Month, week, day views
Full event CRUD across all three views. Each event carries title, description, location, start/end, all-day toggle, color, reminder minutes and status (confirmed / tentative / cancelled).
Events
Full event CRUD across all three views. Each event carries title, description, location, start/end, all-day toggle, color, reminder minutes and status (confirmed / tentative / cancelled).
Propose meeting times to other members, they counter-propose. Share a free/busy/propose/manage view of your calendar with specific contacts. Accept shared proposals in-app.
Events are encrypted client-side. EU-hosted, never sold or profiled. Reminders fire from your device, not from a server that tracks when you open which event.
Authentication and key exchange are post-quantum, as everywhere in UltimaOS. The stored content of Calendar, however, sits outside the end-to-end encrypted envelope today — the details are below, stated plainly rather than glossed over.
All authentication and key exchange uses NIST-standardized ML-DSA-65 (FIPS 204) signatures and ML-KEM-768 (FIPS 203) key encapsulation. There is zero RSA, zero elliptic-curve, zero classical-only crypto in the authentication path. Defeats store-now-decrypt-later attacks.
Calendar sits outside the end-to-end encrypted envelope in the current release: events are stored unencrypted on the server, which means the operator can read them. End-to-end encryption for calendar events is committed for Beta. Until it ships, treat the calendar as server-readable and keep sensitive detail out of event titles.
Authentication, key exchange and transport are post-quantum and unchanged. Your calendar is not sold, profiled or used for advertising, and it runs on EU infrastructure — but that is a policy and an operating commitment, not the mathematical guarantee the encrypted apps give you.
Your private keys are derived in your browser from three secrets only you control, and are held in memory for the session only — never written to browser storage, never sent to the server. A new device derives the same keys locally from the same three secrets.
UltimaOS runs in any modern browser — Chrome, Firefox, Safari, Edge. Nothing to install. Sign in by re-entering the three secrets your keys are derived from, and the same keys are rebuilt locally on whatever device you are using.
Calendar sits outside the end-to-end encrypted envelope in this release, so what you put into it is readable by the operator. The connection is protected in transit, and authentication remains post-quantum, but the stored content is not encrypted to your keys.
Anything you would not want the operator to be able to read should go in one of the encrypted apps instead — chat, files, notes or documents — until end-to-end encryption reaches Calendar.
Any change you make is uploaded and picked up by every other device you are signed in on, so Calendar looks the same wherever you open it.
Propose meeting times to specific contacts. They counter-propose in Calendar.
Schedule sends a calendar invite encrypted by Mail. Recipients RSVP from their Calendar.
Tasks inherit their due date from Calendar events. Completing one unlinks the other.
Calendar events attach to Boards cards as milestones. Drag a card onto a date to set due.
UltimaOS runs in Chrome, Firefox, Safari and Edge. Nothing to install. Sign in with your passphrase to derive your private key locally.
The launcher shows every app. Calendar is right there with its capsule video preview. Click to open.
Calendar works alone, but it shines when combined with the rest of the UltimaOS apps. Same identity, same workspace, one place to work.
Short answer
Not today. Calendar events are stored unencrypted on the server and sit outside the end-to-end encrypted envelope, so the operator can read them. End-to-end encryption for calendar events is committed for Beta. Until it ships, keep sensitive detail out of event titles and descriptions.
Short answer
Calendar uses the same post-quantum authentication and key exchange as every other UltimaOS app: ML-DSA-65 (FIPS 204) signatures and ML-KEM-768 (FIPS 203) key encapsulation, over a connection protected in transit. What it does not yet use is the XChaCha20-Poly1305 content envelope — calendar events are stored server-readable until that ships with Beta.
Short answer
Yes. Sign in on any device by re-entering your three secrets and the same keys are derived locally, so your Calendar content follows you. Changes sync live across all signed-in devices.
Short answer
Not today. Calendar events are stored unencrypted on the server and sit outside the end-to-end encrypted envelope, so the operator can read them. End-to-end encryption for calendar events is committed for Beta. Until it ships, keep sensitive detail out of event titles and descriptions.
Short answer
UltimaOS is free for individuals and families — permanently, not as a trial. Organizations pay per seat once early access ends, and that is what funds the free accounts. There is no per-app add-on.
Short answer
Yes. UltimaOS supports encrypted export of all your content for backup and portability. The export is encrypted to a key you control; you can store it on your own infrastructure or in a personal encrypted backup.
Short answer
Yes. You can share free/busy, propose-meeting, or full manage access with specific contacts. Each sharing scope is encrypted and revocable at any time.
No ads, no data mining, no trial clock. Individual and family accounts are free — permanently. Organisations pay per seat, and that is what funds it.