Duplical

Private by product design.

Duplical asks for calendar access because it must read source events and maintain destination blocks. We minimize what is stored and shared.

Google permissions

Duplical requests basic identity information, read-only access to your calendar list, and event access so it can preview source events and maintain the destination blocks you authorize.

Encrypted Google credentials

Google refresh tokens are encrypted with authenticated encryption before database storage. Encryption keys live outside the database and support rotation.

Minimal event storage

Duplical stores provider identifiers, timestamps, fingerprints, mappings, and sanitized action reasons needed to reconcile events. Private-block rules do not require storing source descriptions, guest lists, locations, or conferencing data.

Managed-event identity

Private event markers and database mappings prevent duplicate loops. Tenant checks are applied in server-side data access, not only in navigation guards.

Current assurance level

This page describes safeguards implemented in the product. It does not claim an independent security certification. Google OAuth review and external legal and security review remain launch-readiness gates.