Overview
DotCal does not collect your calendar content and does not transmit events, tasks, reminders, attachments, or settings to Dotfield Studio. Your calendar data exists only on your Android device.
This privacy policy covers the DotCal Android application (com.dotfield.dotcal), published by Dotfield Studio. The policy applies from the date of your first installation.
We built DotCal with a simple rule: data about your life belongs to you. The app has no Dotfield backend, no account system, no advertising, and no analytics SDK embedded anywhere in the code. Google Play services are used only for Play Billing, purchase restore, and in-app update checks.
Data We Collect
DotCal does not collect, store, or transmit your calendar content to Dotfield Studio. The following data exists on your device when you use the app:
| Data Type | Where Stored | Sent Anywhere? | We Can Access? |
|---|---|---|---|
| Calendar events & tasks | Device local database | Never | No |
| Reminder alarms | Android AlarmManager | Never | No |
| Voice note recordings | App private directory | Never | No |
| Image attachments | App private directory | Never | No |
| Theme & app settings | SharedPreferences (local) | Never | No |
| Contact birthdays (if enabled) | Read-only, not copied | Never | No |
| Google Calendar events (if imported) | Copied locally from CalendarProvider | Never | No |
| Pro entitlement state | Device local preferences | Not by DotCal | No |
| Crash or usage analytics | Not collected | Never | No |
Payment processing, receipts, and account-level purchase data are handled by Google Play, not by Dotfield Studio. DotCal stores only a local Pro entitlement flag after a successful purchase or restore.
App Permissions
DotCal requests only the permissions it needs to function. Each permission is described below — including why it is needed and what it cannot access.
| Permission | Type | Why It's Needed |
|---|---|---|
| READ_CALENDAR | Required* | Read events from Android's CalendarProvider (Google Calendar, device calendars). Only imports locally — no data leaves device. *Only required if you enable Google Calendar sync. |
| WRITE_CALENDAR | Required* | Create and edit events via CalendarProvider for two-way sync. *Only if sync is enabled. |
| READ_CONTACTS | Optional | Read contact birthdays to create yearly recurring events. Only reads dates, not full contact data. Enabled via Settings toggle. |
| SCHEDULE_EXACT_ALARM | Required | Schedule precise reminder alarms via AlarmManager. User must grant via Android Battery settings on API 31+. |
| RECEIVE_BOOT_COMPLETED | Required | Re-register reminder alarms after device reboot. Without this, reminders set before a restart would not fire. |
| POST_NOTIFICATIONS | Required | Display event reminder notifications. Required on Android 13 (API 33) and above. |
| RECORD_AUDIO | Optional | Record voice notes attached to events using MediaRecorder. Recordings saved to app-private storage. Only requested when you tap the voice note button. |
| READ_MEDIA_IMAGES | Optional | Select photos via the Android Photo Picker. DotCal never accesses your full gallery — Photo Picker restricts access to selected items only. |
| USE_BIOMETRIC | Optional | Unlock the app with fingerprint or face authentication. Biometric data never leaves Android's Biometric API — not stored by DotCal. |
| INTERNET / ACCESS_NETWORK_STATE | Required | Used by Google Play Billing and in-app update checks. DotCal does not use network access to upload calendar data, analytics, or ads. |
Google Calendar Sync
DotCal's calendar sync does not connect to Google's Calendar API. It reads from Android's built-in CalendarProvider — the same local database the default Calendar app uses. No Google Calendar credentials are ever seen or stored by DotCal.
When you enable Google Calendar sync, DotCal queries Android's CalendarProvider (a local content provider, not a network API). Events that Google has already synced to your device are read locally and copied into DotCal's own database.
This is fundamentally different from apps that use the Google Calendar REST API or OAuth. DotCal does not make HTTP requests for calendar sync. It never sees your Google credentials. No Google token is stored in the app.
If you disable sync in DotCal settings, the app stops querying CalendarProvider. Previously imported events remain in DotCal's local database until you delete them.
Local Storage
All DotCal data is stored in Android's app-private storage under /data/data/com.dotfield.dotcal/. This directory is not accessible to other apps without root access. It is deleted automatically when you uninstall DotCal.
Stored data includes:
· SQLite database — calendar events, tasks, recurrence rules, event metadata
· SharedPreferences XML — theme selection, view preferences, sync toggle states
· Voice note files — AAC-encoded recordings, named by event ID
· Image attachment files — copies of selected photos, named by event ID
DotCal does not write to any shared external storage location. If your device's Google Backup is enabled at the system level, Android may back up app data — this is outside DotCal's control and governed by Google's backup policy.
Third Parties
DotCal does not integrate any third-party SDKs for analytics, advertising, crash reporting, or remote configuration. The app contains no Firebase Analytics, no Facebook SDK, no Crashlytics, no advertising networks, and no A/B testing frameworks.
DotCal uses Google Play Billing for the one-time Pro purchase and restore flow, Google Play In-App Updates for update checks, and the Nothing Glyph SDK for local Glyph Toy integration on supported Nothing devices. These services do not receive your calendar events, tasks, reminders, attachments, voice notes, or settings from DotCal.
Security
Because DotCal stores calendar data locally and does not upload your calendar content, the main risk is physical device access. We recommend keeping your device PIN or biometric lock active and enabling DotCal's built-in biometric lock if you use it on a shared device.
DotCal's local database is not encrypted by default. Android's app sandbox provides the primary protection. If your device supports hardware-backed encryption (most modern Android devices do), the OS-level encryption protects DotCal data at rest.
Children's Privacy
DotCal does not knowingly collect any information from anyone, including children under 13. Because DotCal collects no data at all, there is no children's data to protect beyond standard Android privacy protections. The app is a general-purpose calendar with no content directed at children.
Your Rights
Because DotCal does not collect or store any personal data on our servers, there is no data for us to access, export, or delete on your behalf. All of your data is under your direct control:
· Access — your data is in the app on your device
· Delete — uninstall the app to delete all data, or delete individual events from within the app
· Export — PDF export of calendar views is a planned feature
· Portability — events synced via CalendarProvider remain in Android's calendar database
If you are in the EU, UK, or California, GDPR and CCPA rights apply. Because we hold no data, your rights are exercised entirely on-device.
Policy Changes
If this policy changes materially — for example, if DotCal adds cloud sync, analytics, advertising, or a Dotfield server feature — we will update this page and the effective date below. A release note will flag the change. We commit to never adding advertising, analytics, or cloud storage without updating this policy and prominently notifying users.
Effective date: July 14, 2026
Contact
Questions about this privacy policy or DotCal's data practices: