Data we handle
Scheduler stores these data categories:
- Identity data: your Google subject, name, email address, profile image, and authentication sessions.
- Scheduling poll data:poll details, candidate times, invited participants, participation, and the organizer's chosen time.
- Response data: the availability you explicitly submit for each candidate time.
- Calendar configuration: connection status, private Calendar identifiers and labels, and the calendars selected for conflict checks.
- Credential data: encrypted OAuth credentials needed for authorized Google Calendar operations.
Calendar busy intervals are transient assistance data. They are never stored, logged, or shared. Scheduler does not request or store Calendar event titles, descriptions, locations, or attendees during availability checks. Only your submitted responses are shared with other participants.
How we use data
- Identity and session data authenticate you and secure access.
- Poll, participation, and response data create scheduling polls, collect explicit answers, rank candidate times, and record the organizer's final choice.
- Calendar configuration and transient busy information let Calendar assist privately with availability checks.
- Encrypted OAuth credentials support authorized checks and the creation, reconciliation, or cancellation of an organizer-owned Google Calendar event.
Service providers
Google processes identity sign-in and authorized Google Calendar operations. Cloudflare hosts Scheduler and processes application requests and stored application data on Scheduler's behalf. Scheduler remains responsible for how these services are used.
Google Workspace Limited Use
Scheduler's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Google Workspace API User Data Policy Limited Use requirements.
Retention and deletion
- An open poll expires after its latest candidate time ends.
- Expired and canceled polls remove unclaimed invitee emails immediately and are deleted with their remaining poll data after 30 days.
- Finalized polls and their Scheduler data are deleted one year after finalization. The Google Calendar event remains under Google's and the organizer's control.
- Removing a participant or deleting an account removes live direct identifiers immediately. Shared response values may remain de-identified until the poll's normal deletion date. De-identified does not guarantee anonymity.
- Cloudflare D1 Time Travel may keep recovery history for up to 30 days. After a database restore, Scheduler reapplies deletion requests from an encrypted deletion journal kept for 35 days.
Your choices
Account settings let you export JSON containing your Scheduler profile, Calendar configuration without credentials, created polls, claimed participation, and submitted responses.
You can correct poll details you control and replace or withdraw your availability while a poll is open. You can revoke Google Calendar access by disconnecting Calendar and continue responding manually.
You can delete your account. Scheduler removes sessions, OAuth credentials, Calendar configuration, and live direct identifiers immediately; cancels open polls you organize; and de-identifies shared records until their normal deletion date. Finalized Google Calendar events remain intact.
Use restrictions
Scheduler uses no advertising network, no behavioral profiling, and no product or third-party behavioral analytics. We never sell private data or use it for AI training.
Contact
For privacy questions or requests, email bluefeet@gmail.com.