Effective date: 20 July 2026
BusyMax is a desktop calendar and task manager developed by BusyStack.
This Privacy Policy explains how BusyMax handles information when you use the app, including Google, Microsoft, Apple iCloud, Nextcloud, and WebCal connections.
Information BusyMax accesses
BusyMax may access the following information when you connect an account:
Google account information
When you connect a Google account, BusyMax may access:
- Your Google account identifier, email address, and profile name, used to identify the connected account inside BusyMax.
- Your Google Calendar data, including calendar lists, calendar metadata, events, event titles, event times, descriptions, locations, reminders, recurrence rules, attendees, organizers, creators, colors, visibility, and related event metadata.
- Your Google Tasks data, including task lists, task titles, notes, due dates, completion status, task order, parent task relationships, and related task metadata.
BusyMax uses Google Calendar and Google Tasks data only to provide calendar and task management features inside BusyMax, including viewing, creating, editing, deleting, completing, organizing, and synchronizing calendar events and tasks.
BusyMax’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft account information
When you connect a Microsoft account, BusyMax may access:
- Your Microsoft account identifier, email address, and profile name, used to identify the connected account inside BusyMax.
- Your Microsoft Calendar data, including calendars, events, event details, recurrence, reminders, attendees, categories, and related metadata.
- Your Microsoft To Do data, including task lists, tasks, notes, due dates, reminders, completion status, recurrence, importance, categories, and related metadata.
BusyMax uses Microsoft data only to provide calendar and task management features inside BusyMax.
Apple iCloud and Nextcloud information
When you connect iCloud Calendar or Nextcloud, BusyMax may access the account identifiers, calendar and task collections, events, tasks, and related metadata that the selected service makes available. iCloud Calendar uses an Apple app-specific password. Nextcloud uses authorization from the supported HTTPS server. These credentials are used only to authenticate the account and synchronize the collections you select.
Apple Reminders is not supported. Nextcloud task data may include notes, dates and times, reminders, recurrence, hierarchy, status, completion percentage, categories, and priority where the server and collection permit those fields.
WebCal, files, locations, and feedback
When you add a WebCal subscription, BusyMax sends a request to the confirmed HTTPS or WebCal endpoint and stores the returned calendar as read-only data.
BusyMax reads calendar files and writes iCalendar exports only after an explicit file activation or file selection. An imported file is reviewed before its selected content is synchronized to a destination calendar.
Saved location text and provider coordinates may be stored with calendar or task data and sent to the selected account provider during normal synchronization. BusyMax does not perform location autocomplete or geocoding. When you activate an external location action, BusyMax passes the saved destination to the registered maps application or to a browser; the external application or site can receive that destination and normal network metadata.
BusyMax sends feedback only when you explicitly submit it. A submission includes its category, subject, message, a random submission identifier, app/build/platform information, and an optional reply email. Optional technical details are limited to the operating-system version and application locale and are included only when you select that option. Feedback does not silently attach logs, account content, calendar or task content, filenames, screenshots, environment variables, tokens, secrets, or activation payloads.
How BusyMax uses information
BusyMax uses connected account data to:
- Display calendars, events, task lists, and tasks.
- Create, edit, delete, complete, move, and synchronize tasks.
- Create, edit, delete, and synchronize calendar events.
- Keep local BusyMax data synchronized with connected providers.
- Show account labels, such as name or email address, so you can identify connected accounts.
- Maintain pending changes when sync is temporarily unavailable.
- Provide reminders and desktop notifications for tasks and events when enabled.
BusyMax does not use connected-provider data for advertising, marketing, profiling, or unrelated analytics. BusyMax does not add telemetry or analytics.
Local storage
BusyMax stores app data locally on your device.
This may include:
- Connected account records.
- OAuth access tokens, refresh tokens, and DAV app passwords.
- Calendar events and calendar metadata.
- Task lists and tasks.
- Pending sync operations.
- Sync state and conflict-resolution metadata.
- App settings.
OAuth access tokens, refresh tokens, ID tokens, and DAV app passwords are stored separately from BusyMax’s local calendar and task cache. The database itself is not described as wholly encrypted; its protection depends on the user account, filesystem permissions, and device security.
