Privacy
This page describes exactly what Cuco stores and how it protects that data. It covers both the public site and the app. Last updated: October 5, 2026.
What we store
The Google or Microsoft identity you sign in with: the stable identifier the provider gives (for Microsoft, the account’s tenant and object identifier), the email address you sign in with, and a display name and, from Google, a picture when there is one.
For each connected Google or Microsoft calendar account: the provider account identifier, email address, optional display profile, encrypted authorization, and the record of when it was connected and whether it still works.
Your preferences: calendar order and visibility, language, first day of the week, hour format, default event duration, time zones, chosen holiday calendars, preferred route app (Google Maps or Waze), whether you have already seen the welcome tour and the tip for creating events on the grid, and which declined invitations you chose to hide in Cuco — only as references to those events, never their content. For holidays, we store only the canonical identifiers of the selected municipality and state, visibility, order, and whether optional public-administration dates are included.
Technical records of operations in flight — a transfer of an event between accounts that stopped half-way, for example — for as long as you need to finish or undo it.
The days you have Cuco open on screen: only the date (in Brasília time) and whether it was on the web or in the app for Android, iOS, macOS, Windows or Linux — no time of day, device, address or what you did. We keep each day for 90 days, to count how many people use Cuco each day and each week; Cuco’s team can also see which accounts used it, on which days and on which platforms.
If you turn on voice: that setting; for two days, which events each recording created — only the calendar, the events’ identifiers, how many were left out and a cryptographic hash of the request, never what you said; and, for each day you use it, how many recordings you made, how long they were, what understanding them cost and how they turned out, kept for 400 days.
What we do not store
We keep no general copy of your events, guests, calendars or Google Tasks in our databases. Google Calendar, Google Tasks and Outlook Calendar remain the sources of truth. Events and tasks are read from their providers on request, and the disposable cache on your device can be deleted at any time without losing anything at the provider.
We do not store your password, because we never receive it.
Holiday setup does not use GPS or browser geolocation. Cuco does not store an IP address, coordinates, internet provider, browser user agent, or the raw response from the location service.
We use no tracking cookies, no third-party pixels, and no advertising profiles.
We do not keep voice recordings, a transcript of them, or what the model understood from them, and we do not write them to logs.
Automatic holiday setup
While holiday setup is still pending, the app on Windows, macOS and Linux computers and in desktop browsers may directly request https://ipinfo.io/json. Like any internet service you visit, that request exposes the connection’s IP address to IPinfo. Cuco sends no Cuco credentials and uses only country, region and city to resolve a canonical municipality and state.
Android, iPhone, iPad, mobile browsers, mobile web apps and background jobs do not make this request; the location permission the app may ask for serves only the place search described below. Manual selection remains available on every platform and works when IPinfo is unavailable. A completed automatic setup or any manual choice ends future attempts for the account.
Place search and your device’s location
When you choose where an event is, what you type goes to Cuco’s server, which suggests places from open map and address data (OpenStreetMap, IBGE, Foursquare OS Places and Overture Maps) kept on that same server. The text you type is not stored or logged and is not sent to any third party.
The first time you open this search on a device, Cuco asks for the device’s location. If you allow it, your device’s location is sent to Cuco with each search, only to suggest nearby places and show how far they are; it is not stored or logged. If you don’t, Cuco does not ask again and the search still works: the server uses your connection’s approximate location, rounded to about 1 km, only to rank that search’s suggestions. You can change the permission at any time in your device or browser settings.
When you pick a place, its point on the map and the two lines the suggestion showed are written, with the address, as private metadata of the event in Google Calendar or Outlook; they are not sent to guests automatically. Cuco’s database does not keep them, except inside the encrypted copy of an event you are moving to another account, which is erased shortly after that transfer ends.
Your preferred route app is stored with your preferences. When you tap Google Maps or Waze, Cuco opens that app or site with the event’s destination; from there, its own privacy policy applies.
Google data and how it is used
Cuco asks for permission to read the list of calendars you subscribe to and to view and edit events on those calendars. It reads the calendar list to let you choose which calendars to display; it reads event data to show your schedule; and it writes event data only when you ask it to create, edit, move or delete an event.
Google Tasks is a separate, optional permission. If you enable it, Cuco can list your task lists and tasks and can create, edit, complete or delete a task only when you ask. Task titles, notes, due dates, completion state and sync state may remain in Cuco’s disposable, app-isolated cache on your device. Cuco’s server processes task content only to carry requests between the app and Google and keeps no durable general task replica.
When you schedule a task on a calendar, Cuco leaves the task unchanged and writes content-free provider references in private metadata on the new event. A local index uses those references to relate one task to one or more events without copying the task title or notes into Cuco’s database.
Google user data is used only to provide Cuco’s user-facing calendar and task features — never to train or improve generalized AI or machine-learning models, never for advertising or profiling, and never sold.
You can revoke it at any time, either in Cuco or on your Google Account’s permissions page. Revoking stops Cuco’s access immediately.
Microsoft data and how it is used
For an Outlook connection, Cuco requests delegated Microsoft Graph permissions to identify the connected account, read its calendar list, and view and edit events on calendars that account can access, including shared calendars.
Microsoft user data is used only to provide Cuco’s user-facing calendar features — never for advertising, profiling or model training, and never sold. Cuco does not request permission to read Outlook mail, OneDrive files or Microsoft contacts.
