Privacy Policy
- Who we are
- Local-first: what stays on your device
- Google Calendar integration
- What we collect if you sign in
- Cookies and local storage
- How we use information
- Disclosure to third parties
- Overseas disclosure
- Data retention and deletion
- Data security
- Access, correction and complaints
- Children's privacy
- Changes to this policy
- Contact us
1. Who we are
Agenda (the "Service"), a free day-by-day agenda app, is operated by Kazmaros Pty Ltd (ABN 71 695 478 721) of Queensland, Australia ("Agenda", "we", "us" or "our"). This policy is written to meet our obligations, and describe our practices, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), whether or not those obligations formally apply to a business of our size.
2. Local-first: what stays on your device
Agenda is built to work without an account. When you open the app and start typing, your days, blocks and Notes box are saved using your browser's own local storage โ processing happens with JavaScript running on your device. Unless you sign in (see below), your agenda:
- is never transmitted to any Agenda server;
- is never stored by us, in any form, anywhere; and
- is not visible to us โ we have no technical ability to see it.
You're welcome to inspect the source code, which is a static site with no hidden network calls beyond the Google Calendar integration described below. Signing in is the only other thing that changes this โ see the next sections.
3. Google Calendar integration
If you choose to connect a Google account (entirely optional โ the app works fully without
it), Agenda requests Google's calendar.events permission: enough to read your
events and move/edit them (so you can drag an event to a different day), but not enough to
manage your calendars themselves, change calendar sharing, or touch anything outside
events. You'll see Google's own sign-in and permission screen โ we never see your Google
password.
- The connection happens directly between your browser and Google's servers. Your Google access token is kept only in your browser's memory for that browsing session โ we never receive it, and it's never written to local storage or any server, so it's gone the moment you close or reload the tab (reconnecting is then one click).
- When you sync, the event titles, times and dates Google returns are copied into your local agenda, the same as any other block you type โ from that point on they're treated exactly like the rest of your local content described in section 2, including being included in cross-device sync if you're also signed in (see section 4).
- Disconnecting (or simply not reconnecting) stops any further access immediately โ there is nothing on our end to revoke, since we never held the token.
Google's own handling of your Calendar data is governed by Google's Privacy Policy, not this one.
4. What we collect if you sign in
Signing in is entirely optional, and only needed if you want the same agenda on more than one device. If you do, here's exactly what we collect and why:
| Information | Source | Why |
|---|---|---|
| Your email address | You, when requesting a sign-in link | To send you a one-time sign-in link and identify your account. We don't ask for or store a password. |
The content of your agenda โ day blocks, the Notes box, and settings,
including any events copied in via Google Calendar sync or .ics import |
Saved automatically from the app while you're signed in | So the same agenda appears when you sign in on another device. This is the entire purpose of the sync feature โ see section 9 for deleting it. |
| Standard web server/hosting logs โ e.g. IP address, browser and device type, pages requested, date/time | Automatically generated by our hosting/CDN provider whenever any page is requested | Security (e.g. detecting abuse of the sign-in system), diagnosing errors, and understanding aggregate traffic |
| Anything you email us directly โ e.g. your email address and message content | You, if you choose to contact us | Responding to your enquiry, bug report or feedback |
We do not run third-party analytics or advertising trackers on Agenda, and we never read, scan, analyse or use the content of your agenda for anything other than displaying it back to you.
5. Cookies and local storage
If you sign in, we set a single, strictly necessary session cookie so the
app knows you're signed in โ it's HttpOnly (invisible to page scripts) and
contains only a random session identifier, nothing else. We don't set any tracking,
advertising or analytics cookies. Your browser's own local storage holds
your agenda on your device (see section 2) and, if you sign in, a copy that's kept in sync
with our database โ you can clear either through your browser's settings, though clearing
local storage while signed out will remove agenda content you haven't backed up.
6. How we use information
We only use the information described in section 4 to:
- send you sign-in links and let you access your synced agenda;
- store and return your agenda content so it follows you between devices;
- operate, maintain and secure the Service;
- diagnose technical problems and improve performance; and
- respond to enquiries or support requests you send us.
We do not use any information we collect for direct marketing, and we do not sell, rent or trade personal information to anyone.
7. Disclosure to third parties
We don't share, sell or disclose personal information to third parties for their own use. A small number of service providers (sub-processors) process data on our behalf, solely to operate the Service:
- Cloudflare โ hosts the Service and, if you sign in, stores your account and agenda content in Cloudflare's D1 database;
- Resend โ delivers the sign-in link email to your inbox when you request one.
Separately, if you choose to connect it, Google provides the Calendar integration described in section 3 directly to your browser โ Google isn't a sub-processor of ours, since that connection never passes through our servers.
Neither Cloudflare nor Resend is authorised to use your data for their own purposes.
8. Overseas disclosure
Our hosting/CDN and email-delivery providers operate infrastructure in other countries, so the information in section 4 may be processed on servers located outside Australia as an ordinary part of running an internet service. We take reasonable steps to use reputable providers with appropriate security practices.
9. Data retention and deletion
If you've never signed in, we hold nothing to delete โ your agenda exists only in your browser, and clearing it is entirely up to you. If you have signed in, you can permanently delete your account and everything stored against it at any time from the account panel in the app ("Delete my account and synced data") โ this immediately and irreversibly removes your agenda content, your email address, and your active sessions from our database. You can also just ask us to do this for you โ see section 14.
10. Data security
The Service is served over HTTPS to protect data in transit. Sign-in uses one-time links rather than passwords, so there's no password of yours for a breach to expose. Session identifiers are random and cannot be guessed. You're responsible for the security of your own device, browser, and email account (since anyone with access to your email can request a sign-in link for your account).
11. Access, correction and complaints
If you've signed in, the agenda content visible in the app when you're signed in is the personal information we hold about you โ there's nothing hidden. You can access, correct or delete it at any time directly in the app. For anything else (like messages you've sent us), contact us using the details below.
If you believe we've mishandled your personal information, please contact us first so we can try to resolve it. If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
12. Children's privacy
Agenda is a general-purpose tool not directed at children, and we don't knowingly collect personal information from children. See also the age requirement in our Terms of Service.
13. Changes to this policy
We may update this policy from time to time โ for example, if we add a feature that changes what data is handled. The "Last updated" date at the top will always reflect the current version. Continuing to use the Service after an update means you accept the revised policy.
14. Contact us
Questions, feedback, a data deletion request, or a privacy complaint? Email us at contact@kazmaros.com.