← Back home

Privacy policy

Diurnal is a Mac app with a synced account. This policy says what it collects, why, how long it keeps it, and what you can ask for.

Effective 30 August 2026Diurnal for macOS

The short version

  • Diurnal requires an account. You sign in with Google, or with an email address and a password.
  • Your tasks, tags and settings sync, so your day exists on every Mac you use rather than on one disk.
  • Your day is kept on your own Mac, so the app is fast and keeps working without a network.
  • Connecting Google Calendar is optional and separate from signing in.
  • Your data is not sold, and it is not used for advertising.
  • The app does not track how you use it.
  • Signing out empties that Mac.

For the mechanical detail, exact scopes and exact hosts, see Data & permissions.

What is collected

Your account

  • Account identity. The Google account identifier or email address associated with your sign-in, used to know whose data is whose.
  • Your content. The tasks, tags and settings you create, so they can be synchronised to your other Macs.
  • Operational records. The ordinary server logs needed to run and secure a service, such as request timing and error records.

If you connect Google Calendar

  • Authorisation tokens for the account you connected, held so the service can read the days you look at.
  • Calendar entries for the range being displayed, cached so the calendar pane can draw your day.

Why it is collected

Each item above exists to deliver a feature you asked for: identity so your data can be told apart from someone else’s, content so it can appear on your other Mac, tokens so your calendar can be read, and logs so faults can be diagnosed and abuse prevented. None of it is used to build a profile of you, and none of it is used for advertising.

Where a legal basis is required, processing rests on performing the service you requested, and on the legitimate interest in keeping that service secure and working.

Calendar data

Calendar information is used for one purpose: to show your events beside your tasks, and to create an event when you ask for one. It is not analysed, not mined, not used to train anything, and not shared with anyone.

Diurnal requests the narrowest Google scopes that make those two things work. It does not request the scope that permits deleting calendars, and it does not request the broad read scope that would expose calendars you have not chosen to display. The exact scopes and the reasoning are listed on Data & permissions.

Diurnal’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How long it is kept

  • Local data stays on your Mac until you delete it or sign out; signing out removes that Mac’s local copy.
  • Synchronised content is kept while your account exists, so it can be delivered to your other Macs.
  • Calendar tokens are kept until you disconnect the account or revoke access at Google, at which point they stop working and are discarded.
  • Cached calendar entries are transient and exist only to draw the range currently in view.
  • Operational logs are kept for a limited period for security and debugging, then discarded.

Who it is shared with

Your data is not sold, rented, or shared for advertising. There are no third-party advertising or analytics services in the app.

Data is disclosed only in these cases:

  • Google, when you have connected a calendar. The requests Diurnal makes on your behalf go to Google’s API, and are governed by your agreement with Google.
  • Infrastructure providers that host the sync service, acting on instructions and not permitted to use your data for their own purposes.
  • When legally required, such as in response to a valid legal demand.

How it is protected

Traffic between the app and the sync service is encrypted in transit. Calendar authorisation tokens are encrypted at rest. Access to stored data is scoped per account, so a request authenticated as one account cannot read another’s.

No system is perfectly secure, and this policy does not claim otherwise. The mitigations above are stated so you can judge them rather than take a reassurance on faith.

Your choices

  • Keep the calendar out of it. Connecting a calendar is a separate step, and declining it costs you nothing else in the app.
  • Disconnect a calendar in Diurnal’s Calendars settings, or revoke access from your Google Account security settings.
  • Sign out to remove that Mac’s local copy of your data.
  • Request access or deletion of the data associated with your account. Depending on where you live, you may also have rights to correction, portability, or to object to processing.

Children

Diurnal is not directed at children, and it is not knowingly used to collect information from a child. If you believe a child has provided information, get in touch and it will be removed.

Changes to this policy

If this policy changes in a way that affects how your data is handled, the effective date at the top of this page changes with it, and material changes will be surfaced in the app rather than left here to be discovered.

Contact

For any question about this policy, or to make a request about your data, contact us through the project’s repository. Please say which account the request concerns so it can be answered.