InstaCal

Privacy Policy

Effective September 8, 2026

InstaCal is built to be useful without building a profile about you. This policy explains what the InstaCal apps for Mac, iPhone, iPad, and Apple Watch access, when they connect to other services, and the choices you control.

1. The short version

InstaCal is developed by Higher Bar Apps. We do not operate an InstaCal account service or a server that receives your calendars, reminders, contacts, location, or usage history. We do not sell personal data, show ads, track you across apps or websites, or use your activity for analytics.

InstaCal's Apple privacy manifest declares no tracking and no data collected. The app uses Apple's UserDefaults API only to save its own preferences on your device.

Some features make network requests to services you choose, such as Apple, Google, Microsoft, a CalDAV server or calendar feed you add, Todoist, Zoom, The Weather Company, or Maps. Those requests go from your device to the selected service; they do not pass through a Higher Bar Apps server. The two things the app sends to us are a feature request you choose to write in Settings → Request a Feature, and a stock-photo search or image description you type in the countdown editor, both described in section 3.

2. Information InstaCal can access on your Apple devices

InstaCal asks Apple for permission only when a feature needs it. You can decline a permission or change it later in System Settings or Settings. Depending on the features you use, InstaCal may request:

  • Calendars: full calendar access lets InstaCal display, create, edit, and delete events in the calendars available through Apple Calendar.
  • Reminders: full reminders access lets InstaCal display, add, edit, and complete Apple Reminders.
  • Contacts: contact access lets InstaCal autocomplete people when you add invitees to an event. If you add an invitee, that attendee information becomes part of the event and is handled by the calendar provider you use.
  • Location: when-in-use location access can provide weather for your area and estimate travel time to an event. You can instead choose a fixed weather location.
  • Notifications and Live Activities: if enabled, the operating system can show event alerts, departure reminders, invitation counts, and next-event countdowns. InstaCal schedules and updates these through Apple's platform features.

Calendar, reminder, and contact information accessed through Apple frameworks is processed by the app on your device. Your Apple-hosted data remains subject to your Apple account settings and Apple's terms.

3. Optional services and network requests

InstaCal works with calendars already available through Apple Calendar. You may also choose to connect a provider directly or enable features that need another service. The service you select receives the information needed to answer your request and applies its own privacy policy.

Google Calendar & Google Tasks

If you connect Google Calendar, InstaCal uses Google's OAuth sign-in and Calendar API to identify the account and sync its calendars, events, invitations, and changes directly with Google.

If you separately enable Google Tasks or connect a task-only Google account, InstaCal requests permission to read and write your Google tasks. It accesses task lists, task titles, notes, due dates, completion status, and identifiers to display your tasks and let you create, edit, complete, reopen, or delete them. Task-only connections do not request Calendar access. Google task requests go directly from your device to Google.

Google account data is used only for the calendar and task features you choose. Higher Bar Apps does not receive that data or use it for advertising or AI training. InstaCal's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Microsoft

If you connect Microsoft, InstaCal uses Microsoft's OAuth sign-in and Microsoft Graph to identify the account and sync calendars, events, invitations, and changes directly with Microsoft.

CalDAV accounts

If you add a CalDAV account — iCloud, Fastmail, Yahoo, Fruux, or any other server whose address you enter — InstaCal connects to that server itself over HTTPS. It signs in with the username and app-specific password you provide, sent as standard HTTP Basic authentication over the encrypted connection, and reads and writes the calendars you select. Plain unencrypted connections are refused, and your credentials are not forwarded if the server redirects to a different host.

Calendar subscriptions

If you subscribe to a calendar feed — a webcal or HTTPS .ics address, a WebDAV calendar, or a Meetup feed — InstaCal downloads it from that address directly, on the re-check interval you choose. Subscriptions are read-only. If you fill in the optional username and password, they are sent as HTTP Basic authentication to that host only.

Todoist

If you connect Todoist, InstaCal uses Todoist's OAuth sign-in and its API to identify the account and sync your tasks and projects directly with Todoist.

Zoom

If you connect Zoom, InstaCal uses Zoom's OAuth sign-in to identify the account, and contacts Zoom only when you add, change, or remove a Zoom meeting on an event. Zoom receives the meeting's title, start time, length, and time zone — not your calendar.

Weather

If you turn on weather, InstaCal sends a current or chosen coordinate to the weather source you select: Apple Weather or The Weather Company. A request may also include language and measurement-unit preferences.

Maps and travel time

If you use location search, event maps, directions, or travel-time estimates, InstaCal uses Apple's MapKit and Maps services with relevant locations, addresses, route choices, and timing.

Countdown photos

A countdown can wear a photo: one from your Photos library (which never leaves your device), a stock photo, or a generated image. If you search for a stock photo, InstaCal sends the words you type to Higher Bar Apps at instacalapp.com, which forwards them to Unsplash or Pexels and returns the results; the photo you pick is downloaded by your device directly from that provider, and the provider is told a download happened, as its license requires. If you generate an image, the description you write is sent to us and forwarded to OpenAI's image API, which returns the picture; if you choose to add a photo of yourself so the image includes you, that photo is resized on your device, held by our server only while that one image is being drawn, forwarded to OpenAI for it, and deleted the moment the drawing finishes. The same random per-install ID used by Request a Feature is sent to limit how many searches and generations one install can make per day. We log the search words or description with that ID for those limits and for accounting, and delete the log after 90 days. The finished picture is stored only on your device, where its widget can show it. No calendar data, account, or location is involved, and nothing is sent until you search or press Generate.

