Privacy Policy
add2calendr is operated by UnderdogDesign BV, Velaertbosweg 4, 1860 Meise, Belgium — company number BE0428.440.882. Contact: privacy@underdogdesign.be. Version 2026.1.
add2calendr reads a list of events from a web page you link or a screenshot you upload, shows them to you for review, and — only if you ask it to — creates those events in your own Google Calendar. This policy explains exactly what is processed to make that work.
1. What we process
Content you submit: the URL you paste or the screenshot you upload, and the event details extracted from it (title, date, time, location, description).
Account data: when you sign in with Google, we receive your email address and a Google account identifier so we know which calendar to write to.
Calendar authorisation: an access token and refresh token issued by Google, stored encrypted, used only to create the events you approved.
Technical data: standard server and security logs (IP address, browser, timestamps, error traces).
We do not process special categories of personal data (health, religion, political opinions, and similar).
2. Why we process it
To fetch and read the page or image you submitted, to extract the events from it, to let you review and edit them, to identify the calendar account you signed in with, to create the approved events in that calendar, and to keep the service secure and working. We never sell your data and never use it for advertising.
3. Google user data and calendar access
add2calendr requests the calendar.events permission. It is used for one thing only: creating the events you explicitly approved in the review list. We do not read, modify, or delete your existing calendar entries, we do not browse your calendars, and we do not use Google user data to train AI models.
add2calendr's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke access at any time with the “Disconnect” link in the app, or from your Google account permissions. Revoking deletes the stored tokens.
4. Legal grounds
Consent (signing in and granting calendar access), contractual necessity (delivering the service you asked for), legal obligation (accounting and administration where applicable) and legitimate interest (security, abuse prevention and improving the service).
5. Retention
The event list you are reviewing lives in your browser session and disappears when you clear it, inject it, or close the tab. Calendar authorisation tokens are kept until you disconnect or revoke access. Technical logs are kept for a short period for security and debugging. Once events are created, they belong to your calendar and are governed by Google's own terms.
6. Third parties
We use processors strictly to run the service: hosting and database infrastructure, and an AI model provider used to read the schedule from the page or screenshot you submit. The content you submit is sent to that provider only for extraction; it is not used to train models. All processors act under our responsibility and under GDPR-compliant agreements. We never sell personal data.
7. Security
Encrypted connections, encrypted storage of calendar tokens, restricted access, logging and monitoring. In case of a data breach we follow the statutory notification duties.
8. Automated extraction
Event extraction is performed by an AI model and can be incomplete or wrong. That is why nothing is written to your calendar before you have reviewed the list. You remain responsible for checking the events you approve.
9. Cookies
add2calendr uses only functional storage needed to keep you signed in and to hold the event list you are reviewing. No advertising or tracking cookies.
10. Your GDPR rights
You have the right to access, correct, delete, restrict, port, or object to the processing of your personal data, and to withdraw consent at any time. Contact privacy@underdogdesign.be; we respond within the statutory 30 days. You may also lodge a complaint with the Belgian Data Protection Authority.
11. Minors
add2calendr is not directed at children. If you believe a minor's data has been submitted, contact us and we will remove it.
12. International transfers
Data is stored within the EU where possible. When a provider operates outside the EU, transfers take place under GDPR safeguards such as Standard Contractual Clauses.
13. Changes
We may update this policy. The current version is always published on this page and applies from the moment it is posted.