How we keep your calendar safe.
Last updated August 2026
In transit and at rest
Every connection uses TLS 1.3. Data at rest is encrypted with AES-256, and the keys are managed by our cloud provider's key service with rotation on a fixed schedule.
Calendar tokens from Google, Microsoft and Apple are encrypted separately, with a key that our application servers can use but cannot export.
Your account
Passwords are hashed with Argon2id. Two-factor authentication is available to everyone, and recovery codes are single-use.
You can see every signed-in device in Settings and end any session immediately. Ending a session revokes its tokens on the server, not just in the browser.
Access by our team
Engineers do not have standing access to customer calendars. Access requires your written permission on a specific support ticket, is time-limited, and is logged where you can request the log.
Isolation between Spaces
Space isolation is enforced in the data layer, not in the interface. A query that would return an event from a Space you can't see does not return it — there is no client-side filter to bypass.
Deletion
Deleting your account removes your calendars, tasks and history immediately, and clears them from encrypted backups within 30 days. Spaces you own are deleted with the account; Spaces you joined are simply left.
Reporting something
Found a vulnerability? Email security@daykite.com. We acknowledge within one working day, and we don't take legal action against good-faith research.