Qlok

Privacy policy

Effective date: 23 July 2026

1. Who we are

Qlok (qlok.day) is operated by InVanilla SIA, a company registered in Latvia, Reg. No. 40203218282, registered office in Riga, Latvia (“we”, “us”). We are the data controller for personal data processed through Qlok within the meaning of Regulation (EU) 2016/679 (GDPR). Contact: privacy@qlok.day.

2. The short version

3. What we process, why, and on what legal basis

DataPurposeLegal basis (GDPR)
Local calendar data (free, no account) — stays on your deviceRendering your calendar; never transmitted to usNot processed by us
Account data: email address, name, authentication identifiersSign-in, account management, billingArt. 6(1)(b) — performance of a contract
Billing data: subscription status, invoices (handled by Clerk Billing / Stripe)Paid plan management, tax complianceArt. 6(1)(b), (c) — contract and legal obligation
Synced calendar data: events (title, times, location, notes), calendar metadata, OAuth tokens for calendars you connectProviding two-way calendar sync you requestArt. 6(1)(b) — performance of a contract
Technical logs (IP address, user agent, timestamps)Security, abuse prevention, service operationArt. 6(1)(f) — legitimate interest

4. Where your data lives and who processes it

We use a small set of sub-processors:

ProcessorRoleLocation / transfer safeguard
Vercel Inc.Hosting and content deliveryEU edge/compute preferred; EU–US Data Privacy Framework & SCCs
Clerk Inc.Authentication and subscription billingUSA; EU–US Data Privacy Framework & SCCs
Stripe (via Clerk Billing)Payment processingUSA/EU; EU–US Data Privacy Framework & SCCs
Neon Inc.Database for synced calendar dataEU (Frankfurt) region
Google, Microsoft, Apple / your CalDAV hostThe external calendar services you choose to connectPer your agreement with that provider

Where data is transferred outside the EEA, we rely on adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.

5. Calendar sync specifics

Connecting an external calendar uses that provider's OAuth consent (or an app-specific password for CalDAV). We request the minimum scopes needed to read and write events. Tokens are stored encrypted and used only to perform the sync you configured. Disconnecting an account deletes its tokens and stops all processing of that calendar; you can also revoke access at the provider at any time. Use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

6. Retention

7. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). Qlok also ships these as product features: you can export your data as JSON and delete all data from Settings. To exercise any right, email privacy@qlok.day; we respond within one month. You may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija, dvi.gov.lv) or your local supervisory authority.

8. Cookies and local storage

We use only strictly necessary storage: your theme and display preferences and (on the free plan) your calendar data in browser local storage, and Clerk's session cookies when you sign in. We set no advertising or analytics cookies, which is why Qlok shows no cookie banner.

9. Security

All traffic is encrypted in transit (TLS). Synced data is stored in the EU with encryption at rest; OAuth tokens are additionally encrypted at the application layer. Access to production systems is limited and audited.

10. Children

Qlok is not directed at children under 16, and we do not knowingly process their data.

11. Changes

We will announce material changes to this policy in the app and update the effective date above. Questions? privacy@qlok.day.