You can disconnect Outlook in Cuco at any time, which erases the stored authorization. You can also revoke Cuco directly from your Microsoft account’s app permissions; revoking there stops future access.
Optional Zoom connection
If you connect Zoom, Cuco stores your Zoom user identifier and email address to show which account is connected. Your refresh authorization is kept on the server with authenticated XChaCha20-Poly1305 encryption; its key is separate from the database. The identifier and email are ordinary database fields. Short-lived access tokens stay in server memory and are not sent to the app.
When you choose Zoom for an event, Cuco sends Zoom its title and, for a standalone timed event, its start time in UTC and duration. It creates a meeting, then writes the meeting identifier, join link and Cuco ownership metadata into the event at Google Calendar or Outlook. Depending on Zoom settings and the calendar provider, the meeting details or join link may also include a passcode. This data may remain in the disposable cache on your device. Cuco does not request recordings, transcripts or participant lists, and does not send the event description or guest addresses to Zoom.
Zoom data is used only to provide the connection and meetings you request, never for advertising, profiling or model training, and is not sold. Disconnecting Zoom in Settings removes the stored connection and attempts to revoke the authorization at Zoom. Revoking Cuco in Zoom stops future access; a verified Zoom deauthorization notification removes the stored connection. An expired or invalid authorization may leave the identifier and email so you can reconnect.
Deleting your Cuco account removes its stored Zoom connection. Disconnecting, revoking access or deleting the account does not delete existing Zoom meetings or links in calendar events. Historical connection data may remain in encrypted backups until those backups expire. For privacy questions or help deleting data, contact privacidade@cuco.com.vc.
Optional Pix request code
If you choose to add a Pix request code to an event, Cuco writes the key, amount and, when applicable, calculation rule as private metadata on that Google Calendar event. This metadata does not appear in the standard Google Calendar interface and is not sent to guests automatically. It may also remain in Cuco’s disposable on-device cache, but Cuco does not keep a database copy of it.
When you ask to copy the code, Cuco locally generates a static Pix BR Code. Cuco does not connect to banks, payment institutions, DICT or Pix APIs, and does not initiate, authorize, process, confirm, settle or reconcile transfers.
A transfer can occur only after you take the code to an independent financial app, review the details presented by that institution and confirm the payment there.
Voice (experimental)
Voice lets you record up to two minutes saying what you want in your calendar, and Cuco adds those events. It is off until you turn it on in Cuco’s settings, under Experimental, where Cuco offers it (Android, computers and the web, as each gets it); it is not offered on iPhone or iPad.
When you record, Cuco’s server sends the recording, over an encrypted connection, to OpenRouter, which passes it to a Google Gemini model to understand which events you asked for. With it go only the current time, your device’s time zone and language, and your default event length — never your events or the names of your calendars. Cuco asks OpenRouter to use only providers that keep no data from the request.
The model can only fill in a list of new events. Cuco creates them in your own calendar, without guests, and never changes or deletes an event because of a recording.
Cuco does not keep the audio or what the model understood. It keeps only the setting, for two days which events each recording created, and the daily counts and cost described above. Turning voice off stops new recordings; deleting your account erases all of it.
How we protect calendar data
Cuco uses encrypted HTTPS/TLS for its public interfaces and requests to Google, Microsoft and Zoom. Communication between service components on the private internal network may use HTTP. Google OAuth refresh tokens and Microsoft OAuth refresh tokens are kept only on Cuco’s server and are protected at rest with authenticated XChaCha20-Poly1305 encryption. Encryption keys are stored separately from the database, access to them is restricted, and the keyring supports rotation. Short-lived Google and Microsoft access tokens remain in server memory and are never sent to the browser app.
The Cuco application origin and database are not exposed directly to the public internet. Access is limited to the service components and operators that need it to run Cuco. OAuth credentials, session secrets and event contents are excluded from application logs; stored session tokens are protected; and backups are encrypted before they leave the server.
The disposable calendar and task cache on your device contains no provider OAuth credentials, is isolated to Cuco, and is erased when you sign out. Disconnecting the Google account also removes its task cache. We maintain and review these technical and organizational safeguards, although no method of transmission or storage can be guaranteed absolutely secure.
Service providers and disclosure
Cuco sends requests to Google or Microsoft Graph to perform the calendar and task actions you choose. Choosing Zoom for an event also sends its title and, when applicable, start time and duration to Zoom to create the meeting you requested. Cloudflare processes network traffic and encrypted backups as infrastructure needed to deliver and protect Cuco. IPinfo receives only the direct, credential-free request described above when automatic setup is eligible. If you turn on voice, OpenRouter receives the recordings, with the context described above, and passes them to Google’s Gemini model, through providers that keep no data. These providers process data under their respective services and policies; Cuco does not sell calendar or task data or provide it for advertising or model training.
We do not sell or rent Google or Microsoft user data. Disclosure is limited to the user-requested features and service providers described here, or when required by law or necessary to investigate abuse, protect users, or secure the service.
For how long
For as long as your account exists, except the days you had Cuco open, which are kept for 90 days, and voice’s records: which events a recording created, kept for two days, and its daily counts, kept for 400 days. Deleting your account erases the identity, the authorizations, the sessions, those days, the voice records and the preferences; minimal security audit records may remain without identifying you, where security requires it.
Contact
Privacy questions: privacidade@cuco.com.vc.