Privacy Policy
MojoDojo Family Calendar is a privately administered family planning tool at mojodojo.house. Only email addresses approved by the family administrator may sign in. This page explains what Google and local data the service uses, why it uses it, how long records stay in the live system, and what manual backups can still retain.
What Google data MojoDojo accesses
MojoDojo uses Google identity data, calendar-list data, selected calendar event data, and organizer event operations only for the family calendar features described on the public site.
Identity data
The service reads your Google subject identifier, verified email address, and display or given name so it can identify an approved family member and associate that person with the correct local membership.
Calendar list data
The service reads calendar ID, calendar summary or name, time zone, access role, ownership, and primary-calendar status so you can choose which calendars to connect and so event creation is limited to calendars the organizer owns.
Selected event data
For calendars you choose to connect, the service can read event ID, iCalendar UID, start and end times, recurrence and original start times, transparency, status, visibility, title, location, description, attendees, and response state as allowed by your sharing mode and Google permissions.
Organizer event operations
When an organizer creates family plans, MojoDojo can create, read back, update, and cancel MojoDojo-created events only on a calendar the organizer owns, with Google attendee notifications enabled.
Google scopes and why each one is requested
- openid: confirms the identity of the person signing in.
- email: checks the approved email address for family access control.
- profile: displays the approved member's name in the family calendar.
- https://www.googleapis.com/auth/calendar.calendarlist.readonly: lists available calendars, access roles, ownership, and time zones so members can select calendars and so organizers are limited to owned calendars.
- https://www.googleapis.com/auth/calendar.events.readonly: reads the selected calendar events needed to project shared availability, event details when allowed, and invitation response state.
- https://www.googleapis.com/auth/calendar.events.owned: requested later only if a connected member chooses to create family plans on a calendar that member owns.
How MojoDojo uses the data
- Authenticate an approved member.
- List calendars for selection.
- Display authorized family-calendar projections.
- Calculate shared availability and possible trip dates.
- Create, update, and cancel organizer-controlled family plans.
- Produce user-requested .ics downloads.
The service does not interpret hidden, stale, or disconnected calendars as free time. When a calendar is missing, stale, or disconnected, availability is treated as unknown.
Sharing modes and family visibility
Each connected member chooses calendar-by-calendar sharing settings. Hidden calendars do not appear in the shared family cache. Busy-only sharing removes titles, locations, descriptions, and guest lists from the shared cache. Details sharing can show the event information allowed by Google and the chosen sharing mode.
Google-private events appear only as busy to other family members even when a calendar is otherwise shared with details.
Local storage, encryption, and freshness windows
The SQLite database stores approved membership, Google subject, name, email, encrypted Google credentials, granted scopes, connection state, fourteen days of sessions, calendar IDs, calendar names, time zones, ownership, sharing preferences, projected cached events, and references plus inputs for app-created plans.
Google credentials and short-lived OAuth state payloads are encrypted with AES-256-GCM using a separately mounted key. This is encryption at rest inside the application. The policy does not claim end-to-end encryption and does not claim the administrator is technically unable to access server data.
- Visible ranges
- Visible ranges refresh after approximately five minutes while they are in use.
- Cached event ranges
- Cached event ranges older than seven days are purged hourly.
- Sharing-mode changes
- Changing a calendar's sharing mode deletes that calendar's cached projections immediately before a later refresh.
- OAuth sign-in state
- OAuth state expires after ten minutes.
- Sessions
- Login sessions expire after fourteen days or are removed on logout.
Who processes data
Google processes authentication, Calendar API requests, and invitations. Cloudflare provides DNS, HTTPS edge protection, and Tunnel transport and may process ordinary request and security metadata under its services. The family administrator operates the home server and manual backups. No other calendar-content processor was found in the inspected application source.
Disconnection, deletion, and manual backups
Approved membership, sharing preferences, connected credentials, calendar references, and app-plan records remain in the live service until disconnection, administrator removal, or a supported deletion request removes the applicable records, as applicable.
Disconnecting Google removes local credentials, granted scopes, calendar selections, and cached events from the live database, and the application attempts to revoke the Google token. Revoking access through your Google Account permissions stops future Google API access but does not by itself delete local membership records or all backups.
The family administrator can remove a non-administrator membership, which also removes that member's live sessions, calendars, cache, and organizer plan records from the live database. You may also request local deletion by emailing [email protected].
Current manual backups are SQLite snapshots created by the family administrator. Manual backups do not have automatic expiration, so deleted records may remain in those backups until the administrator deliberately removes the backup files.
Existing Google events and invitations remain in Google after disconnection, membership removal, or local deletion unless the organizer separately edits or cancels them in Google. Downloaded .ics files are independent copies controlled by the downloader and do not receive future updates or cancellations.
Advertising, analytics, sale, and Google Limited Use
Google user data is not sold, is not used for advertising, is not used for analytics, and is not used to train AI models.
MojoDojo Family Calendar’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
The Limited Use statement does not replace the disclosures above about Google, Cloudflare, the family administrator, live storage, sharing modes, deletion behavior, or manual backups.