Clock Gallery

Privacy Policy

Privacy Policy

How Clock Gallery handles your information. No accounts, no ads, no analytics.

Contents

    Privacy Policy

    Last updated: October 6, 2026

    This policy explains how the Clock Gallery app (for Apple TV and other platforms, “the App”) and its supporting servers (clockgallery.app and pair.clockgallery.app) handle your information.

    1. No accounts

    The App has no sign-up. It does not collect your name, email address or device location, and it contains no analytics or advertising.

    2. Information used when you connect Google Calendar

    The App connects to your calendar only when you choose to. It then receives from Google:

    • Your Google account email address — to show which account is connected
    • Your calendar list (calendar.calendarlist.readonly) — so you can choose which calendars to show
    • Your events (calendar.events.readonly) — titles, times, all-day status and your response status for the 7 days before and after today, used to display events beside the clock, the time until your next event, and reminders before events

    The App requests read-only access. It cannot create, change or delete events. Private events are shown as “Busy” without their titles.

    Where it is stored

    • Your events and calendar list are stored only on your Apple TV. The App fetches them directly from Google; they never pass through our servers.
    • Google access tokens are stored in the Apple TV keychain (this device only, not synced to iCloud). The long-lived refresh token is kept on your device only in a form encrypted with our server’s key; we do not store it on our servers.
    • Our server (pair.clockgallery.app) only hands over the sign-in result and relays token refreshes. Temporary sign-in data is deleted within 10 minutes. Our server logs never contain tokens, email addresses or events.

    Google API Services User Data Policy

    Clock Gallery’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use this information only for the display features described above. We do not use it for advertising, sell it, share it with third parties, allow humans to read it, or use it to train AI models.

    3. Information used when you connect Apple (iCloud) Calendar

    The App connects only when you choose to.

    • The Apple Account email address and app-specific password you enter (created at appleid.apple.com; not your Apple Account password) are stored in the Apple TV keychain (this device only) and sent only to Apple’s iCloud servers. They are never sent to our servers.
    • Your calendar list and events are read directly by the Apple TV from Apple’s servers (CalDAV, read-only) and stored only on the device.
    • Disconnecting in the menu deletes the password and events from the device.

    4. How we protect your data

    We protect sensitive data, such as your calendar data and access tokens, with the following measures.

    • Encryption in transit: all communication between the App, our server, Google and Apple is encrypted with HTTPS (TLS).
    • Storage on your device: Google tokens and your Apple app-specific password are stored in the Apple TV keychain with the “this device only” setting (ThisDeviceOnly), so they are not backed up to other devices or synced to iCloud. Events are stored only in the App’s own sandboxed storage, which other apps cannot read.
    • Encrypted refresh token: the long-lived refresh token is kept on your device only after being encrypted with our server’s key using AES-256-GCM. Our server does not store it.
    • Protected sign-in hand-off: sign-in uses PKCE, and the sign-in result is encrypted to a public key generated by your TV (ECDH P-256 with AES-256-GCM) before it is handed to the TV. The same 6-digit number is shown on the TV and on your phone so you can confirm them before signing in. Token refresh and revoke requests are verified with a signature from the TV’s key (ECDSA P-256).
    • On our server: temporary sign-in data is deleted automatically within 10 minutes. Tokens, email addresses and events are never written to server storage or logs. Server keys and the Google client secret are not included in source code; they are kept as encrypted secrets in Cloudflare and are accessible only to a limited number of developers.
    • Least privilege: the App requests read-only access and uses only the fields needed for the display features.

    5. Disconnecting and deleting your data

    • In the App, choose Calendar → Disconnect. This revokes Google’s permission and deletes the tokens and events stored on your device.
    • You can also revoke access at any time from Third-party access in your Google Account.
    • Deleting the App also deletes the events stored on the device.

    Our servers keep no per-user records, so there is nothing to delete on our side.

    6. Other features

    • Weather: the name of the city you choose in the App (not your device location) is sent to our relay (pair.clockgallery.app). The relay obtains the weather for each city from Apple WeatherKit, keeps it for 30 minutes and returns the same data to every user. It does not store anything that identifies you. Weather data is provided by Apple Weather.
    • Purchases: handled by Apple through the App Store. We do not receive payment information.
    • Settings: your chosen clocks and display settings are stored on your device.

    7. Children

    The App is not designed to collect personal information from children.

    8. Changes

    We will update this page and its date when this policy changes. Before using your information in any new way, we will tell you in the App.

    9. Contact

    support@clockgallery.app