プライバシーポリシー kichijitsu Privacy Policy
最終更新: 2026-07-31
概要
kichijitsu(以下「本アプリ」)は、Google カレンダーのクライアントアプリです。 本ポリシーは、本インスタンス(kichijitsu.love-rox.cc)が取り扱う情報と、その扱い方を説明します。
取得・保存する情報
サーバー(Cloudflare D1 / Durable Objects)に保存されるのは、次の情報です。機能を使って いない場合、その機能に対応する情報は作成されません。
- Google アカウント識別子とメールアドレス — ログインと、連携した複数アカウントの識別のため
- Google OAuth トークン — カレンダーとの同期のため。リフレッシュトークンは AES-256-GCM で暗号化して保存します(復号鍵はデータベースとは別に保持します)。 有効期限の短いアクセストークン(1時間程度)は、同期を担う Durable Object に一時的にキャッシュされます
- 同期の状態 — 差分同期のカーソル(syncToken、カレンダーと端末の組ごと)、 ポーリングの状態、および Google からの更新通知を受け取るための購読登録(通知チャネルの ID・対象カレンダー・有効期限)
- 表示するカレンダーの選択 — どのカレンダーを表示するかの選択を、 端末をまたいで揃えるため
- カレンダーブロックの設定 — 予定を別のカレンダーへ「予定あり/不在」として自動複製 する機能を使う場合、その転記元・転記先カレンダーの指定と、「元の予定の ID → 生成したブロックの ID」の対応表。対応表が持つのは ID と更新時刻だけで、予定の内容は含みません
- GitHub 連携の情報 — GitHub と連携した場合、GitHub のユーザー識別子・ログイン名・許可された範囲(スコープ)と、AES-256-GCM で暗号化したアクセストークン
- MCP トークンのハッシュ値 — エージェント連携(MCP)用のトークンを発行した場合、 その SHA-256 ハッシュ値・ラベル・最終使用日時。トークンの生の値は発行時に一度だけ表示し、 サーバーには残しません
作業実績(ワークログ)
作業時間を記録すると(アプリの右ペインでの手動記録と、MCP 経由のエージェントからの記録の いずれも)、作業実績がサーバーに保存されます — リポジトリ名、issue の参照、ブランチ名、エージェント名、開始と終了の時刻です。 これは Google に元のデータが存在せず、kichijitsu の上で作られる、あなた自身の活動記録です。 上に挙げた他の情報が Google 側のデータを指す手がかりか、あなたの設定であるのに対し、 これだけは性質が異なり、サーバーがそのようなデータを保管しているのは現在ここだけです。 この機能を使わなければ作成されません。
予定の内容について
カレンダーの予定の内容(タイトル・説明・参加者など)はサーバーに保存しません。 予定データは Google から取得後、あなたのブラウザ内のローカルストレージ(IndexedDB)に保存されます。 上に挙げたもののうち予定に関わる情報は、いずれも ID・時刻・設定であって、予定の中身では ありません。MCP 連携でエージェントに返す予定の要約も、その場の応答として返すだけで、サーバー側に保存されません。
また、デスクトップ版で予定のリマインダー通知を使う場合、同じ通知を二度出さないための記録が 同じ端末のブラウザ内ストレージ(localStorage)に残ります。この記録には カレンダーの ID(多くはメールアドレスの形をしています)・予定の ID・予定の開始時刻 が含まれます(予定のタイトル・説明・参加者は含まれません)。この記録は端末の中だけに置かれ、 サーバーにも Google にも送信されず、開始時刻から24時間を過ぎたものは自動的に削除されます。
情報の利用目的
取得した情報は、カレンダーの表示・同期・編集と、あなたが有効にした機能(カレンダーブロック、 GitHub 連携、エージェント連携と作業実績の記録)の提供のみに使用します。 広告への利用、第三者への販売・提供は一切行いません。人による閲覧も、セキュリティ対応・法令対応・ ユーザー同意がある場合を除いて行いません。
Google ユーザーデータの取り扱い(Limited Use)
本アプリによる Google API から取得した情報の利用は、 Google API Services User Data Policy (Limited Use の要件を含む)に準拠します。
データの保持と削除
上記の情報は、連携が続いているあいだ保持されます(作業実績を含め、期間による自動削除は 行いません)。
アプリ内の「連携解除」を実行すると、そのアカウントについて Google からの更新通知(push 通知)の購読を停止し、Google トークンを失効させたうえで、アカウント情報・カレンダーの選択・同期状態・購読の記録・ そのアカウントが関わるカレンダーブロック設定(書き込み先が解除されたアカウントならルールごと、 参照元の一部なら該当の参照だけ)をサーバーから削除します。最後の1アカウントを解除すると、そのプロファイルに紐づく GitHub 連携・MCP トークン・作業実績もあわせて削除され、ログイン状態も破棄されます。 Google アカウントの設定からもいつでもアクセス権を取り消せます。 ブラウザ内のローカルデータは、設定の「ログアウト」で消去できます(予定・タスク・GitHub の一覧が端末から消えます。タイムブロックと作業タイマーの記録はこの端末にしか無いデータの ため残ります)。すべて消したい場合はブラウザのサイトデータ削除を使ってください。
なお、カレンダーブロック機能が Google カレンダー上に作成した「予定あり」等のブロック予定の扱いは、解除によってルールが残るかどうかで変わります。複数の参照元を持つルールの一部だけを解除した場合、ルールは残った参照元で生き続け、解除したカレンダー由来のブロック予定は解除の直後に削除されます(生きているルールが元の予定に追従した結果であり、参照元が次に変化した時点でいずれ削除されるものを待たずに行うだけです)。ルールごと消える場合(書き込み先を解除した場合や、参照元をすべて解除した場合)は、ブロック予定はそのカレンダーに残ります。解除の操作には削除の可否を確認する場面が無いためで、参照元をすべて解除した場合のように書き込み先のアカウントが残っていても削除は行いません(あわせてサーバー側の対応表も削除されるため、以後アプリからは操作できません)。不要な場合は Google カレンダー側で削除してください。このほかにブロック予定を Google カレンダーから消せるのは、アプリ内でブロックのルールを削除するときに「作成済みのブロック予定も削除する」を選んだ場合だけです(ルールの書き込み先を変更しただけでは、作成済みのブロック予定は削除しません)。
セキュリティ
通信はすべて TLS で暗号化されます。Google のリフレッシュトークンと GitHub のアクセストークンは保存時に AES-256-GCM で暗号化され、その復号鍵はデータベースの中ではなく 別の秘密情報として保持されます。MCP トークンはハッシュ値のみを保存します。 インフラは Cloudflare(Workers / D1 / Durable Objects)上で運用されます。
連絡先
運営者: love-rox
Privacy Policy (English)
kichijitsu is a calendar client for Google Calendar. When you use this instance (kichijitsu.love-rox.cc), the following is stored on the server (Cloudflare D1 and Durable Objects). Data for a feature is only created if you use that feature.
