Security
A summary of our approach. We do not publish secrets or implementation details that would weaken it.
- Token storage: OAuth tokens are kept only in protected, encrypted storage on the server side, never in web pages or browser code.
- Least privilege: we request the minimum Google permissions, and Drive and Sheets access is requested separately from Calendar access.
- Isolation: every Google account and every brand is handled as a separate connection; there is no cross-account or cross-brand access.
- Access control: only the owner and authorised operators can access connected data; access is checked on every request.
- No public data: connected Calendar, Drive and Sheets data is never shown on this website.
- Encryption in transit: this site is served over HTTPS.
- Revocation: connections can be disconnected at any time (/disconnect) or revoked in your Google account.
Report a security issue: [email protected]