Privacy Policy

How Schedule Builder handles account, schedule, calendar-import, support, push, and subscription information. Last updated August 26, 2026.

Privacy Policy

Last updated August 26, 2026

How Schedule Builder handles account, schedule, calendar-import, support, push, and subscription information.

This Privacy Policy explains how Schedule Builder handles information when you use the site, create an account, save schedules, use Calendar Import, enable push reminders, publish share links, contact support, or subscribe to Pro.

By creating an account with email/password or by using Google or Microsoft sign-in, you acknowledge this Privacy Policy and consent to the data practices described here.

1. Information we collect

We collect information you provide directly, such as your name, email address, password login details, OAuth provider identity details, support messages, billing selections, cancellation reasons and optional details, schedule content, branding preferences, and optional uploaded assets such as logos or images.

We also collect technical and usage information needed to operate the service, such as session identifiers, basic device or browser data, IP-derived region information, pages or features used, and bounded logs for performance, security, abuse prevention, and troubleshooting. If you enable push reminders, we collect the browser push endpoint, encryption keys, and time zone needed to deliver reminders.

2. How we use information

We use information to provide the service, authenticate accounts, sync schedules across devices, render published schedules and embeds, process subscription state, send requested push reminders, respond to support requests, prevent abuse, and maintain the reliability and security of the app.

We use aggregated or de-identified information to understand how people use Schedule Builder and to improve product decisions, pricing presentation, onboarding, and feature quality. We do not include Google Calendar data in analytics or product-usage measurement.

3. Calendar connections

Calendar Import is optional. You may connect Google Calendar or Microsoft Outlook without creating a Schedule Builder account; Apple Calendar Import requires a signed-in account. When you explicitly connect Google Calendar, we access the calendar names, identifiers, colours, and primary-calendar status needed for you to choose a calendar. For the calendar and week you select, we access event titles, start and end dates and times, and all-day status. We access event descriptions only when you choose to include descriptions in the import.

We use this information only to create the selected week’s editable, one-time Schedule Builder preview. Google and Microsoft Calendar Import use separate provider authorization. Apple Calendar Import uses your Apple Account email and an app-specific password; we never ask for your regular Apple Account password. Calendar Import does not create an ongoing sync.

Provider credentials are not returned to the browser. We store a credential only as AES-GCM-encrypted data for up to 15 minutes. Signed-in imports are bound to the current signed-in browser session. Guest Google and Microsoft imports are bound to an opaque, HTTP-only browser cookie; we store only a hash of that cookie. We delete the credential after a populated preview, cancellation, a failed provider request, or expiry. A valid empty-week result remains available only until that short session expires so that you can choose another week. We do not separately persist raw provider event data; an imported snapshot becomes Schedule Builder schedule content only after you confirm it. If you explicitly publish, embed, or export that resulting schedule, you direct us to provide it for that feature.

Schedule Builder’s use and transfer of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google Calendar data, use it for advertising, user profiling, creditworthiness, lending, or data brokerage, or use it for analytics. We do not allow people to read Google Calendar data unless you give affirmative agreement for specific data, or access is necessary for security, legal compliance, or permitted aggregated operational purposes.

4. Sharing your information

We share information with service providers only when needed to run Schedule Builder, including Cloudflare for hosting, database, storage, and abuse protection; Stripe for payments; ZeptoMail for transactional email; and browser push services when you enable reminders. We do not provide Google Calendar data to advertising, analytics, data-broker, or other unrelated service providers.

We may disclose information if required by law, to protect rights or safety, to investigate abuse, or as part of a merger, acquisition, financing, or sale of assets involving the service. Any use or transfer of Google Calendar data in those circumstances remains subject to the Google API Services User Data Policy and Limited Use requirements.

We do not sell your personal information for money. If you publish a schedule through a share link or embed, the content you chose to publish is shared with anyone who can access that link or page. Published links are not password protected, and we record when a published link was last accessed. Custom background and branding-logo images are served through public asset URLs, so anyone with an asset URL can retrieve the image.

5. OAuth, payment, push, support, and telemetry

If you sign in with Google or Microsoft, we receive the account details those providers make available for authentication and account creation, such as your name, email address, and provider identifier. We store the provider and provider subject with your account; provider access tokens used for sign-in are not stored as account data.

If you subscribe to Pro, Stripe handles payment. We receive subscription and transaction metadata needed for billing and account management, including Stripe customer, subscription, price, and Checkout identifiers, status, billing period, trial, and cancellation information. We do not store your full payment card details. We use Cloudflare country metadata at account registration to assign and store a regional pricing tier for later account checkouts.

When you explicitly enable push reminders, we store the browser push endpoint, encryption keys, and time zone with your account. To deliver a reminder, we send an encrypted Web Push payload containing the event title, schedule name, occurrence time label, and a link to the builder to that browser’s push service.

In-app support stores ticket subjects and messages. Authorized support administrators can view the requester’s name, email address, subscription status, and schedule names to resolve a ticket, but the support view does not expose schedule contents. We use ZeptoMail to send support notification emails containing the ticket subject and relevant sender identity, not the full message body.

We record first-party operational, error, export-failure, and conversion telemetry in our database. Conversion telemetry contains a limited event name, source, and optional billing interval or feature. Error and operational telemetry uses bounded, scrubbed technical metadata and is designed not to retain raw IP addresses, emails, cookies, tokens, request bodies, schedule contents, provider payloads, full URLs, or raw stack traces.

6. Cookies, local storage, and similar technologies

We use cookies, local storage, and similar technologies to keep you signed in, remember app state, store local schedule drafts, improve performance, and understand how core features are used.

Some local planning features may work without an account by saving information on your device. If you clear browser storage, those locally stored schedules or preferences may be removed.

7. Data retention

We keep personal information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security and financial records. A session may last up to 30 days, password-reset tokens expire after one hour, and temporary Calendar Import credentials expire after up to 15 minutes.

We retain operational events and Stripe webhook idempotency records for 30 days, schedule-write operation records for 15 days, push-delivery metadata for 35 days, and audit records for one year. Account, billing, support, and shared-schedule records may have different retention periods based on operational or legal needs. Uploaded-image deletion is asynchronous and public caches may retain a copy until their cache expires.

8. Your choices and controls

You can update profile details, manage subscription status, control what schedules you publish, and delete your account using available in-app tools or by contacting us through the support flow. Delete an active Stripe subscription before deleting your account; account deletion does not cancel it.

You can choose not to create an account and continue using local-only planning features. You can avoid Calendar Import by not connecting a provider, avoid public sharing by not creating share links or embeds, and decline browser push permission or remove a push subscription through your browser settings.

9. Security

We use reasonable administrative, technical, and organizational safeguards intended to protect personal information. No system is perfectly secure, and we cannot guarantee absolute security.

You help protect your information by using a strong password, keeping your device secure, and signing out or revoking access if you suspect unauthorized account activity.

10. Children

Schedule Builder is not intended for children under 13, and you should not create an account or submit personal information if you are under 13 or below the minimum age required in your jurisdiction to consent to online services.

11. International processing

Your information may be processed and stored in locations where our hosting, authentication, storage, or payment providers operate. Those locations may have privacy laws that differ from those in your country or region.

12. Changes to this Privacy Policy

We may update this Privacy Policy as the product and legal requirements change. When we do, we will update the last-updated date and may provide additional notice if the changes are material.

13. Contact

For privacy questions, data requests, or concerns about this policy, contact us through the in-app support flow or at [email protected].

العودة إلى ScheduleBuilder