Privacy Policy
This Privacy Policy explains how Harmonise collects, uses, discloses, stores, transfers, and protects personal data when you use our website, mobile application, calendar and planning features, integrations, and related services.
Using or accessing Harmonise means that you acknowledge this Privacy Policy and accept the Terms of Service. Questions about this Privacy Policy, personal data, data protection, or Harmonise's obligations under the Singapore Personal Data Protection Act can be sent to Harmonise through the Harmonise privacy contact channel.
Last updated:
Scope and who we are
This Privacy Policy describes how Cursive Pte. Ltd., a company incorporated in Singapore ("Harmonise", "we", "us", or "our"), handles personal data in connection with the Harmonise services.
The "Harmonise services" include the Harmonise marketing website, mobile applications, backend services, calendars, events, tasks, planning features, shared planning features, integrations, messaging features, subscription services, customer support, and other services that link to this Privacy Policy.
This Privacy Policy applies to Harmonise account holders, website and application users, participants in shared planning workflows, people who communicate with Harmonise through supported integrations, and people who contact us.
This Privacy Policy should be read together with ourTerms of Service and any additional notice shown when you use a particular feature or connect a third-party service.
Where Harmonise is available
Harmonise is operated from Singapore and is made available in supported jurisdictions around the world.
Harmonise is not currently offered or marketed to individuals in the European Economic Area ("EEA"), including the member states of the European Union, Iceland, Liechtenstein, and Norway. We may restrict registration, purchases, or use from unsupported jurisdictions.
Availability may also be restricted where necessary because of legal requirements, sanctions, payment-provider rules, application-store rules, third-party service limitations, or operational considerations.
If we expand Harmonise into a jurisdiction requiring materially different privacy disclosures or rights, we may provide additional or jurisdiction-specific privacy terms before offering the Service there.
Information we collect
The information we process depends on the features you use, the information you choose to provide, the people you interact with, and the external services you connect.
Account and profile information
We may process your name, email address, public username, profile image, password hash, email-verification status, connected sign-in identities, timezone, locale, week-start preference, date and time preferences, notification settings, privacy settings, and other account or profile settings.
If you sign in through a provider such as Google or Apple, we receive information that the provider makes available according to the permissions and choices shown to you.
Authentication and security information
We may process session identifiers, access and refresh credentials, trusted-device identifiers, verification records, account-recovery records, login information, security events, request identifiers, timestamps, IP addresses, browser or application information, and other information needed to authenticate users and protect Harmonise.
Calendar, event, and task information
Depending on how you use Harmonise, we may process calendar names and settings, events, tasks, subtasks, descriptions, notes, dates, times, durations, timezones, recurrence rules, reminders, completion status, priorities, locations, meeting links, attendees, organisers, attendance responses, availability, scheduling conflicts, free/busy information, and relationships between events and tasks.
People and group information
We may process friendships, contacts, invitations, group memberships, planning-space information, participation status, permissions, and information required to manage coordination between people.
Connected-service information
When you connect an external service, we may process provider account identifiers, calendar identifiers, event identifiers, permissions, authorization credentials, synchronization cursors, webhook information, reconciliation records, and information returned by that provider.
For integrations using CalDAV or similar authentication, this may include a server address, username, app-specific password, or other credential you provide to enable the connection.
Messaging information
If you use a supported messaging integration, we may process the messaging-platform identifier associated with you or the conversation, message text, commands, message identifiers, chat identifiers, timestamps, delivery state, and information required to link the messaging interaction to your Harmonise account.
Assistant and natural-language information
If you use assistant or natural-language features, we may process the text you submit, clarification responses, relevant dates and times, timezone, locale, selected calendar names, interpretation results, confirmation state, and information required to carry out the request.
Files and attachments
If you upload files, we may process the file contents together with filenames, media types, sizes, ownership information, upload status, storage identifiers, validation results, malware or security scanning results, and related metadata.
Subscription and transaction information
Harmonise offers paid subscriptions. We may process customer identifiers, product identifiers, transaction references, subscription state, entitlement information, purchase status, renewal state, expiry information, restore-purchase information, and other billing metadata supplied by an application store or subscription-management provider.
Where payment is processed through Apple, Google, or another payment provider, Harmonise generally does not receive your complete payment-card information.
Technical and operational information
We may process application version, operating system, device platform, browser information, installation identifiers, push tokens, synchronization state, network information, API activity, error information, performance information, security logs, and other technical information produced through normal operation of the Service.
Support and correspondence
If you contact us, we process the content of your communication and information needed to investigate and respond. This can include contact information, screenshots, diagnostic information, account details, and correspondence history.
Potentially sensitive information
Calendar events, tasks, locations, attendees, notes, attachments, messages, and other content can reveal sensitive or confidential matters even where Harmonise did not specifically request that type of information.
You should avoid entering highly sensitive information unless it is reasonably necessary for your use of Harmonise and you are permitted to provide it.
Where information comes from
We may receive information:
- directly from you when you create an account, enter planning information, configure settings, purchase a subscription, upload files, contact support, or otherwise use Harmonise;
- from other Harmonise users when they invite you, add you to an event or group, coordinate with you, or otherwise provide information about you through a shared feature;
- from services you connect, such as identity, calendar, meeting, messaging, notification, or subscription providers;
- from your device where information is needed for authentication, offline use, synchronization, notifications, or diagnostics; and
- from our systems and service providers through normal security, technical, billing, and operational activity.
How we use information
We use personal data where reasonably necessary to:
- create, authenticate, maintain, and secure accounts;
- provide calendars, events, tasks, reminders, and planning features;
- synchronize information across devices;
- synchronize supported information with services you connect;
- calculate calendar free/busy information and scheduling conflicts;
- support people, groups, invitations, and shared planning;
- send notifications and service communications;
- interpret assistant or natural-language requests you initiate;
- store, validate, scan, retrieve, and deliver files;
- process subscriptions, purchases, and entitlements;
- provide customer support;
- respond to privacy requests and complaints;
- detect and prevent fraud, abuse, spam, and security incidents;
- diagnose errors and maintain Service reliability;
- enforce our Terms of Service;
- maintain records reasonably required for security and compliance; and
- comply with applicable laws and valid legal requirements.
We may create aggregated or de-identified information that cannot reasonably identify an individual and use that information for product, security, operational, or analytical purposes, subject to applicable law.
We do not use private calendar, task, messaging, or assistant content for third-party behavioural advertising.
Singapore PDPA
As a Singapore organisation, Harmonise handles personal data in accordance with applicable obligations under Singapore's Personal Data Protection Act 2012 ("PDPA").
Notification and purposes
We aim to tell you the purposes for which personal data is collected, used, or disclosed at or before the time required by applicable law. This Privacy Policy provides our general notice, while additional notices may be presented for particular features.
Consent and other permitted processing
Where the PDPA requires consent, we collect, use, or disclose personal data with the required consent. The PDPA also permits processing in circumstances involving deemed consent or exceptions provided by law, and we may rely on those provisions where applicable.
Where another country's law applies, we process personal data under the permissions or lawful grounds required by that law.
Withdrawal of consent
Where processing depends on consent, you may withdraw consent with reasonable notice, subject to applicable law and contractual consequences.
If information is necessary to provide a requested feature, withdrawing consent for that processing may mean we can no longer provide the affected feature or, in some cases, the account.
Accuracy
We take reasonable steps to ensure personal data we use or disclose is accurate and complete where the information is likely to be used to make a decision affecting you or disclosed to another organisation.
You are responsible for keeping account information you control reasonably current.
Protection
We maintain reasonable security arrangements intended to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks.
Retention
We cease retaining personal data, or remove the means by which it can be associated with particular individuals, when retention no longer serves the purpose for which it was collected and is no longer necessary for legal or business purposes, subject to the exceptions described below.
Data Protection Officer
Harmonise has designated a Data Protection Officer ("DPO") responsible for overseeing our data-protection practices and handling privacy enquiries.
The DPO can be contacted at privacy@harmonisecal.com.
