Last updated 17 August 2026 · shsked.com · SHSked.com ·
https://shsked.com
Last updated: 16 August 2026
Short version: this app has no server. Your schedule file and
your calendar data stay on your device and are never transmitted to, collected by, or
stored by the developer.
What the app accesses
With your permission, SHSked.com requests two Google Calendar permissions:
View and edit events on your calendars (calendar.events)
— used solely to create and update the schedule events you ask it to create.
See the list of Google calendars you’re subscribed to (calendar.calendarlist.readonly)
— used solely to display your calendar names so you can pick a destination.
The app does not read, collect, or transmit the contents of your existing calendar
events.
What is collected
Nothing. The app is a single web page that runs entirely in your browser. It has no
backend server, no database, and no analytics. The developer has no access to your
schedule file, your calendar, or your Google account, and receives no information about
your use of the app.
Where your data goes
The schedule spreadsheet you select is read in your browser's memory and is never uploaded.
Events are sent directly from your browser to Google's Calendar API over an encrypted connection.
The access token issued by Google is held in the page's memory only and is discarded when the tab closes. It is not written to cookies, local storage, or any other persistent location.
Data protection and security
SHSked.com is designed so that sensitive data is protected primarily by never being
collected, transmitted to us, or stored. The following measures apply:
Encryption in transit
The application and all of its pages are served exclusively over HTTPS (TLS). Plain
HTTP requests are redirected to HTTPS.
All communication with Google's servers — the sign-in flow and every Google
Calendar API request — takes place over HTTPS (TLS) directly between the user's
browser and Google. No intermediary server is involved.
No storage of sensitive data
There is no backend server, database, log store or file store operated by the
developer. No user data is received by the developer at any point.
The schedule spreadsheet the user selects is read in the browser's memory only. It
is never uploaded, copied, or written to disk by the application.
The OAuth access token issued by Google is held in the memory of the open page only.
It is never written to cookies, localStorage, sessionStorage, or any other
persistent location, and it is destroyed when the browser tab is closed.
No refresh tokens are requested or stored, so access cannot be re-established
without the user explicitly signing in again.
Access control
User data is accessible only to the signed-in user, within their own browser
session. The developer has no ability to access, view, or export any user's
spreadsheet, calendar, or Google account data.
Access to Google Calendar is granted by the user through Google's OAuth consent
screen and can be withdrawn by the user at any time at
myaccount.google.com/permissions.
The OAuth client is restricted to a fixed list of authorized JavaScript origins, so
credentials cannot be used from any other website.
The application source is served as static files from a repository controlled by a
single owner account protected by two-factor authentication.
Minimum scopes
The application requests the narrowest scopes that permit its function:
calendar.events to create and update the user's schedule
events, and calendar.calendarlist.readonly to display the
names of the user's calendars for selection.
The broader calendar.readonly scope was deliberately
replaced with calendar.calendarlist.readonly so that the
application cannot read the contents of existing calendar events.
Limited use
Google user data is used solely to provide the user-facing feature described on this
site: writing the user's own work schedule to their own calendar.
Google user data is never transferred to third parties, sold, used for advertising,
used to build user profiles, or used to develop, improve, or train generalized
artificial intelligence or machine learning models.
No humans read Google user data. The developer has no technical means of doing so.
Retention and deletion
No user data is retained, because none is collected. There is no account to close
and no stored record to delete.
Data held transiently in the browser is discarded when the page is closed.
Calendar events created by the application belong to the user and can be deleted by
them at any time in Google Calendar.
Sharing
No data is shared with any third party, because no data is collected. The app makes
network requests to Google only, for the purpose of signing you in and writing the events
you requested.
Retention and deletion
Because nothing is stored, there is nothing to retain or delete. You can revoke the
app's access to your Google account at any time at
myaccount.google.com/permissions.
Events already written to your calendar belong to you and can be deleted from Google
Calendar like any other event.
Google API Services User Data Policy
SHSked.com's use and transfer of information received from Google APIs
adheres to the
Google API Services User Data Policy,
including the Limited Use requirements.
Hosting
This page and the app are served as static files. The hosting provider may log
standard web request information such as IP addresses; the developer does not access or
process those logs.
Changes
If this policy changes, the revised version will be posted here with an updated date.