← Up Next

Security overview

Written for someone reviewing whether this is safe to run on a managed Mac. It describes what the app is, what it can reach, how the Google credential is protected, and who can get at any of it. The threat model and the full design are in the repository, in docs/spec.md §8.

Last updated: 30 September 2026

Summary

What it is technically

An Electron app (Chromium plus Node) for macOS on Apple silicon, written in TypeScript. It has four windows: a floating widget, a settings window, a small quick-add box for typing a TODO, and notifications. There is no Dock icon; it lives in the menu bar.

The app is split into a privileged process, which holds the credential and talks to Google, and sandboxed UI processes, which draw pixels and can do nothing else. Everything sensitive stays on the privileged side of that line. The four runtime dependencies are Google’s official calendar and auth clients, a logger, a settings store, and a schema validator.

Access to Google data

Token management

Who has access

One person: the user sitting at the Mac. There is nobody else in the system to grant access to, because there is no system.

What is on disk, and what is not

Hardening

Supply chain and updates

Limits, stated plainly

Every control above protects against something specific. These are the things it does not protect against, and pretending otherwise would make the rest less useful.

For a reviewer

The source is public and the design document states the threat model, the attack surface with a named control for each entry, and the reasons behind each decision, including the ones that were reversed. The test suite covers the security paths specifically: that credentials never appear in logs, that meeting URLs never reach the UI, that unexpected message senders are rejected, and that privacy mode redacts before anything is displayed.

Questions are welcome, as are findings. Raise them on the source repository, or at the support address on the Google consent screen. If you believe you have found a vulnerability, please report it privately first.