Last updated: September 2026, for Calendar Mirror 2.0
Your calendar belongs to you — not to us, and not to a server. Calendar Mirror has no account and, until you turn on AskWhen.me, makes no network request of any kind. It never sends your calendar anywhere. AskWhen.me is a separate product you can turn on from inside the app; it does use a server — one built so it cannot see your calendar either. This page says exactly what that server holds instead, and for how long.
You tell Calendar Mirror which calendar to copy and where to copy it. It reads events from the source and writes copies into the destination, using Apple's Calendar framework on your device. That's the whole job. The list of pairs you set up is stored only on your device.
Send times — the app's line of your next free times, for pasting into a message — is worked out on your device from the calendars you chose, and nothing about it leaves the device. If you have an AskWhen.me page, a link to it is added after the times; that is the only part that touches a server, and only because you turned the page on.
No analytics. No advertising or tracking SDKs. No behavioral data. No crash or usage telemetry sent to us. Calendar Mirror ships with none of that and never will — surveillance isn't a feature we're interested in building.
Calendar Mirror works through calendars that are already set up on your device, so it never asks for, sees, or stores any account passwords or tokens.
Because of that, Calendar Mirror lets each pair decide what a copy actually contains. A copy can carry the full event, or the title and location only, or nothing but a block reading “Busy” — and individual events can be skipped, hidden, or shared in full with a tag in their notes. If you would rather a provider never hold the details, don’t send them.
If your destination calendar lives in an account like iCloud, Google, or Exchange, then once a copy lands there, that provider syncs and retains it under their policies — exactly as it would for any event you added to that calendar yourself. Calendar Mirror isn't part of that sync and can't reach into it: on your device it keeps to itself, and beyond it your account provider's terms apply. If that matters to you, point Calendar Mirror at a local or self-hosted calendar as the destination.
Until you turn AskWhen.me on, nothing in this section applies to you. AskWhen.me is its own product, with its own server; Calendar Mirror is the app you turn it on from. It is off by default. Until you choose it, Calendar Mirror 2.0 behaves exactly as every version before it: no account, no server, no network request of any kind — not a version check, not a price. The first time the app contacts anyone is when you ask what AskWhen.me costs, and that contact is with Apple. Everything below describes AskWhen.me only, and only after you opt in.
AskWhen.me gives you a page at askwhen.me/yourpage where someone can
ask you for a time. That page needs a server, and this section is the whole of
what that server does with data. The design is called a dead drop: your
device works out which times to offer and sends only those; the server holds
requests until your device collects them. At no point does the server have your
calendar, your email address, or a way to contact you.
Your device replaces that list whenever your offers change and at least daily. If it stops, the page goes dark within a day rather than serving stale times. Delete the page in the app and everything above is deleted at once, along with every request on it.
Your page is yours because your device holds a key to it — there is no account, no password, and nothing we could reset. The key is kept in your device's Keychain and, if you use iCloud Keychain, travels with it to your other devices and to a new phone, end-to-end encrypted by Apple. We never hold it in a form we could use: the server keeps only a hash, enough to recognise the key when your device presents it.
Someone asking for a time gives their name, email address, and an optional note, and picks a slot. The server holds those only as long as it takes to get an answer to them:
These limits are enforced by the database itself, not by a schedule somebody could forget to run. There is no requester account, no history, and nothing that links one request to another.
When you send someone your times from the app, the link after them is a personal link: it opens your page once, for seven days, and then it is spent. Because you sent it, a request through it skips the email confirmation — the link is the proof of who they are — and if the time is still clear in your calendar, your device accepts it without you tapping anything, and they receive the calendar file. If the time has been taken since, it waits for you like any other request. The server stores the link's code, the page it belongs to, when it expires, and — once used — which request spent it. Nothing about who you sent it to. A spent or expired link is removed within two days of expiring.
The page loads nothing from anyone else: no fonts, no analytics, no scripts from a third party, no captcha service. It makes exactly two requests, both to askwhen.me. That is checked by the build, which fails if a third appears. Rate limiting exists to stop abuse, but it does not store IP addresses: it stores a keyed hash that rotates daily, after which yesterday's entries cannot be linked to an address even by us.
The confirmation, the answer, and the calendar file are sent from
no-reply@askwhen.me through a mail server we run ourselves, on
infrastructure we own. Delivery reports come back from it so that "delivered"
can mean the request is deleted; nothing about what an email says is logged.
The person who asked gets your display name and the meeting
time. They never get your email address — the server does not have it to give.
If you claim a subdomain, or point your own domain at your page, the server stores that hostname and checks, from time to time, that it still points here. That is all it holds about the domain. What happens to the address if your subscription ends is in the terms.
AskWhen.me is a subscription bought through the App Store. Apple handles payment; we never see a card, a name, or a billing address. Apple tells our server when a subscription starts, renews, or ends, using the same anonymous identifier as above, so a lapsed page can be taken down.
On a server we operate in Colorado, United States, behind a reverse proxy that keeps ordinary access logs.
calendarmirror.com uses a self-hosted, cookieless page counter on our own infrastructure to see which pages are read. It sets no cookie, stores no IP address, and is not shared with anyone. The request page at askwhen.me carries nothing of the kind.
If this policy ever changes, the update will be here and in the source, which is public. The bar it has to clear is simple: the app still collects nothing, and AskWhen.me still holds nothing longer than it takes to get someone an answer.
Questions, concerns, or something that went wrong with a request: support@askwhen.me, or github.com/mattbaylor/cal-mirror.