Draft for review — not legal advice. This document is a working draft prepared for Dan Leitao / DPC Consulting to review (and to have reviewed by a qualified lawyer) before publication. It does not constitute legal advice.
Doba Cal — Privacy Policy
Effective date: [DATE]
Last updated: [DATE]
Who we are
Doba Cal (“Doba”, “we”, “us”) is a calendar app for Mac and iPhone, operated by DPC Consulting, a sole proprietorship of Dan Leitao based in Ontario, Canada.
For any privacy question or request, contact us at [email protected]. Dan Leitao is the person accountable for how Doba handles your personal information.
What this policy covers
This policy explains what personal information Doba collects, why, how we protect it, who we share it with, and the choices and rights you have. It applies to the Doba apps and the Doba backend service.
Doba has two tiers:
- Free tier runs entirely on your device: the calendar interface, sync with your connected calendars, invitees, and local alerts. It does not require a Doba account or our server.
- Paid tier adds server-backed features: real-time push alerts for surprise events, cross-calendar mirroring (busy-blocking), and instant multi-device sync. These features require a Doba account and our backend.
Information we collect
Account information. If you create a Doba account, we store your email address and name. If you use Sign in with Apple, we receive whatever Apple relays — which may be a private Apple relay email address rather than your real one. A Doba account exists to link your connected provider accounts and enable paid, server-backed features.
Provider OAuth tokens. When you connect a calendar provider (Google Calendar, iCloud/EventKit, later Outlook), we store the OAuth tokens that let Doba act on your behalf. On the server, these tokens are encrypted at rest in our database. They are deleted when you disconnect the provider and when you delete your account. For Google, we also revoke the tokens with Google on account deletion.
Calendar event data. To sync and mirror your calendars, Doba reads your events. On the server, this event data is processed transiently (held only long enough to do the work) and is not persisted. We do not store event titles, bodies, attendees, or notes on our server. What we do store is the mirror mapping: the minimal metadata that records which event blocks which (identifiers and time metadata), so busy-blocking stays consistent across your calendars. The mapping never contains the content of your events.
Subscription status. For the paid tier, we receive your subscription entitlement status (active, expired, etc.) via RevenueCat and Apple. We do not receive or store your payment card details — Apple handles payment.
Diagnostic and error logs. We may collect limited technical logs (for example, error traces and timestamps) to keep the service working and to diagnose problems. We keep these for a bounded period and avoid putting your calendar content in them.
Why we collect it (purposes)
We collect the above only to provide and operate the features you use: to display your schedule, to create and manage events and invitees when you ask, to deliver alerts, to mirror busy-time across your calendars, to sync across your devices, and to manage your subscription. We identify these purposes here so your consent is informed; connecting a provider or subscribing is how you consent to the related processing. You can withdraw consent by disconnecting a provider or deleting your account.
Google user data
This section describes how Doba handles data from Google APIs, in addition to everything above.
Doba’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google Calendar scopes we request
Doba asks only for the Google Calendar access its features need. Each scope enables specific things:
- calendar.readonly — read your calendars and events so Doba can display your schedule and de-duplicate mirror noise (recognising events that are already reflections of one another).
- calendar.events — create, edit, and delete events and manage invitees on your behalf, so features like one-tap join, RSVP, and event editing work.
- calendar.app.created — create and manage the busy-block / mirror events that Doba itself creates, without Doba touching the rest of your events.
Limited Use commitments
Our use of Google user data follows Google’s Limited Use requirements:
- We use Google user data only to provide and improve user-facing features that are prominent in Doba. We do not use it for advertising.
- We do not sell or transfer Google user data, and we do not transfer it to others except as needed to provide or improve these features, to comply with law, or as part of a merger or acquisition (with notice).
- No humans read your Google user data, except: with your explicit consent (for example, to help with a support issue you raise); where necessary for security purposes such as investigating abuse; to comply with applicable law; or for internal operations, and then only on data that has been aggregated and de-identified, as permitted.
- We do not use Google user data to train, develop, or improve any generalized or non-personalized AI/ML models.
Who processes your data (sub-processors)
We rely on a small number of service providers to run Doba. They process data only to provide their service to us:
- Railway — hosting and database for the Doba backend (where encrypted tokens and mirror mappings live).
- RevenueCat — subscription entitlement management.
- Apple — App Store distribution, in-app purchases, Sign in with Apple, and push notification delivery.
Some of these providers process data in the United States. Your information may therefore be stored or processed outside Canada and, while there, may be accessible to authorities under the laws of that country. Doba is operated from Canada, and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our handling of your personal information.
How we protect your data (safeguards)
- OAuth tokens are encrypted at rest in our database.
