Privacy policy

Breez is built to combine calendars into controlled outputs without exposing more than you permit. This page explains how Breez collects, uses, stores, shares, retains, and deletes account and calendar data.

Last updated August 7, 2026

Return home

Data Breez collects

When you sign in, Breez may receive and store account information from the authentication provider, such as your account ID, email address, display name, profile metadata supplied by the provider, and session information needed to keep you signed in.

When you connect a calendar provider, Breez stores the provider account details needed to identify and maintain the connection, such as provider user IDs, email addresses if supplied by the provider, connection identifiers, OAuth access tokens, refresh tokens, token expiration times, and token refresh status.

Breez currently supports Google Calendar, Outlook, and ICS calendar subscriptions. For Google, Breez requests read-only calendar access plus OpenID and email scopes used to complete OAuth and identify the connected Google account. For Outlook, Breez requests OpenID, profile, email, offline access, User.Read, Calendars.Read, and Calendars.Read.Shared permissions to identify the account and read calendars available to that account.

For each reusable source calendar, Breez stores metadata such as the provider name, external account ID, external calendar ID, external calendar name, sync status, and last sync time. For ICS subscriptions, Breez stores the normalized subscription URL as the connection and source calendar identifier.

To build your Home Calendar and Views, Breez reads and stores event data from calendars you link. Depending on what the provider returns, this may include event IDs, event status, recurrence data, original start times, start and end times, summary or title, description, location, attendee information, and free/busy status.

Breez also stores your View composition and Sharing settings, including selected source calendars, per-source visibility levels, timezone, the enabled state, an encrypted Sharing token and lookup hash, and account-wide Busy blocks you create.

How Breez uses data

Breez uses account and calendar data to authenticate users, connect provider accounts, discover calendars available to you, refresh OAuth access when needed, sync source calendars, maintain your Home Calendar and Views, apply visibility settings, serve enabled Sharing, troubleshoot reliability issues, secure the service, and prevent abuse.

Breez stores each synced source event once so it can build multiple living Views without repeatedly fetching or duplicating the same provider event.

Breez does not use connected calendar content for advertising, does not sell connected calendar data, and does not use connected calendar data to train generalized AI or machine learning models.

Breez does not create, update, or delete events in your source calendars as part of the current service.

Shared Views

You can enable one Sharing link for a View. Anyone with that bearer link can view the projected calendar or subscribe to its live, read-only feed until you disable Sharing or reset access.

The output may show event titles, times, locations, and descriptions only when you select the corresponding visibility level for that source. Busy-only sources and account-wide Busy blocks are emitted as merged generic Busy intervals.

Breez never republishes attendee lists, account identifiers, provider metadata, authentication-linked fields, or private Busy-block labels through a shared View.

The public page and subscription feed use the same Sharing token and rotation lifecycle. Breez stores a lookup hash plus an encrypted token value so an owner can retrieve a stable link without resetting subscribers.

Sharing with service providers and legal recipients

Breez shares data only as needed to operate the service, as you direct it, or as required by law. Breez does not publish your source calendars directly as standalone calendars.

Breez may disclose data to service providers that host, store, secure, authenticate, deliver, and monitor Breez on our behalf, such as hosting, managed database, authentication, logging, monitoring, and cloud infrastructure providers. These providers may process data only to provide services for Breez.

Breez may disclose data when required to comply with law, enforce terms, or protect the rights, safety, and security of Breez, its users, or others.

Breez's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How Breez stores and protects data

OAuth credentials, connected-account metadata, source-calendar metadata, Sharing configuration, View settings, and synced event data are stored server-side. Breez uses access controls to limit access to account-owned records and keeps service credentials on the server side only.

Breez is designed to redact sensitive values such as access tokens, refresh tokens, public tokens, and event content from application logs where feasible.

Breez limits human access to personal data to cases where access is needed to operate, secure, support, debug, or legally protect the service.

Breez uses technical and organizational safeguards designed to protect data in transit and at rest, but no method of transmission or storage can be guaranteed to be completely secure.

Retention and deletion

Breez retains account data, connected-account metadata, source-calendar metadata, OAuth credentials, sharing configuration, View settings, and synced event data for as long as they are needed to provide the service, maintain active source calendars, and support any shared Views you keep active.

If you disable a View's Sharing, Breez stops serving both its public page and Calendar subscription. If you disconnect an account, delete a source calendar, or ask Breez to delete your data, Breez will stop using the affected data for future syncs and will delete or clean up associated Breez records, subject to limited retention needed for security, fraud prevention, legal compliance, dispute resolution, or backup recovery.

Breez sync processes also update or remove copied event data when source events or source calendars are removed from the provider or from Breez.

Cookies and analytics

Breez uses cookies and similar session storage to keep you signed in and to protect authentication flows.

Breez records privacy-safe product analytics and latency metrics for launch and reliability work, such as page views, auth outcomes, source-calendar setup, public sharing interactions, performance, and friction signals. These analytics are designed to avoid raw public tokens, calendar event contents, and direct personal details in event properties.

Privacy questions and deletion requests

For support, privacy questions, or deletion requests, contact Breez at support@breezcal.com.

When contacting Breez about deletion, please include enough information for Breez to identify the relevant account, connected provider, and source calendars so the request can be verified and processed.

Breez may update this page as the product changes. Material updates will be reflected by the last updated date above.