eInk Calendar – Privacy Policy

This privacy policy applies to the eInk Calendar application described on the eInk Calendar project page. It covers only that application. The privacy policy for this website is available here.

Person in Charge

Christian Neuhaus
Fabriciusstr. 11–12
40721 Hilden, Germany
info@44-2.de

What the Application Is

eInk Calendar is a private, non-commercial device built and operated by the person named above, for their own use only. It runs on an ESP8266 microcontroller located in the operator’s home. There is no server, no database, no hosted backend and no other user.

What Google Data Is Accessed

With the operator’s explicit consent, the application accesses the Google Calendar API in read-only mode, using the scope https://www.googleapis.com/auth/calendar.readonly.

The only data read is the title, date and time of upcoming calendar entries. No other Google user data is requested or accessed.

How the Data Is Used

The retrieved appointments are used for exactly one purpose: rendering them on the e-paper display in the operator’s home. They are not used for any other purpose.

How the Data Is Stored

  • Calendar entries are processed transiently in the device’s memory in order to draw them on the display. They are not written to any persistent storage and are gone when the device powers down.
  • The OAuth refresh token is stored locally in the flash memory of the microcontroller, so the device can renew its access without asking for authorization on every run. It never leaves the device.
  • No data is transmitted to any server operated by the developer or by any third party. All network traffic goes directly between the device and Google’s API endpoints over TLS.

Sharing and Transfer

No Google user data is sold, shared, transferred or disclosed to any third party. It is not used for advertising, analytics, profiling, credit assessment, or for training artificial intelligence or machine learning models. No human other than the operator reads it.

Limited Use

eInk Calendar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data Retention and Deletion

Because no calendar data is retained, there is nothing to delete on the server side. The stored refresh token is erased when the device is reset or re-flashed. Revoking access (see below) invalidates the token immediately.

Revoking Access

Access granted to this application can be withdrawn at any time at myaccount.google.com/permissions. Once revoked, the application can no longer read any calendar data.

Rights of Data Subjects

As the application processes data of its operator only, and stores nothing beyond the local access token, the rights of access, rectification, erasure, restriction and data portability under the GDPR are exercised directly by the operator on the device itself.

Changes to This Privacy Policy

This policy may be updated if the application’s data handling changes. The current version always applies.

Last updated: 28 August 2026