Calendar and meeting integrations
Harmonise can connect to supported external calendars and related services. Depending on platform availability and configuration, integrations may include Google Calendar, Microsoft Outlook Calendar, iCloud Calendar through CalDAV, Yahoo Calendar through CalDAV, generic CalDAV services, ICS imports or subscriptions, and supported meeting services including Google Meet, Microsoft Teams, Zoom, and Discord.
Separately, Harmonise may display calendars and events made available through the calendar database on your device. Device-calendar access uses operating-system calendar APIs rather than creating a direct Harmonise connection to the account or provider that supplied the calendar. See the Device calendar data section for details.
When you connect a calendar provider, Harmonise may access information made available under the permissions you grant, including calendar lists, calendar settings, events, event times, recurrence, reminders, attendees, organisers, locations, descriptions, meeting information, provider identifiers, and free/busy information.
Where supported, Harmonise may also send changes back to the provider.
OAuth integrations
For providers that use OAuth, Harmonise receives authorization credentials that permit us to access the provider within the permissions you granted. We use those credentials to provide, maintain, and secure the integration.
CalDAV integrations
A CalDAV provider may require a server address, username, app-specific password, or other credential. Harmonise uses that information to authenticate and perform the synchronization you requested.
ICS files and subscriptions
If you import an ICS file, Harmonise processes the calendar information in that file. If you subscribe to a remote calendar feed, Harmonise may periodically retrieve the feed from the address you provide.
A private calendar-feed URL can function like a password. Anyone who obtains the URL may be able to access the information exposed through the feed.
Disconnecting
When you disconnect a supported integration, Harmonise stops using that connection for future synchronization and removes, revokes, or makes stored authorization credentials unusable where supported.
Disconnecting a provider from Harmonise does not automatically delete information stored independently by that provider.
Google user data
If you connect a Google service to Harmonise, Harmonise accesses Google user data only through the permissions you grant and only as necessary to provide or improve user-facing Harmonise features that you request or use.
The Google data Harmonise can access depends on the Google services you connect and the permissions you approve during Google's authorization process. Harmonise does not access Google user data beyond the permissions granted to it.
Google Calendar data
If you connect Google Calendar, Harmonise may access Google Calendar event information available through the permissions you grant. Depending on the event and the functionality you use, this may include event titles, descriptions, start and end times, timezones, recurrence information, reminders, locations, attendees, organisers, attendance responses, conference or meeting information, event identifiers, and other event metadata made available through the Google Calendar API.
Harmonise uses Google Calendar data to provide calendar and planning functionality you request. This may include displaying your Google Calendar events in Harmonise, synchronizing supported event changes between Harmonise and Google Calendar, creating or updating events at your direction, identifying scheduling conflicts, determining availability, coordinating events and tasks around your schedule, and supporting calendar-first planning.
Where you authorize Harmonise to edit Google Calendar events, Harmonise may create, modify, or delete supported event information when you perform an action in Harmonise that requires the corresponding change in Google Calendar.
Google Meet data
If you choose to create or manage a Google Meet meeting through Harmonise, Harmonise may use the Google Meet API to create, modify, and retrieve metadata about Google Meet meeting spaces created through Harmonise.
Google Meet information processed by Harmonise may include meeting-space identifiers, meeting codes or joining information, meeting URIs, meeting-space configuration or settings that Harmonise is authorised to access, and other metadata returned by Google for a meeting space created through Harmonise.
Harmonise uses this information only to provide the Google Meet functionality you request, such as creating a Google Meet space for an event, associating the meeting with the relevant event, displaying meeting information, and making supported changes to a meeting space created through Harmonise.
The Google Meet permissions used by Harmonise for this functionality do not give Harmonise access to the audio or video contents of a Google Meet call, and Harmonise does not use these permissions to record or monitor the contents of Google Meet calls.
Google authorization credentials
When you authorize Harmonise to access a Google service, Google provides authorization credentials that allow Harmonise to access the permissions you approved. Harmonise may store and use those credentials where necessary to maintain the connection, perform synchronization, and provide the Google-connected functionality you requested.
Harmonise does not ask you to provide your Google password. Authentication is performed through Google's authorization process.
Storage of Google user data
Harmonise may store Google user data where reasonably necessary to provide the connected functionality. Depending on the features you use, this may include synchronized Google Calendar event information, Google Meet metadata, Google resource identifiers, synchronization state, and authorization credentials.
Google user data stored by Harmonise is subject to the security, access-control, retention, and deletion practices described in this Privacy Policy.
Sharing and transfer of Google user data
Harmonise does not sell Google user data. Harmonise does not transfer Google user data to advertising platforms, data brokers, information resellers, or other third parties for their own advertising, marketing, lending, or creditworthiness purposes.
We limit transfers or disclosures of Google user data to circumstances permitted by the Google User Data Policy and applicable law. This may include:
- processing or transferring information where necessary to provide or improve a user-facing Harmonise feature that you requested or use, with the required user authorization or consent;
- using service providers acting on behalf of Harmonise where their processing is necessary to operate the relevant user-facing functionality and is subject to appropriate contractual, security, and confidentiality requirements;
- accessing, processing, or disclosing information where necessary to investigate fraud, abuse, security incidents, or other threats to Harmonise or its users;
- disclosing information where required to comply with applicable law, regulation, court order, or a valid request from an authorised public authority; or
- transferring information as part of a merger, acquisition, or sale of assets where permitted under Google's policies and after obtaining any user consent required by those policies or applicable law.
Any employee, contractor, service provider, agent, or successor that is permitted to process Google user data on Harmonise's behalf is required to handle that information consistently with applicable Google user-data requirements and applicable law.
Human access to Google user data
Harmonise restricts human access to Google user data. We do not allow employees, contractors, or other personnel to read private Google user data except in circumstances permitted by Google's policies, such as:
- when you have given explicit permission for access to specific information, such as when it is reasonably necessary to investigate a support request;
- when information has been aggregated and anonymised for permitted internal operations;
- when access is reasonably necessary to investigate a security incident, fraud, abuse, or technical problem; or
- when access is required to comply with applicable law or a valid legal requirement.
Advertising, credit, and sale restrictions
Harmonise does not sell Google user data, use Google user data for targeted, personalised, interest-based, or retargeted advertising, or transfer Google user data to third parties for those purposes.
Harmonise does not use or transfer Google user data to determine creditworthiness or for lending purposes.
Artificial intelligence and machine learning
Harmonise does not use Google Workspace APIs or data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models.
Harmonise does not sell or transfer Google user data to third parties for the purpose of developing, improving, or training generalized or non-personalized artificial-intelligence or machine-learning models.
If Harmonise provides assistant or natural-language functionality, access to Google user data for that functionality remains subject to Google's Limited Use requirements and is limited to permitted user-facing functionality requested by the user.
Security of Google user data
Harmonise uses technical and organisational safeguards intended to protect Google user data against unauthorised access, use, disclosure, alteration, or loss. Depending on the system involved, these safeguards may include secure transport, access controls, encrypted provider credentials, ownership and authorization checks, logging, rate limiting, and restrictions on production access.
Google authorization credentials and Google user data are accessible only to systems and people that require access for an authorised purpose, subject to the controls described in this Privacy Policy.
Retention and deletion of Google user data
Harmonise retains Google user data only for as long as reasonably necessary to provide the Google-connected functionality you use, maintain security, comply with applicable legal requirements, or fulfil another purpose permitted under Google's policies.
When Google user data is no longer required for a permitted purpose, Harmonise deletes, anonymises, or otherwise removes the information from active systems in accordance with the retention and deletion practices described in this Privacy Policy, subject to limited retention that may be required for security, legal compliance, dispute resolution, or other lawful purposes.
Information contained in backups may remain until the applicable backup expires or is rotated out, as described in the Retention and deletion section of this Privacy Policy.
Disconnecting Google
You can disconnect your Google account from Harmonise using supported account or integration settings. You can also revoke Harmonise's access through your Google Account settings.
When you disconnect Google from Harmonise, Harmonise stops using that Google connection for future synchronization and removes, revokes, or makes stored Google authorization credentials unusable where supported.
Google user data that was previously synchronized or stored in Harmonise is handled according to the retention and deletion practices described above and elsewhere in this Privacy Policy. Disconnecting Harmonise does not automatically delete information stored independently by Google.
