Privacy

What Calcendar stores, and why.

This page describes how the software actually behaves. It is not legal advice, and where your practice has its own agreement with us, that agreement wins.

Two kinds of people

Practitioners and staff hold an account: an email address, a name, a hashed password (never the password itself), and the settings and permissions that go with the account.

Patients do not hold an account. Their details are entered by the practice that treats them, and belong to that practice. We store them so the practice can use them; we do not sell them, mine them, or use them to train anything.

What the practice records

  • Patient name, phone, email and any custom fields the practice added
  • Sessions: when, how long, where, and their status
  • Clinical records: history, consultation notes, treatment plans, reports and attachments, scored assessments
  • Money: charges, payments, currency, and the practice's own expenses and revenue

Clinical and financial records are visible only to accounts in that practice, and only to the roles the practice grants. A practice never sees another practice's data.

Where it lives

In a managed MongoDB database and on the server that runs the application. Traffic between the app and the server is over HTTPS. Attachments on a clinical report are stored inside the record itself rather than on a public file host, so nothing is reachable by guessing a URL.

Email and WhatsApp

Emails to a patient (a reminder, a receipt) are sent by the server through the practice's configured mail account. WhatsApp is different by design: the app only opens the practitioner's own WhatsApp with the message prefilled, and a person presses send. We never message a patient on a practice's behalf without that.

A patient can be switched out of email entirely, per patient, by the practice.

Google

Signing in with Google is one of the two ways to hold an account. Google tells us the email address, the name and the profile picture on the account, and a stable identifier for it, and that is all we ask for. It becomes the Calcendar account in the same way a typed email address would. We are never given the Google password, and we cannot see anything else in the account.

Google Calendar is separate, and off unless it is turned on. A practice can connect a Google account, and from then on the server writes each of that practice's sessions into that account and keeps them in step when one moves or is cancelled. Connecting is optional, it is done by the practice owner, and nothing goes to Google until it is done.

The sessions go into a calendar Calcendar creates in that account for the purpose, named after the practice. That calendar is the only one Calcendar can see or change: the account's own calendars are never read, never written to, and never deleted.

What reaches Google is the session: who it is with, when it is, how long it runs, and the clinic and its address. Nothing clinical, ever. No notes, no history, no assessment, no report, no fee.

The permission asked for is the one that covers calendars an app makes for itself (calendar.app.created), plus the email address of the account being connected. That permission does not reach any other calendar in the account, so events written by anyone or anything else cannot be read or touched. The email address is stored so the practice can see which of their Google accounts the diary is going to; it is shown back to them and used for nothing else.

The connection is held as a token, encrypted in our database, and belongs to the one practice that made it. Disconnecting in Calcendar deletes the calendar it made, and every session in it, then hands the permission back to Google and deletes the token. Nothing else in the account is touched, and the diary in Calcendar is unchanged. Access can also be withdrawn from your Google account's permissions page, which stops any further sessions being written and leaves the calendar there for you to delete.

Calcendar's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That data is not sold, is not shared with anyone else, is not used for advertising, and is not used to train any model.

Cookies

The website you are reading sets no cookies. Signing in to the admin dashboard sets one session cookie, which exists to keep you signed in and is not shared with anyone. There is no advertising, no analytics script and no third-party tracker on these pages.

Three pages are an exception, and all three are the same exception: the contact page, the sign-up form in the app and the payment page run a Cloudflare Turnstile check. It is what stops a program filling any of them in thousands of times. Cloudflare is told the address you are connecting from and enough about your browser to tell it from a script, and it may store a short-lived token in your browser to remember that you have already passed. It is not an analytics or advertising tool, it is not used to follow you between sites, and it runs nowhere else on Calcendar. The three pages it runs on are the only ones a stranger can post to.

Paying for a licence

Paying for a plan hands the payment off to a payment provider. They are told the amount, the plan it is for, and the email address the licence is being bought for, so the payment can be matched to the account when it clears. We never see or store a card number: the card is entered on the provider's own page, not on ours. What we keep is the record of the order: what was bought, what it cost, whether it succeeded, and the provider's reference for it.

Notifications on a phone

A reminder that appears on a phone is delivered through Google's notification service, which requires the app to register the device with Google and to keep the token that identifies it. The token is stored against the account and is deleted when that device signs out. The content of a notification is the little it needs: that a session is coming, or that a licence is about to end. Turning notifications off in the app stops the registration.

Keeping and deleting

Records stay until the practice deletes them. Deleting a patient deletes their sessions, notes, history, plans, reports, assessments and transactions with them. Ask us and we will delete a whole practice.

Asking us something

Write to us from the contact page or at [email protected]. If you are a patient, ask the practice that treats you first: the records are theirs, and they can answer faster than we can.

You are leaving Calcendar

This opens Elia El Khoury’s portfolio, a site we do not run.

Open the portfolio