Privacy Policy
Last updated July 29, 2026
Horizon (the “App”) is a macOS menu bar application created by Soraphoj Damrongpiriyapong. Horizon is built to be local-first: your calendar data stays on your Mac. This policy explains what the App handles and how.
What we collect
Nothing is collected on our servers — Horizon has no accounts and no backend. When you connect a calendar provider such as Google Calendar, the App requests read access to your calendar events so it can display them. That data is fetched directly from the provider to your Mac and used only to render your upcoming events.
Where your data lives
- Calendar events are held in memory and local caches on your device to display them in the menu bar.
- Authentication tokens are stored securely in the macOS Keychain and never leave your device except to communicate with the provider you authorized.
- Your preferences (such as focus scopes and settings) are stored locally on your Mac.
How we protect your data
Horizon requests sensitive Google API scopes (read access to your calendar events), and we take the following measures to keep that data secure:
- Encryption in transit. All communication with Google and any calendar provider happens over HTTPS/TLS, so calendar data and credentials are encrypted while moving between your Mac and the provider.
- Encryption at rest. OAuth access and refresh tokens are stored in the macOS Keychain, which encrypts secrets at rest and ties access to your user account and device. Local caches of calendar data reside within the App’s sandboxed container on your encrypted device storage.
- Least privilege. Horizon requests only the minimum scopes needed to display your events and does not request write or delete permissions on your calendar.
- Local-first, no server. Because Horizon has no backend and no accounts, your Google user data is never transmitted to or stored on our servers, eliminating server-side breach exposure.
- Access controls. Data never leaves your Mac except to communicate directly with the provider you authorized, and it is accessible only to the App running under your macOS user account.
- Retention and deletion. Calendar data is cached only as long as needed to display your events. Disconnecting a provider or revoking access removes its stored token from the Keychain and clears the associated cached data from your device.
What we don’t do
Horizon does not sell, rent, or share your data. It does not send your calendar contents to us or to any third party other than the calendar provider you connect. Google user data accessed by Horizon is used only to provide the app’s calendar features and is never used for advertising.
Analytics
The App itself does not include third-party advertising or tracking. If the App reports anonymous crash or diagnostic information in the future, it will not include the contents of your calendar events.
Revoking access
You can disconnect a provider at any time from within Horizon, which removes its stored token from your Keychain. You can also revoke Horizon’s access from your provider’s account settings — for Google, at your Google account permissions page.
Changes
This policy may be updated from time to time. Material changes will be reflected by updating the date above.
Contact
Questions about privacy can be sent to peterdpong@gmail.com.