ONHARU is a local-first app with no membership system or central event-storage server. Local events and settings stay on your Windows PC. ONHARU connects to external services or onharu.app only when needed for the Google or Microsoft calendar account you choose and ONHARU guidance-content updates.
1. Information we process and why
| Category | Information processed | Purpose |
|---|---|---|
| Local features | Events, to-dos, anniversaries, alarms, timetable, settings, backups, and diaries created in earlier versions | Calendar display, notifications, search, backup, and restore |
| Subscribed calendars | ICS addresses, display names, user slots, last-fetch metadata, and downloaded event copies supplied by the user | Display an external calendar read-only and fetch changes |
| Google Calendar | Calendar lists and event titles, times, descriptions, recurrence, reminders, and related fields | View, create, edit, delete, and synchronize the Google calendars you select |
| Google Tasks | Task lists, titles, dates, notes, and completion status | Display and synchronize tasks you create, edit, delete, or complete |
| Microsoft Outlook Calendar | Calendar lists and event titles, times, descriptions, recurrence, reminders, Outlook category settings, and related fields | View, create, edit, delete, and synchronize the Outlook calendars you select. MailboxSettings.ReadWrite is used to create and update the anniversary category and its color. |
| Account authentication | OAuth tokens and account display information for the Google or Microsoft account you choose | Show the connected account and synchronize without requiring a new sign-in each time |
| Error logs | Error time, operation location, and technical error details | Diagnose app errors. Email addresses and token-like strings are masked before they are recorded. |
2. Storage location and retention
Events, settings, connection data, and automatic safety backups are stored on your PC in %LOCALAPPDATA%\Onharu. Subscribed-calendar addresses, settings, and the last downloaded event copies are stored in the subscriptions folder under the same data location and are removed when you delete that subscription. Google or Microsoft OAuth tokens are encrypted for the current Windows user. Local data is not sent to ONHARU servers. Data remains on the PC until you use the in-app deletion feature or delete the folder yourself.
3. External services and data transfers
ONHARU does not sell personal information or disclose it for advertising. It does not use a third-party advertising SDK, personalized advertising, user tracking, or a separate usage-analytics service.
ONHARU guidance content. ONHARU downloads the text, colors, and icon names shown in the guidance area below the detailed calendar. The app requests this content once at startup and every six hours thereafter. The request includes only the app version (ONHARU/2.2); it contains no identifier, event, or account data. Standard web-server logs may retain the IP address and access time. If the device is offline or the request fails, the app displays its built-in content. Downloaded content is cached in ads\creative.json. ONHARU uses no third-party advertising SDK and performs no tracking.
| External service | Information transmitted and purpose |
|---|---|
| Google Calendar and Tasks | The calendars, events, tasks, and authentication data you authorize are used only to provide synchronization. Google processes this data under its Privacy Policy. |
| Microsoft Graph | The Outlook calendars, events, and authentication data you authorize are used only to provide synchronization. The MailboxSettings.ReadWrite permission is used only to create or update the ONHARU Anniversary category and its color. It is not used to read email content or send mail. Microsoft processes this data under its Privacy Statement. |
| onharu.app guidance content | Guidance content is refreshed at app startup and every six hours. The request includes only the app version; the IP address and access time may appear in standard web-server logs. |
| GitHub | The app version and general connection information may be used to check for updates and download an installer you approve. |
Subscribed-calendar host. Your PC requests the ICS address you entered directly. The host may receive your IP address, access time, and ordinary request information and processes them under its own policy. ONHARU servers do not proxy the feed address or its events.
4. Limitation on using Google API data
Information received from Google API is used only to provide and improve calendar and task features requested by users. It is not used for advertising, credit evaluation, user tracking, or third-party sales, and it is not accessed manually by humans.
ONHARU’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Your choices and deletion
- Connecting a calendar account is optional. Local features and subscribed calendars work without an account.
- You can hide or delete a subscribed calendar at any time. Deleting it also removes its downloaded event copy from your PC.
- You can connect either Google or Microsoft, but not both at the same time. To switch providers, log out of the current account and connect the other one.
- Logging out in Settings removes the authentication information stored by ONHARU.
- You can revoke ONHARU's access at any time in your Google or Microsoft account's security and app-permission settings.
- You can delete events, settings, and authentication information with the local-data deletion feature in Settings. Uninstalling the program alone may leave user data available for reinstallation.
- You can export events to JSON or CSV before deletion.
6. Data protection
ONHARU protects Google user data and other sensitive data as follows.
- Encryption in transit. All communication between ONHARU and Google APIs, Microsoft Graph, onharu.app, and the update server uses HTTPS with TLS 1.2 or higher.
- Secure sign-in. Google and Microsoft sign-in use OAuth 2.0 with PKCE and state verification. The sign-in response is received only on your own PC's loopback address (127.0.0.1). ONHARU never sees your account password.
- Encrypted credentials. OAuth access and refresh tokens are encrypted with the Windows Data Protection API (DPAPI) and bound to your Windows user account, so other users or other PCs cannot decrypt them. Logging out in Settings deletes them.
- Local-only storage. Calendar events and tasks received from Google are stored only on your PC, in your Windows user profile folder (
%LOCALAPPDATA%\Onharu), which is protected by Windows account permissions. They are not uploaded to or stored on ONHARU servers. We recommend Windows device encryption (such as BitLocker) for additional protection of data on your PC. - No server-side storage. The developer does not operate a database of Google user data. ONHARU does not send email on your behalf, and it has no feature that uploads an event file to a server.
- Access restriction. No person, including the developer, reads your Google user data. The developer has no access to data stored on your PC.
- Minimal data in logs. Diagnostic logs stay on your PC. Email addresses and authentication information are masked, and calendar names are replaced with one-way keyed hashes (HMAC-SHA256) that use a key unique to each installation.
- Least privilege. ONHARU requests only the scopes needed for the calendar and task features you use, and calendars marked read-only by the provider cannot be edited by the app.
- Update integrity. Updates are downloaded over HTTPS, checked against a published SHA-256 hash, and installed only after you approve them.
If you find a security issue, please contact us at the address in Section 8.
7. Children's Personal Information
ONHARU does not collect age information and does not intentionally collect personal information from children.
8. Policy Changes and Inquiries
If the data we process or the app's features change, we will update this page and its effective date before the change takes effect. Before introducing advertising, we will disclose the provider, transmitted data, and whether personalization is used. Google user data will never be used for advertising. For privacy inquiries, email support@onharu.app or visit Support. Data controller: JUAN.HJLEE, developer of ONHARU.