Privacy policy
Loefte (løfte) · Last updated 7 September 2026
Who runs this and what it is
Loefte is a self-hosted personal workspace — notes, ideas, tasks, a calendar, trip plans and a household budget. There is no Loefte company and no shared cloud service. This instance is installed and operated privately by one person (the "operator"), for themselves and the small number of people they share it with, on a server they control. The operator is the data controller for everything described below.
Registration is not open to the public: accounts on this instance exist only because the operator created them.
What Loefte stores about you
Your own content, because storing it is what the app is for:
- Notes, ideas, tasks, calendar events, database rows, plans and budget records that you create.
- Files you upload — images pasted into notes, a plan's cover photo, PDF attachments.
- Your account: the name and email address supplied by the sign-in provider used to log in, and your settings.
- Ordinary server logs (request path, status, timing) kept by the web server.
All of it is stored in this instance's own PostgreSQL database and on its own disk. None of it is sent to an analytics service, an advertising network or any other third party — the application deliberately makes no third-party requests at all while you use it, and there is an automated test in the codebase that fails the build if one is ever introduced.
What Google data we access
Connecting a Google account is optional and every part of Loefte works without it. If you do connect one, Loefte requests exactly these scopes and uses them only as described:
| Scope | What Loefte reads or writes | Why |
|---|---|---|
https://www.googleapis.com/auth/calendar |
Events in the Google calendars you select: their title, description, location, start and end times, recurrence, attendees and reminders. Loefte both reads them and writes events you create or change in Loefte back to that calendar. | Two-way calendar sync, so the calendar in Loefte and the one on your phone are the same calendar. |
https://www.googleapis.com/auth/tasks |
Your Google Tasks lists and the tasks in them: title, notes, due date and completion state. Loefte reads them and writes back the ones you add, edit or tick off in Loefte. | Two-way task sync. Read-only access would make completing a task in Loefte invisible everywhere else. |
https://www.googleapis.com/auth/userinfo.email |
The email address of the Google account you connected. Nothing else from your profile. | To label the connection on the Settings page, so you can see which account is linked and disconnect the right one. |
Loefte does not request access to Gmail, Google Drive, Contacts, Photos, location history or any other Google service. Calendar and task data fetched from Google is stored in this instance's own database so the app works offline and can show it alongside your own records; it is used for nothing else.
The access and refresh tokens Google issues are stored encrypted (AES-256-GCM) in the instance's database. They are used only to call the Google Calendar and Google Tasks APIs on your behalf.
Limited Use. Loefte's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: data obtained through these scopes is used only to provide and improve the calendar and task features described above; it is not transferred to anyone except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition (none of which applies to a privately operated instance); it is not used for advertising of any kind; and no human reads it except you, unless you give explicit permission, it is needed for security purposes or to comply with applicable law, or the data is aggregated and anonymised.
Storage, retention and deletion of Google data
- Where. Events and tasks fetched from Google are stored in this instance's own PostgreSQL database, on the operator's own server. They are not copied anywhere else.
- Encryption. The OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. All traffic to and from the server is over HTTPS.
- How long. Tokens are kept until you disconnect, and are deleted immediately when you do. Synced events and tasks are kept until you delete them in the app or ask for the account to be removed; there is no other expiry, because they are your own calendar entries.
- Sharing. None. Data obtained from Google APIs is not sold, not shared with any third party, not used for advertising and never sent to an AI provider. The only place it goes is back to the Google calendar or task list you chose to sync with.
- Deletion. Press Disconnect on Settings → Connections to delete the tokens and stop all access. Revoke independently at any time at myaccount.google.com/permissions. To have everything removed, including already-synced events and tasks, write to the contact address at the bottom of this page and the account will be deleted.
Microsoft accounts
Loefte can connect to Microsoft Outlook calendars in the same optional
way, using the scopes Calendars.ReadWrite,
User.Read, openid, email and
offline_access. Everything said above about storage,
encryption, sharing, retention and deletion applies identically.
Sharing
Nobody, by default. Your data is not sold, rented or given to any third party, and is not used to train anything. There are exactly three ways data leaves this server:
- Back to Google or Microsoft, when you have connected an account: events and tasks you create or edit in Loefte are written to the calendar or task list you chose to sync. That is the feature.
- To another person on this instance, when you deliberately share a note, plan or ledger with them, or publish a public read-only share link.
- To an AI provider you configure yourself — the assistant is optional and off unless the operator supplies an API key. When it is on, the text you send it, and the notes you explicitly ask it to work with, are sent to that provider (for example Anthropic or OpenAI) to produce an answer. Data obtained from Google APIs is never sent to an AI provider.
Deletion and retention
- Your content is kept until you delete it. Deleted items go to the Trash and are removed permanently from there.
- Google and Microsoft tokens are deleted immediately when you press Disconnect on the Settings → Connections page. That revokes Loefte's further access at once.
- Calendar events and tasks already synced remain in your Loefte workspace after disconnecting, because they are now your records too. Delete them in the app, or ask for the whole account to be removed.
- Your whole account, with everything in it, is deleted on request — write to the address below. Deleting the account removes your notes, files, tokens and every synced record from the database.
- Server logs are kept only as long as the container's log rotation holds them, and are not used for profiling.
You can also revoke Loefte's access to your Google account at any time, independently of this app, at myaccount.google.com/permissions.
Storage and security
- All traffic is served over HTTPS.
- OAuth tokens and other stored secrets are encrypted at rest with AES-256-GCM.
- Sign-in uses an external identity provider; Loefte never sees your Google or Microsoft password.
- Every API request is scoped to the signed-in user, and shared items are checked against an explicit grant.
- Files you upload are served only to you, or to the people you shared the item with.
Your rights
The operator is in the EU, so the GDPR applies: you may ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, or object to a particular use. Write to the address below and the operator will answer. Loefte also has a built-in export (Settings → Export) that gives you your notes, calendars and databases as files, without asking anyone.
Children
Loefte is not directed at children and no account is created for anyone without the operator doing it deliberately.
Changes
If what the app collects changes, this page changes with it and the date at the top is updated. The scopes listed above are the ones the code requests today.
Contact
The operator of this instance, as data controller, can be reached at privacy@lnln.eu.