Private by product design.
Duplical asks for calendar access because it must read source events and maintain destination blocks. We minimize what is stored and shared.
Google permissions
Duplical requests basic identity information, read-only access to your calendar list, and event access so it can preview source events and maintain the destination blocks you authorize.
Encrypted Google credentials
Google refresh tokens are encrypted with authenticated encryption before database storage. Encryption keys live outside the database and support rotation.
Minimal event storage
Duplical stores provider identifiers, timestamps, fingerprints, mappings, and sanitized action reasons needed to reconcile events. Private-block rules do not require storing source descriptions, guest lists, locations, or conferencing data.
Managed-event identity
Private event markers and database mappings prevent duplicate loops. Tenant checks are applied in server-side data access, not only in navigation guards.
Current assurance level
This page describes safeguards implemented in the product. It does not claim an independent security certification. Google OAuth review and external legal and security review remain launch-readiness gates.