On Linux installations outside the Snap package, BusyMax stores OAuth tokens using operating-system-backed secure credential storage.
In the Snap package, BusyMax encrypts OAuth tokens using AES-256-GCM authenticated encryption. The encryption key is derived using HKDF-SHA-256 from a secret obtained through the XDG Desktop Secret portal. The encryption key is not stored in the encrypted token file.
Calendar, task, account, sync, and settings data are stored in BusyMax’s application-data directory for the current user. Access to this local data is governed by the user account, filesystem permissions, and device security. In the Snap package, this data is stored in BusyMax’s per-user Snap data area and BusyMax runs under strict Snap confinement.
Data sharing
BusyMax does not sell your personal data.
BusyMax does not share connected calendar or task data with advertisers, data brokers, or unrelated third parties.
BusyMax sends account data only to the relevant service provider as required for synchronization:
- Google data is sent to Google APIs to read, create, update, delete, and synchronize Google Calendar events and Google Tasks.
- Microsoft data is sent to Microsoft Graph APIs to read, create, update, delete, and synchronize Microsoft calendar events and Microsoft To Do tasks.
- iCloud data is sent to Apple iCloud services to read and synchronize supported calendar data.
- Nextcloud data is sent to the HTTPS server you authorized to read and synchronize supported calendar and task data.
- WebCal requests are sent to the subscription endpoint you confirm; subscriptions remain read-only.
Provider synchronization is separate from user-activated external location opening and explicit feedback submission. BusyMax does not automatically send connected calendar or task content to BusyStack servers. Explicit feedback sends only the fields described above to the configured BusyStack feedback endpoint. An external maps application or website receives a saved destination only when you activate that action.
Data retention
BusyMax keeps local account, calendar, task, token, and sync data on your device while the account remains connected in the app.
When you remove or sign out of an account in BusyMax, BusyMax removes local authentication tokens for that account and may remove local account-related sync data from the app database.
You can also revoke BusyMax’s access from your provider’s account or server settings where that option is available.
Account authorization
Google and Microsoft use browser-based OAuth, so BusyMax does not ask for or store those account passwords. iCloud Calendar uses an Apple app-specific password, and Nextcloud uses the supported server authorization flow. WebCal requires only the subscription address you confirm.
You can revoke BusyMax’s Google access at any time from your Google Account permissions page.
You can revoke BusyMax’s Microsoft access at any time from your Microsoft account permissions page.
Removing an iCloud or Nextcloud account removes its locally stored credential as applicable. You can separately revoke an app-specific password or authorized client through the provider or server.
Data protection and security
BusyMax uses the following mechanisms to protect connected-account data:
- BusyMax uses the OAuth 2.0 Authorization Code flow with PKCE using the S256 challenge method. Each authorization attempt uses a cryptographically random state value, and BusyMax validates the returned state before accepting the authorization response.
- The OAuth callback listener is bound only to the local loopback interface and accepts callbacks only for the selected local port.
- Communications with Google and Microsoft authorization and API endpoints, Apple iCloud, supported Nextcloud servers, and confirmed WebCal endpoints use HTTPS/TLS.
- OAuth access tokens, refresh tokens, ID tokens, and DAV app passwords are protected using operating-system-backed secure credential storage or, in the Snap package, AES-256-GCM authenticated encryption as described in the Local storage section.
- BusyMax’s logging system redacts bearer tokens, OAuth access tokens, refresh tokens, authorization codes, PKCE code verifiers, client secrets, and Authorization headers before log messages are written.
- BusyMax stores calendar and task data locally in the current user’s application-data directory and does not automatically transmit connected-provider content to BusyStack servers.
- The Snap package runs under strict confinement and stores application data in BusyMax’s per-user Snap data area.
No method of electronic storage or transmission is completely secure. Users are responsible for protecting access to their operating-system account, device, and any device-level backups.
Children’s privacy
BusyMax is not directed to children under 13. BusyMax does not knowingly collect personal information from children under 13.
Changes to this Privacy Policy
This Privacy Policy may be updated from time to time. When it changes, the effective date at the top of this page will be updated.
Contact
For privacy questions or requests, contact:
support@busystack.org