Privacy Policy
Effective October 10, 2026
TimeTug is a macOS app made and operated by Binary Companion, LLC. It reads your calendars, shows your upcoming meetings, and takes over your screen shortly before one starts so you don't miss it. To do that, TimeTug talks directly to wherever your calendar already lives: Google, Microsoft, iCloud, another CalDAV calendar provider, or the Apple Calendar system built into your Mac. The calendar data goes between your Mac and that provider, and TimeTug works with it on your Mac. This page explains what TimeTug reads, exactly what it keeps on your Mac, what is protected and how, and how to remove it.
What TimeTug reads, and why
TimeTug reads events from the calendars you choose, so it can show them in your agenda, warn you before they start, and offer a Join button for video calls. Depending on the calendar, an event can include its title, start and end times, location, description or notes, the people invited, and a video-call link. TimeTug uses these while it is running; the next section says which of them are ever saved.
- Apple Calendar (built into macOS). If you grant Calendar access, TimeTug reads events from the calendars macOS already has configured (iCloud, Google, Exchange, or anything else added in System Settings). The events stay in Apple's own calendar system on your Mac; TimeTug asks it for them and never sees the Apple ID or passwords behind those accounts.
- Google Calendar, if you connect an account. TimeTug uses Google's OAuth
sign-in and requests two scopes:
Your Mac asks Google directly, using a token Google issues to you. Google Calendar support is currently in beta, pending Google's certification (OAuth verification) of TimeTug.
calendar.events.readonly— view events on your calendars, so TimeTug can show them in your agenda and trigger a takeover before they start. TimeTug only reads events; it does not create, edit or delete them.calendar.calendarlist.readonly— see the list of calendars you're subscribed to, so you can choose which ones TimeTug pays attention to.
- Microsoft (Outlook) calendars, if you connect an account. TimeTug uses
Microsoft's sign-in and requests these read-only permissions:
offline_access(stay signed in without asking again),User.Read(your name and email address, to label the account),MailboxSettings.Read(your time zone), andCalendars.ReadandCalendars.Read.Shared(view your calendars, and calendars shared with you). TimeTug only reads events; it cannot create, change or delete anything in your Microsoft calendar. - iCloud and other CalDAV calendars. For iCloud, you give TimeTug your Apple ID and an app-specific password that you create yourself at account.apple.com, so your real Apple Account password is never needed. For any other CalDAV provider (for example Fastmail or Nextcloud), you give TimeTug the provider's server address, your user name and your password. TimeTug uses them to ask that provider for your events, and only sends them to that provider.
- Calendar subscription links, if you add one. You can paste an iCal link (a
webcal://orhttps://address) that a service such as Meetup gives you for your events. TimeTug downloads that address every 15 minutes and reads the events in it: their titles, times, places, descriptions and links. It only reads; it cannot change anything at the service. Anyone who has the link can read the same feed, so treat it like a password, and revoke or replace it at the service if it leaks. TimeTug only sends the link to the address it names. - An on-device Apple Intelligence model, only if you turn it on. Settings › Calendars has an opt-in, off-by-default, Beta feature that asks your Mac's own on-device model whether two ambiguous events are the same meeting, to avoid double-tugging you. It requires macOS 26 on a supported Mac. For each pair of events it is shown their titles, times, calendar names, and, where they exist, locations, the names of attendees (not email addresses) and the start of the notes. It runs entirely on your Mac, answers with one word (same, different or unsure), and nothing about your calendar leaves your Mac for this. Your calendar data is never used to train or improve any AI or machine-learning model.
What TimeTug keeps on your Mac
Everything below stays on your Mac. TimeTug has no TimeTug account, and it doesn't upload, sync or back up any of it. Your Mac's own backups, such as Time Machine, may include these files like any other file on your Mac.
Locked in the macOS Keychain (encrypted)
Only sign-in secrets go here. macOS encrypts them and only lets TimeTug read them, and only after you have unlocked your Mac at least once since it started up.
- For Google and Microsoft: the token that keeps TimeTug signed in. It is not your password.
- For iCloud and other CalDAV providers: the user name and the app-specific password or password you entered.
- For calendar subscription links: the link you pasted.
Saved as ordinary files (not encrypted by TimeTug)
These are plain files. They are protected by your Mac's account permissions and, if you have turned it
on, FileVault, which encrypts your whole disk. The first four are in
~/Library/Application Support/TimeTug/; the agenda file is in a folder that TimeTug shares
with its widgets. In everyday terms, here is what is in them.
- Your list of accounts. Each connected account's type (Google, Microsoft, iCloud, CalDAV, iCal link), its email address, Apple ID or user name, and, for CalDAV, the server address, the web addresses of your calendars on that server, and the email addresses your account uses on invitations. For an iCal link, the calendar's own name (if the feed has one) and the web site name are kept in this file; the link itself is only in the Keychain. No passwords or tokens are in this file.
- Sync bookmarks. Short markers that let TimeTug ask a provider for only what changed since the last check, plus a list of your calendars (their IDs and, for CalDAV, their names and colours) so TimeTug notices when one is added or changed. They contain no event information.
- Alert history, so TimeTug never repeats an alert after a restart or snooze that you set. For each event that has already alerted or been snoozed it saves a reference to the event made from the account, the event's ID at the provider and its start time, and a lookup key made of the event's title (lowercased), start time and end time. It does not save who was invited, the description, notes or location. Entries are kept for at most seven days.
