Until

Privacy Policy

Last updated: July 14, 2026

Until is a macOS menubar app that shows your next Google Calendar event and helps you join meetings and take notes. The short version:

  • Everything runs on your Mac. There is no Until server — the app talks directly to Google.
  • No account with us, no data collection by us. No analytics, no telemetry, no trackers.
  • Sign-in tokens stay in the macOS Keychain, never in plain files.

The sections below explain in detail what Google user data the app accesses, how that data is used, with whom it is shared, how it is protected, and how it is retained and deleted.

What Google user data Until accesses

When you sign in with Google, Until requests the following OAuth scopes and accesses only the Google user data they cover:

  • Calendar list (calendar.calendarlist.readonly) — the names, colors, and IDs of the calendars in your account.
  • Calendar events (calendar.events) — event details such as title, time, attendees, location, description, RSVP status, conferencing links, and attachments.
  • Files the app itself creates in Google Drive (drive.file) — your meeting-notes documents, the optional notes template, and the folder that holds them. Until uses the drive.file scope and accesses only the files it creates; it does not request broad Drive access and cannot see, read, or list anything else in your Drive.
  • Your Google account email address (userinfo.email, openid) — the email address of the signed-in account.

Until does not access any other Google user data.

How Until uses Google user data

Until uses the data above only to provide the app’s user-facing features:

  • Calendar list is used to let you choose which calendars to show or hide.
  • Calendar events are used to display and filter your upcoming events in the menubar, schedule local reminders (macOS notifications) for events you opted into, open event and meeting links, determine who receives a meeting-notes document, and populate notes documents with the event title, date and time, Calendar link, and attendee email addresses. Only when you ask, Until also updates an event to add a Google Meet link or to attach a meeting-notes document.
  • Drive files created by the app are used to create, name, and organize your meeting-notes documents (and, if you set one up, the notes template they are copied from). When you create notes, Until gives edit access to the event’s attendees — the confirmation dialog lists the ones at your email domain, and Until asks separately before sharing with attendees outside it. Notes never reach anyone who isn’t already invited to the event.
  • Your email address is used to show which account is connected and to tell your own domain apart from external attendees when sharing notes documents.

Until does not use Google user data for advertising, analytics, profiling, or any purpose other than the features described above.

Sharing, transfer, and disclosure of Google user data

Until does not sell, rent, transfer, or disclose Google user data to any third party. There is no Until server: the app makes direct API calls from your Mac to Google (Calendar, Drive, Docs, and sign-in), and Google user data is never routed through or stored on a server operated by us or anyone else. No ad networks, no data brokers, no analytics services.

How Until protects Google user data

  • Sensitive data is stored in the macOS Keychain. Your Google OAuth tokens — the most sensitive data the app holds — are stored in the macOS Keychain, encrypted and protected by the operating system like any other credential. They are never written to plain files or logs.
  • All network traffic is encrypted. All Google user data transmitted by Until travels directly between the app and Google’s APIs over HTTPS (TLS). Until’s automatic update checker contacts GitHub over HTTPS, and that traffic never includes Google user data.
  • Data stays on your device. Calendar and event data is fetched on demand and kept in memory or in local app storage on your Mac, protected by your macOS user account. There is no server-side copy to breach.
  • Minimum scopes. Until requests only the scopes listed above, uses the read-only calendar-list scope, and uses the restricted-to-own-files drive.file scope instead of full Drive access.

Retention and deletion of Google user data

  • Calendar and event data is fetched on demand and held in memory while Until runs. It is not accumulated or archived. If you enabled reminders, macOS may keep event titles, times, locations, and meeting links in pending or delivered notifications until they fire, are dismissed, or are cleared from Notification Center.
  • Settings — including which calendars you selected and references (IDs) to the app’s own Drive folder and template — are stored in the app’s Application Support folder on your Mac.
  • OAuth tokens are retained in the macOS Keychain only while your account is connected. Removing the account in Settings → Accounts deletes the tokens from your Keychain immediately, along with the account’s settings.
  • Meeting-notes documents live in your own Google Drive and belong to you. Until keeps no copy; you can delete them in Drive at any time.
  • To delete all Google user data the app holds: remove each account in Settings → Accounts (this deletes tokens and account data — do this before deleting the app, since uninstalling alone does not clear the Keychain), clear any Until notifications from Notification Center, then delete the app. Because Until has no server, there is no server-side data to request deletion of.

Google API Services User Data Policy and Limited Use

Until’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google is used only to provide the user-facing features described above and is never transferred to others except as described above to provide those features. Until does not use Google user data for advertising, and no one at combinatrix.ai reads your Google user data. Until does not use or transfer information received from Google Workspace APIs to develop, improve, or train generalized or non-personalized AI and/or machine-learning models, and does not transfer that information to third-party AI/ML tools.

How to revoke access

You can disconnect Until at any time:

  • In the app, open Settings → Accounts and choose Remove to sign out and clear the stored tokens from your Keychain.
  • From your Google Account, visit Google Account permissions and remove Until’s access.

Changes to this policy

If the app’s data practices change, this page will be updated and the date at the top revised before the change takes effect.

Contact

Until is developed by combinatrix.ai. For privacy questions or concerns, email until@combinatrix.ai or open an issue on GitHub.

← Back to Until