AttorneyCal policy

Privacy

Last updated August 9, 2026

Information AttorneyCal collects

AttorneyCal collects the email address and authentication identifiers used for sign-in; the Utah Bar number and attorney record you claim; the identity, email address, authorization credentials, dedicated calendar identifier, and AttorneyCal-created event identifiers associated with a calendar account you connect; publicly available Utah court calendar and hearing information associated with your attorney record; and limited operational, security, and error information needed to run and protect the service.

The provider-calendar entries AttorneyCal creates may include client or party names, case number and type, hearing type and time, judge, court, room, address, and an authorized remote-appearance link when available. Those details come from AttorneyCal’s court data and are sent to the calendar provider you select.

OAuth access and refresh tokens for connected calendar providers are encrypted before backend storage. The Supabase sign-in client stores authentication session information in your browser so you can remain signed in. AttorneyCal does not ask you for your Google or Microsoft password.

How AttorneyCal uses information

AttorneyCal uses this information only to authenticate users, verify claimed attorney records, create and maintain the dedicated AttorneyCal calendar, synchronize public hearing information, provide support, diagnose failures, prevent abuse, and improve the reliability and security of the service. AttorneyCal does not sell personal information, use calendar data for advertising, or use Google or Microsoft user data to train generalized artificial-intelligence models.

Google user data

AttorneyCal requests an OpenID account identifier and email address to identify the Google account you connect. Its calendar.app.created permission is limited to calendars created by AttorneyCal. AttorneyCal uses that access only to create and maintain the dedicated AttorneyCal calendar and its hearing events; it cannot use that permission to list or edit your pre-existing calendars and does not import events from them.

AttorneyCal stores the connected Google account identifier and email address, encrypted OAuth credentials, the dedicated calendar identifier, and AttorneyCal-created event identifiers needed to maintain the synchronization.

AttorneyCal does not sell Google user data or transfer it to advertisers or data brokers. It shares Google user data only with service providers that process it on AttorneyCal’s behalf as necessary to operate, secure, and support the service; when you direct or consent to the sharing; or when disclosure is required by law or necessary to protect users or the service. Those providers may not use Google user data for AttorneyCal-unrelated advertising.

AttorneyCal keeps the connected Google account identifier and email address, encrypted OAuth credentials, dedicated calendar identifier, and AttorneyCal-created event identifiers while the Google connection is active and as necessary to provide synchronization. Disconnecting Google sends a revocation request; after Google accepts it, the stored grant can no longer be used. A verified account-deletion request removes the stored credentials and other active Google-integration records, subject to ordinary backup expiration and limited retention required by law or necessary for security, audit, and dispute resolution. Events already written to Google Calendar remain there unless you delete them.

AttorneyCal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Microsoft user data

AttorneyCal requests User.Read to identify the Microsoft account you connect. Microsoft does not offer an app-created-calendar-only permission comparable to Google’s, so its consent screen also requests Calendars.ReadWrite. AttorneyCal limits its use of that broader permission to creating and maintaining the dedicated AttorneyCal calendar and its events and does not import events from your existing calendars.

AttorneyCal stores the connected Microsoft account identifier and email address, an encrypted Microsoft authentication cache, the dedicated calendar identifier, and AttorneyCal-created event identifiers needed to maintain the synchronization.

When information is shared

AttorneyCal shares information only with service providers that process it on AttorneyCal’s behalf, such as hosting, database and authentication, transactional email, monitoring, and the calendar provider you choose; when you direct or consent to the sharing; or when disclosure is required to comply with law, protect users, or secure the service. Service providers may include Fly.io, Supabase, Resend, Sentry, Google, and Microsoft as applicable. AttorneyCal does not permit these providers to use your information for AttorneyCal-unrelated advertising.

Retention and deletion

AttorneyCal keeps account, attorney-match, calendar integration, and synchronization records while your account is active and as reasonably necessary for security, audit, backup, legal, and dispute-resolution purposes. Disconnecting Google revokes the stored grant when Google accepts the revocation request; disconnecting Microsoft discards AttorneyCal’s encrypted token cache, and you may separately remove the grant in your Microsoft account. Events already written to a provider calendar remain there unless you delete them.

You may request access, correction, or deletion of your AttorneyCal account information by emailing support@attorneycal.com. During the pilot, AttorneyCal handles these requests manually after verifying the requester’s identity. For a verified deletion request, AttorneyCal removes the active authentication mapping, stored provider credentials, and other account-linked integration records, subject to ordinary backup expiration and limited retention required by law or necessary for security, audit, and dispute resolution.

Security

AttorneyCal uses technical and organizational safeguards intended to protect information, including encrypted OAuth credentials, authenticated account access, purpose-limited provider use, and restricted production secrets. No system can guarantee absolute security.

Changes and contact

AttorneyCal may update this policy as the service changes. Material changes will be posted here with a revised date and, when appropriate, communicated to pilot users. Questions or privacy requests may be sent to support@attorneycal.com.