Privacy Policy
Transparency and data protection are important to us.
1. Introduction
This Privacy Policy explains how CALinONE handles your data. CALinONE is an all-in-one calendar and shift-planning application developed and published by Igeling ("the Developer"). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller within the meaning of the GDPR is the Developer identified above. CALinONE stores all user data on your device. The only exception is the optional Share Calendar feature, which relays an end-to-end-encrypted copy of your shared entries through Google Firebase so that a person you connect with can view it (see section 3.7). Because this data is end-to-end encrypted, neither the Developer nor Google can read its content. Apart from this opt-in feature, the Developer does not have access to your personal data during use of the App.
3. Data We Process
3.1 Data Stored Locally on Your Device
All of the following data is stored exclusively on your device and is never transmitted to our servers (we do not operate any servers):
- Shift data: Shift entries, shift types, and shift rotations you create
- Leave data: Leave entries, leave types, and annual quotas
- Wage calculation data: Hourly rate, break times, bonus configurations, and calculated results
- App settings: Selected country and region, language preference, and display settings
- Home Assistant configuration: If you choose to use the Home Assistant integration, the webhook URL you provide is stored locally on your device. No access token is used
This data is stored using your device's local storage (Android SharedPreferences / iOS UserDefaults) and remains on your device at all times. It is not backed up to any cloud service by the App itself.
3.2 Purchase Data
When you purchase CALinONE Pro, the transaction is processed entirely by the app store you use (Google Play on Android, the Apple App Store on iOS). We store a purchase verification token locally on your device using your device's secure storage (Android Keystore / iOS Keychain) to verify your Pro status offline. This token is:
- Stored only on your device in encrypted form
- Used solely to verify your Pro purchase status
- Not transmitted to any server operated by us
We do not have access to your payment information, billing address, or Google account details. Please refer to Google's Privacy Policy for information on how Google processes purchase data.
3.3 Network Connectivity Status
The App monitors your device's network connectivity status solely to:
- Verify your Pro purchase status with Google Play when an internet connection becomes available
- Enable the optional Home Assistant synchronization feature
No data about your network usage, IP address, or browsing activity is collected or transmitted to us.
3.4 Home Assistant Integration (Optional, Pro Feature)
If you choose to enable the Home Assistant integration:
- Your schedule data is transmitted directly from your device to your own Home Assistant instance — exclusively to the webhook of the CALinONE integration; the app has no further access to Home Assistant
- This communication occurs exclusively between your device and your Home Assistant server
- No data passes through any servers operated by us
- You are the data controller for this data transfer, and you are responsible for the security of your Home Assistant instance
3.5 Data Exports (Optional, Pro Feature)
When you export data (CSV, PDF, or ICS files), the exported files are saved to a location you choose on your device. Exported files are not transmitted to any external server by the App.
3.6 Google Calendar Integration (Optional)
If you choose to connect CALinONE with Google Calendar:
- Authentication: You sign in with your Google account using Google Sign-In. CALinONE requests access only to your Google Calendar (calendar events scope) — no access to your email, contacts, or other Google services
- Data transfer: Your shift data (shift name, start and end times, and any notes) is transmitted from your device to your Google Calendar. This transfer is one-way only (App → Google Calendar). CALinONE does not read, modify, or delete any existing calendar entries
- Token storage: The Google OAuth token is stored locally on your device in encrypted form (Android Keystore). It is never transmitted to any server operated by us
- Revocation: You can disconnect the Google Calendar integration at any time in the app's settings. You can also revoke access at myaccount.google.com/permissions
- Google's data processing: When you use this feature, Google processes your data in accordance with Google's Privacy Policy. CALinONE has no control over how Google processes your data once it has been transferred to Google Calendar
3.7 Share Calendar / Colleague Calendar (Optional, Pro Feature)
If you connect with another person using the optional "Share calendar" feature, a copy of your shared entries is synchronised through Google Firebase (Cloud Firestore) so that the person you connect with can view it (read-only). The following applies:
- End-to-end encryption: Your shared entries are encrypted on your device (X25519 key exchange + AES-256-GCM) before it leaves the device. Firebase stores only the resulting ciphertext, a random non-identifying channel ID, a timestamp, and an anonymous owner identifier. Neither Google nor the Developer can read the content. The decryption key never leaves the devices; it is derived from the codes you and your colleague exchange.
- What is shared: By default only shift and leave entries within a rolling window (3 months back to 12 months ahead) — shift names, abbreviations, colours and times. Appointments (including their title/note, time, location and category) are only transferred if you explicitly enable this via a switch. Wages and personal identifiers are never shared.
- Anonymous authentication: The App signs in to Firebase using Firebase Anonymous Authentication. This creates a random, anonymous identifier with no personal data, used solely so that only your own device may overwrite or delete your own channel.
- Abuse protection: Firebase App Check (Play Integrity on Android, App Attest on iOS) protects the service against automated misuse. No additional personal data is collected for this.
- Deletion: When you revoke a connection in the App, your encrypted channel document is deleted from Firebase. Uninstalling the App stops further synchronisation.