Google Limited Use requirements
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Microsoft user data
If you connect a Microsoft service to Harmonise, Harmonise accesses Microsoft user data only through the permissions you grant and only as necessary to provide the Microsoft-connected functionality you request or use.
The Microsoft data Harmonise can access depends on the Microsoft services you connect and the permissions you approve during Microsoft's authorization process. Harmonise does not access Microsoft user data beyond the permissions granted to it.
Microsoft account information
When you connect a Microsoft service, Harmonise may receive limited account information needed to identify and maintain the connection. Depending on the connection, this may include your Microsoft account identifier, email address or user principal name, account type, granted permissions, and related authorization information.
Harmonise uses this information to associate the Microsoft connection with your Harmonise account, verify that requests are made through the correct connected account, and determine whether the connected account supports the requested Microsoft functionality.
Microsoft Outlook Calendar data
If you connect Microsoft Outlook Calendar, Harmonise may access calendar and event information made available through the permissions you grant. Depending on the event and the functionality you use, this may include calendar names and identifiers, event titles, descriptions, start and end times, timezones, recurrence information, reminders, locations, attendees, organisers, attendance responses, meeting information, provider identifiers, and other event metadata made available through Microsoft Graph.
Harmonise uses Microsoft Outlook Calendar data to provide calendar and planning functionality you request. This may include displaying your Microsoft calendars and events in Harmonise, synchronizing supported event changes between Harmonise and Microsoft, identifying scheduling conflicts, determining availability, coordinating events and tasks around your schedule, and supporting availability and scheduling workflows.
Where you authorize Harmonise to edit Microsoft calendars, Harmonise may create, read, update, or delete supported events when you perform an action in Harmonise that requires the corresponding change in Microsoft Outlook Calendar.
Microsoft Teams meeting data
Microsoft Teams meeting access is authorized separately from the normal Microsoft Outlook Calendar connection. Connecting Microsoft Outlook Calendar does not by itself authorize Harmonise to create or manage Microsoft Teams online meetings.
If you choose to connect Microsoft Teams meeting functionality, Harmonise may access the limited Microsoft account and online-meeting information required to provide that functionality.
When you create or manage a Microsoft Teams meeting through Harmonise, Harmonise may send information from the relevant Harmonise event to Microsoft, including the meeting subject, start time, end time, and an identifier used to associate the Microsoft meeting with the corresponding Harmonise event.
Microsoft may return information such as an online-meeting identifier, joining URL, and other limited meeting metadata required for Harmonise to associate, display, retrieve, update, verify, or delete the meeting.
Harmonise uses this information only to provide the Microsoft Teams meeting functionality you request, including creating a meeting for an event, displaying its joining information, keeping supported meeting details aligned with the event, and making supported updates or deletions.
Harmonise does not use its Microsoft Teams integration to access, collect, monitor, or store the audio or video contents of Teams meetings, meeting recordings, transcripts, or in-meeting chat content. Harmonise does not record Microsoft Teams meetings through this integration.
Microsoft Teams online-meeting functionality requires a supported Microsoft work or school account. Availability may also depend on the Microsoft licences, organisation settings, and administrator policies applicable to that account.
Microsoft authorization credentials
When you authorize Harmonise to access a Microsoft service, Microsoft provides authorization credentials that allow Harmonise to exercise the permissions you approved. Depending on the connection, this may include access tokens, refresh tokens, granted permission information, and token-expiry information.
Harmonise may securely store and use these credentials where necessary to maintain the connection, synchronize supported information, and perform Microsoft actions you request.
Harmonise does not ask you to provide your Microsoft password. Authentication and authorization are performed through Microsoft's authorization process.
Storage of Microsoft user data
Harmonise may store Microsoft user data where reasonably necessary to provide the connected functionality. Depending on the features you use, this may include Microsoft account identifiers, synchronized calendar and event information, Microsoft Teams meeting metadata, Microsoft resource identifiers, synchronization state, granted permissions, and authorization credentials.
Microsoft user data stored by Harmonise is subject to the security, access-control, retention, and deletion practices described in this Privacy Policy.
Use, sharing, and advertising restrictions
Harmonise does not sell or rent information obtained through Microsoft APIs.
Harmonise does not use or transfer information accessed or obtained through Microsoft APIs for advertising or marketing purposes. This restriction also applies to information that has been aggregated, anonymised, or derived from Microsoft API data.
We limit access to and disclosure of Microsoft user data to circumstances reasonably necessary to provide the Microsoft-connected functionality you request, protect Harmonise and its users, comply with applicable law, or use service providers acting on our behalf.
Where a service provider processes Microsoft user data on behalf of Harmonise, its access is limited to what is reasonably necessary to perform its function and is subject to appropriate contractual, confidentiality, and security obligations.
Permissions and changes in processing
Harmonise uses Microsoft user data only within the permissions you grant. If Harmonise needs additional Microsoft permissions or materially changes how Microsoft user data is processed, Harmonise will request any additional authorization or consent required before using the data for the expanded purpose.
Where Microsoft data is synchronized into Harmonise, Harmonise uses synchronization processes intended to keep supported information current and to reflect supported updates, corrections, restrictions, or deletions received from Microsoft.
Security of Microsoft user data
Harmonise uses technical and organisational safeguards intended to protect Microsoft user data against unauthorised access, use, disclosure, alteration, or loss. Depending on the system involved, these safeguards may include secure transport, access controls, encrypted provider credentials, ownership and authorization checks, logging, rate limiting, and restrictions on production access.
Microsoft authorization credentials and Microsoft user data are accessible only to systems and people that require access for an authorised purpose, subject to the controls described in this Privacy Policy.
Retention and deletion of Microsoft user data
Harmonise retains Microsoft user data only for as long as reasonably necessary to provide the Microsoft-connected functionality you use, maintain security, comply with applicable legal requirements, resolve disputes, or fulfil another purpose described in this Privacy Policy.
When you disconnect a Microsoft connection through Harmonise, Harmonise stops using that connection for future Microsoft API access and removes or makes stored authorization credentials unusable where supported.
Information no longer required to provide the Microsoft integration is deleted or anonymised from active systems in accordance with our deletion processes, subject to limited retention that may be reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, enforcement, or backup rotation.
When you delete your Harmonise account, Microsoft user data associated with that account is handled through the account-deletion process described in this Privacy Policy and is deleted or anonymised from active systems as that process completes, subject to limited information that Harmonise is permitted or required to retain.
Information contained in backups may remain until the applicable backup expires or is rotated out, as described in the Retention and deletion section of this Privacy Policy.
Disconnecting Microsoft from Harmonise does not automatically delete information independently stored by Microsoft. Similarly, deleting or changing information through Microsoft does not necessarily delete related information that is independently stored in Harmonise unless the relevant change is received through synchronization or the information is removed through another applicable deletion process.
Your Microsoft data choices
You may disconnect your Microsoft account or Microsoft Teams connection from Harmonise using the available integration controls.
You may also manage or revoke permissions granted to Harmonise through Microsoft's account and application-consent controls. For a personal Microsoft account, Microsoft provides consent-management controls ataccount.live.com/consent/Manage. For a work or school account, Microsoft provides application-management controls atmyapps.microsoft.com.
Revoking Microsoft access prevents future Microsoft API access using the affected authorization, but it does not automatically delete information independently stored in Harmonise before access was revoked. That information remains subject to the deletion and retention practices described in this Privacy Policy.
You may contact our Data Protection Officer atprivacy@harmonisecal.comto request access to, correction of, or deletion of personal data Harmonise has obtained from Microsoft, subject to applicable law, identity verification, and any information we are permitted or required to retain.
Apple user data
Harmonise uses several Apple services for different purposes. These may include Sign in with Apple, iCloud Calendar through CalDAV, device calendar APIs provided by Apple, Apple Push Notification service, and App Store purchases.
These features are separate and do not automatically grant Harmonise access to one another. In particular, granting device-calendar permission on an Apple device does not connect your Apple Account or iCloud Calendar directly to Harmonise. The device calendar database may also contain calendars supplied by other accounts or services configured with the device.