- Data in transit is protected with TLS.
- Access to production systems is restricted to those who need it to operate the service.
- We minimise what we store: no event content on the server, only the mirror mapping.
No system is perfectly secure, but we design Doba to hold as little of your data as possible and to protect what it does hold.
Keeping data accurate
Your account details come from you (or from Apple, via Sign in with Apple). You can update your name and email, and your calendar content stays under your control in your providers. If something we hold about you is wrong, contact us and we’ll correct it.
How long we keep data (retention)
- OAuth tokens are kept only while the provider is connected. Disconnecting the provider, or deleting your account, deletes them.
- Mirror mappings are kept only while the relevant mirror/busy-block relationship is active. They are removed when the mirror is removed or when you delete your account.
- Account records are kept while your account exists.
- Diagnostic/error logs are kept for a bounded period and then discarded.
Disconnecting vs. deleting your account
Disconnecting a provider stops Doba from accessing that provider and deletes the stored tokens for it, while leaving your Doba account and other connections intact.
Deleting your account (available in-app) removes your account record, all stored OAuth tokens, and all mirror mappings, and revokes your Google OAuth tokens with Google. Deletion is the complete off-switch for our server-side data about you.
Deleting your Doba account does not cancel your App Store subscription. Apple manages billing, so you must cancel the subscription separately in your Apple ID settings (see the Terms of Service, or Settings > Apple ID > Subscriptions). If you delete your account but leave the subscription active, Apple will keep billing you.
Children
Doba is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we’ll delete it.
International users
Doba is operated from Canada and is available in multiple regions, including the European Union, the United Kingdom, and the United States. As noted above, some processing happens in the United States. The sections below add region-specific detail.
For users in the EU, EEA, and UK (GDPR)
If you are in the European Union, the European Economic Area, or the United Kingdom, the GDPR (or UK GDPR) applies to our processing of your personal data. This section explains how.
Controller. The controller is DPC Consulting (Dan Leitao), Ontario, Canada. Contact: [email protected].
EU representative. Under Article 27 GDPR, our representative in the European Union is:
[EU REPRESENTATIVE NAME]
[EU REPRESENTATIVE ADDRESS]
You may contact the representative on any matter related to our processing of your personal data, in addition to or instead of contacting us directly.
Legal bases. We process your personal data on these bases:
- Consent(Art. 6(1)(a)) for access to your calendar data. You grant it through the provider’s authorization screen when you connect a calendar, and you can withdraw it at any time by disconnecting the provider or deleting your account. Withdrawal doesn’t affect the lawfulness of processing before it.
- Contract (Art. 6(1)(b)) for your Doba account, subscription entitlements, sync, mirroring, and alert delivery: the things you sign up for.
- Legitimate interest (Art. 6(1)(f)) for diagnostic and error logging and for securing the service. Our interest is keeping Doba working and safe; the logs are limited, time-bounded, and exclude your calendar content.
Your rights. You have the right to access your personal data, to have it rectified or erased, to receive it in a portable format, to restrict or object to processing, and to withdraw consent at any time. Deleting your account and disconnecting providers are self-service in the app; for anything else, email [email protected]and we’ll respond within the timelines the GDPR sets. You also have the right to lodge a complaint with your local supervisory authority.
International transfers. Your data is processed in Canada and the United States. Canada holds an EU adequacy decision covering commercial organizations subject to PIPEDA, which includes DPC Consulting. For processing in the United States (Railway, our hosting sub-processor), transfers rely on Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, as applicable to the provider.
Retention.The retention criteria in “How long we keep data” above apply to you: tokens while connected, mappings while a mirror is active, account records while the account exists, logs time-bounded.
Automated decision-making. Doba does not profile you and makes no automated decisions that produce legal or similarly significant effects.
For users in the United States
Doba does not sell or share your personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA), and it uses no personal information for cross-context behavioral advertising. We honor access, correction, and deletion requests from all users regardless of which state you live in or whether a state law’s thresholds apply to us. Some states grant privacy rights that cannot be waived; nothing in this policy limits them.
Your rights and how to exercise them
You can ask us to access, correct, or delete the personal information we hold about you, and you can ask questions about how we handle it. Many of these are also self-service: disconnect a provider or delete your account in-app at any time. For anything else (access requests, corrections, or concerns about our compliance), email [email protected]and we’ll respond. If you’re not satisfied with how we’ve handled a concern, you also have the right to raise it with the Office of the Privacy Commissioner of Canada.
Changes to this policy
We may update this policy. When we do, we’ll post the new version and update the effective date above. If the changes are material, we’ll give you notice in-app or by email.
Contact
DPC Consulting (Dan Leitao) — Ontario, Canada
[email protected]