Jason LeeCal.com

Item 56 of 59

The license never reached the meeting

7 min 1,517 words

The Cal.com wordmark in charcoal letters centered on a pale gray background

The most senior partner I ever worked for did not own a scheduling link. This was 2018, when every vendor had one, and he had a paper diary and an assistant who typed confirmations in a typeface I associate with insurance documents. If you wanted forty-five minutes of his time, you sent him two windows and he picked one. That was the entire negotiation.

I suggested, early and stupidly, that a booking tool would modernize the intake for client calls. He asked me one question. Who else would be able to put things in my calendar. I said, well, whoever you gave the link to, plus the tool. He wrote my two windows in the diary and the meeting happened anyway, and I forgot the exchange for eight years.

I remembered it in April, when Cal.com, the open-source scheduler that built its brand on being the anti-Calendly, moved its production codebase into a private repository. Because a scheduling link is a small claim on another person's time dressed as a courtesy, and the software underneath it has almost nothing to do with that claim; the link moves the coordination cost onto whoever can only click. It's not a calendar question. It's a permissions question, and the permissions were always the product.

My own stake: I run a booking link on Cal.com's free plan for readers who want to argue with me live. I pay them nothing, so I'm reviewing the $0 tier of a company whose customers are elsewhere and whose subsidies bought my link.

Open source is a property of the code, not of the calendar

What open source actually changes about a booking tool is narrow and real. You can host it yourself. Your booking data lives where your server lives. That matters for scheduling specifically, because the lock-in in this category isn't features, it's every link you have ever sent, sitting dead in inboxes you no longer control.

What open source does not change is the meeting. The invite still lands in someone's calendar and still costs the same thirty minutes. The license had no opinion about that. Cal.com spent five years as the open-source alternative, fifty thousand GitHub stars and a Y Combinator badge, and the openness worked as a wedge against Calendly. It told developers and privacy-conscious buyers a story about ownership. It never told them one about their Tuesdays, because no license can.

On April 14 the company announced that the production code behind its hosted service was moving to a private repository, citing AI-driven vulnerability scanning of public code. The old public repo was relaunched as Cal.diy under an MIT license with the commercial features stripped out: teams, workflows, analytics, SSO. The documentation calls the fork strictly personal, non-production use, at your own risk. Per The New Stack's reporting, the production code had already diverged from the public one, with authentication and data handling rewritten outside the open repo before the announcement. April is when they drew an existing boundary on the map.

Consider the incentive. Openness was the marketing asset while the asset sold to developers. The buyers who pay the bills are enterprises, and enterprises buy compliance, and compliance buyers don't read code, they read certifications. Once the open repo reads as a security liability to that buyer, the asset gets repriced. Bailey Pumfleet told The New Stack the decision was entirely about security, and co-founder Peer Richelsen went further, arguing that any open-source application is at risk and should take its sensitive parts private. I believe both of them, which is not the same as believing the move was inevitable.

The free tier is priced like a funnel

The free individual plan is the best deal in scheduling and I don't trust it as far as I can throw it. Unlimited event types, unlimited bookings, a hundred-plus integrations, payments through Stripe. Cal.com's free tier is the full product for one person, and the paid tiers run Teams at $12 per user monthly billed annually, Organizations at $28, Enterprise at a number you negotiate, per the company's pricing page. Calendly's free tier allows one active event type, a product decision dressed as a limitation: the one link you send is a demo. The cost structure, checked against those pages in October 2026:

Tier Cal.com Calendly equivalent
Individual, free $0, unlimited event types $0, one active event type
Team $12 per user, annual billing about $15 per user
Organization $28 per user, adds SSO and SCIM about $20 per user, enterprise tier
Self-hosted MIT license via Cal.diy, personal use not offered

Now watch the funnel. Every scheduler in this market converges on the same buyer: the sales org that needs round-robin routing, the enterprise that needs SAML and audit trails. The solo freelancer is not the customer. The freelancer is the distribution, links seeding a market the paid tiers harvest, and the $0 plan costs the company a rounding error. The enterprise drift is the business model announcing itself. The free user was never the customer. Calendly walked this road first. Cal.com is walking it with a developer's accent.

The metered edges show where the road goes. Cal.ai, the phone agent that calls people to book, bills $0.29 a minute once you exhaust the bundled credits, per meetergo's June 2026 pricing guide. A flat subscription turning into a per-minute charge is a genre of invoice I know from the consulting years: we billed a scheduling tool by the seat, watched the seat count become a headcount metric, and watched the metric become a line item nobody could justify and nobody would kill. The tool was fine. The pricing was an org chart.

Self-hosting doesn't make the calendar free either. The license costs nothing. A ten-person hosted team pays about $120 a month at the annual rate, while a self-hosted instance runs on maybe $20 of server plus the engineer-hours to patch, back up and keep it online, and for most teams that math lands on the hosted plan, per meetergo's breakdown. Free code, paid calendar.

The residency promise had an expiry date

The sharpest example arrived on July 30, when the company announced that Cal.eu, its European-hosted edition built for data-residency buyers, would shut down on November 1. People chose Cal.eu because they wanted their scheduling data on European soil. They received a migration notice, an export link and a deadline. Enterprise customers keep access for the term of their contracts, which tells you whose term matters. The company's privacy policy names the United States as the place of processing, per a Convios audit from August, and the pricing page had listed EU hosting as an upper-tier feature. The feature had a date.

Self-hosting was supposed to be the answer here. No vendor can take away a thing that runs on your own server. But the self-hosted option that exists today is a fork with the team features removed and a personal-use warning label, and it cannot run the thing Cal.eu customers were buying. The DIY answer arrived after the promise died, and in a weaker form. That sequencing is the audit.

The security argument deserves better than its marketing

The outrage has the weaker case, so I'll be unsympathetic to it. Here is the strongest honest version of Cal.com's position. Heartbleed lived in open code for two years, Log4Shell for about seven, both found by researchers rather than attackers precisely because the code was auditable. Automated scanning at today's capability changes the economics of that audit: finding an exploitable bug in a public codebase used to cost a researcher weeks, now it costs an afternoon, and the marginal attacker gains everything while the marginal defender gains nothing that publicity would protect. Meanwhile the public repo had already diverged from production, so the open code was an audit of a product nobody runs. Open source never really protected the user of a hosted service anyway. It protected the fork.

That last clause is where my sympathies sit, so state my conflict plainly. I got eighteen months of a free booking link out of a company that spent real money subsidizing it, and my interest in calling the closed-source move a betrayal is partly aesthetic, the pleasure of watching a principle lose. The people this genuinely inconveniences are Cal.eu customers and self-hosters who built on a repo the company had already stopped treating as the product. The principle wasn't theirs to lose.

It depends on whose calendar it is. If you're one person with one booking link, the free plan is still the best deal in the category and I would take it again. If the platform becomes load-bearing for a team, price the second variable before the first: not the seat cost, the renegotiation cost, what happens the day the promise you bought gets repriced. And watch Cal.diy. A community fork with no teams, no workflows and no support is either the start of a real commons or a museum piece, and twelve months tells you which. The partner never needed the code to be open. He needed the calendar to be his, and he priced the claim accordingly.