01 — 収集

What we collect.

TL;DR

The minimum to run the service. We don't sell it. Traffic to the hosted service is encrypted in transit, access to stored data is restricted, and Musubi is open source if you prefer to host it yourself.

Account information

When you create an account we collect your email address, the display name you choose, and an optional profile picture. If you sign in with Google, we receive your name, email address, and profile picture from your Google account.

Newsletter

If you join the newsletter, we collect the email address you submit so we can send you early access invitations and occasional product news. This is separate from your Musubi account, optional, and you can unsubscribe from every message.

Calendar data

Event titles, dates, times, locations, links, notes, recurrence, and attendance you enter into Musubi — and events synced from calendars you connect — are stored on our servers. This is what makes sharing and cross-provider sync possible; the trade-off is that Musubi is not end-to-end encrypted, and we say so plainly rather than promise otherwise.

Usage data

The mobile app does not currently collect automatic usage analytics or crash reports. We plan to introduce self-hosted, open-source monitoring in the future and will update this policy before automatic collection begins.

Technical and support information

Authentication sessions may record an IP address and user-agent string for account security and abuse prevention. If you choose Report a Problem, Musubi opens an editable email draft containing the app version/build, platform and OS version, and selected Musubi server. Nothing is sent until you choose to send that email.

Event reminders are scheduled locally on your device. No push-notification token or reminder content leaves the device today. If server-delivered notifications are introduced, we will update this policy first.

02 — 接続

Connected calendars & Google user data.

TL;DR

When you connect Google, Microsoft, Apple, or a CalDAV server, we access that calendar only to run the two-way sync you set up. Credentials are restricted to the sync service; disconnect any time and we delete them.

What we access

If you connect an external calendar account, Musubi requests access to that account's calendars and events. For Google this means the Google Calendar API scope you approve on the consent screen; for Microsoft the Microsoft Graph calendar scope you approve when signing in; for Apple/iCloud and other CalDAV servers, an app-specific password or credentials you provide.

Google Calendar access

Rather than one broad permission, Musubi requests only the narrowest Google Calendar OAuth scopes it needs:

These permissions allow Musubi to provide calendar synchronization and calendar management features — synchronizing calendar and event changes between Google Calendar and Musubi. Depending on the actions you choose to perform, Musubi may exercise any of the above.

Musubi does not perform these actions for advertising, profiling, or unrelated purposes. Calendar data is used only to provide functionality requested or enabled by the user.

Microsoft (Outlook) calendar access

Musubi requests the Calendars.ReadWrite Microsoft Graph scope (plus the standard sign-in scopes: openid, profile, email, User.Read, offline_access). It allows the same calendar synchronization and management features as described for Google above — reading your calendars and events, creating, updating, and deleting them, and keeping both sides in sync. Calendar data obtained from Microsoft is used only to provide functionality you requested or enabled.

What we do with it

We read events to display them alongside your Musubi calendars, and write events back when you create or edit them in Musubi — that is the entire purpose. Synced event data is stored on our servers so your devices and the people you share with can see it.

How credentials are stored

CalDAV app passwords, cross-server Musubi membership tokens, and Google and Microsoft OAuth tokens are encrypted at the application level with authenticated encryption, using a key held outside the database. These credentials are used exclusively to perform the synchronization you configured. No human looks at your calendar data except with your explicit consent (for example when you ask for support), or where necessary for security or compliance with law.

What we never do

We do not use data obtained from connected calendars for advertising, we do not sell it, we do not use it to train AI or machine-learning models, and we do not transfer it to third parties except as needed to provide the sync you requested or as required by law.

Google API Services — Limited Use disclosure

Musubi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting

You can disconnect any external account in the app at any time; we then delete the stored credentials. You can also revoke Musubi's access from your Google account permissions or your Microsoft account permissions (or by rotating your app-specific password for Apple/CalDAV). Deleting your Musubi account deletes stored credentials and mirrored event data.

03 — 利用

How we use it.

TL;DR

To run the app, schedule the reminders you ask for, and fix things when they break. That's it.

We use your data to: create and authenticate your account; sync calendars across your devices and connected providers; share calendars with people you invite; schedule reminders locally on your device; respond to support requests; and detect and prevent abuse of the Service.

We do not use your data to build advertising profiles, sell to third parties, or train AI models.

04 — 保管

Storage & security.

TL;DR

The hosted service's primary application and database run in Germany (EU). Connections use HTTPS/TLS, access is restricted, and we keep personal data only as long as needed.