Sign in with Apple
If you choose Sign in with Apple, Harmonise receives information made available by Apple and selected by you during the authorization process. Depending on what you choose to share, this may include an Apple-provided user identifier, a verified email address, and your name when Apple supplies it to Harmonise.
The email address provided by Apple may be your personal email address or a private relay address created through Apple's Hide My Email service.
Harmonise uses your Apple-provided user identifier as the stable identity for the Sign in with Apple connection. We use Sign in with Apple information to create or authenticate your Harmonise account, link an Apple sign-in method when you request it, reauthenticate supported sensitive actions, protect account security, and manage the Apple authorization lifecycle.
If you intentionally link Sign in with Apple to an existing Harmonise account, Harmonise associates the Apple identity with that account as part of the linking action you requested.
Apple private relay addresses
If you choose Apple's Hide My Email option, Harmonise may receive an address ending in Apple's private relay domain instead of your personal email address.
Harmonise treats that private relay address as the email address Apple chose to provide to us. Harmonise does not attempt to discover or infer the personal email address hidden behind an Apple private relay address.
You can manage email forwarding for a private relay address through your Apple Account settings. If you disable forwarding, messages that Harmonise sends to the relay address may no longer reach your personal inbox.
Sign in with Apple authorization credentials
When you authorize Sign in with Apple, Harmonise may exchange the Apple authorization code with Apple and receive authorization credentials required to securely establish and manage the Apple sign-in relationship.
Harmonise may securely store encrypted Apple authorization credentials where required to maintain the authorization lifecycle and support credential revocation when an Apple sign-in method is unlinked or a Harmonise account is deleted.
Harmonise does not receive or store your Apple Account password through Sign in with Apple.
Sign in with Apple sharing restrictions
Harmonise does not sell information obtained through Sign in with Apple or provide that information to advertising platforms, data brokers, or information resellers for their own advertising or marketing purposes.
Where a service provider processes Apple-related personal data on behalf of Harmonise, its access is limited to what is reasonably necessary to perform its function and is subject to contractual, confidentiality, and security requirements intended to provide the same or equivalent protection described in this Privacy Policy.
iCloud Calendar
Sign in with Apple and the Harmonise iCloud Calendar connection are separate features. Signing in to Harmonise with Apple does not give Harmonise access to your iCloud calendars.
The current Harmonise iCloud Calendar connection uses Apple's CalDAV service. To connect it, you provide the Apple Account email address or username used for the calendar connection and an app-specific password created for third-party access.
Harmonise does not ask you to provide your normal Apple Account password for an iCloud Calendar connection. The app-specific password is a separate credential that you can create and revoke through your Apple Account.
When you connect iCloud Calendar, Harmonise may access calendar and event information available through Apple's CalDAV service. Depending on the calendar and event, this may include calendar names and identifiers, event titles, descriptions, start and end times, timezones, recurrence information, reminders, locations, attendees, organisers, attendance responses, event identifiers, and other supported calendar metadata.
Harmonise uses iCloud Calendar information to display and synchronize your selected calendars and events, identify scheduling conflicts, determine availability, coordinate events and tasks around your schedule, and support calendar-first planning.
Where the iCloud calendar permits changes, Harmonise may create, update, or delete supported event information when you perform an action in Harmonise that requires the corresponding change in iCloud Calendar.
iCloud Calendar credentials
The app-specific password used for an iCloud Calendar connection is treated as an authentication credential. Harmonise encrypts the credential when stored and uses it only to authenticate supported requests to Apple's iCloud Calendar service.
When you disconnect the iCloud Calendar connection, Harmonise stops using that connection for future synchronization and removes, clears, or makes the stored connection credential unusable through its normal disconnect process.
You may also revoke the app-specific password through your Apple Account settings. Revoking the password prevents Harmonise from continuing to access iCloud Calendar using that credential.
Device calendars on Apple devices
On supported Apple devices, Harmonise uses Apple's device calendar APIs to access calendars made available through the device's calendar database for the Device calendars feature.
The device calendar database may contain calendars from different sources configured with the device. These may include local calendars, Exchange calendars, CalDAV or iCloud calendars, subscribed calendars, birthday calendars, and other calendar sources supported by the operating system. Access through the device calendar APIs does not mean that Harmonise has directly connected to the underlying calendar provider.
On iOS, reading existing calendar events requires Full Calendar Access. Harmonise requests this system permission only when you choose to enable Device calendars.
Although iOS describes the permission as Full Calendar Access, Harmonise uses it to read and display existing calendar information. Harmonise does not programmatically create, change, or delete device-calendar events through this feature.
Where supported, Harmonise may open a selected event in Apple's system Calendar interface. If the source calendar permits changes, you may choose to edit the event through that system interface. Those changes are made by you through the system Calendar interface rather than programmatically by Harmonise.
The information Harmonise reads, stores, and uses through Device calendars is described in the Device calendar data section of this Privacy Policy.
You can revoke or change Harmonise's access to calendars through the privacy or application settings on your Apple device. If access is removed, Harmonise can no longer read those calendars through the Device calendars feature.
Apple Push Notification service
On supported Apple devices, Harmonise may use Apple Push Notification service ("APNs") to deliver push notifications that you have permitted.
To provide push notifications, Harmonise may process and store the APNs device token associated with the Harmonise installation and provide Apple with that token together with the notification information required for delivery.
Notification content may include information relevant to the notification you requested or enabled, such as a reminder, invitation, task, event, account, or security message. Apple processes APNs delivery information according to Apple's own terms and privacy practices.
You can manage notification permission through Harmonise and your device settings. Where Harmonise detects that push permission has been withdrawn, it may disable the associated Harmonise push registration so that future notifications are no longer sent to that installation.
Security of Apple-related data
Harmonise uses technical and organisational safeguards intended to protect Apple-related personal data against unauthorised access, use, disclosure, alteration, or loss.
Depending on the information involved, safeguards may include encrypted authentication credentials, secure transport, access controls, ownership and authorization checks, short-lived authentication flows, logging controls, input validation, and restrictions on production access.
Retention and deletion of Apple-related data
Harmonise retains Apple-related personal data only for as long as reasonably necessary to provide the feature you use, maintain security, comply with applicable legal requirements, resolve disputes, or fulfil another purpose described in this Privacy Policy.
If you unlink Sign in with Apple from Harmonise or delete a Harmonise account associated with Sign in with Apple, Harmonise removes the local Apple sign-in relationship as part of the applicable account process and, where Harmonise holds the authorization required to do so, submits or queues revocation of the associated Apple authorization.
If Apple authorization cannot be revoked immediately because of a temporary provider or network failure, Harmonise may retain encrypted revocation information for a limited period so that revocation can be retried securely.
Disconnecting iCloud Calendar stops future synchronization using the affected connection. Previously synchronized calendar information stored in Harmonise is handled according to the retention and deletion practices in this Privacy Policy and applicable account-deletion processes.
Deleting or disconnecting information in Harmonise does not automatically delete information independently stored by Apple. Similarly, changes made directly through Apple may remain represented in Harmonise until the relevant synchronization or cleanup process occurs.
Information contained in backups may remain until the applicable backup expires or is rotated out, as described in the Retention and deletion section of this Privacy Policy.
Your Apple data choices
You can manage or stop using Sign in with Apple for Harmonise through your Apple Account settings. You can also manage private-email forwarding associated with Sign in with Apple through Apple.
You can manage or revoke an iCloud Calendar app-specific password through your Apple Account ataccount.apple.com.
You can manage push-notification permission through your Apple device settings. Device calendar permissions and choices are described separately in the Device calendar data section.
You may also contact our Data Protection Officer atprivacy@harmonisecal.comto request access to, correction of, or deletion of personal data Harmonise has obtained or stored in connection with Apple services, subject to applicable law, identity verification, and any information we are permitted or required to retain.
Yahoo user data
If you connect Yahoo Calendar to Harmonise, Harmonise accesses Yahoo Calendar information only as necessary to provide the calendar and planning functionality you request.
