§  Privacy Policy

Privacy Policy

Effective July 17, 2026 · Wallpaper Calendar, a DCG app

The short version

Wallpaper Calendar is a local-first desktop app. Your events live in files on your own computer. We run no servers that receive, store, or process your calendar data, we require no account, and we collect no analytics or telemetry.

Data stored on your device

Events, tasks, notes, settings, and your Pro license key are stored in plain files under your own user folder (%LOCALAPPDATA%\WallpaperCalendar on Windows, ~/Library/Application Support/WallpaperCalendar on macOS). They stay on your machine, are kept when you update or uninstall, and can be deleted by you at any time by removing that folder.

Google user data (optional Google Calendar sync)

If, and only if, you connect a Google account, the app syncs events two-way between your device and Google Calendar using the calendar.events permission. Specifically:

  • Google Calendar data is accessed solely to display and synchronize your events between the app on your device and your Google Calendar.
  • All processing happens on your device. Your calendar data is transmitted only between your computer and Google’s own API, never to us or any other party.
  • Sign-in tokens are stored locally on your device and can be revoked at any time via the Disconnect button in the app or at myaccount.google.com/permissions.
  • We do not sell, share, transfer, or use Google user data for advertising, and no human reads it.

Wallpaper Calendar’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

Sensitive data is protected with the following mechanisms:

  • Encryption in transit. Every network connection the app makes, to Google’s APIs, to our relay server, and to this website, uses HTTPS/TLS. No calendar data is ever sent over an unencrypted connection.
  • Google sign-in tokens. OAuth access and refresh tokens are stored only in a file inside your own operating-system user profile (%LOCALAPPDATA%\WallpaperCalendar on Windows, ~/Library/Application Support/WallpaperCalendar on macOS), protected by your OS user-account permissions. Tokens never leave your device, are never transmitted to us, and are deleted when you click Disconnect in the app or remove the app’s data folder. You can also revoke them at any time at myaccount.google.com/permissions.
  • No server-side storage of Google data. We operate no database, log, or cache of Google user data. Your Google Calendar events exist only on your device and in your Google account, so there is no copy of them for us to lose, leak, or disclose.
  • End-to-end encryption for shared calendars. If you use the optional shared-calendars feature, events, notes, and lists are encrypted on your device with AES-256-GCM before upload, using a key derived (SHA-256) from an invite code that is never transmitted to us. Our relay server stores only ciphertext it cannot decrypt. Google Calendar data is never placed in shared calendars by the app.
  • Access control. No DCG personnel can read your calendar data: local data never reaches us, and shared-calendar data is readable only by holders of the invite code. There is no administrative interface, master key, or recovery mechanism that can decrypt user content.
  • Data retention & deletion. Local data persists only on your device and is removed by deleting the app’s data folder. Shared-calendar ciphertext is deleted from the relay server when the calendar’s owner deletes the calendar in the app. We keep no backups of user content.
  • Incident notice. In the unlikely event of a security incident affecting the relay server, we would post notice on this website; note that shared-calendar content on that server is ciphertext and remains unreadable without invite codes, which we do not hold.

Shared calendars (optional)

If you create or join a shared calendar, the events in that one calendar sync through our relay server so other people you invited can see them. Those events are encrypted on your device before upload, using a key derived from the invite code, and the code itself is never sent to us: the server stores ciphertext it cannot read. We can see only technical metadata (calendar id, timestamps, blob sizes). Events outside shared calendars never leave your device. Leaving a shared calendar stops all syncing for it.

Purchases

Pro purchases are processed by Stripe; we never see your card details. The email you enter at checkout is used only to issue your license key, which itself is verified offline on your device: the app never contacts a license server.

Other optional connections

Features you can enable make direct requests from your device to: Open-Meteo (weather, sends your chosen city’s coordinates), iCal feed URLs you paste, Anthropic (AI assistant, only if you provide your own API key), and this website (update checks send no personal data). None of these are active until you turn the feature on.

Changes & contact

If this policy changes, the update will be posted here with a new effective date. Questions: contact@dcgapps.com.