Skip to content
Ghost Suite

GhostCal

A calendar and a scheduling tool you host yourself, on iPhone and in the browser. This is the support page. It says what the product does, what it does not, and how to reach us.

Last updated:

What GhostCal does

The title, location and description of your events are encrypted on your device, with a key derived from your passphrase. That phrase never leaves the device. The title and notes of your tasks are sealed the same way.

  • Your day: today’s agenda, your calendars, and the events you create from the app, with their title, location, description, times and all-day flag.
  • Your tasks, with their due date, sorted by urgency.
  • Your booked appointments: the meetings your invitees took through your public links (who, when, where, and their answers to your questions). You can cancel one from the app.
  • Your booking links: switch an event type on or off, and copy its public link in one gesture.
  • Your time-slot polls: see who voted for what, and keep the winning slot.
  • Your team: the members of your organisation, their roles, and what it takes to change them.
  • Face ID or Touch ID reopen your calendar without retyping the phrase. It is sealed by the device hardware: adding a face or a fingerprint invalidates the seal, and GhostCal tells you so instead of pretending. Auto-lock is configurable: immediately, or after 1, 5 or 15 minutes.
  • On your server: you type the address of your instance on the first screen. GhostCal knows no default server and imposes none.

No trackers, no advertising, no behavioural analytics.

What the server sees, and why

GhostCal is not “fully encrypted”, and writing that would be false. The server keeps the times: it needs to know when you are busy in order to refuse an overlapping booking, and to send reminders.

So the following travel in cleartext: times, time zones, email addresses, calendar names, meeting titles and booking locations. The following are sealed: the title, location and description of an event, and the title and notes of a task. The app says so on the creation screen itself, rather than leaving you to guess.

GhostCal cannot be blind, and saying so is more honest than implying otherwise. The detail, field by field, is in the privacy policy, which names GhostCal.

What the iOS app does not do

This list is the counterpart of the first one. Every line is something that neighbouring products advertise, that GhostCal does not have today on iPhone, and that is better read here than discovered in use.

  • No offline access. No cache, no local database, no sync queue: without a network, nothing is displayed.
  • No notifications on the device. Reminders go out from the server, by email.
  • No inviting participants from the event creation screen.
  • No recurring events. The occurrences of an existing series are displayed, but cannot be edited from the app.
  • No week or month view. The calendar shows a single day.
  • Creating polls, event types and working hours happens on the web. The app reads them and toggles them; it says so on screen.
  • No inviting a member into the team from the app.
  • No changing your password or passphrase from the app.
  • No adding a profile picture: you can remove one, not choose one.
  • No import or export from the app.
  • The iOS app is in French only.

What it does on its own, without going through the web: creating and editing events, managing tasks, cancelling meetings, toggling booking links, settling polls, administering team roles.

Where your calendar runs

GhostCal is self-hosted, and that is the heart of the model rather than a footnote. The software is free, the instructions live in its repository, and the app is fully usable without paying anything: no feature sits behind a payment.

For those who would rather not host, StackOps makes a machine available: it is the machine that is on offer, never the software. Write to us if you want to talk about it.

GhostCal is under the Elastic License 2.0: the code is readable, modifiable and self-hostable, the only limit being reselling it as a hosted service. That is source available, not open source in the OSI sense.

Getting help

Write to contact@stackops.ch. It is the only support address, and it is read by the people who write the code.

For the answer to be of any use, say in your message:

  • the device and iOS version, or the browser if you are on the web;
  • what you were doing, what you expected, and what happened instead;
  • the exact text of the error message, if there was one;
  • the address of the server you connect to, if it is not ours.

Never send your passphrase, or the content of an event or a task. We do not need any of that to help you, and sealed content would tell us nothing anyway.

We do not advertise a guaranteed response time. There is no support team on rotation, and announcing an hour we would not keep would cost more than writing it this way.

Reporting a problem

A malfunction is reported to the same address, contact@stackops.ch.

A security vulnerability too, and it goes ahead of everything else: we acknowledge receipt within 72 hours, we keep you posted on what follows, and we credit you if you wish.

For a request concerning your personal data, access, rectification, erasure or portability, write to privacy@stackops.ch.