokens and calendar details) is fully encrypted in transit using secure HTTPS (SSL/TLS 1.2 or TLS 1.3) protocols.
- On-Device Encryption: Google OAuth credentials and authentication tokens are stored securely in Android's EncryptedSharedPreferences (backed by the hardware-level Android Keystore system), ensuring other apps on the device cannot access them.
- Application Sandboxing: The local SQLite database holding your timetables and sync preferences is kept in the App's isolated sandbox storage, protected by system-level Linux user ID separation on Android.
- No Server-Side Retention: The App does not utilize any remote server or database to store or transfer your credentials. Your Google user data remains local to your device and is only shared directly with Google's API endpoints.
5. Access Revocation and Data Deletion
You have full control over the App's access to your Google Account:
- You can log out/disconnect from Google Calendar at any time directly through the Settings screen in the App. This immediately purges all OAuth access and refresh tokens from your device.
- You can revoke the App's permissions at any time through your Google Account security dashboard under "Apps with access to your account."
6. Compliance with Google API Services User Data Policy
AttendMate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.