- Your merge corrections. If the same meeting appears on two calendars and you tell TimeTug that two events are the same, or are different, it remembers your answer so it doesn't ask again. It saves the two event titles, which calendars they were on, a note of what details each event had (for example "no details" or "has a location and notes"), and your decision. It does not save who was invited, descriptions, notes or locations. TimeTug keeps up to 300 of them, for about six months after you last needed them. If the on-device model is on, TimeTug also remembers its same/different answers for a week, stored under an anonymous fingerprint of the pair, with no titles or other event details. You can erase all of this at once with Forget learned corrections in Settings › Calendars.
- An agenda for the widgets, because macOS widgets can't reach the app's data themselves. It covers today and the next two days and contains, for each event, an internal ID, the title, start and end times, whether it lasts all day, the calendar's colour, and the video-call link if there is one. It does not contain who was invited, the description, notes or location. It is replaced every time TimeTug refreshes, and the widgets ignore it if it is more than 12 hours old. Events from calendars you've hidden are left out.
Preferences
Your settings, such as how early to alert you, appearance, and which calendars you've switched on or off (by the calendar's ID, which for some providers is an email address), are stored in the standard macOS preferences for TimeTug.
Never saved
While TimeTug is running it holds the full details of upcoming events in memory: descriptions and notes, locations, the names and email addresses of invitees, who accepted or declined, and reminders. It uses them to show your agenda and pop-up cards and to find video-call links. It does not write them to disk, and they are gone when you quit TimeTug. Event titles that appear in macOS's system logs are marked private.
Diagnostics log
TimeTug keeps a short log in memory of what it has been doing, the last few hundred events: counts, status codes and kinds of error. It never contains calendar links, event titles or event contents. The same entries are written to the macOS system log, where values that come from your calendar data are marked private. Nothing is sent anywhere. The log is gone when you quit TimeTug, and it is copied only if you press Copy Diagnostics in Settings and choose to share it.
How we protect your data
- Encrypted in transit. TimeTug talks to Google, Microsoft, iCloud and other CalDAV
providers over HTTPS/TLS. For CalDAV it refuses any server address that isn't
https://(a local test machine is the only exception) and refuses addresses that have a password typed into them. For calendar subscription links it likewise refuses any address that isn'thttps://(webcal://is treated ashttps://, and a local test machine is the only exception) and will not follow a redirect to a web address that isn'thttps://. Apple Calendar events come through macOS itself. - Secrets in the Keychain, not in files. The Keychain encrypts sign-in tokens and passwords at rest, as described above. The plain files on your Mac never contain them.
- Safer sign-in. Google and Microsoft sign-in use OAuth with PKCE (a one-time secret that stops an intercepted sign-in code from being reused), in your own browser or the system sign-in sheet. TimeTug never sees your Google or Microsoft password. For iCloud we ask for an app-specific password, so your Apple Account password isn't needed and the app-specific password can be revoked at any time.
- Least data saved. As described above, TimeTug saves the least it needs to work: titles and times in some files, and never invitee names, descriptions, notes or locations.
- Limited access. TimeTug uses macOS's hardened runtime and is code-signed, which limits what other software can inject into or change in the running app. The widgets run in the macOS App Sandbox, and the only TimeTug data they can read is the agenda file above and a few shared on/off preferences.
- Read-only permissions. TimeTug asks Google and Microsoft only for read-only calendar permissions, so it cannot change or delete anything in your Google or Microsoft account.
- No extra copies. There is no TimeTug account, database or cloud copy of your calendar data, and nobody but you has access to it through TimeTug.
If you find a security problem in TimeTug, or believe your data has been exposed, please email sobryan@binarycompanion.com.
What TimeTug does not do
- No analytics, telemetry, or crash reporting of any kind.
- No advertising and no ad or tracking SDKs.
- We do not sell, rent, or share your calendar data with anyone, for any purpose.
- Your calendar data is not used to train or improve any AI or machine-learning model.
- TimeTug does not require a TimeTug account to read or show your calendars.
Software updates
TimeTug checks a public update feed (hosted on GitHub Pages) to see whether a newer version exists. That request carries no calendar data or personal information — it's the same kind of request your browser makes loading any web page, logged the same way GitHub logs any visitor to its pages.
Your controls
- Disconnect an account anytime in TimeTug's Settings › Accounts. TimeTug stops reading it, deletes its sign-in token or password from the Keychain, deletes its entry in the account list and its sync bookmarks, and immediately rewrites the widget agenda without its events. The alert history and merge corrections described above aren't deleted at that moment: alert history disappears within seven days, and you can erase corrections at once with Forget learned corrections.
- Revoke access at the provider. Disconnecting in TimeTug removes TimeTug's copy of your sign-in from your Mac. To also cancel the access on the provider's side, revoke it there: for Google, at Google Account › Third-party access; for Microsoft, in your Microsoft account's app permissions; for iCloud, by deleting the app-specific password at account.apple.com.
- Turn off Apple Intelligence matching anytime in Settings › Calendars; TimeTug falls back to rules-only matching.
- Remove local data entirely. Quit TimeTug and disconnect your accounts (which clears
the Keychain items), then delete
~/Library/Application Support/TimeTug/. Uninstalling the app on its own does not remove those files or Keychain items, so do this first.
Google API Services User Data Policy
TimeTug's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children's privacy
TimeTug is not directed at children, and we do not knowingly collect information from anyone under 13.
Changes to this policy
If this policy changes in a way that matters — a new data source, a new third party — the date at the top will change and, for anything material, we'll say what changed here.
Contact
Questions about this policy or your data: sobryan@binarycompanion.com, or open an issue on GitHub.