Privacy Policy
1. Overview
Ahem! ("the app", "we", "our") is a Windows and Mac desktop application, developed by Invisible Game Design s.r.o., that displays full-screen meeting reminders by reading your calendar. This policy explains what data the app accesses, how it is used, and where it goes — which is: nowhere.
Ahem! has no servers, no telemetry, no analytics, and no cloud component of any kind. The app runs entirely on your local machine.
2. Data we access
To display your upcoming meetings, Ahem! requests read-only access to your calendars. On both Windows and Mac, it supports:
- Google Calendar (via Google OAuth)
- Outlook and Microsoft 365 (via Microsoft OAuth)
Ahem! also supports iCloud Calendar, on both Mac and Windows, though the connection method differs by platform:
- On Mac, iCloud Calendar access uses Apple's native EventKit framework, the same permission model as Apple's own Calendar app: you click "Connect iCloud Calendar," macOS shows its standard system permission prompt, and you tap Allow. Ahem! never sees or stores your Apple ID, password, or any app-specific password — access is a macOS-managed permission grant, revocable at any time via System Settings → Privacy & Security → Calendars.
- On Windows, which has no built-in iCloud permission system, iCloud Calendar access uses CalDAV: you provide your Apple ID email address and an app-specific password generated at appleid.apple.com — never your regular Apple ID password. This connects directly to Apple's own iCloud CalDAV servers to read your calendars.
The app requests the minimum permissions required — read-only access to event data. It cannot create, edit, or delete calendar events.
3. How your data is stored
All data accessed by Ahem! remains on your local machine:
- OAuth access tokens and refresh tokens for Google and Outlook are stored exclusively in the OS keychain — Windows Credential Manager on Windows, the macOS Keychain on Mac. They are never written to disk in plain text and never leave your device.
- iCloud Calendar access on Mac has no token to store at all — it's a permission grant managed entirely by macOS via EventKit. On Windows, the app-specific password used for iCloud CalDAV is stored exclusively in the Windows Credential Manager, the same OS keychain used for Google and Outlook tokens — never written to disk in plain text.
- Calendar event data (titles, times, and meeting links) is cached in a local file inside the app's data folder so your reminders keep working even if you start your computer without a network connection.
- App settings and reminder state (which calendars are enabled, snooze/dismiss history, etc.) are stored in local configuration files in the same folder.
- No data is ever sent to our servers — because we have no servers.
4. Data protection mechanisms
Because calendar data and OAuth credentials can be sensitive, Ahem! protects them as follows:
- Encryption in transit: all communication with Google's and Microsoft's APIs, and with Apple's iCloud CalDAV servers on Windows, happens over HTTPS/TLS. Ahem! never transmits calendar data or credentials over an unencrypted connection.
- Encryption at rest (Windows): OAuth access and refresh tokens, and the iCloud CalDAV app-specific password, are stored exclusively in the Windows Credential Manager, which encrypts secrets using the Windows Data Protection API (DPAPI) tied to your Windows user account. Nothing is ever written to disk in plain text.
- Encryption at rest (Mac): OAuth access and refresh tokens are stored exclusively in the macOS Keychain, encrypted and tied to your Mac user account. iCloud Calendar access has no token to encrypt — it's a system-level EventKit permission grant.
- No server-side storage: since Ahem! has no backend, there is no remote database, log, or server that could be breached to expose your calendar data — the only copy exists on your own device.
- Access scope: the local event cache and settings files are stored under your OS user profile (
%APPDATA%on Windows,~/Library/Application Supporton Mac) and are only readable by your own OS account, the same as any other per-user application data. - Least-privilege access: Ahem! requests only read-only calendar scopes (
calendar.readonlyfor Google,Calendars.Readfor Outlook, read-only EventKit access for iCloud on Mac, read-only CalDAV requests for iCloud on Windows) — it never requests write, delete, or broader account access than is needed to display your schedule.
5. Data we do not collect
Ahem! does not collect, transmit, or store:
- Your name, email address, or any account information
- Your calendar event titles, descriptions, or attendee lists
- Usage statistics, crash reports, or analytics of any kind
- Device identifiers, IP addresses, or location data
- Any behavioral or usage data whatsoever
6. Purchases
Ahem! is sold as a one-time purchase through multiple storefronts:
- Polar — our direct checkout, covering both the Windows and Mac builds. Payment information (name, email, billing details) is collected and handled by Polar. Please review Polar's Privacy Policy for details.
- Microsoft Store — available via the Windows Store. Purchases made through the Microsoft Store are subject to Microsoft's Privacy Statement.
- Mac App Store — available via the Mac App Store. Purchases made through the Mac App Store are subject to Apple's Privacy Policy.
Regardless of storefront, we receive only confirmation that the purchase was completed. We do not receive or store your payment details.
7. Third-party services
Ahem! connects to Google and Microsoft's calendar APIs solely to fetch your event data for local display. These connections are governed by their respective privacy policies:
- Google Privacy Policy
- Microsoft Privacy Statement
- Apple Privacy Policy (Windows iCloud CalDAV connections only — see below)
On Mac, Ahem! does not connect to Apple's servers at all — it reads iCloud Calendar events through macOS's own EventKit framework, the same local API Apple's Calendar app uses. Any syncing between your Mac and iCloud is handled entirely by macOS, outside of Ahem!. On Windows, by contrast, Ahem! connects directly to Apple's own iCloud CalDAV servers (caldav.icloud.com) to fetch your calendar events — this connection is read-only and governed by Apple's privacy policy.
We do not share any data with Google, Microsoft, or Apple beyond what is necessary to authenticate and fetch your calendar events.
8. Google API Services — Limited Use disclosure
Ahem!'s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data obtained from the Google Calendar API is used only to provide Ahem!'s user-facing reminder features on your own device — it is never transferred to third parties, never used for advertising, and never read by any human.
9. Children's privacy
Ahem! is not directed at children under 13. We do not knowingly collect any information from children.
10. Changes to this policy
If we make material changes to this policy, we will update the effective date at the top of this page. Given the nature of the app — purely local, no data collection — significant changes are unlikely.
11. Contact
Questions about this policy? Submit your question via this form and we'll get back to you.