Privacy Policy
Last updated: August 11, 2026
What Schedu Collects
Schedu stores event details, the organizer's display name, optional organizer and invitee contact information, availability responses, invitation delivery status, and scheduling decisions.
Google Data
Google sign-in is optional. When you connect Google for identity, Schedu accesses your basic profile and email address to prefill forms. If you choose Google contact suggestions, Schedu accesses the names and email addresses in your saved Google Contacts and automatically created Other Contacts. If you connect Google Calendar, Schedu accesses free/busy intervals to help you mark availability. Schedu does not access Gmail messages or Google Calendar event titles, descriptions, locations, or attendee lists.
Schedu uses Google data only to provide scheduling, contact autocomplete, and calendar import features. Schedu does not sell Google user data, use it for advertising, or transfer it for unrelated purposes. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you create with Google, Schedu stores the verified organizer email address with the relevant event. Invitee email addresses are stored when they are provided for an invitation or response. When you reconnect the same Google account, Schedu verifies its email address and uses that match to show your existing invitations and organized events, including their private management links. Schedu never receives or stores your Google password. The verified identity and encrypted Google access credentials are kept in a first-party organizer session so returning routes do not repeatedly ask for an unchanged grant.
Data Protection
Schedu protects sensitive and Google user data using HTTPS/TLS encryption in transit and encryption at rest provided by its hosting platform. Production database and deployment access is restricted to authorized operators, and OAuth client credentials are held in protected environment variables rather than application source code.
Schedu requests only the Google permissions needed for verified identity, optional contact suggestions, and calendar free/busy. The browser stores only an opaque Secure, HttpOnly, SameSite Schedu session key. Google access and refresh credentials are encrypted before database storage, are never exposed to browser JavaScript, and are deleted on disconnect or after 30 days without use. Contact suggestions are fetched on demand, returned in private no-store responses, and are not written to Schedu's database. Tokenized organizer and invitee links, request validation, and rate limits further restrict access to scheduling data and Google-backed features.
If you explicitly choose Save on this device, Schedu stores the event's private organizer and response links in that browser's local storage. Those links are not uploaded as part of that feature. You can remove them from My events & invitations or clear the browser's site data; anyone who can use that browser profile may be able to open them.
When you open a private invitation or identify yourself for an event, Schedu automatically remembers your name, the event title, and your private response link in this browser's local storage. This lets the original event link reopen your response without signing in. You can turn off Remember me in this browser on the response page, choose Forget in My invitations, or clear site data. Anyone using the same browser profile can open a remembered response. This does not sync to other devices.
Google User Data Retention And Deletion
- Google Contacts and Other Contacts results are not retained on Schedu's servers. They are used only to display the current autocomplete suggestions and are discarded when that request and browser session end.
- A temporary Google Calendar import containing only profile identity and free/busy intervals becomes unusable after 10 minutes. It is deleted as soon as it is applied, or by the recurring expiration cleanup, normally no later than 15 minutes after creation.
- If you submit availability derived from Google Calendar, the resulting busy/available time intervals become part of the scheduling response. They are retained with the event so the scheduling feature can work; Google event titles and other event details are never retained.
- You may disconnect inside Schedu or revoke access from Google Account permissions. Disconnecting immediately deletes the first-party organizer session and its encrypted Google credentials. Revocation prevents future refreshes; Schedu then marks Google capabilities as disconnected. Neither action deletes availability already submitted to an event.
- Self-service deletion is available from private Schedu links. An invitee can choose Delete my response to immediately remove their identity, contact details, response history, availability, and any pending Google import for that event. An organizer can choose Delete event data from the private dashboard to immediately remove the event, organizer details, invitees, availability, delivery history, and temporary imports. Those private links stop working after deletion.
- Self-service deletion removes data from Schedu's active database. It cannot remove copies already delivered to another person's email inbox or calendar application. A private organizer or invitee link authorizes deletion. If the event record is associated with your email address, reconnecting the matching Google account can restore that private link from your invitations or organized-events list. If no matching verified Google email is available, you must retain the private link; Schedu does not authorize deletion using only an unverified name or email address.
Email And Tracking
Schedu sends invitation, reminder, response, and confirmation emails through Resend. Invitation emails can include tracked links and a small open pixel so organizers can see basic delivery progress. Open tracking is approximate because email clients may block or prefetch images.
Data Sharing
Schedu shares availability and scheduling information with the event organizer and relevant invitees through tokenized links. Invitee-side group signals are aggregate-only unless the organizer dashboard is accessed with the organizer token.
Security
Schedu uses tokenized event and invitee links rather than required accounts. Anyone with a valid organizer or invitee link can access the corresponding view, so treat those links as private.
Contact
For privacy questions or other requests, contact help@schedu.xyz.