Harmonise connects to Yahoo Calendar using Yahoo's CalDAV service. The Yahoo Calendar connection does not use Sign in with Yahoo or a Yahoo OAuth authorization flow.
Yahoo Calendar connection
To connect Yahoo Calendar, you provide the Yahoo Account email address or username used for the calendar connection and a Yahoo-generated app password intended for use with third-party applications.
Harmonise does not ask you to provide your normal Yahoo Account password for a Yahoo Calendar connection.
The Yahoo app password is used only to authenticate supported requests to Yahoo Calendar's CalDAV service and to maintain the calendar connection you requested.
Yahoo Calendar data
When you connect Yahoo Calendar, Harmonise may access calendar and event information available through Yahoo's CalDAV service. Depending on the calendar, event, and functionality you use, this may include calendar names and identifiers, event titles, descriptions, start and end times, timezones, recurrence information, reminders, locations, attendees, organisers, attendance responses, provider event identifiers, and other supported calendar metadata.
Harmonise uses Yahoo Calendar information to display and synchronize your selected calendars and events, identify scheduling conflicts, determine availability, coordinate events and tasks around your schedule, and support calendar-first planning.
Where the relevant Yahoo calendar permits changes, Harmonise may create, update, or delete supported event information when you perform an action in Harmonise that requires the corresponding change in Yahoo Calendar.
Yahoo Calendar credentials
The Yahoo Account identifier and app password used for a Yahoo Calendar connection are treated as authentication credentials. Harmonise encrypts these credentials when stored and uses them only as necessary to provide and maintain the Yahoo Calendar connection.
Harmonise sends Yahoo Calendar credentials only to the supported Yahoo Calendar CalDAV service over secure connections. The credential values are not returned through normal Harmonise API responses.
Storage and security
Harmonise may store Yahoo Calendar information where reasonably necessary to provide the connected functionality. This may include synchronized calendar and event information, Yahoo calendar and event identifiers, synchronization state, and encrypted connection credentials.
Harmonise uses technical and organisational safeguards intended to protect Yahoo-related personal data against unauthorised access, use, disclosure, alteration, or loss. Depending on the information involved, these safeguards may include secure transport, encrypted credentials, access controls, ownership and authorization checks, bounded remote requests, and restrictions on production access.
Retention and deletion of Yahoo user data
Harmonise retains Yahoo Calendar information only for as long as reasonably necessary to provide the connected functionality you use, maintain security, comply with applicable legal requirements, resolve disputes, or fulfil another purpose described in this Privacy Policy.
When you disconnect Yahoo Calendar from Harmonise, Harmonise stops using that connection for future synchronization and removes, clears, or makes the Yahoo Calendar credentials stored by Harmonise unusable through its normal disconnect process.
Previously synchronized Yahoo Calendar information stored in Harmonise is handled according to the retention and deletion practices described in this Privacy Policy and the applicable account-deletion process.
When you delete your Harmonise account, Yahoo Calendar credentials and Yahoo Calendar information associated with that account are handled through the account-deletion process described in this Privacy Policy, subject to limited information Harmonise is permitted or required to retain.
Information contained in backups may remain until the applicable backup expires or is rotated out, as described in the Retention and deletion section of this Privacy Policy.
Disconnecting Yahoo Calendar from Harmonise does not delete calendars, events, or other information independently stored by Yahoo. Information retained by Yahoo remains subject to Yahoo's own terms and privacy practices.
Yahoo app-password revocation
Disconnecting Yahoo Calendar from Harmonise removes or makes unusable the copy of the Yahoo app password stored by Harmonise, but it does not itself delete that app password from your Yahoo Account.
If you also want Yahoo to invalidate the credential, you can delete the applicable app password through Yahoo Account Security. Changing your normal Yahoo Account password does not necessarily invalidate an existing Yahoo app password.
Your Yahoo data choices
You may disconnect Yahoo Calendar using the available Harmonise integration controls. You may separately manage or delete app passwords through Yahoo Account Security.
Revoking or deleting the Yahoo app password prevents Harmonise from continuing to access Yahoo Calendar using that credential. You may need to create a new Yahoo app password if you later choose to reconnect Yahoo Calendar.
You may contact our Data Protection Officer atprivacy@harmonisecal.comto request access to, correction of, or deletion of personal data Harmonise has stored in connection with Yahoo Calendar, subject to applicable law, identity verification, and any information we are permitted or required to retain.
Device calendar data
Harmonise may allow you to display calendars and events that the operating system makes available through the calendar database on your device.
Device calendars are different from calendar accounts that you connect directly to Harmonise. A calendar available through the device may originate from a local calendar or from an account or service configured with the operating system. Harmonise does not treat the device calendar's source information as proof that you have connected that provider directly to Harmonise.
Device-calendar permission
Harmonise accesses device calendars only after you grant the applicable operating-system permission.
On Apple devices, Harmonise uses calendar access provided by the operating system. Because Harmonise needs to read existing events, iOS requires Full Calendar Access even though Harmonise's Device calendars feature does not itself programmatically create, change, or delete calendar events.
On supported Android devices, Harmonise requests calendar read access for the Device calendars feature and does not request Android calendar write permission for this feature.
Calendar information read from your device
When you use Device calendars, Harmonise may read information that the operating system makes available for the calendars you select. Depending on the platform, calendar, and event, this may include:
- calendar names and identifiers;
- calendar source and account metadata exposed by the operating system;
- calendar colour and availability or modification capabilities;
- event identifiers and titles;
- start and end dates and times;
- timezones and all-day status;
- locations and notes;
- recurrence information;
- alarms and reminders associated with the event;
- organiser information;
- attendee names, email addresses, roles, and attendance status where available;
- event URLs;
- event status and occurrence information; and
- other supported metadata required to display the calendar or event.
Harmonise reads detailed information such as attendee information only where needed for the feature you are using. For example, attendee information may be loaded when you open the details of a particular device-calendar event rather than for every event displayed in the calendar overview.
How Device calendar data is used
Harmonise uses Device calendar data to display selected calendars and events alongside your Harmonise planning information and to provide context for the Device calendars feature.
The Device calendars feature does not treat a device calendar as a synchronized Harmonise calendar and does not use the device-calendar source to automatically create or link a Google, Microsoft, Apple, CalDAV, or other provider connection.
Local processing and storage
Device-calendar event records read through this feature are processed locally on your device. Harmonise does not upload those event records to Harmonise servers or copy them into the Harmonise server-synchronized calendar store.
Device-calendar events used for the calendar overlay are held temporarily in application memory and are refreshed from the operating system as needed. Harmonise does not persist the event contents as part of the Device calendars feature.
Harmonise may store the opaque identifiers of the device calendars you choose to display so that your selection can be remembered. Those identifiers are stored in account-scoped encrypted application storage on the device.
Harmonise may also store limited device-local permission state needed to determine whether calendar access has previously been granted, denied, or blocked. This permission metadata does not contain the contents of your calendars or events.
Editing device-calendar events
Harmonise does not programmatically create, change, or delete events through the Device calendars feature.
Where supported, Harmonise may hand a selected event to the operating system's calendar interface. If the underlying calendar permits changes, you may choose to edit the event in that system interface. Any resulting change is made through the operating system and the underlying calendar source rather than by Harmonise's Device calendars feature.
Calendar sources and external providers
A calendar exposed through the device calendar database may originate from an external provider or account configured on the device. That provider may separately synchronize, store, or process the calendar according to its own terms and privacy practices.
Harmonise's local access to a device calendar does not give Harmonise the credentials for the underlying account and does not by itself establish a direct server-to-server connection between Harmonise and that calendar provider.
Your Device calendar choices
You can choose which available device calendars Harmonise displays through the Device calendars settings.
You can change or revoke Harmonise's calendar permission through your operating-system or application settings. If permission is revoked, Harmonise can no longer read device calendars until access is granted again.
Signing out of Harmonise or clearing the relevant application data may remove locally stored device-calendar selections. Calendar events themselves remain controlled by the operating system and the calendar source that stores them.
Zoom user data
If you connect Zoom to Harmonise, Harmonise accesses Zoom user data only through the permissions you grant and only as necessary to provide the Zoom-connected functionality you request or use.
