Privacy Policy
Last updated 3 September 2026
The short version
- Increment runs on your device. Your calendar, tasks and goals are stored there, and the app works with no account at all.
- If you sign in, a copy is kept so your other devices can see it. It is never read, mined or sold.
- If you connect a Google or Outlook calendar, it is read only — never written to — and only the calendars you tick.
- The app itself has no analytics, no tracking, no advertising, and no third-party scripts.
- This website uses Google Analytics. See section 2 and section 10.
- You can disconnect a calendar, or delete everything, at any time.
1. Who is responsible for your data
Increment is run by Stefany Nizamova, a sole trader based in the United Kingdom. For the purposes of the UK GDPR and the Data Protection Act 2018, I am the data controller for the personal data described in this policy.
Contact: [email protected]
2. What data Increment holds
| What | Why |
|---|---|
| Your email address | Only if you create an account. It is how sign-in links are sent and how your devices find the same account. |
| A random device identifier | Generated on your device. It is shown to you as a list of your own devices, and is never used to refuse anything. |
| Your licence key and its activation id | To check that your licence is valid. Payment itself is handled by Lemon Squeezy — I never see your card details. |
| Your calendar contents | Tasks, events, goals, projects, journal entries and logged time. This is the app. It lives on your device, and is copied to your account only if you sign in. |
| Connected calendar data | Only if you connect Google or Outlook. See section 3. |
| A message you send me | Only if you write one in the app's help panel. It reaches me as an email, with the address you give for a reply if you give one, and the email address of the account signed in on that device if there is one — so that a report about syncing can be answered. |
There is no analytics, no telemetry and no tracking of any kind — no pixels, no session recording, no advertising identifiers, and no third-party scripts in the application itself.
This website, increment-app.com, is a separate, static site and does use Google Analytics to see how many people visit, which pages they read, and which buttons and links they click. See section 10 for what it sets and how to opt out.
3. Connected calendars, and Google user data
Connecting a calendar is entirely optional, and Increment is fully usable without it. If you do connect one, this is exactly what happens.
What is requested
| Permission | What it is for |
|---|---|
calendar.events.readonly (Google)Calendars.Read (Microsoft) | To read the events on the calendars you tick, so the scheduler knows when you are already busy. |
calendar.calendarlist.readonly (Google) | To show you the list of your calendars so you can choose which ones count. |
openid, email | To show you which account is connected, and to recognise the same account if you reconnect. |
Every one of these is read-only. Increment has no ability to create, change or delete anything in your Google or Outlook calendar, and no code in it does so.
What is done with it
Events from the calendars you tick are turned into blocks of busy time, so that when Increment schedules your flexible work it does not book over a meeting. That is the entire purpose. Event titles and times are shown to you on your own calendar in the app.
An event's description and its meeting join link are also read and stored, so that you can see what a meeting is about and join it from Increment. The description is converted to plain text and shortened to its first 2,000 characters; formatting, images and anything embedded in it are discarded and never stored. A link is treated as a join link only when it points at a known meeting service, so ordinary links inside an invitation are not singled out or treated as anything special.
Where the invitation prints a meeting ID and passcode, those are kept as
well, so that you can join from a phone or a meeting room where the link is no use. Please
be aware of what that means: taken together, what Increment stores about a meeting is
enough to join it. It is held in the same places, and protected in the same ways, as the
rest of your calendar — but if that is not a trade you want to make, do not connect
the calendar, and use the .ics import instead.
Attendee lists are still discarded and never stored. Increment does not read, keep or show who else is invited to your meetings.
Descriptions and join links live in exactly the same places as the rest of your calendar: on your device, and in your account's private store if you have signed in (see section 4). Disconnecting a calendar removes its events, and their descriptions and links with them.
Limited Use
Increment's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, data obtained from your Google or Microsoft calendar is:
- never sold, rented or shared with anyone;
- never used for advertising, profiling or market research;
- never used to train machine-learning or AI models;
- never read by a human, except where you have explicitly asked me to look at something in order to help you with a support problem, or where the law requires it.
To be straightforward about that last one: as the person who operates the service I can technically reach what is stored, in the same way anyone running a service that holds data can. That is a capability, not a practice — there is no tool that surfaces your calendar to me, nothing is reviewed, and nothing is analysed. Where I say data is not read, I mean it is not read, not that it would be impossible for me to.
