← CJ Designs

Calandora — Privacy Policy

Effective 24 September 2026

Calandora is a calendar, notes and tasks app made by CJ Designs. It runs on iPhone, iPad and Android, and in your web browser at calandora.com. You sign in with an email address and password, and your calendars, notes and tasks stay in sync across all of them.

The short version: your data is used to run Calandora for you, and for nothing else.

There is no analytics, no advertising, no crash reporting and no tracking of any kind. We never sell or share your data. It is stored on servers we operate ourselves, not with a third-party cloud service, and only you can see it.

What Calandora stores

WhatWhy
Your email address and passwordTo create your account and sign you in. The password is stored only as a one-way hash, never in readable form.
Calendars, events, reminders and repeat rulesSo your calendar is the same on every device.
Notes, folders, tags, favourites and pinsSo your notes are the same on every device.
Tasks, task lists, due dates and prioritiesSo your tasks are the same on every device.
Links between items, and files you attachSo an event, note or task can point to the others and keep its attachments.
Your settings, such as theme and default reminderSo your preferences follow you between devices.

Calendar entries and notes often contain personal details, such as appointments, health, work or family matters. We treat everything you put in Calandora as private.

What we never collect

Where your data is kept

Your account and everything in it are stored in a database on a server in the United Kingdom (London), which we operate ourselves on hosting rented from IONOS. The website at calandora.com runs on a separate server in Germany. Your data passes through it when you use the website, but it does not keep a copy.

To protect against data loss, the database is backed up every night. Backup copies are kept for up to 30 days on a separate server in the European Union, which we also operate.

Everything sent between your devices and our servers is encrypted in transit (HTTPS). Access rules in the database itself make sure each account can only ever read its own data. Attached files are stored privately and can only be opened through a checked, time-limited link.

To be clear about what we do not claim: your data is not end-to-end encrypted. It is protected in transit and by access controls, but it is technically readable on our server. We say so rather than implying stronger protection than exists.

On your devices

The iPhone and Android apps keep a copy of your data on the device so they work offline, and sync changes when you are back online. That copy is protected by your device's own security, such as its passcode. Your sign-in session is kept in the iOS Keychain or Android Keystore.

When you sign out, the app deletes its copy of your data from that device, so the next person to use the device cannot see it.

The website uses a sign-in cookie to keep you signed in, and remembers your chosen theme in your browser. It uses no advertising or tracking cookies.

Emails we send

We only email you when you ask us to: a 6-digit code to confirm a new account, or to reset your password. These emails are delivered by Resend, an email delivery service, which receives your email address and the message for that purpose only.

Permissions the app asks for

PermissionWhy
NotificationsTo show the reminders you set for events and tasks.
Alarms and reminders (Android)So reminders arrive at the exact time you chose. Without it they still arrive, but may be a little late.
FilesOnly when you choose a file to attach or import, or save an export. The app sees only the file you pick.

Reminders are scheduled on your own device, not sent from a server. A reminder shows the title of the event or task on your lock screen, so avoid putting anything in a title you would not want seen there.

Exports and backups you make

You can export your calendars (.ics), notes, tasks, or a full backup of your account. These files are created on your device and saved wherever you choose. We never receive a copy, and what happens to them afterwards is up to you.

Keeping it, and deleting it

Your data is kept for as long as you have an account. Notes and tasks you delete go to Trash so you can restore them, and stay there until you delete your account.

You can delete your account at any time: in the app under Settings → Account → Delete account, or on the website under Account. This permanently deletes your account, every calendar, event, note and task, and every file you attached. It cannot be undone. Copies in our nightly backups expire within 30 days.

If you use the same email address in another CJ Designs app, read this first. Our apps share one sign-in, so deleting your account from Calandora deletes that sign-in for every CJ Designs app, together with your data in those apps. If you only want to stop using Calandora, delete your calendars, notes and tasks instead, or email us and we will remove only your Calandora data.

Your rights

Under UK and EU data protection law (GDPR), you can ask to see, correct, export or delete the personal data we hold about you, and you can object to or restrict how we use it. You can do most of this yourself in the app: edit anything, export a full backup, or delete your account. For anything else, email support@cjdesigns.app and we will respond within 30 days.

If you think we have handled your data improperly, you can complain to the UK Information Commissioner's Office at ico.org.uk.

Children

Calandora is not directed at children under 13, and we do not knowingly create accounts for them.

Changes to this policy

If this policy changes, the updated version will be posted at this address with a new effective date.

Contact

CJ Designs — support@cjdesigns.app