$ cat PRIVACY

Privacy Policy

Mysticals has no servers. Your accounts, passwords and calendar events travel only between your device and your calendar provider.

Effective September 25, 2026. This policy covers the Mysticals desktop app, the Mysticals terminal app (the mysticals npm package) and the website mysticals.sashkoratushnyi.com. Mysticals is an open-source project run by Oleksandr Ratushnyi (“we”). The source code is on GitHub, so every claim here can be checked.

What the apps handle

To show your calendars, the apps connect directly from your device to the providers you add:

Where this data lives:

None of this is sent to us or to anyone other than the provider it belongs to. We don’t operate a backend, and we can’t see your accounts or events.

Google user data

For Google accounts the apps request these scopes:

Google data is used only to provide these calendar features inside the app on your device. It is never transferred to us or to third parties, never sold, never used for advertising, and never used to train AI or machine-learning models. No person reads it.

Mysticals’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

To disconnect, remove the account in the app. That deletes its tokens and cached events from your device. You can also revoke access at any time at myaccount.google.com/permissions.

Anonymous usage stats in the apps

To know how many people use Mysticals, the apps send two events to PostHog, hosted in the EU:

Each event carries the app (desktop or terminal), its version, your OS and CPU architecture, and a random ID generated on your device. That’s all. No emails, names, server addresses, calendars or events. GeoIP lookup is disabled and PostHog is set to discard IP addresses.

To turn the stats off:

This website

The website counts page views and download-button clicks with PostHog (EU). It sets no cookies and stores nothing in your browser: analytics state lives in memory and is gone when you close the tab. There’s no session recording, and a Do Not Track signal turns analytics off. Fonts are loaded from Google Fonts, which receives your IP address as part of the request.

Other services the apps contact

These update checks send no personal data beyond what any HTTP request contains, like your IP address.

Deleting your data

Everything is on your device, so you’re in control. Remove an account in the app to delete its credentials and cache. To remove everything, delete the data folder:

We hold no copy of your data, so there is nothing for us to delete. The anonymous stats can’t be tied to you, but if you send us the random ID from the telemetry-id file in the data folder, we’ll delete its events.

Children

Mysticals isn’t directed at children under 13 and we don’t knowingly collect their data.

Changes

If this policy changes, we’ll update this page and its effective date. The history of every change is in the public repository.

Contact

Questions or requests: forcewizu@gmail.com.