Effective date: 20 July 2026
BusyMax is a Linux desktop calendar and task manager developed by BusyStack.
This Privacy Policy explains how BusyMax handles information when you use the app, including Google Calendar, Google Tasks, Microsoft Calendar, and Microsoft To Do integration.
Information BusyMax accesses
BusyMax may access the following information when you connect an account:
Google account information
When you connect a Google account, BusyMax may access:
- Your Google account identifier, email address, and profile name, used to identify the connected account inside BusyMax.
- Your Google Calendar data, including calendar lists, calendar metadata, events, event titles, event times, descriptions, locations, reminders, recurrence rules, attendees, organizers, creators, colors, visibility, and related event metadata.
- Your Google Tasks data, including task lists, task titles, notes, due dates, completion status, task order, parent task relationships, and related task metadata.
BusyMax uses Google Calendar and Google Tasks data only to provide calendar and task management features inside BusyMax, including viewing, creating, editing, deleting, completing, organizing, and synchronizing calendar events and tasks.
BusyMax’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft account information
When you connect a Microsoft account, BusyMax may access:
- Your Microsoft account identifier, email address, and profile name, used to identify the connected account inside BusyMax.
- Your Microsoft Calendar data, including calendars, events, event details, recurrence, reminders, attendees, categories, and related metadata.
- Your Microsoft To Do data, including task lists, tasks, notes, due dates, reminders, completion status, recurrence, importance, categories, and related metadata.
BusyMax uses Microsoft data only to provide calendar and task management features inside BusyMax.
How BusyMax uses information
BusyMax uses connected account data to:
- Display calendars, events, task lists, and tasks.
- Create, edit, delete, complete, move, and synchronize tasks.
- Create, edit, delete, and synchronize calendar events.
- Keep local BusyMax data synchronized with connected providers.
- Show account labels, such as name or email address, so you can identify connected accounts.
- Maintain pending changes when sync is temporarily unavailable.
- Provide reminders and desktop notifications for tasks and events when enabled.
BusyMax does not use Google or Microsoft user data for advertising, marketing, profiling, or unrelated analytics.
Local storage
BusyMax stores app data locally on your device.
This may include:
- Connected account records.
- OAuth access tokens and refresh tokens.
- Calendar events and calendar metadata.
- Task lists and tasks.
- Pending sync operations.
- Sync state and conflict-resolution metadata.
- App settings.
OAuth access tokens, refresh tokens, and ID tokens are stored separately from BusyMax’s local calendar and task database.
On Linux installations outside the Snap package, BusyMax stores OAuth tokens using operating-system-backed secure credential storage.
In the Snap package, BusyMax encrypts OAuth tokens using AES-256-GCM authenticated encryption. The encryption key is derived using HKDF-SHA-256 from a secret obtained through the XDG Desktop Secret portal. The encryption key is not stored in the encrypted token file.
Calendar, task, account, sync, and settings data are stored in BusyMax’s application-data directory for the current Linux user. Access to this local data is governed by the user’s Linux account, filesystem permissions, and device security. In the Snap package, this data is stored in BusyMax’s per-user Snap data area and BusyMax runs under strict Snap confinement.
Data sharing
BusyMax does not sell your personal data.
BusyMax does not share your Google Calendar, Google Tasks, Microsoft Calendar, or Microsoft To Do data with advertisers, data brokers, or unrelated third parties.
BusyMax sends account data only to the relevant service provider as required for synchronization:
- Google data is sent to Google APIs to read, create, update, delete, and synchronize Google Calendar events and Google Tasks.
- Microsoft data is sent to Microsoft Graph APIs to read, create, update, delete, and synchronize Microsoft calendar events and Microsoft To Do tasks.
BusyMax does not send your Google or Microsoft calendar/task data to BusyStack servers.
Data retention
BusyMax keeps local account, calendar, task, token, and sync data on your device while the account remains connected in the app.
When you remove or sign out of an account in BusyMax, BusyMax removes local authentication tokens for that account and may remove local account-related sync data from the app database.
You can also revoke BusyMax’s access from your Google Account or Microsoft Account security settings.
Account authorization
BusyMax uses OAuth to connect accounts. BusyMax does not ask for or store your Google or Microsoft account password.
You can revoke BusyMax’s Google access at any time from your Google Account permissions page.
You can revoke BusyMax’s Microsoft access at any time from your Microsoft account permissions page.
Data protection and security
BusyMax uses the following mechanisms to protect Google and Microsoft user data:
- BusyMax uses the OAuth 2.0 Authorization Code flow with PKCE using the S256 challenge method. Each authorization attempt uses a cryptographically random state value, and BusyMax validates the returned state before accepting the authorization response.
- The OAuth callback listener is bound only to the local loopback interface and accepts callbacks only for the selected local port.
- Communications with Google OAuth endpoints, Google APIs, Microsoft identity endpoints, and Microsoft Graph APIs use HTTPS/TLS.
- OAuth access tokens, refresh tokens, and ID tokens are protected using operating-system-backed secure credential storage or, in the Snap package, AES-256-GCM authenticated encryption as described in the Local storage section.
- BusyMax’s logging system redacts bearer tokens, OAuth access tokens, refresh tokens, authorization codes, PKCE code verifiers, client secrets, and Authorization headers before log messages are written.
- BusyMax stores calendar and task data locally in the current user’s application-data directory and does not transmit Google Calendar or Google Tasks data to BusyStack servers.
- The Snap package runs under strict confinement and stores application data in BusyMax’s per-user Snap data area.
No method of electronic storage or transmission is completely secure. Users are responsible for protecting access to their Linux account, device, and any device-level backups.
Children’s privacy
BusyMax is not directed to children under 13. BusyMax does not knowingly collect personal information from children under 13.
Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. When it changes, the effective date at the top of this page will be updated.
Contact
For privacy questions or requests, contact:
support@busystack.org