Back

Privacy Policy

Last updated: July 22, 2026

What Schedu Collects

Schedu stores event details, organizer contact information, invitee names, optional emails and phone numbers, availability responses, invitation delivery status, and scheduling decisions.

Google Data

Google sign-in is optional. When you connect Google for identity, Schedu accesses your basic profile and email address to prefill forms. If you choose Google contact suggestions, Schedu accesses the names and email addresses in your saved Google Contacts and automatically created Other Contacts. If you connect Google Calendar, Schedu accesses free/busy intervals to help you mark availability. Schedu does not access Gmail messages or Google Calendar event titles, descriptions, locations, or attendee lists.

Schedu uses Google data only to provide scheduling, contact autocomplete, and calendar import features. Schedu does not sell Google user data, use it for advertising, or transfer it for unrelated purposes. Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Schedu stores the organizer or invitee email address with the relevant event record. When you reconnect the same Google account, Schedu verifies its email address and uses that match to show your existing invitations and organized events, including their private management links. This restores access without storing your Google access token, refresh token, password, or a long-lived Schedu login session.

Data Protection

Schedu protects sensitive and Google user data using HTTPS/TLS encryption in transit and encryption at rest provided by its hosting platform. Production database and deployment access is restricted to authorized operators, and OAuth client credentials are held in protected environment variables rather than application source code.

Schedu requests only the Google permissions needed for the features described above. The short-lived organizer Google access token is held in a Secure, HttpOnly, SameSite browser cookie for up to 30 minutes; Schedu does not store that token or a Google refresh token in its database. Contact suggestions are fetched on demand, returned in private no-store responses, and are not written to Schedu's database. Tokenized organizer and invitee links, request validation, and rate limits further restrict access to scheduling data and Google-backed features.

Google User Data Retention And Deletion

  • Google Contacts and Other Contacts results are not retained on Schedu's servers. They are used only to display the current autocomplete suggestions and are discarded when that request and browser session end.
  • A temporary Google Calendar import containing only profile identity and free/busy intervals becomes unusable after 10 minutes. It is deleted as soon as it is applied, or by the recurring expiration cleanup, normally no later than 15 minutes after creation.
  • If you submit availability derived from Google Calendar, the resulting busy/available time intervals become part of the scheduling response. They are retained with the event so the scheduling feature can work; Google event titles and other event details are never retained.
  • You may revoke Schedu's Google access at any time from your Google Account permissions. Revocation prevents future Google API access, and the local short-lived access-token cookie expires within 30 minutes. Revocation does not by itself delete availability already submitted to an event.
  • Self-service deletion is available from private Schedu links. An invitee can choose Delete my response to immediately remove their identity, contact details, response history, availability, and any pending Google import for that event. An organizer can choose Delete event data from the private dashboard to immediately remove the event, organizer details, invitees, availability, delivery history, and temporary imports. Those private links stop working after deletion.
  • Self-service deletion removes data from Schedu's active database. It cannot remove copies already delivered to another person's email inbox or calendar application. A private organizer or invitee link authorizes deletion. If the event record is associated with your email address, reconnecting the matching Google account can restore that private link from your invitations or organized-events list. If no matching verified Google email is available, you must retain the private link; Schedu does not authorize deletion using only an unverified name or email address.

Email And Tracking

Schedu sends invitation, reminder, response, and confirmation emails through Resend. Invitation emails can include tracked links and a small open pixel so organizers can see basic delivery progress. Open tracking is approximate because email clients may block or prefetch images.

Data Sharing

Schedu shares availability and scheduling information with the event organizer and relevant invitees through tokenized links. Invitee-side group signals are aggregate-only unless the organizer dashboard is accessed with the organizer token.

Security

Schedu uses tokenized event and invitee links rather than required accounts. Anyone with a valid organizer or invitee link can access the corresponding view, so treat those links as private.

Contact

For privacy questions or other requests, contact help@schedu.xyz.