- Processor: For this feature, Google acts as a processor and only ever handles encrypted content and connection metadata, in accordance with Firebase's Privacy and Security information and Google's Privacy Policy. The encrypted data is stored in Google's EU region (Frankfurt, Germany), so it is not transferred outside the EU (see section 10).
4. Data We Do NOT Collect
To be clear, CALinONE does not:
- Collect personal identification information (name, email, phone number)
- Use analytics or tracking services
- Display advertisements or share data with ad networks
- Transmit any data to servers operated by us
- Create user accounts or profiles containing personal data (the optional Share Calendar feature uses an anonymous Firebase identifier with no personal data — see section 3.7)
- Use cookies or similar tracking technologies
- Process data of children differently, as no personal data is collected from any user
- Access your contacts, camera, microphone, or location
The Google Calendar integration is entirely optional and is only activated if you explicitly choose to connect your Google account. No data is sent to Google without your active consent. The same applies to the optional Share Calendar feature (section 3.7): it is only activated when you explicitly connect with a colleague, and the data it relays is end-to-end encrypted, so its content is never readable by us or Google.
5. Legal Basis for Processing (Art. 6 GDPR)
Since all data processing occurs locally on your device and is initiated by your actions:
- Art. 6(1)(b) – Contractual necessity: Processing your shift and leave data is necessary to provide the core functionality of the App
- Art. 6(1)(a) – Consent: The optional Home Assistant integration and data export features are activated only by your explicit action
- Art. 6(1)(f) – Legitimate interest: Verifying Pro purchase status is necessary to provide the purchased features
6. Data Retention
All data is stored on your device for as long as the App is installed. You can delete all App data at any time by:
- Uninstalling the App (removes all data)
- Clearing the App's data through Android Settings > Apps > CALinONE > Storage > Clear Data
- Using the App's built-in backup/export features to manage your data
The encrypted purchase verification token is retained for the duration of your Pro subscription to enable offline verification. It is automatically deleted if your purchase is refunded and the verification grace period expires.
7. Data Sharing and Third Parties
We do not sell your data or share it with third parties for their own purposes. The third-party services involved are:
- Google Play Billing: Processes Pro upgrade purchases. Google's handling of your payment data is governed by Google's Privacy Policy.
- Google Calendar API: If you choose to use the Google Calendar integration, your shift data is transmitted to your Google Calendar. This is initiated only by your explicit action. See section 3.6 for details.
- Google Firebase (Cloud Firestore, Authentication, App Check): If you use the optional Share Calendar feature, your end-to-end-encrypted shared entries are relayed through Google Firebase so a connected person can view them. Google acts as a processor and only ever handles encrypted content. See section 3.7. Google's processing is governed by Firebase's Privacy and Security information.
8. Data Security
We implement appropriate technical measures to protect your data:
- Purchase tokens are encrypted using your device's secure storage (Android Keystore / iOS Keychain, AES-256)
- The Home Assistant webhook URL is stored in the App's private storage, inaccessible to other apps
- Google OAuth tokens and colleague-connection keys are stored in your device's secure storage (Android Keystore / iOS Keychain) and never transmitted to our servers
- Code obfuscation (R8/ProGuard) is applied to the release build to protect against reverse engineering
- Shared entries (Share Calendar feature) are end-to-end encrypted on your device using X25519 key exchange and AES-256-GCM before being relayed, so the server only ever stores ciphertext
- All data resides in the app-private storage sandbox of Android or iOS, which is protected by the operating system
9. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): All your data is stored locally on your device and is fully accessible to you within the App at all times
- Right to rectification (Art. 16): You can edit all data directly within the App
- Right to erasure (Art. 17): You can delete individual entries within the App or all data by clearing App storage or uninstalling
- Right to data portability (Art. 20): You can export your data in standard formats (CSV, PDF, ICS) using the App's export features
- Right to restriction of processing (Art. 18): Since all processing occurs locally on your device, you control all processing
- Right to object (Art. 21): You may stop all data processing by uninstalling the App
Since we do not collect or store your personal data on any server, most of these rights are inherently fulfilled by the App's local-only architecture. If you have any questions about exercising your rights, please contact us at the email address provided above.
10. International Data Transfers
Apart from the optional features you activate, CALinONE does not transfer your data to any server; all data remains on your device. Cross-border data flows can occur only through optional features: (a) the Share Calendar feature relays an end-to-end-encrypted copy of your shared entries through Google Firebase, where this (encrypted) data is stored in Google's EU region (Frankfurt, Germany) and is therefore not transferred outside the EU; and (b) connecting to a Home Assistant instance hosted outside your country. Both are entirely under your control. Google processes the encrypted data in accordance with Google's Privacy Policy. Although the data is stored in the EU, Google's parent company is based in the United States; for any potential access by the parent company, Google relies on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs). As the data is end-to-end encrypted, its content would remain unreadable in any case.
11. Children's Privacy
CALinONE is a workplace tool and is not directed at children under the age of 16. We do not knowingly collect personal data from children, as we do not collect personal data from any user.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this document. The current version is always available within the App and on our Google Play Store listing. We encourage you to review this Privacy Policy periodically.
13. Contact
If you have any questions or concerns about this Privacy Policy or CALinONE's data practices, please contact us at:
Email: support.shiftmate@gmail.com
14. Supervisory Authority
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory data protection authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.