TulsaCal legal
Privacy Policy
Effective August 1, 2026
The short version
TulsaCal is a public local-events utility. The website has no public user accounts, advertising trackers, or first-party analytics. Its private collection tools process the minimum source material needed to identify and verify public event facts. TulsaCal does not sell personal information.
Scope
This policy applies to the TulsaCal website, downloadable event feeds, and the private tools used to collect event information through websites, Instagram, Facebook, and manually supplied source evidence. It does not govern third-party websites linked from an event record.
Information handled
Website visits
TulsaCal does not require an account or offer a public contact or submission form. The site does not intentionally set advertising or analytics cookies. Cloudflare hosts and protects the site and may process connection data such as IP address, request URL, browser or device information, routing data, and security signals. See Cloudflare's Privacy Policy.
Meta-authorized account data
When an authorized operator connects a professional Instagram account and linked Facebook Page, TulsaCal may receive account and Page identifiers, account metadata, granted permissions, and an access token needed to make approved API requests. Access tokens are treated as secrets and are not published with event data.
Public event-source material
For public professional accounts that Meta makes available through Business Discovery, TulsaCal may process account identifiers, usernames, captions, timestamps, permalinks, media URLs, images, carousel images, and video thumbnails. A manually supplied evidence bundle may also contain public post text, public comment text, and images that materially support an event fact.
Operators are instructed to omit names, contact details, unrelated conversation, and other personal information that is not needed to verify the event. TulsaCal does not request direct messages, passwords, browser cookies, contact lists, or private Group-member data.
Requests and correspondence
If you contact TulsaCal about privacy, correction, or deletion, the service receives the information you provide, such as your email address, the source URL or account involved, and the substance of your request.
How information is used
- Identify, structure, verify, deduplicate, and update public event facts.
- Preserve a source permalink and limited evidence provenance for accountability.
- Authenticate approved Meta API requests and maintain source connections.
- Prevent unchanged posts from being processed repeatedly.
- Operate, secure, troubleshoot, and improve TulsaCal.
- Respond to correction, access, objection, and deletion requests.
- Comply with applicable law and enforce the service's terms.
Automated extraction proposes event fields for the collection pipeline. It is not used to make decisions that produce legal or similarly significant effects about an individual.
Service providers and disclosure
TulsaCal may disclose limited information to:
- Cloudflare, which provides DNS, security, hosting, delivery, and request logging.
- Meta, which provides the Facebook and Instagram authentication and API services.
- OpenAI, which processes selected public text and images to extract structured event facts. Requests use the API with application storage disabled. OpenAI states that API inputs and outputs are not used for model training by default; its default abuse-monitoring retention may be up to 30 days. See OpenAI API data controls.
- Authorities or other parties when reasonably necessary to comply with law, protect rights or safety, or investigate misuse.
TulsaCal does not sell personal information, share it for cross-context behavioral advertising, or use source material to build advertising profiles.
Retention
- Meta access tokens are retained only while the connection is authorized and needed, then revoked or deleted.
- Source-owned images are sent for extraction but are not copied into published observations or event feeds.
- Manual working bundles may be kept while ingestion or review is pending.
- Content hashes may be retained to prevent duplicate processing.
- Derived event facts, source links, and limited provenance may remain in the civic event archive and version history.
- Privacy correspondence is kept as long as needed to complete and document the request.
Personal information that is not needed for these purposes is deleted or de-identified. A verified deletion request can require earlier removal, subject to legal obligations and the distinction between personal information and non-personal public event facts.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection, or to withdraw consent. TulsaCal will not discriminate against you for making a privacy request. See the data-deletion instructions for the request process.
Removing TulsaCal from your Facebook or Instagram connected apps stops future access to non-public account data, but it does not by itself delete data previously received by TulsaCal. Submit a deletion request for that step.
Children
TulsaCal is a general-audience local-events utility and is not directed to children under 13. It does not knowingly collect personal information from children through the website or Meta integration. Contact TulsaCal if you believe such information was collected.
Security and international processing
TulsaCal uses reasonable administrative and technical safeguards, including encrypted connections and secret storage for API credentials. No system is perfectly secure. Cloudflare, Meta, and OpenAI may process information in the United States and other countries under their applicable terms and safeguards.
Changes to this policy
This policy will be updated when TulsaCal's data practices materially change. The effective date at the top identifies the current version.
Contact
This legal page is an in-progress draft. The public operator and monitored privacy contact are not configured yet, so this page is not release-ready.