Features Privacy controls
Private calendars stay private
Busy means busy. It doesn't mean "here's my life".
Mark any calendar private and it contributes busy intervals and nothing else. Titles, guests and notes are never written to our database, so there is nothing to leak, subpoena or breach.
Minimised at ingest, not at display
A private calendar's event titles are discarded when the event is read. We don't store them and hide them — we never store them.
Per-calendar, not per-account
Your brokerage calendar can show titles on your merged view while your personal one stays anonymous.
Encrypted OAuth tokens
Provider tokens are encrypted with AES-256-GCM at rest, separate from the calendar mirror.
Least-privilege scopes
We request the narrowest Google scopes that do the job, and document exactly what each one is for.
This is the part most calendar tools get backwards. They pull full event details into their database because it is easier, then add a display toggle. The data is still there.
If a calendar is private in Linemerge, the only thing that exists on our side is a start time, an end time and a source tag. That is a design decision that is expensive to reverse, which is exactly why it is worth making up front.