Skip to main content

Last updated July 21, 2026

Privacy and data use

Scheduler handles the minimum data needed to help invited groups agree on a time. This page explains what is handled, why, and the choices available to you.

Data we handle

Scheduler stores these data categories:

  • Identity data: your Google subject, name, email address, profile image, and authentication sessions.
  • Scheduling poll data:poll details, candidate times, invited participants, participation, and the organizer's chosen time.
  • Response data: the availability you explicitly submit for each candidate time.
  • Calendar configuration: connection status, private Calendar identifiers and labels, and the calendars selected for conflict checks.
  • Credential data: encrypted OAuth credentials needed for authorized Google Calendar operations.
  • Security and operations data: authentication session metadata such as IP address and user agent, HMAC-derived rate-limit identifiers and counters, and restricted operational records containing identifiers, actions, outcomes, timing, and error categories.

An unfinished create-poll form may be saved in your browser's session storage so it can survive a sign-in or a recoverable error. It is scoped to your account in that browser session and cleared after successful creation.

Calendar busy intervals are transient assistance data. They are never stored, logged, or shared. Scheduler does not request or store Calendar event titles, descriptions, locations, or attendees during availability checks. Only your submitted responses are shared with other participants.

How we use data

  • Identity and session data authenticate you and secure access.
  • Poll, participation, and response data create scheduling polls, collect explicit answers, rank candidate times, and record the organizer's final choice.
  • Calendar configuration and transient busy information let Calendar assist privately with availability checks.
  • Encrypted OAuth credentials support authorized checks and the creation, reconciliation, or cancellation of an organizer-owned Google Calendar event.
  • Request and security metadata protects accounts, limits abuse, diagnoses failures, and verifies automatic retention and deletion recovery.

Service providers

Google processes identity sign-in and authorized Google Calendar operations. Cloudflare hosts Scheduler and processes application requests and stored application data on Scheduler's behalf. Scheduler remains responsible for how these services are used.

On Scheduler's current Cloudflare Workers Free plan, Workers Logs containing request and response metadata and restricted application operational logs are retained for up to three days. Workers Logpush is not enabled, so Scheduler does not export those logs to a separate log store. Cloudflare separately makes aggregate Worker metrics, such as request counts, errors, and performance measurements, available for up to three months; those metrics are not individual log events.

Google Workspace Limited Use

Scheduler's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Retention and deletion

  • An open poll expires after its latest candidate time ends.
  • Expired and canceled polls remove unclaimed invitee emails immediately and are deleted with their remaining poll data after 30 days.
  • Finalized polls and their Scheduler data are deleted one year after finalization. The Google Calendar event remains under Google's and the organizer's control.
  • Removing a participant removes live direct identifiers immediately. Account deletion removes them during local deletion processing; if a confirmed request cannot finish, Scheduler reapplies it automatically. Shared response values may remain de-identified until the poll's normal deletion date. De-identified does not guarantee anonymity.
  • Cloudflare D1 Time Travel may keep recovery history for up to 30 days, so deletion from the live database does not mean immediate removal from recovery history. After a database restore, Scheduler automatically reapplies confirmed deletion requests in bounded batches during controlled restore maintenance from an encrypted deletion journal kept for 35 days.
  • After account deletion, Scheduler keeps the opaque account identifier in a deletion barrier for 35 days. This prevents an already-started request from restoring deleted identity, and the barrier is then deleted automatically.
  • Rate-limit counters stop applying after at most five minutes. Expired counter rows and expired deletion barriers are removed by the bounded daily retention job.
  • Expired authentication sessions and verification records, including temporary OAuth state, are scheduled for daily removal and normally disappear on the next successful run, within about 24 hours. A failed run can delay removal and is monitored operationally.

Your choices

Choose Download my data in Account settings to export JSON containing your Scheduler profile, Calendar configuration without credentials, created polls, claimed participation, and submitted responses.

You can correct poll details you control and replace or withdraw your availability while a poll is open. Contact us to request a correction you cannot make in the application. You can withdraw Google Calendar access by disconnecting Calendar, revoke access in your Google Account, and continue responding manually.

You can delete your account. Scheduler removes sessions, OAuth credentials, Calendar configuration, and live direct identifiers during local deletion processing; cancels open polls you organize; and de-identifies shared records until their normal deletion date. A confirmed request that cannot finish is safely reapplied. Finalized Google Calendar events remain intact.

Deleting Scheduler data or disconnecting Calendar does not remove a Google Calendar event that Scheduler already created. Google and the event organizer or attendees control that external record. If an in-progress Calendar operation cannot be reconciled during account deletion, you may need to manage the Google Calendar event directly.

Use restrictions

Scheduler uses no advertising network, no behavioral profiling, and no product or third-party behavioral analytics. We never sell private data or use it for AI training.

Contact

For privacy questions or requests, email bluefeet@gmail.com.