Privacy policy

The public calendar

Anyone can use the public calendar without signing in. It sets no cookies and loads nothing from other sites: no analytics, ads, trackers or third-party fonts. Your “church feasts” and “fasts” choices are remembered only in your own browser.

Signing in

“My calendar” is protected by Cloudflare Access. Signing in sets Cloudflare's sign-in cookies (CF_Authorization and CF_Binding), which are needed to keep you signed in. Dayjar receives your email address from Access and uses it only to find your data.

What is stored

Your events, birthdays, tasks, notes and settings, plus the push addresses of the devices on which you turn notifications on. Each person's data lives in a separate private database (a Cloudflare Durable Object), encrypted at rest by Cloudflare.

Notifications

Reminders are end-to-end encrypted to your device with the Web Push standard. Browser push services (Google, Apple, Mozilla or Microsoft) see only when a message is sent, never what it says.

Logs

Cloudflare keeps short-lived technical logs of requests for security and troubleshooting. Dayjar does not log the contents of your entries or your email address.

Your control

In Settings you can download everything as JSON or iCalendar at any time, and delete all your data. Deletion is immediate and permanent.

Who processes the data

Dayjar runs on Cloudflare (hosting, sign-in and storage). Questions: security@shkriuss.dev.