What is WipeAway?
WipeAway is a web application that allows users to remove unwanted events from Google Calendar safely and quickly. Users sign in with their Google account via OAuth, select which of their calendars to clean, set a cut-off date, count the events that will be removed, and then — only if they choose to proceed — start the deletion process.
- Users choose which Google account to authorise
- Users choose which calendars to clean
- Users choose a cut-off date — only events before that date are affected
- Users review an event count before anything is deleted
- No changes are made until the user explicitly starts the deletion process
Why Google Calendar Access is Required
WipeAway's sole purpose is to manage Google Calendar events on behalf of the user. Google Calendar access is not an optional feature — it is the entire function of the application.
The application requires Google Calendar access in order to:
- List the user's calendars so they can choose which ones to clean
- Count the number of events before deletion so the user can review the scope
- Delete only the events the user has selected, within the date range they specified
Requested Google Scopes
WipeAway requests exactly two Google API scopes. Both are listed below with their precise justification.
Required because WipeAway must list calendars, count events, and delete the events the user selects. This scope is the minimum required to perform all three operations.
- List the user's calendars so they can select which ones to clean
- Count events in a selected calendar before deletion begins
- Delete only the events the user has explicitly chosen, within the date range they set
Required solely to lock a purchased licence key to the correct Google account, preventing a single key from being shared across multiple users. The email address is never used for marketing, never stored in a database, and never shared with any third party.
- Read the user's Google account email address immediately after sign-in
- Associate the email with a licence key to prevent key sharing
- The email address is discarded at end of session — not retained long-term
Data Usage
WipeAway is designed with a minimal-data approach. The application accesses only what is necessary to perform the specific deletion the user has requested.
✓Calendar names and IDs — to populate the calendar selection list
✓Event IDs and dates — to count and delete events within the user's chosen date range
✓Google account email — to lock the licence key to the correct account
✗Sell, share or transfer user data to any third party
✗Use calendar data for advertising, analytics or marketing
✗Access Gmail, Drive, Contacts or any other Google service
✗Read or store the content of calendar events
✗Access calendars the user has not explicitly selected
Data Storage
WipeAway does not permanently store Google Calendar contents.
While a deletion is running, minimal job-state data (progress counters, continuation tokens) is held temporarily in Upstash Redis. This data contains no calendar event content — only metadata needed to track deletion progress across server invocations.
Once the deletion has completed, all job-state data is discarded. Calendar event data is never written to any of WipeAway's servers, databases or logs.
Only the following is retained after a session ends:
✓Licence key and associated purchase email — stored in a private Google Sheet, used solely for licence validation
✓Operational server logs — standard Vercel function logs, retained per Vercel's default retention policy
OAuth tokens are stored in a short-lived, Secure, HttpOnly session cookie (24-hour expiry) and are never written to any server-side store.
Security
state parameter, stored in a short-lived HttpOnly cookie and validated on callback, preventing cross-site request forgery attacks on the OAuth handshake.Demonstration Video
The video below shows the complete user journey: signing in with Google, reviewing the OAuth consent screen, selecting a calendar, counting events, confirming the deletion, running the deletion to completion, and verifying the result with a recount.
Privacy Policy & Terms of Service
WipeAway's full Privacy Policy and Terms of Service are publicly available and linked from every page of the application.
Reviewer Test Access
To assist with Google's verification process, we have created three dedicated reviewer licences. These have been created specifically for Google's review team and have not been activated.
- Visit https://wipeaway.app
- Click "Already a customer?" and enter one of the licence keys below
- Sign in with your own Google account
- The licence will automatically become linked to that Google account during activation
- You may then use the application normally for verification purposes
If the first licence has already been activated by a previous reviewer, please use Licence B or C. If you have any difficulty activating a key, please contact us at hello@wipeaway.app and we will issue a replacement immediately.
Contact
For any questions about this application or the verification process, please contact us directly. We aim to respond within one business day.
4–6 Middlesex Street
London E1 7JH
United Kingdom