The Zoom data Harmonise can access depends on the permissions you approve during Zoom's authorization process. Harmonise does not access Zoom user data beyond the permissions granted to it.
Zoom account information
When you connect Zoom, Harmonise may receive your Zoom user identifier, email address, information about the permissions granted to Harmonise, and other limited account information required to establish and maintain the connection.
Harmonise uses this information to associate the Zoom connection with your Harmonise account and to confirm that requests to Zoom are made through the correct connected account.
Zoom meeting information
If you choose to create or manage a Zoom meeting through Harmonise, Harmonise may send information from the relevant Harmonise event to Zoom. Depending on the event and functionality you use, this may include the event title, description, start time, timezone, duration, and recurrence information.
Zoom may return meeting information such as the Zoom meeting identifier, joining URL, and other limited metadata required for Harmonise to associate the Zoom meeting with the relevant Harmonise event and subsequently retrieve, update, verify, or delete that meeting at your direction.
Harmonise uses this information only to provide the Zoom functionality you request, including creating a Zoom meeting for an event, displaying its joining information, keeping supported meeting details aligned with the event, and making supported updates or deletions.
Harmonise does not use its Zoom integration to access or monitor the audio or video contents of Zoom meetings, Zoom recordings, transcripts, or in-meeting chat content. Harmonise does not record Zoom meetings through this integration.
Zoom authorization credentials
When you authorize Harmonise to access Zoom, Zoom provides authorization credentials that allow Harmonise to exercise the permissions you approved. This may include access tokens, refresh tokens, permission information, and token-expiry information.
Harmonise may securely store and use these credentials where necessary to maintain the connection and perform Zoom actions you request.
Harmonise does not ask you to provide your Zoom password. Authentication is performed through Zoom's authorization process.
Storage of Zoom user data
Harmonise may store Zoom user data where reasonably necessary to provide the connected functionality. Depending on the features you use, this may include your Zoom account identifier, email address, authorization information, meeting identifiers, joining information, associated meeting metadata, and authorization credentials.
Zoom user data stored by Harmonise is subject to the security, access-control, retention, and deletion practices described in this Privacy Policy.
Sharing and transfer of Zoom user data
Harmonise does not sell or rent Zoom user data.
Harmonise does not use Zoom user data to create advertising or marketing profiles and does not disclose Zoom user data to advertising platforms, data brokers, or information resellers for their own advertising or marketing purposes.
We limit access to and disclosure of Zoom user data to circumstances reasonably necessary to provide the Zoom-connected functionality you request, protect Harmonise and its users, comply with applicable law, or use service providers acting on our behalf.
Where a service provider processes Zoom user data on behalf of Harmonise, its access is limited to what is reasonably necessary to perform its function and is subject to appropriate contractual, confidentiality, and security obligations designed to provide protection that is consistent with applicable Zoom requirements and applicable law.
Security of Zoom user data
Harmonise uses technical and organisational safeguards intended to protect Zoom user data against unauthorised access, use, disclosure, alteration, or loss.
Zoom authorization credentials are treated as authentication credentials and are accessible only to systems and people that require access for an authorised purpose, subject to the controls described in this Privacy Policy.
Retention and deletion of Zoom user data
Harmonise retains Zoom user data only for as long as reasonably necessary to provide the Zoom-connected functionality you use, maintain security, comply with applicable legal requirements, resolve disputes, or fulfil another purpose described in this Privacy Policy.
When you disconnect Zoom through Harmonise, Harmonise stops using that connection for future Zoom API access and removes, revokes, or makes stored authorization credentials unusable where supported.
Information no longer required to provide the Zoom integration is deleted or anonymised from active systems in accordance with our normal deletion processes, subject to limited retention that may be reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, enforcement, or backup rotation.
Disconnecting Zoom from Harmonise does not automatically delete information independently stored by Zoom. Similarly, deleting a Zoom meeting or other information through Zoom does not necessarily delete related information independently stored in Harmonise unless it is also deleted through Harmonise or another applicable deletion process.
Your Zoom data choices
You may disconnect your Zoom account from Harmonise using the available integration controls. You may also manage or revoke Harmonise's access through Zoom where Zoom provides that functionality.
You may contact our Data Protection Officer atprivacy@harmonisecal.comto request access to, correction of, or deletion of personal data Harmonise has obtained from Zoom, subject to applicable law, identity verification, and any information we are permitted or required to retain.
Deleting your Harmonise account is governed by the account-deletion process described in this Privacy Policy. Removing Harmonise does not delete information independently retained by Zoom under Zoom's own terms and privacy practices.
Discord user data
If you connect Discord to Harmonise, Harmonise accesses Discord data only through the permissions and authorization you grant and only as necessary to provide the Discord-connected functionality you request or use.
The Discord data Harmonise can access depends on the authorization scopes, server permissions, bot permissions, and functionality involved. Harmonise does not use Discord API data for purposes unrelated to the Discord functionality described in this Privacy Policy.
Connecting Discord
Connecting Discord involves authorizing Harmonise through Discord and installing the Harmonise bot into a Discord server that you are authorised to manage.
During installation, Harmonise requests Discord authorization that allows it to identify the person performing the installation, retrieve the Discord servers available to that person, verify that they have sufficient authority over the selected server, and install the Harmonise bot.
Discord may make basic account information available during this authorization process. Harmonise uses the installer's Discord user identifier to associate and validate the installation. Harmonise does not request the Discord email scope for this integration and does not ask you to provide your Discord password.
The Discord user OAuth access token used during installation is used to complete the authorization and verification process and is not retained by Harmonise after the installation process has completed. Ongoing Discord functionality is performed through the Harmonise bot rather than through the installer's user OAuth token.
Discord server and channel information
During installation, Harmonise may temporarily retrieve information about Discord servers available to the installer so that Harmonise can confirm the selected server and verify that the installer has sufficient authority to install the integration.
Harmonise does not retain the installer's complete Discord server list as part of the installation record.
For the Discord server selected for Harmonise, we may process and store information needed to operate and secure the integration. Depending on the configuration, this may include:
- the Discord application identifier;
- the selected Discord server or guild identifier and name;
- the Discord user identifier of the person who installed Harmonise;
- the selected voice or stage channel identifier and channel type;
- server, role, channel, and effective permission information needed to determine whether the Harmonise bot is authorised to perform a requested action;
- installation, disconnection, and cleanup state; and
- technical identifiers and metadata needed to maintain and secure the integration.
Harmonise may retrieve information about server roles and available channels where needed to verify the Harmonise bot's permissions and allow you to select or use a supported voice or stage channel.
Discord events and invitation links
If you choose to create or manage Discord functionality for a Harmonise event, Harmonise may send information from the relevant Harmonise event to Discord.
For a Discord Scheduled Event, this may include the event title, description, start time, end time, and the Discord channel in which the scheduled event is created.
If you choose to create a Discord invitation link, Harmonise may request an invitation for the selected Discord channel.
Discord may return information such as a scheduled-event identifier, invitation code, invitation expiry information, channel information, server identifier, and other limited metadata required to associate the Discord resource with the corresponding Harmonise event.
Harmonise uses this information to display joining information and to create, retrieve, update, verify, or delete supported Discord resources when required by actions you take in Harmonise.
Information Harmonise does not access
The Discord integration described in this section does not use Discord APIs to access private or direct messages, message content, message attachments, Discord email addresses, friend or connection lists, user presence information, or the audio contents of Discord voice or stage conversations.
Harmonise does not record or monitor Discord voice or stage conversations through this integration.
Use and sharing of Discord API data
Harmonise uses Discord API data only where necessary to provide, maintain, secure, or support the Discord functionality you request.
Harmonise does not sell, license, rent, or otherwise commercialise Discord API data. Harmonise does not disclose Discord API data to advertising networks, data brokers, or other advertising or monetisation services.
Harmonise does not use Discord API data to build profiles of Discord users, their identities, or their relationships with other Discord users, and does not use Discord API data for targeted advertising or marketing.
Harmonise does not mine or scrape Discord for data.
Harmonise does not use Discord message content to train artificial-intelligence or machine-learning models. The Discord integration described in this section does not access Discord message content.