Request a Feature

If you send a request from Settings → Request a Feature, InstaCal sends what you typed — a category, a summary, and any details — to Higher Bar Apps at instacalapp.com, with the app version, OS version, and device model so we can read it in context. An email address and a screenshot are included only if you add them; the screenshot is resized on your device first. A random ID created for this form and stored on your device is sent with it, used only to limit how many requests one install can send per day; it is not linked to your calendars, accounts, or location. Requests are stored on our server, relayed to the people who build InstaCal, kept while they are being considered, and deleted on request to support@higherbarapps.com. Nothing is sent until you press Send.

Higher Bar Apps is not an intermediary. Calendar and provider data travels between your device and the provider you choose, including any CalDAV server or calendar feed you add. Weather and map requests likewise go directly to the selected platform service. Only a feature request you write yourself, or a countdown photo search or image description you type, is addressed to us.

4. On-device storage and security

InstaCal stores preferences and the local data needed to make the app work on your device, including cached calendar information for connected providers. This lets the app remain responsive and show recently synced information when a provider is temporarily unavailable. The cache is written inside the app's own container and is removed, for that account, when you disconnect it.

Connected Google and Microsoft tasks are also cached locally. This connected-task cache is excluded from device backups and is kept separate from your personal InstaCal task library; InstaCal does not copy it into your personal iCloud task library. Disabling Tasks removes that account's connected-task cache; disconnecting the account also removes its saved credentials. These actions do not delete the original tasks from the provider.

Credentials for directly connected accounts are stored in Apple's Keychain: OAuth access and refresh tokens for Google, Microsoft, Todoist, and Zoom, and the username and app-specific password you enter for a CalDAV account or a password-protected subscription. Provider requests use encrypted HTTPS connections. Account labels and app preferences are stored locally using Apple platform storage.

InstaCal does not upload this local cache, your settings, or your OAuth tokens to Higher Bar Apps. No method of local storage or internet transmission can be guaranteed absolutely secure, but InstaCal limits data handling to what its features require and relies on Apple's security facilities and the selected providers' secure connections.

5. Your controls and choices

  • Grant, deny, or revoke Calendar, Reminders, Contacts, Location, and Notifications access in your device's Settings or System Settings.
  • Leave direct connections turned off, or disconnect an account — Google, Microsoft, a CalDAV server, a subscription, Todoist, or Zoom — from InstaCal to remove its stored credentials and local connection data.
  • Leave weather and travel-time features off, choose the weather provider, or use a fixed location instead of your current location.
  • Delete InstaCal to remove the app and its local app data, subject to the normal behavior of Apple platform backups and Keychain.
  • Manage or delete calendar, reminder, contact, and provider data through Apple or the provider that stores it.

Because Higher Bar Apps does not receive or maintain your personal data through InstaCal, we generally have no personal app-data record to access, export, correct, or delete. Requests about data held by Apple, Google, Microsoft, The Weather Company, or another provider should be directed to that provider.

6. Your data protection rights

Depending on where you live, data protection law gives you rights over your personal information. These include the right to know what is held about you and to get a copy of it, to have it corrected, to have it deleted, to receive it in a portable form, to restrict or object to how it is used, and not to be treated differently for exercising any of them. If you are in California, they also include the right to know what is collected, sold, or shared, and the right to opt out of sale or sharing.

Higher Bar Apps does not sell or share your personal information, and does not use it for cross-context behavioral advertising. InstaCal has no account system and no server that receives your data, so in the ordinary case we hold no personal information about you to disclose, correct, export, or erase.

How to exercise them

  • With us. Email support@higherbarapps.com and say what you are asking for. We will respond within the time the applicable law allows, normally within 30 days, and will tell you plainly if we hold nothing that falls within your request. You may use an authorized agent, and we may need to confirm that the request really comes from you before acting on it. Making a request costs nothing and will not change how the app works for you.
  • With the service that holds the data. Because your calendars, reminders, contacts, and meetings live with the provider you chose, requests about that data have to be made to them: Apple, Google, Microsoft, Zoom, Todoist, your CalDAV host, or The Weather Company. Each publishes its own privacy contact and request process. We are happy to point you to the right one if you ask.
  • On your device. The controls in section 5 let you revoke access, disconnect an account, or delete the app and its local data at any time, without contacting anyone.

If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your national data protection authority. If you are in California, you may contact the California Privacy Protection Agency or the Attorney General. We would rather hear from you first so we can put things right.

7. Changes to this policy

We may update this policy when InstaCal's features or legal obligations change. The effective date at the top of this page identifies the current version. If a change materially affects how the app handles data, we will update this page before or when that change takes effect.

8. Contact

Questions about InstaCal or this privacy policy can be sent to Higher Bar Apps at support@higherbarapps.com.