BookMyCal
Privacy
Last updated September 6, 2026
BookMyCal schedules meetings. We do not sell data, use advertising or cross-app tracking, show ads, or include third-party analytics.
Calendar
With your permission, BookMyCal checks selected Apple calendars on this iPhone to find busy times. Existing event titles, notes, locations, and attendees are not uploaded. When you confirm a booking, BookMyCal writes its title, time, notes, location, and meeting link to the Apple calendar you choose; that calendar may sync under your calendar provider's settings.
On your device
BookMyCal stores your name and settings; availability rules; contacts you explicitly select, including their name, email, and phone; booking pages and requests; confirmed-booking details; meeting links or locations; Calendar identifiers; and delivery or error status in its local database. Separate private encryption and link-control keys are kept in device-only Keychain storage that becomes available to background delivery after you unlock the device once following a restart.
Shared links
BookMyCal stores your display name, event type, time zone, duration, offered times, meeting-method category, expiry, page and slot identifiers, status, timestamps, and public cryptographic keys in Apple CloudKit. Anyone with the link can see the booking offer and service-visible metadata. Existing calendar-event contents and private meeting details are never included.
Guest requests
A guest's name, email address, browser time zone, and note are encrypted in the guest's browser for the host before the protected booking service receives them. Cloudflare processes the encrypted envelope, selected offered time, request and page identifiers, timestamps, request status, network address, and anti-abuse signals to validate and deliver the request. Apple CloudKit stores the encrypted envelope plus that service-visible routing and timing metadata.
If delivery cannot be confirmed, that browser tab keeps only the encrypted submission and selected-time metadata, plus a random comparison salt and salted hash of the entered details, in session storage for up to nine minutes. This lets the same request ID be retried after a reload without storing the plaintext details there. After that retry window, the tab replaces those values with an expiry-only marker for up to 24 hours and 15 minutes so it can block a potentially duplicate request. Closing the tab normally clears session storage; BookMyCal removes the marker after its blocking window ends.
Service security and retention
BookMyCal's Worker code does not write guest details, encrypted envelopes, request or page identifiers, signatures, raw notification device tokens or token digests, or raw network addresses to its application logs. It temporarily stores one-way salted network keys and attempt times, request receipts, fingerprints, and notification delivery intent for up to 24 hours; host-command and push-registration receipts for up to seven days; and an active page's notification device registration for no more than seven days and never beyond that page's expiry. To preserve one host's signing authority and safely repair decisions after public records expire, Apple CloudKit also stores service-only page-control records containing a page identifier, public signing identity, and lifecycle timestamps, and request-control records containing request, page, and slot identifiers, status, a one-way ownership digest, lifecycle timestamps, and host-command metadata. The protected service keeps an immutable local copy of a page's public signing identity and expiry through that same control horizon. These control records contain neither guest details nor an encrypted guest envelope; they become eligible for scheduled deletion after the applicable page or booking-window control horizon, which is no more than about 90 days. The service periodically rechecks that the page remains active. These records limit abuse, prevent duplicate delivery, and safely repair interrupted updates. Cloudflare necessarily processes connection metadata and may retain platform security or operational records under its policies.
Notifications
Notification permission is optional. For active shared links, BookMyCal sends the current Apple Push Notification service device token to the protected booking service, tied to the installation's signing-key identifier and each active page. After an accepted request, the service may ask Apple Push Notification service to show a generic new-request alert. The alert contains no guest details or page or request identifiers. Opening BookMyCal checks Pending through a signed protected request. While the app is open, it refreshes Pending without showing a system banner; polling remains a recovery path.
Your control
Shared links expire after seven days. Pending requests expire after 24 hours, while a confirmed slot remains unavailable until its end. Cleanup may not be immediate, and stopping or expiring a link prevents new requests but does not by itself prove every stored record was erased. Stopping a link also causes its notification registration to be removed during app reconciliation or the service's periodic page check; an uncontacted registration expires within the limits above. You can stop a link in Shared Links, revoke Calendar or notification access in Settings, or delete BookMyCal to remove its local database. Keychain data may survive deletion. Calendar events remain in Apple Calendar until you delete them.
Apple provides Calendar, the system contact picker, Notifications, Keychain, and CloudKit under Apple's privacy terms. Cloudflare operates the protected booking website and request boundary under its privacy terms. Any service that receives BookMyCal data must protect it to the same standard.
Contact
Questions or deletion requests: admin@bookmycal.app.