WonderCal

Privacy Policy

Last updated: July 13, 2026

Who we are

WonderCal ("we", "us") is a family scheduling and routines app operated at wondercal.app. We help households coordinate calendars, routines, tasks, goals, and rewards.

What we collect

  • Account info: name, email, and profile photo you provide.
  • Household content: children, tasks, routines, goals, meals, rewards, and notes you create.
  • Google Calendar data: if you connect Google Calendar, we read your calendar list and upcoming events (read-only) on the calendars you select, solely to display them on your WonderCal dashboard.
  • Usage & device info: basic logs (IP, browser, timestamps) to keep the service running and secure.

Google User Data

When you connect your Google Calendar, WonderCal requests the https://www.googleapis.com/auth/calendar scope. This allows us to read your calendar list and upcoming events so we can display your family's schedule on your WonderCal dashboard. It also allows us to create events in your Google Calendar when you explicitly choose to sync a WonderCal event to Google Calendar.

WonderCal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell, share, or transfer Google user data to third parties, do not use it for advertising, and do not use it to train AI/ML models. Humans do not read Google user data except (a) with your explicit consent, (b) for security investigations, or (c) to comply with the law.

Storage & retention. WonderCal does not store a copy of your Google Calendar events. Events are fetched live from Google each time your dashboard loads and are only held in memory to render the page. We do store the OAuth tokens needed to make those requests (encrypted; see below) and the list of calendar IDs you selected. You can disconnect at any time from Settings → Permissions, which immediately deletes your stored tokens and revokes them at Google, or revoke access directly at myaccount.google.com/permissions.

How we protect your data

We apply the following technical and organizational safeguards to protect your information, including Google user data received via Google APIs:

  • Encryption in transit. All traffic between your browser, our servers, and Google's APIs is encrypted using TLS 1.2 or higher (HTTPS). We do not accept unencrypted connections.
  • Encryption at rest. All application data — including Google OAuth refresh tokens and access tokens — is stored in databases encrypted at rest using AES-256. Google OAuth access and refresh tokens are additionally encrypted at the application layer with AES-256-GCM before being written to the database, so the plaintext token value is never present in the database.
  • Access controls. Access to production systems is restricted to a small number of authorized personnel, protected by multi-factor authentication, and audit-logged. Row-Level Security in our database enforces that household data is only readable by members of that household.
  • Secret management. API keys, OAuth client secrets, and signing keys are stored in a managed secrets vault, never in source code, and are rotated when personnel changes occur.
  • Least-privilege scopes. We request only the Google Calendar scope required to display and create your events, and only for calendars you explicitly select.
  • Retention limits. Cached Google Calendar events are not stored — events are fetched live from Google on each request and only held in memory to render the page. When you disconnect Google Calendar, your stored OAuth tokens are revoked at Google and deleted from our database immediately.
  • No secondary use. Google user data is never used for advertising, sold, shared with third parties, or used to train AI/ML models, in line with the Google API Services User Data Policy Limited Use requirements.
  • Incident response. If we become aware of a security incident affecting your data, we will notify affected users without undue delay and cooperate with any required regulatory reporting.

How we share data

Your household data is visible only to parents in your household and (in limited form) to children you add. We use trusted infrastructure providers (hosting, database, email) under contract to operate the service. We never sell your data.

Your choices

  • Disconnect Google Calendar at any time in Settings → Permissions.
  • Export your data in Settings → Privacy.
  • Email support@wondercal.app to delete your account and all associated data within 7 days.

Children

WonderCal is designed for parents to manage on behalf of their families. Child profiles are created and controlled by a parent in the household.

Contact

Questions or requests? Email support@wondercal.app.