Privacy and data handling

Last updated: July 24, 2026

What Oggie does

Oggie lets you connect Google Calendar and Microsoft Calendar to calendar tools used by you or by agent surfaces such as CLI, ChatGPT, and Claude.

Data we handle

How we use data

We use this data to authenticate you, connect your calendar, run calendar tools, make requested calendar changes, prevent abuse, debug issues, and keep audit records.

Oggie reads calendar events from Google or Microsoft when needed. Oggie does not keep a local copy of your calendar events for normal list, search, free/busy, availability, or policy preview answers.

Oggie uses one Main conversation across its first-party surfaces. For example, a Telegram conversation can provide context for a later Oggie CLI, WhatsApp, or native-app request without copying that earlier message into the other messaging app's interface. Oggie sends only a bounded recent suffix of complete conversation turns, the shared working-context scratchpad, and durable memory to the native agent model. It does not generate conversation summaries or search older transcript history for model context.

Working context and memory are treated as potentially stale context, not authority; current instructions and live calendar-provider data remain authoritative.

When you submit screenshots, Oggie temporarily stores only encrypted image objects, decrypts and normalizes them in server memory, and sends them through the native agent's zero-retention, no-prompt-training model route. Conversation history stores encrypted opaque screenshot references rather than image bytes, storage paths, URLs, OCR, or extracted text.

Google API data

Oggie accesses your Google account identifier, email address, and profile name to identify and label the Google account you connect. Oggie accesses your calendar list, calendar events, event attendees, event descriptions and locations, and free/busy information to provide the calendar features you request.

Oggie uses this data to list and distinguish your calendars, read and search events, check availability and conflicts, create events, update events, cancel events, watch for event changes, and run calendar sync policies that you configure.

Oggie does not sell Google user data, use it for advertising, or use Google Workspace API data to develop, improve, or train generalized AI or machine-learning models.

Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.

Microsoft Graph data

Oggie uses Microsoft Calendar data from Microsoft Graph only to provide calendar features you request. We do not sell Microsoft user data, use it for ads, or use it to train generalized AI models.

Agent surfaces

When you use Oggie through Telegram, ChatGPT, Claude, or another connected agent, Oggie returns only the calendar data needed for the request. That surface may process the data under its own terms and privacy policy.

Every active connection you authorize may read and edit your shared working-context scratchpad and may read, create, correct, and delete durable memory. Concurrent scratchpad edits use revision checks so one agent cannot silently overwrite another agent's newer edit. Their private host transcripts are not automatically copied into Oggie.

How we protect sensitive data

Oggie uses HTTPS/TLS to protect data in transit between your browser, Oggie, Google, Microsoft, and authorized agent surfaces.

Google and Microsoft OAuth access and refresh tokens stay server-side and are encrypted with AES-256-GCM before they are stored in the database. The encryption key is kept in the server environment separately from the encrypted database records. Agent connection tokens and short-lived channel-link challenges are stored only as SHA-256 hashes.

Oggie encrypts native-agent message content, screenshots, the shared working-context scratchpad, durable agent memory, and pending Telegram reply text with AES-256-GCM before storing them. Each user has a separate random content key, and each screenshot has an additional random image key wrapped by that user key. User content keys are encrypted by a root key kept in Oggie's server environment, separately from Supabase. This application-level encryption adds protection beyond the database provider's own infrastructure security: access to the database or Storage alone is not enough to read your conversations, memories, or images. It is not end-to-end encryption because Oggie's authorized server runtime must decrypt content to operate the agent; an attacker controlling both that runtime and the stored data could access it.

Native-agent model requests require providers that support zero data retention and no prompt training through Oggie's model gateway configuration.

Authentication and database row-level security restrict stored records to the authorized user and Oggie server processes. Raw calendar tool inputs and outputs are not retained in activity logs.

Storage and retention

Oggie stores operational calendar metadata such as connected calendar names, provider calendar IDs, sync markers, compact activity logs, and provenance for events Oggie creates or syncs. Compact activity logs are retained for 90 days.

Your Main conversation transcript and durable memory remain stored until you explicitly delete the relevant history or memory, or delete your account. The working-context scratchpad remains stored until an authorized agent edits or clears it, you clear conversation history, or you delete your account.

Prepared screenshots expire 24 hours after processing. Unfinished uploads expire sooner. Oggie deletes encrypted Storage objects before deleting their durable cleanup records, and failed cleanup remains queued for retry.

Sharing

We share data only with providers needed to operate Oggie, with Google or Microsoft when using their calendar services, with connected agent surfaces you authorize, or when required by law. We do not sell personal data.

Deletion

You can ask Oggie explicitly to clear conversation history. This queues referenced screenshots for Storage cleanup, removes earlier transcript messages, and clears working context while preserving the clearing turn and durable memory. You can inspect, correct, or forget individual durable memories. Revoking or deleting one connection stops that connection's access but does not delete the user-owned Main conversation.

To request account deletion, email privacy@getoggie.com. Account deletion removes the Main conversation, history, working context, and memory. We may retain limited security, activity, or legal records where necessary.

Contact

Email privacy@getoggie.com.