We limit disclosure of Discord API data to service providers acting on behalf of Harmonise where processing is reasonably necessary to operate the relevant functionality, where disclosure is required by applicable law, or where you expressly direct the relevant information to be shared.
Service providers processing Discord API data on behalf of Harmonise are subject to appropriate contractual, confidentiality, and security obligations and may use the information only for the services they provide to Harmonise.
Security of Discord data
Harmonise uses technical and organisational safeguards intended to protect Discord API data against unauthorised access, use, disclosure, alteration, or loss.
Access to Discord API data is limited to systems and people that require access for an authorised purpose, subject to the controls described in this Privacy Policy.
The Harmonise Discord bot credential is an application credential controlled by Harmonise and is not a credential belonging to the Discord user who installs the integration. Harmonise does not ask users to provide Discord passwords, bot tokens, or other unnecessary Discord authentication secrets.
Retention and deletion of Discord data
Harmonise retains Discord API data only for as long as reasonably necessary to provide the Discord-connected functionality you use, maintain security, comply with applicable legal requirements, resolve disputes, or fulfil another purpose permitted under Discord's applicable developer requirements.
Harmonise deletes or anonymises Discord API data from active systems when retaining that information is no longer necessary for the Discord functionality provided by Harmonise, when the applicable user requests its deletion, when Discord requires its deletion, when Harmonise stops providing the relevant integration, or when deletion is otherwise required by applicable law.
Disconnecting or removing Harmonise from Discord
When you disconnect a Discord server through Harmonise, Harmonise begins cleanup of the associated Discord installation. This prevents the installation from being used for future Harmonise actions and, where applicable, causes the Harmonise bot to leave the selected Discord server.
As part of the cleanup process, Harmonise deletes or anonymises Discord API data that is no longer required from active systems. This includes Discord installation information, server and channel associations, installer identifiers, permission metadata, and Discord resource identifiers that no longer need to be retained, subject to limited information that Harmonise is permitted or required to retain for security, legal compliance, dispute resolution, enforcement, or similar lawful purposes.
If you remove the Harmonise app or bot directly from Discord, Harmonise stops future Discord operations for that server once Harmonise receives or detects the removal. Harmonise then begins the corresponding cleanup and deletion process for Discord API data that is no longer required.
Discord Scheduled Events, invitation links, server information, messages, and other information independently retained by Discord remain subject to Discord's own systems, terms, and privacy practices. Removing Harmonise does not require Harmonise to delete information independently controlled and retained by Discord.
Information contained in Harmonise backups may remain until the applicable backup expires or is rotated out, as described in the Retention and deletion section of this Privacy Policy. Backup information is not used for ordinary Discord integration activity, and relevant deletion state is reapplied if a backup is restored for disaster recovery.
Your Discord data choices
You may disconnect a Discord installation through the available Harmonise integration controls. A person with appropriate permissions in the relevant Discord server may also remove the Harmonise app or bot through Discord.
You may contact our Data Protection Officer atprivacy@harmonisecal.comto request access to, correction of, or deletion of personal data Harmonise has obtained from Discord, subject to identity verification, applicable law, and any information Harmonise is permitted or required to retain.
Deleting your Harmonise account also initiates cleanup of Discord installations associated with that account and deletion or anonymisation of Discord API data that is no longer required, subject to the limited retention described in this Privacy Policy.
People, groups, and shared planning
Harmonise may allow people to connect with other users, join groups, coordinate plans, send invitations, or otherwise collaborate.
What another person can see depends on the feature, relationship, permissions, privacy settings, and information intentionally shared.
Users should provide information about another person only where they have an appropriate reason and any permission required by law.
Telegram integration
Harmonise may allow you to connect or interact with Harmonise through Telegram.
When you communicate with Harmonise through Telegram, Telegram may provide Harmonise with information required for the interaction, such as a Telegram user or chat identifier, message content, message identifiers, conversation information, and timestamps.
We use this information to receive and understand your request, associate the interaction with your Harmonise account where linked, perform supported commands, return responses, maintain delivery and security records, and provide support where necessary.
If a Telegram message uses natural-language functionality, it may also be processed as described in the Assistant and AI processing section.
Disconnecting Telegram prevents the linked integration from being used for future Harmonise account actions, but it does not delete messages or information independently stored by Telegram.
Harmonise does not require your Telegram password or Telegram one-time password. Do not send those credentials to a Harmonise bot.
Assistant and AI processing
Harmonise may provide functionality that lets you describe a calendar, event, task, planning, or scheduling action using natural language.
When you intentionally use these features, Harmonise processes the text you provide and the context reasonably needed to interpret the request. Depending on the request, this can include reference dates and times, timezone, locale, or calendar display names.
The interpretation path may use Harmonise-operated logic and, where configured, OpenAI to process some assistant or natural-language requests.
Information sent to an external inference provider is intended to be limited to information needed for the requested feature. Harmonise is designed not to send provider passwords, OAuth access tokens, refresh tokens, or unrelated authentication secrets as assistant context.
We do not intentionally use private Harmonise calendar, task, messaging, or assistant content to train a generalized Harmonise artificial-intelligence model.
Where OpenAI is used to process an assistant or natural-language request, it processes the information according to the commercial or API terms, data-processing arrangements, and technical configuration applicable to the OpenAI service used by Harmonise.
Assistant results may be inaccurate. Where assistant output can result in a change to your information, Harmonise may use validation, permission checks, or confirmation steps before applying the change.
Files and attachments
If you upload profile images, event attachments, task attachments, or other files, we process those files so they can be associated with the relevant account or content and made available to authorised users.
Files may be processed through validation, malware-scanning, or security services. A file may be temporarily stored, rejected, quarantined, or removed if it fails an applicable security check.
Private files may be delivered using signed, temporary, or otherwise access-controlled URLs.
Device and offline storage
The Harmonise mobile app supports synchronized and offline use. Some account and planning information may therefore be stored locally on a device as well as on Harmonise servers.
Mobile applications may use a local database together with secure or application storage for authentication information, device identity, preferences, synchronization state, and related data.
Local copies can contain calendars, events, tasks, synchronization changes, conflicts, and related metadata.
Signing out, uninstalling the mobile app, clearing local app data, or completing account deletion may affect local information differently depending on synchronization state.
Notifications and communications
Harmonise may send verification, password-reset, security, invitation, reminder, planning, subscription, account, and support communications.
Messages may be delivered through email, push notification, the Harmonise inbox, or a supported messaging integration.
We may use third-party delivery providers to send these communications and provide them with information reasonably required to deliver and manage the message.
You may control supported optional notification categories through product or device settings. Account-security, transactional, legal, or other necessary communications may still be sent where appropriate.
Where we send marketing communications, we comply with applicable marketing, telecommunications, and Singapore Do Not Call requirements where those requirements apply.
Diagnostics and analytics
We use technical and operational information to maintain security, investigate failures, measure reliability, and improve performance.
Our infrastructure may generate request logs, access records, security events, performance information, error information, and similar operational records.
Where enabled, Harmonise may use a diagnostics provider such as Sentry to help identify errors and performance problems.
Harmonise may also calculate planning summaries, scheduling statistics, or similar information from calendar and task information in order to provide product functionality to you.
We do not use private planning content for third-party targeted advertising.
Payments and subscriptions
Harmonise offers paid subscriptions. Purchases may be processed through supported application stores or other payment channels.
Harmonise may use RevenueCat to manage subscription status and feature entitlements for the mobile application.
We may receive a customer identifier, product identifier, entitlement, transaction reference, purchase status, subscription status, renewal information, expiry information, and related billing metadata.
Where a payment is processed by Apple, Google, or another payment provider, that provider handles payment information according to its own privacy policy. Harmonise generally does not receive complete payment-card details.
Deleting your Harmonise account does not automatically cancel a subscription billed by an application store or other external marketplace.
Service providers and third parties
A service you choose to connect to Harmonise is different from a service provider that Harmonise engages to operate the Service.
User-connected services
Depending on availability, services you choose to connect or interact with may include Google, Microsoft, Apple, Yahoo, Zoom, Discord, Telegram, other meeting providers, CalDAV services, ICS feed providers, application stores, and other integrations.
