Privacy
What we collect, in full
What browsing, contributions and private notifications store.
Browser storage. Opening private access sets a session cookie so you can manage your subscriptions and agent access. It expires after seven days; signing out ends that session. Your colour scheme is stored separately in your browser and is not sent with requests. Clearing browser storage also signs you out, so keep your private management link somewhere safe.
Counting visits, without following you. When analytics are running we use PostHog on EU infrastructure, in cookieless mode: no identifier is stored on your device, nothing persists between visits, and session replay, autocapture and surveys are all switched off. It tells us which pages people read. It is not used to identify your private space. Private management and authorization pages are excluded from analytics.
Errors. When something breaks, the stack trace is reported so it can be fixed. Sensitive request fields and private URLs are redacted before error reports are sent.
What you send us. If you submit an event or report a wrong listing, we keep your message, the link it is about, and your email address if you gave one — which is optional. It is used to answer you, and for one thing more: if the event you sent is published, we may write once to tell you, which means that address is passed to Brevo, the company that delivers our email. It goes on no mailing list. Nothing is sold or passed to advertisers.
Agents and event review. A contribution made through private access also records its owner, the credential used, its receipt and whether it came through the site, API or MCP. Receipts are visible to that owner and the admin. Submission context can be used alongside the event page by our extraction provider, Anthropic, to draft a listing for review. Submitting something does not publish it or verify that you are its organiser.
Private access and subscriptions. We store your saved criteria, followed events, notification history, credential names and permissions, and agent authorizations. Management links and access tokens are stored as hashes. You do not need to provide an email to use this space. Notification history is available for 90 days; expired notifications and temporary access records are cleaned up by scheduled maintenance. The admin sees aggregate matching owner and subscription counts while reviewing events, without a list of your private criteria or contact details.
Optional webhooks. If you add an endpoint, we store its address, an encrypted signing secret and delivery attempts. We send a verification challenge and then notifications containing public event information and the identifiers of the subscriptions that matched. Delivery can be retried. Your endpoint receives these requests and manages its own copies; turning it off does not remove information it already received.
Abuse prevention. We keep temporary request counters, including a keyed hash derived from the network address, to limit automated account creation and submissions. Private credentials have separate request limits. These counters are not used for advertising.
The listings themselves are public information: an event, its organiser, its date, its city, taken from the pages organisers publish. If you organise one of them and want it changed or removed, ask and it is done.
Your controls. In private access you can revoke agent credentials or delete the space. Deleting it removes its credentials, subscriptions, inbox, webhook endpoints and tracked contributions. A public listing created after review remains part of the catalogue. Revoking one agent key alone keeps your subscriptions and notifications running. No email recovery is configured for a lost management link.
Write to hello@hackalendar.com for a copy of information you sent us, or to request its deletion.
Last updated 14 September 2026
← Back to the hackathons