Legal resources

Google Calendar privacy notice

This notice covers the optional Calendar connection, not the entire PrepOS website, learning platform, payments, or AI features.

Last updated:

Who provides this connection

PrepOS is operated by TESTPREP SOFTWARE SOLUTIONS LTD, company number HE491893, at 10 Odos Apollonos, Office 1, 5290 Paralimni, Cyprus. Contact us about this Calendar connection or your data at hello@getprepos.com.

This notice explains how the optional PrepOS Google Calendar connection handles your data, including when you use PrepOS through a branded learning space such as IMATMentor. Your learning provider’s notices and applicable agreements govern its separate use of course, membership, and learning records.

Connecting is optional. You can use your learning platform without connecting a Google calendar. Google displays the shared PrepOS application identity when asking you to authorize the connection.

What access you grant

We request Google’s calendar.app.created permission. It allows management of secondary calendars created by this application and their events. It does not grant this integration access to your pre-existing personal, work, or other calendars, Gmail, contacts, or Drive files.

For each connected learning space, the integration creates and manages a dedicated Google calendar. During the IMATMentor pilot it is named “IMATMentor Calendar.” Although Google’s permission is application-wide, our integration keeps each space’s connection and event mappings separate.

Data used and why

We use the connection only to show your authorized learning events in Google Calendar and maintain those copies when their details, schedule, cancellation status, or your access change.

Data sent from your learning space to Google includes the event title, description, start and end, timezone, online joining link where present, in-person location and room where present, and technical identifiers connecting the copy to its source space, event, and occurrence. The integration does not attach an attendee list or send invitations to other people.

Google returns authorization tokens, the dedicated calendar’s identifier, and responses needed to create, update, verify, or remove that calendar and its events. We store an encrypted refresh token, your platform user and space identifiers, the dedicated calendar identifier/name, event-mapping identifiers, source version numbers, and connection/sync status timestamps. Short-lived authorization records protect the sign-in callback. Operational error records may contain user/space identifiers, timestamps, and error codes.

This is one-way synchronization from the learning platform to Google. Changes you make in Google do not update the source event. Do not store unrelated personal events in the dedicated calendar: disconnecting removes that entire calendar, including anything you added yourself.

Sharing, protection, and limits

Google receives the event information needed to provide the calendar you requested. Cloudflare provides the integration’s application hosting, database, and background processing. The learning platform uses Firebase/Google Cloud to authenticate your platform account and check current membership and event access. These services can process data in countries outside your own; applicable provider terms and data-processing arrangements also apply.

Refresh tokens are encrypted before database storage. Access tokens are used server-side to call Google; the connection does not ask for or store your Google password. Access to production systems must be limited to authorized personnel and service providers for operating, securing, or supporting the connection and meeting legal obligations.

We do not use Google Calendar data for advertising, sell it, or use it to train AI models. Use and transfer of information received from Google APIs must follow the Google API Services User Data Policy, including applicable Limited Use requirements.

Your own Google Calendar sharing settings and other applications you authorize may affect who can see copied events. Revoking learning-platform access cannot recall screenshots, exports, or independent copies already made by someone with access.

Retention, disconnecting, and deletion

While connected, we retain the authorization and mapping records needed to maintain the dedicated calendar. Cancelling an event or losing access causes its managed Google copy to be removed during synchronization; this depends on successful processing and Google being reachable.

Use “Disconnect Google Calendar” in the space’s notification settings to stop that space’s connection. A successful disconnect removes its stored refresh token, dedicated calendar identifier, and event mappings from the active integration database, and deletes the dedicated Google calendar when authorization still permits it. If you already revoked Google access, you may need to remove the calendar in Google yourself. Temporary provider or storage failures can require retrying disconnect; do not assume deletion succeeded when an error is shown.

Disconnecting does not delete the original learning-platform events or your membership. It does not disconnect other spaces. To revoke PrepOS’s application-wide Google authorization, use Google Account connections; this affects your other PrepOS connections as well. Revocation alone does not guarantee that calendars or copies already stored in Google are deleted.

The current pilot retains a minimal disconnected-connection record containing the platform user/space identifiers, calendar name, and status timestamps after the token and mappings are removed. Expired authorization records cannot be used; they are removed when a later authorization request performs cleanup. Backup, operational-log, and residual-record deletion are separate from active-database disconnect. Contact us to request deletion of remaining integration records.

Your choices and requests

You can decline the connection, disconnect a space, or revoke PrepOS in Google Account settings. Contact hello@getprepos.com to request information, access, correction, or deletion of connection data, or to raise a privacy concern. Tell us the relevant learning space; never send your password, refresh token, or private calendar-feed link. We may need to verify your identity and involve the learning provider for requests concerning its source records. Your applicable data-protection rights and rights to complain to a supervisory authority remain unaffected.

We will date the published notice and explain material changes. New uses or access beyond what you authorized require an updated disclosure and any required fresh consent before they begin.