- Your Google account identifier and email address — for sign-in and to tell connected accounts apart
- Google OAuth tokens — for calendar sync. Refresh tokens are encrypted at rest with AES-256-GCM (the decryption key is held separately from the database). Short-lived access tokens (about one hour) are cached temporarily in the Durable Object that performs the sync
- Sync state — incremental sync cursors (syncTokens, per calendar and device), polling state, and the push-notification subscriptions used to receive updates from Google (channel ID, target calendar, expiry)
- Your choice of visible calendars — so the same selection applies across your devices
- Calendar blocking settings — if you use the feature that mirrors events onto another calendar as busy/out-of-office: the source and target calendars, and a mapping from original event ID to generated block ID. That mapping holds IDs and update timestamps only, never event contents
- GitHub connection details — if you connect GitHub: your GitHub user ID, login name and granted scopes, plus an access token encrypted with AES-256-GCM
- Hashes of MCP tokens — if you issue tokens for agent access (MCP): their SHA-256 hash, label and last-used time. The raw token is shown once at issuance and is never stored
Work logs
If you record work time — either manually in the app's right pane or through an agent over MCP — your work logs are stored on the server: repository name, issue reference, branch name, agent name, and start/end times. This is a record of your own activity created within kichijitsu, with no original held by Google — and it is currently the only such data the server keeps. Everything else listed above is either a pointer to data that lives in Google or a setting of yours. Nothing is created unless you use the feature.
About event contents
Your calendar event contents (titles, descriptions, attendees) are never stored on our servers — events are synced directly to your browser's local storage (IndexedDB). Everything listed above that relates to events consists of IDs, timestamps and settings, not the events themselves. Summaries of the events MCP returns to an agent are likewise sent straight back as the response and never stored on the server.
In addition, if you use event reminder notifications in the desktop app, a record of which notifications have already been shown is kept in that device's browser storage (localStorage) so the same notification is not shown twice. Each entry contains the calendar ID (often in the form of an email address), the event ID and the event's start time — never the event's title, description or attendees. This record stays on the device, is never sent to our servers or to Google, and entries are discarded automatically 24 hours after the event's start time.
We use this information solely to provide calendar display, sync, and editing. We do not use it for advertising, sell it, or share it with third parties. kichijitsu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The data above is retained for as long as the connection exists; nothing (work logs included) is deleted automatically on a schedule. Disconnecting an account from within the app stops that account's push-notification subscriptions with Google, revokes its Google token, and deletes that account's credentials, calendar selection, sync state, subscription records, and any calendar blocking settings involving it — the whole rule if the disconnected account was the target, or just the affected reference if it was one of several sources. Disconnecting the last remaining account also deletes the GitHub connection, MCP tokens and work logs belonging to that profile, and signs you out. You can also revoke access at any time from your Google Account settings. To clear local data, use Log out in settings — it removes this device's copy of your events, tasks and GitHub list. Time blocks and manual timer records stay, because this device is the only place they exist. To erase everything, clear the site's data in your browser.
What happens to busy/out-of-office blocks the blocking feature already created in Google Calendar depends on whether the rule survives the disconnect. If you disconnect only some of a rule's source calendars, the rule lives on through the remaining sources and the blocks derived from the disconnected calendar are deleted right away (that is the surviving rule following its sources, and only brings forward a deletion that the next change to a remaining source would have made anyway). If the rule itself goes away — you disconnected its destination calendar, or all of its sources — the blocks remain in that calendar. Disconnecting offers no moment to ask whether they should be deleted, so the app does not delete them, not even when the destination account is still connected (as it is when you disconnect all of a rule's sources); the server-side mapping is deleted as well, so the app can no longer manage them. Delete them in Google Calendar if you no longer want them. Apart from that, the only case where the app deletes those blocks is when you delete a blocking rule in the app and leave "delete the blocks already created" checked; changing a rule's destination calendar alone never deletes blocks that were already created.
Operator: love-rox
Contact: kichijitsu@love-rox.cc