Privacy Policy for Pinluma

Your privacy is important to us. Learn how we handle your data.

Last Updated: June 21, 2026

1. Introduction

Pinluma ("we", "our", or "the Application") is a calendar product developed by Expeditise LLC, available as a Windows/macOS desktop widget and as the Pinluma web and mobile apps (collectively, "the Service"). This Privacy Policy explains how we collect, use, store, and protect your information when you use Pinluma.

Desktop vs. cloud custody. On the desktop apps, your data — including provider OAuth tokens — stays on your device. The web and mobile apps require a server-side connection to your calendar provider, so for those products we hold an encrypted copy of your provider refresh token on our servers. Where this policy distinguishes the two, it says "desktop" or "web/cloud" explicitly.

By using Pinluma, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Calendar Data

When you connect your accounts to Pinluma, we access the following information:

2.2 AI Feature Data (Optional)

If you enable AI features and provide your own OpenAI API key:

2.3 Calendar Sharing Data (Optional)

If you enable calendar sharing:

2.4 Application Settings

We store local preferences including:

Important: Pinluma operates entirely on your local device. We do not transmit your calendar data to any external servers beyond what's necessary to sync with Google Calendar.

3. How We Use Your Information

Your information is used exclusively for the following purposes:

We do NOT:

4. How We Store and Protect Your Information

4.1 Local Storage (Desktop apps)

On the desktop apps, all your data is stored locally on your computer in the following locations:

4.2 Server-Side Custody (Web & mobile apps)

The web and mobile apps connect to your calendar provider on the server so your calendar can sync even when your device is offline. To do this we store, in our cloud (Amazon Web Services), only what is necessary:

You can disconnect a provider at any time, which deletes the stored refresh token and revokes our server-side access. See Section 7 for retention and deletion.

4.3 Security Measures

We implement industry-standard security practices:

4.4 Calendar Sharing

When you enable calendar sharing:

5. AI Features and OpenAI API

Pinluma offers optional AI-powered features that require your own OpenAI API key:

5.1 How AI Features Work

5.2 Data Sent to OpenAI

When you use AI features, the following may be sent to OpenAI:

5.3 Your Responsibilities

Important: AI features are completely optional. Pinluma works fully without AI capabilities if you prefer not to use them.

6. Google and Microsoft API Services

6.1 Google Calendar API

Pinluma's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google Limited Use disclosure. This applies to Google user data accessed by our web/cloud service as well as the desktop apps. Specifically:

6.2 Microsoft Graph API

When connecting Outlook/Microsoft Calendar, we comply with Microsoft's data handling requirements and the Microsoft Privacy Statement.

For both services:

7. Data Retention and Deletion

7.1 How Long We Keep Your Data

Desktop apps. Your calendar data is cached locally and automatically updated during sync operations. Cached events are retained on your device until you:

  • Sign out of your Google account within the application
  • Uninstall Pinluma
  • Manually delete the application data folder

Web & mobile apps. Server-side data is retained while your account is active. Disconnecting a calendar provider deletes its stored refresh token and synced data for that provider. Deleting your account removes your account record, provider tokens, and synced calendar data from our systems (subject to short operational/backup windows and any retention required by law).

7.2 How to Delete Your Data

On the desktop apps you can delete all your data at any time by:

  1. Opening Pinluma settings and clicking "Sign Out"
  2. Uninstalling the application from Windows
  3. Manually deleting %AppData%\Pinluma folder
  4. Removing OAuth access from your Google Account settings

On the web & mobile apps you can:

  1. Click "Disconnect" on a connected calendar to delete its server-side token and synced data
  2. Delete your account from account settings to remove all server-side data
  3. Revoke our access from your Google or Microsoft account settings

Note: Deleting your data from Pinluma does not affect your Google Calendar. Your events remain safely stored in your Google account.

8. Third-Party Services

Pinluma integrates with the following third-party services:

We do not use any other third-party services, analytics tools, or advertising platforms.

9. Children's Privacy

Pinluma is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

10. Your Rights

You have the right to:

  • Access Your Data: View all locally stored data in the %AppData%\Pinluma folder
  • Delete Your Data: Remove all application data at any time (see Section 6.2)
  • Revoke Access: Disconnect Pinluma from your Google account through Google's permission settings
  • Export Your Data: Your calendar data remains accessible in your Google Calendar account

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Displaying a notification in the application (for significant changes)

Your continued use of Pinluma after any changes indicates your acceptance of the updated policy.

Questions or Concerns?

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Email: privacy@expeditise.com
Website: https://expeditise.com
Company: Expeditise LLC