Subprocessors, Platforms & Intelligence Sources
Service subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (AWS Lightsail) | Production application hosting, API/webhook execution, application storage, and operational logging. | Account information, encrypted OAuth and mailbox credentials, calendar and optional email-scan processing, settings, rules, review and removal records, native purchase-verification records, and limited service/security data. |
| Stripe | Subscription checkout, recurring billing, payment processing, receipts, fraud prevention, and customer billing portal. | Name and email address where provided, payment information provided directly to Stripe, billing address where collected, Stripe customer and subscription identifiers, payment and subscription status, and transaction records. CalendarGuardian does not receive or store full card numbers or card security codes. |
Authorized calendar, identity, and commerce platforms
| Platform | Purpose |
|---|---|
| Microsoft identity / Microsoft Graph | User authentication, authorization, Microsoft calendar connectivity, change notifications, and authorized event actions and separately authorized Microsoft mailbox scanning or invitation cleanup. |
| Google identity / Google Calendar API | Google authorization, identity, Google Calendar event access, and push-notification channels for connected users, and separately authorized Gmail scanning or invitation cleanup. |
| Apple EventKit / App Store | Device Calendar authorization and actions; native subscription purchase, signed transaction verification, renewal, and restore-purchase state. |
| Android Calendar Provider / Google Play | Device Calendar authorization and actions; native subscription purchase, signed purchase verification, acknowledgment, renewal, and restore-purchase state. |
Optional Yahoo and iCloud mailbox connections
Yahoo Mail and Apple iCloud Mail provide IMAP access authorized with provider-generated app passwords. Selected mailbox folders and supported invitation data are processed on the CalendarGuardian server. Invitation cleanup can move matching invitation email to provider Trash folders after separate consent.
Threat-intelligence sources
| Source | Status | Use and data flow |
|---|---|---|
| CERT.PL Warning List | Enabled when service threat intelligence is on | CalendarGuardian downloads the public domain list and matches invitation-link domains locally. No calendar data is sent to CERT.PL. |
| URLhaus (abuse.ch) | Adapter available; disabled until credentials and commercial-use confirmation are configured | Malware-distribution URL/domain intelligence downloaded into the local cache. Subject to abuse.ch terms. |
| ThreatFox (abuse.ch) | Adapter available; disabled until credentials and commercial-use confirmation are configured | Recent malware IOC domains/URLs downloaded into the local cache. Subject to abuse.ch terms. |
Namecheap is used for CalendarGuardian.com domain registration and DNS management. DNS service ordinarily does not receive CalendarGuardian calendar content.
Account email delivery
Where account email is enabled, the configured Postmark or Resend service delivers account verification, password-reset, and connection security messages. Only the selected service receives the recipient address and message, including a one-time verification/reset link or the connected address and verification details. It does not send calendar-event or scanned-mailbox content.