Privacy policy
Effective date: 23 July 2026
1. Who we are
Qlok (qlok.day) is operated by InVanilla SIA, a company registered in Latvia, Reg. No. 40203218282, registered office in Riga, Latvia (“we”, “us”). We are the data controller for personal data processed through Qlok within the meaning of Regulation (EU) 2016/679 (GDPR). Contact: privacy@qlok.day.
2. The short version
- On the free plan without an account, your calendar data lives only in your browser's local storage. It never reaches our servers, and we cannot see it.
- If you create an account, we process your sign-in data (email, name) through our authentication provider, Clerk.
- If you subscribe and connect external calendars, we process the calendar data needed to provide two-way sync, stored in the EU.
- We run no advertising and no third-party tracking.
3. What we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Local calendar data (free, no account) — stays on your device | Rendering your calendar; never transmitted to us | Not processed by us |
| Account data: email address, name, authentication identifiers | Sign-in, account management, billing | Art. 6(1)(b) — performance of a contract |
| Billing data: subscription status, invoices (handled by Clerk Billing / Stripe) | Paid plan management, tax compliance | Art. 6(1)(b), (c) — contract and legal obligation |
| Synced calendar data: events (title, times, location, notes), calendar metadata, OAuth tokens for calendars you connect | Providing two-way calendar sync you request | Art. 6(1)(b) — performance of a contract |
| Technical logs (IP address, user agent, timestamps) | Security, abuse prevention, service operation | Art. 6(1)(f) — legitimate interest |
4. Where your data lives and who processes it
We use a small set of sub-processors:
| Processor | Role | Location / transfer safeguard |
|---|---|---|
| Vercel Inc. | Hosting and content delivery | EU edge/compute preferred; EU–US Data Privacy Framework & SCCs |
| Clerk Inc. | Authentication and subscription billing | USA; EU–US Data Privacy Framework & SCCs |
| Stripe (via Clerk Billing) | Payment processing | USA/EU; EU–US Data Privacy Framework & SCCs |
| Neon Inc. | Database for synced calendar data | EU (Frankfurt) region |
| Google, Microsoft, Apple / your CalDAV host | The external calendar services you choose to connect | Per your agreement with that provider |
Where data is transferred outside the EEA, we rely on adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.
5. Calendar sync specifics
Connecting an external calendar uses that provider's OAuth consent (or an app-specific password for CalDAV). We request the minimum scopes needed to read and write events. Tokens are stored encrypted and used only to perform the sync you configured. Disconnecting an account deletes its tokens and stops all processing of that calendar; you can also revoke access at the provider at any time. Use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. Retention
- Local data: under your control, in your browser.
- Account data: kept until you delete your account.
- Synced calendar data and tokens: deleted when you disconnect the calendar or delete your account, and at the latest 30 days after account deletion (backups).
- Invoices: retained as required by Latvian accounting law.
- Technical logs: up to 90 days.
7. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). Qlok also ships these as product features: you can export your data as JSON and delete all data from Settings. To exercise any right, email privacy@qlok.day; we respond within one month. You may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv) or your local supervisory authority.
8. Cookies and local storage
We use only strictly necessary storage: your theme and display preferences and (on the free plan) your calendar data in browser local storage, and Clerk's session cookies when you sign in. We set no advertising or analytics cookies, which is why Qlok shows no cookie banner.
9. Security
All traffic is encrypted in transit (TLS). Synced data is stored in the EU with encryption at rest; OAuth tokens are additionally encrypted at the application layer. Access to production systems is limited and audited.
10. Children
Qlok is not directed at children under 16, and we do not knowingly process their data.
11. Changes
We will announce material changes to this policy in the app and update the effective date above. Questions? privacy@qlok.day.