Skip to main content
AIRIN
PricingSign in

How long does Caretta keep your data?

Describes how OAuth tokens are handled: a refresh token is retained for the calendar connection via offline access, the Drive token is short-lived and is not retained, and calendar write access remains disabled in production until scope approval and user enablement — detailing differential retention and activation conditions for each token type.

Their words · Privacy Policy

“ Google Calendar uses the access_type=offline OAuth parameter so Caretta can receive a refresh token and maintain the calendar connection. The Drive token is short-lived and is not retained. The calendar.events.owned scope is used only in our development verification flow. Calendar write access remains disabled in production while verification is pending. Production will request it incrementally only after Google approves the scope and you enable follow-up invites.”

Captured 2026-09-24. Open captured source →Snapshot SHA-256: 0c3bb62b5484c04ba6512d02001b948489d3a41312a458227b26f35b922edf5e

Permalink to this finding →

Informational only, not legal advice. Terms can change; check the cited policy and capture date before relying on this answer.

The same question for other platforms

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.