Privacy Policy
Effective September 9, 2026 · Applies to ONHARU 2.2.8
ONHARU is a local-first application. It does not operate a membership service or a central server that stores your calendar.
1. Information and purposes
| Feature | Information and purpose |
|---|---|
| Local features | Schedules, Todo items, anniversaries, alarms, timetables, settings and backups are stored on your PC to provide the requested functions. |
| Google Calendar | Authorized calendar lists and event details are processed to display, create, edit, delete and synchronize events. |
| Google Tasks | Authorized task lists, titles, dates, notes and completion status are processed to provide Tasks integration. |
| Authentication | A Google OAuth refresh token is protected on this Windows account so synchronization can continue without repeated sign-in. |
| Email backup | Only when you request it, the selected backup, connected Gmail address and a short-lived Google ID token are processed once to send the file to that same address. Calendar access and refresh tokens are not sent. |
| Error log | Time, operation and technical error details may be stored locally for diagnosis. Email addresses and token-like strings are masked. |
2. Storage and retention
Local information is stored under %LOCALAPPDATA%\Onharu. Google tokens are encrypted with Windows DPAPI for the current Windows account. Information remains until you delete it using ONHARU, uninstall and remove its data, or revoke Google access.
3. External services and transfers
ONHARU does not sell personal information. It uses no third-party advertising SDK, behavioral advertising or user tracking.
- Google Calendar and Tasks: data covered by the permissions you approve is exchanged directly between your PC and Google.
- ONHARU email backup on AWS: processes the selected file only when you request delivery to your verified connected Gmail address.
- onharu.app notice creative: the app requests text, colors and an icon name at startup and every six hours. The request contains the app version but no identifier, schedule or account data. Standard server logs may retain the IP address and request time. A cached copy is stored in
ads\creative.json. - GitHub: may receive the app version and normal connection information when checking for or downloading an update.
- Parse.bot: receives the API key and query you provide only when you use the optional KBO feature. The key is not sent to an ONHARU server.
4. Google API data policy
ONHARU's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Google information is used only to provide user-requested Calendar, Tasks and backup identity-verification features. It is not used for advertising, profiling or unrelated analytics.
5. Your choices
You may use ONHARU without Google integration, disconnect Google at any time, delete local data, revoke access from your Google Account, and contact us about privacy. Disconnecting removes local OAuth tokens; deleting data does not automatically delete events already stored by Google unless you explicitly delete them there.
6. Security and children
Tokens are protected with DPAPI, logs mask sensitive patterns, and backup delivery requires an identity check. ONHARU is a general productivity tool and does not knowingly collect children's information through a membership service.
7. Changes and contact
Material changes will be published before they take effect whenever practicable. Questions: [email protected]