Where

The hosted Musubi application and primary database run with Hetzner Online GmbH in Germany. Data can also be processed by an email-delivery provider or a calendar provider you explicitly connect. Those providers may process data outside the European Economic Area under their own terms and applicable transfer safeguards.

How long

We keep your account data while your account is active. In-app deletion removes the active account and associated data; a verified web request is completed within 30 days. Residual backup copies age out through the normal backup-retention cycle and are isolated from ordinary use.

The newsletter is separate from the app account: we keep that address until you unsubscribe, and deleting a Musubi account does not silently change the newsletter choice. Support and deletion-request correspondence is kept only as long as needed to resolve the request and meet legal or security obligations. Website analytics follows the configured retention period of our self-hosted Rybbit instance.

Encryption

The hosted service and its provider connections use HTTPS/TLS. Database, backup, and administrative access is restricted; CalDAV passwords, cross-server membership tokens, and Google/Microsoft OAuth tokens receive additional application-level authenticated encryption. Musubi is not end-to-end encrypted — shared calendars and cross-provider sync require the server to read event data to do its job. If you want full control, the entire stack is open source and self-hostable.

05 — 共有

Who we share with.

TL;DR

Nobody buys your data from us. Ever. We use a small number of sub-processors to run the service, listed below.

We do not sell personal data or share mobile-app data with advertisers, data brokers, or third-party advertising analytics.

We may share the minimum necessary information with the following categories of service providers, solely to operate Musubi:

  • Hosting & infrastructure — Hetzner Online GmbH (hosted application and primary database) and restricted S3-compatible backup storage
  • Email delivery — Resend for the website newsletter and deletion-request delivery, plus the hosted service's configured transactional email provider for password-reset messages
  • Connected calendar providers — Google, Microsoft, or a CalDAV service you explicitly connect, solely for the synchronization you request
  • Website analytics — a self-hosted Rybbit instance on FRGTN infrastructure; it is not embedded in the mobile app

The mobile app currently has no advertising SDK, automatic crash-reporting SDK, remote push-delivery service, or payment processor.

We may disclose data if required by law, but we will tell you when we can and will push back on overly broad requests.

06 — 権利

Your rights.

TL;DR

You can see, correct, export, or delete your data at any time. Just ask.

Depending on where you live you may have the right to:

  • Access — know what personal data we hold about you
  • Correction — fix inaccurate information
  • Deletion — ask us to delete your account and data
  • Portability — export a calendar you can access as .ics in the app, or request a broader copy of your data
  • Objection — object to certain types of processing

To exercise any of these rights, email us at [email protected]. To delete an account without the app, use the account deletion form. We will respond within 30 days.

We are subject to the EU General Data Protection Regulation (GDPR). Our legal bases for processing are: contract performance (Art. 6(1)(b) GDPR) for account data, requested support, and calendar sync; consent (Art. 6(1)(a) GDPR) for the newsletter; and legitimate interest (Art. 6(1)(f) GDPR) for service security, abuse prevention, and privacy-preserving website analytics. You have the right to lodge a complaint with the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.cz).

07 — クッキー

Cookies & analytics.

TL;DR

This website uses cookie-free, self-hosted analytics. The mobile app has no advertising or analytics cookies.

This website does not set tracking or advertising cookies.

We use Rybbit Analytics — a self-hosted, open-source, cookie-free analytics tool — to understand website use. It records page URLs and referrers, browser/OS and device category, screen size, country/region derived from the request IP, anonymous session identifiers, and configured product interactions such as a successful newsletter signup. The submitted email address is never sent to analytics, raw IP storage and identified-user tracking are disabled, and this analytics script is not present in the mobile app.

08 — 子供

Children.

TL;DR

Musubi is not intended for children under 16. We don't knowingly collect their data.

Musubi requires users to be at least 16 years old. If we learn that we have collected personal data from a person under 16 without appropriate consent, we will delete it promptly. If you believe this has happened, please contact us at [email protected].

09 — 変更

Changes to this policy.

TL;DR

We'll tell you before anything meaningful changes. You won't wake up to a surprise.

We will notify you of material changes by posting a notice in the app and, where required by law, by email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the latest revision.

10 — 連絡

Contact.

TL;DR

One email. Real humans read it.

Questions about this policy or your data? Write to us:

Email: [email protected]
Company: forgotten s.r.o., IČO 23642467
Address: Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic

forgotten s.r.o. does not have a designated Data Protection Officer. For all data-related enquiries please use the email above.