Those providers independently process information according to their own terms and privacy policies.
Harmonise service providers
Depending on our production configuration, Harmonise may use third parties for cloud infrastructure, application hosting, database hosting, storage, security scanning, email delivery, push notifications, error diagnostics, subscriptions, and inference.
Not every provider processes information about every user. A provider receives information only when its service is used for the relevant feature or operation.
We may replace or add providers that perform comparable functions. We update our disclosures where a change materially affects how personal data is processed.
Maps and location services
Harmonise provides optional map and location functionality. Depending on your device and operating system, Harmonise may use Google Maps Platform services on Android and Apple Maps or MapKit on Apple devices.
Information used for location features
When you use location functionality, Harmonise may process information such as the location-search text you enter, the area of the map being viewed, a location or place you select, provider location identifiers, and information needed to associate a confirmed location with an event.
If you grant Harmonise foreground location permission, Harmonise may also access your device's current or recently determined location, including approximate or precise latitude and longitude depending on your operating-system settings and the permission you grant.
Where you have already granted location permission, Harmonise may use that permission when you open supported location functionality to determine your location, center or bias the map, or provide current-location functionality.
You can deny or revoke device location permission through your operating-system settings. Location search that does not require your device's current location may remain available where supported.
How we use location information
We use location-related information to provide features you request, including displaying maps, searching for places, suggesting nearby locations, resolving a selected place or address, centering or biasing a map, allowing you to select a map location, and associating a location with an event.
If you choose to save location information with an event, that event-location information is processed as part of your Harmonise event data and is subject to the retention, security, synchronization, and deletion practices described in this Privacy Policy.
Google Maps and Google Places
On supported Android devices, Harmonise may use Google Maps Platform services, including Google Maps and Google Places.
When you use these features, information necessary to perform the request may be transmitted to Google. Depending on the feature, this can include location-search terms, map or Places request information, IP address, the geographic area relevant to a search, location coordinates used for the request, and information about the place you select.
Google processes information it receives through Google Maps Platform in accordance with the Google Privacy Policy.
For a location selected through Google Places, Harmonise is designed to retain the user's own event-location text and a Google Place ID where required for the feature rather than indefinitely retaining Google-provided Places coordinates or other Google Maps content unless such retention is permitted by the applicable Google Maps Platform terms.
Apple Maps and MapKit
On supported Apple devices, Harmonise may use Apple Maps and MapKit to display maps, search for places, and resolve locations.
When Apple Maps functionality is used, Apple may receive information necessary to provide that functionality. Depending on the feature and your settings, this can include the time and context of a request, search terms, the area of the map being viewed, device and software information, and device location where location access has been authorised.
Apple describes its handling of this information inApple Maps & Privacyand the Apple Privacy Policy.
Harmonise uses Apple Maps information in accordance with the applicable Apple developer and MapKit requirements. Apple Maps data returned for search and map functionality is not retained by Harmonise beyond what Apple permits. Where Apple permits a provider location identifier to be stored, Harmonise may retain that identifier to support the location functionality you requested.
Current location
Device current-location functionality is separate from place-search services.
When you choose to use current-location functionality, or when you have previously granted foreground location permission and open a feature that uses that permission, Harmonise may obtain your device's current or recently determined coordinates using the operating system's location services.
If you choose to confirm your own current location as an event location, Harmonise may store the location information you selected as part of that event. Harmonise does not request background location access for this location-picker functionality.
You can withdraw location permission at any time through your device settings. Revoking permission prevents Harmonise from obtaining new device-location information through that permission until access is granted again.
Retention and deletion
We retain personal data only for as long as reasonably necessary to provide Harmonise, maintain security, fulfil the purposes described in this policy, comply with legal obligations, resolve disputes, and maintain legitimate business records.
Retention periods vary depending on the type and sensitivity of information, the feature involved, whether an account remains active, security needs, contractual requirements, and applicable law.
Account deletion
When an account-deletion request is confirmed, Harmonise may disable account access and revoke sessions before final cleanup occurs.
The applicable deletion or recovery period is shown through the account-deletion workflow. After that process completes, account-owned personal data is deleted or anonymised from active systems, subject to lawful or necessary retention.
We may retain limited information for security, fraud prevention, legal compliance, accounting, dispute resolution, enforcement, or legal claims where applicable.
Backups
Information in backups may not be removed at the same moment as information in active systems. Backup copies are removed through the applicable backup expiration and rotation process.
Backups are intended for service recovery rather than ordinary access. Where a backup containing previously deleted information is restored for disaster recovery, we take reasonable steps to reapply relevant deletion state.
Shared records
Some records involving more than one person may need to remain for another user's legitimate workflow. Where appropriate, we may remove or anonymise your account-specific information while preserving another user's event or coordination record.
External providers
Deleting information from Harmonise does not automatically delete information independently stored by a connected calendar, messaging provider, application store, or other external service.
International transfers
Harmonise is operated from Singapore, and some service providers or connected services may process personal data outside Singapore.
Where the Singapore PDPA's Transfer Limitation Obligation applies, we take appropriate steps to ensure that personal data transferred outside Singapore receives a standard of protection comparable to the protection required under the PDPA.
Depending on the transfer, safeguards may include legally enforceable contractual obligations, applicable law, recognised certifications, or other mechanisms permitted under the PDPA.
If you deliberately connect a third-party service, the provider may process information in countries in which that provider operates. The provider's own privacy policy also applies to its independent processing.
Security
We use technical and organisational safeguards intended to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss, or similar risks.
Depending on the system involved, safeguards may include password hashing, server-side session validation, trusted-device verification, access controls, encrypted provider credentials, secure transport, signed or temporary file access, ownership checks, input validation, rate limiting, logging, and account-deletion controls.
Access to production information is limited according to operational need and access control.
No method of storing or transmitting information can be guaranteed to be completely secure.
If a data breach occurs, we assess and handle notification obligations under the Singapore PDPA and any other applicable law.
More information about our security approach may be available on theHarmonise Security page.
Your privacy rights
Your rights depend on the laws that apply to you and the circumstances of the processing.
Singapore access and correction rights
Subject to exceptions under the PDPA, you may request access to personal data about you that Harmonise holds and information about how it has been used or disclosed within the applicable period.
You may also request correction of personal data that is inaccurate or incomplete, subject to applicable exceptions.
Withdrawal of consent
Where processing depends on consent, you may withdraw that consent with reasonable notice. We will inform you of reasonably foreseeable consequences where required.
Other jurisdictions
Depending on applicable law, you may also have rights relating to deletion, restriction, objection, portability, information about disclosures, or complaints to a privacy regulator.
Product controls
Harmonise may allow you to edit profile information, change notification or privacy settings, disconnect integrations, revoke supported links, manage subscriptions, and request account deletion.
Identity verification
We may need to verify your identity before responding to a request involving personal data or account security.
Children
Harmonise accounts are intended for people who are at least 18 years old and legally capable of entering into the Terms of Service.
We do not knowingly offer Harmonise accounts to children under 18.
If we learn that a person under 18 has created an account contrary to these Terms, we may take appropriate steps to restrict or delete the account and associated personal data, subject to applicable law.
A parent or guardian who believes a child has provided personal data to Harmonise can contact our DPO.
Changes to this policy
We may update this Privacy Policy as Harmonise changes, our providers change, or legal requirements evolve.
When we update it, we will update the "Last updated" date shown on this page.
If a change materially affects how we handle personal data, we will provide additional notice where appropriate.
Where applicable law requires consent to a new processing activity, an update to this Privacy Policy will not by itself substitute for that consent.
Data Protection Officer and contact
Harmonise has designated a Data Protection Officer to oversee our personal-data protection practices and respond to privacy enquiries, access and correction requests, withdrawals of consent, and privacy complaints.
Data Protection Officer and privacy contact:privacy@harmonisecal.com
When contacting the DPO, please provide enough information for us to understand your request. Do not send passwords, one-time passwords, recovery codes, or other unnecessary authentication secrets by email.
We may request reasonable information to verify your identity before responding to a request involving personal data.