4. Where it is stored, and in what form
| Where | Holds |
|---|---|
| Your device | Your whole calendar, in the browser's local storage. This is what the app reads to draw the screen. A device with no account keeps everything here and sends nothing anywhere. |
| Your account's private store (Cloudflare, one isolated store per account) | A copy of your records, if you sign in, so a second device can catch up. The server does not interpret them. They are not encrypted in a way that hides them from me as the operator. |
| The account directory (Cloudflare D1) | Your email address, your devices, licence status, and — if you connected a calendar — the provider account address, the calendar names, and which ones you ticked. |
Credentials
- Sign-in links and session tokens are stored only as an irreversible SHA-256 hash. A copy of the database is not a set of working logins.
- Calendar access tokens must be reusable, so they cannot be hashed. They are encrypted with AES-256-GCM. The encryption key is held separately from the database, in Cloudflare's secret store, and is never written into it — so a copy of the database alone cannot be used to reach your calendar.
- Your card details are never seen or held by Increment at all. Lemon Squeezy handles payment.
5. Lawful bases for processing
- Performance of a contract — holding your email address, licence status and synced records so that the product you bought works across your devices.
- Consent — reading a connected Google or Outlook calendar. You give it on the provider's own consent screen, and you can withdraw it at any time (section 8) without affecting anything else.
- Legitimate interests — keeping the service secure and preventing abuse, such as rate-limiting sign-in emails so the service cannot be used to send unwanted mail.
6. Who else is involved
I use a small number of providers, each doing one job. None of them is permitted to use your data for their own purposes.
| Provider | Role |
|---|---|
| Cloudflare | Hosting, and the storage described in section 4. |
| Resend | Delivers sign-in emails, and the messages you send from the app's help panel. Receives your email address and what is being sent. |
| Lemon Squeezy | Merchant of record. Handles payment, invoicing and licence keys. |
| Google · Microsoft | Only if you connect a calendar, and only as the source you have asked Increment to read. |
| Google Analytics | Website visits to increment-app.com only — not the app. See section 10. |
International transfers. These providers may process data outside the United Kingdom, including in the United States. Where that happens, transfers are covered by the safeguards those providers offer — the UK International Data Transfer Addendum or Standard Contractual Clauses.
7. How long it is kept
- Your records — for as long as your account exists, or until you ask me to erase them.
- Records you delete — the contents are removed, but a marker saying "this was deleted" is kept indefinitely so that a device which has been offline for a long time still learns about the deletion rather than resurrecting the record. The marker holds an identifier and a timestamp, not the thing you deleted. It goes when the account does.
- Sign-in links — 15 minutes, and destroyed the moment one is used.
- Sessions — 90 days, or until you sign out.
- Calendar connections — until you disconnect, at which point the row and its encrypted tokens are deleted.
- Events imported from a connected calendar — removed from your device as soon as you untick the calendar or disconnect the account.
- Messages you send me — kept in my mailbox while they are useful: to answer you, and to fix what you reported. Ask and I will delete one.
8. Disconnecting and deleting
- Untick a calendar — Settings → Connected calendars. Its events are removed from your calendar immediately.
- Disconnect an account — the same screen. The stored tokens are deleted and every event that came from it is removed from your device. For Google, Increment also asks Google to revoke the access; if Google cannot be reached at that moment the disconnection still goes ahead on my side, so use the link below if you want to be certain. Microsoft offers no equivalent revocation endpoint, so for Outlook the link below is the way to withdraw access at the source.
- Revoke at the source — you can withdraw access yourself at any time at myaccount.google.com/permissions or account.live.com/consent/Manage.
- Delete everything — email [email protected]. I will erase your account, its stored records and any calendar connections, and confirm when it is done. This is done by hand at present, so allow a few days; it is within the one month the law allows. Deleting your account does not touch the copy on your own device — that one is yours, and you remove it by clearing the app's data or uninstalling.
9. Your rights
Under the UK GDPR you have the right to:
- ask what personal data I hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing;
- receive your data in a portable form;
- withdraw consent at any time, where processing relies on it.
Email [email protected] and I will respond within one month. If you are unhappy with how I have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
10. Cookies
The app sets one cookie, and only if you sign in: a session cookie that keeps you signed in. It is strictly necessary, cannot be read by JavaScript, and is not used to track you.
This website sets cookies from Google Analytics, used to see how many people visit, which pages they read, and which buttons and links they click — for example, which pricing plan or which call-to-action gets pressed. It is not used to identify you personally, and Increment does not use it for advertising. You can opt out with the Google Analytics opt-out browser add-on, or block it with a browser extension or your browser's tracking-protection settings.
11. Children
Increment is not intended for children under 13, and I do not knowingly collect their data.
12. Changes to this policy
If this policy changes in a way that materially affects you, I will say so in the app or by email before the change takes effect. The date at the top always reflects the current version.
13. Contact
Stefany Nizamova
United Kingdom
[email protected]