Who is responsible?
The operator below is responsible for the personal information processed to provide Done Cal’s website, browser beta and mailing lists. This notice also links to the additional details for our native apps.
Operator: Aran Labs LLC
Based in: United States — Delaware limited liability company
Registered office: 8 The Green, Suite A, Dover, Delaware 19901, United States
Company registration: Delaware Division of Corporations, file number 7691974
Privacy & support: contact@aranlabs.com
This notice describes features when enabled. Preview availability does not mean accounts, calendar connections or email delivery have been activated. Guest plans stay on your device; requests to the website still reach its host.
What we collect and why
Browser accounts
Your email address, verified account identifier and sign-in records let us create your account, verify it is you, maintain sessions and provide support. Supabase handles email verification and authentication. We do not ask you to create a password in the browser beta.
Your plans and progress
When signed in, event titles, dates, times, calendar names, source identifiers, checkmarks, postponements and Focus records are saved on the Done Cal server so you can use them in another browser. Local plans are copied to an account only when you choose the transfer control.
Without an account, your created or imported plans and progress remain in this browser’s local storage. Downloaded backups contain calendar information and are saved wherever you choose.
Connected calendars
If you connect Google or Microsoft, we receive authorization credentials, your selected calendar names and identifiers, and calendar event responses from that provider. The server extracts the event details needed by Done Cal; it does not retain event descriptions, locations or attendee lists as saved browser event fields. Read-only access is used to show your plans. Done Cal checkmarks and postponements do not change the source calendar.
Beta and launch emails
The optional signup form collects your email, optional name, main device, separate email choices and confirmation/unsubscribe records. We use those choices for beta participation and feedback, App Store launch announcements, and Google Play launch announcements. Each store is a separate choice. We confirm your email before adding you to the selected lists.
Support and security
If you contact us, we receive the information you send and use it to address your request. The website’s support-note builder does not upload its text. Web and authentication requests also involve connection information such as IP addresses and request details. Done Cal uses request counts and expiring sessions to limit abuse; hosting and authentication providers may keep security and delivery logs.
Why we are allowed to use it
Where GDPR applies, we rely on performing our agreement with you for account access, requested calendar features and related service messages. We rely on your consent for optional beta and store-launch emails. You can withdraw that consent without losing access to the browser app.
We rely on legitimate interests for proportionate fraud prevention, service security and responding to general enquiries, balanced against your rights. Where a specific legal requirement applies, we may process or retain information to meet that obligation. Calendar-provider permission is separate from mailing-list consent and is not, by itself, a GDPR legal basis. We obtain account and signup information from you, calendar information from your selected provider, and technical records from your requests and service providers. Avoid entering sensitive information, such as health details, into event titles or sending it to support; the service does not require it.
An email address is needed for an account or mailing-list subscription. Your name is optional. Connecting a provider is optional: you can create plans or import a calendar file instead. The main-device field is required only on the beta signup form so we can understand participation across platforms.
Who receives information?
- Supabase provides account authentication and processes account and authentication information.
- Resend provides email delivery and the selected Done Cal mailing lists. This includes recipient details, message content, delivery status and suppression information. It is not sent your calendar database by the mailing-list integration.
- Google or Microsoft handles the provider account you choose to connect, under its own terms and privacy notice.
- Our hosting provider and authorized operators support the server and its security. Railway hosts the browser service. The configured application region is Europe West (Netherlands). Provider support, infrastructure logs and subprocessors may process information elsewhere; their retention and access arrangements remain under review.
We may disclose information when legally required, or where necessary to protect people and the service, subject to applicable law. Done Cal does not sell calendar or signup information or use it for advertising profiles. The browser service does not use automated decisions that produce legal or similarly significant effects about you.
Where processing happens
The prepared Done Cal Supabase authentication project is configured in the EU West region. Railway hosts the browser application in the Netherlands. Aran Labs LLC operates from the United States, and Resend processes email data in the United States even when email is sent from a European region. This does not mean every provider operation, support function or subprocessor is confined to the EU. Supabase and Resend publish data-processing terms and subprocessor information.
Before public collection, we must confirm the actual processing countries, applicable transfer safeguards and how you can obtain a copy. Provider processing agreements and the chosen host must be reviewed; this draft does not claim those steps are complete.
Provider terms include Railway’s DPA, Supabase’s DPA and Resend’s GDPR terms. These describe contractual safeguards, including standard contractual clauses. Linking them does not confirm that our account arrangements or transfer assessments are complete. Contact us for information about applicable safeguards or a copy, subject to necessary redactions.
EU representative: assessment under Article 27 GDPR remains outstanding. The Delaware registered office is not an EU representative.
How long information is kept
Accounts and saved plans: Account, backup and deletion retention periods are awaiting confirmation. The current beta does not automatically delete an account after inactivity.
Mailing-list records: Subscriber, consent, suppression and email-log retention periods are awaiting confirmation. A signup confirmation link expires after 48 hours; expiry does not automatically delete the signup record.
Support correspondence: Support correspondence retention is awaiting confirmation.
Browser account sessions last up to 30 days and sign-in challenges last 10 minutes. Provider-connection authorization attempts expire after 10 minutes. These validity periods are not the retention period for the account itself. Local browser data remains until you remove it or your browser clears it.
Unsubscribing stops Done Cal marketing eligibility immediately; removal from Resend lists is queued for synchronization. Consent and suppression records may need to remain for the approved retention period to respect your choice. Signing out does not delete an account, and deleting an app does not cancel an Apple subscription.
Your rights and controls
You can request access, correction, deletion or restriction of personal information, and portability where it applies. You can object to processing based on legitimate interests for reasons relating to your situation; we must stop unless we demonstrate overriding compelling grounds or need the information for legal claims. Your objection to direct marketing is unconditional: we must stop that use. You can withdraw consent to optional emails at any time, as easily as giving it. These rights depend on the circumstances and applicable law; withdrawing consent does not change the lawfulness of earlier processing.
Use Your data choices for the available controls and contact route. We may ask for proportionate identity verification. Under GDPR, we normally respond within one month; if complexity or the number of requests requires an extension of up to two further months, we explain why within the first month. Requests are normally free. A reasonable fee or refusal is possible only where the law permits, such as a demonstrably manifestly unfounded or excessive request. If we refuse, we explain our reasons and your complaint and judicial-remedy options.
You may complain to a supervisory authority, including where you live, work or believe an infringement occurred. Find your authority in the EDPB directory. You do not have to contact us first.
Security and your device
Saved account calendar content and provider credentials are encrypted on the server, and account requests are checked against the signed-in user. This is server encryption, not end-to-end encryption: the service must read records to provide its features. Keep downloaded backups private and sign out on shared devices.
The beta is a general planning service and is not directed at children. If you believe a child has provided information inappropriately, contact us so we can review it.
Native apps and cookies
The iPhone and iPad app uses device calendar access and private iCloud completion records. Its current storage and purchase identity are separate from browser accounts. Read the native app privacy details for EventKit, iCloud, widgets, Watch and TelemetryDeck analytics.
Our Cookies & storage notice explains the essential browser storage. Creating an account does not automatically join an email list.
Changes and questions
We update the version date when this notice changes and provide additional notice for material changes where required. A new optional email purpose requires its own choice. Contact: contact@aranlabs.com.