Effective 2026-09-01
This Privacy Policy explains how Meetingpad ("we", "us", "our") collects, uses, discloses, and safeguards your information when you use our service, including the macOS application, meetingpad.io website, and related services (the "Service").
Account information: when you sign up, we collect your name, email address, and an identifier from your chosen sign-in provider (Apple, Google, or magic link via email). Authentication is provided by Clerk.
Identity data: for each Google account you connect as an "identity", we store the identity's display name, timezone, email address, and an encrypted OAuth refresh token issued by Google.
Product data: event types you configure, polls you create, votes cast on your polls (including voter name and email), and bookings made through your links (guest name, email, and chosen time).
Payment data: if you upgrade to Pro, our payment processor (Stripe) collects and processes your billing information. We do not store your full card details; we receive a customer ID and subscription status.
AI key: if you provide an Anthropic API key to enable AI features, we store it encrypted at rest and use it only to make API calls to Anthropic on your behalf.
Usage & diagnostics: we log requests to our API (timestamps, endpoints, IP addresses) for security and reliability. The macOS app logs errors locally on your Mac; we only see them if you send us feedback.
We do not read the contents of your calendar events. No titles, descriptions, attendees, or attachments. To compute your availability across accounts, our server queries Google's freeBusy API for each connected Google account, which returns only start/end times of busy intervals. Event contents never leave Google's servers to reach ours.
We do not have your Google password. We do not sell or share personal data with advertisers. We do not use your Google user data to train, improve, or evaluate any generalized artificial intelligence or machine learning models.
We use your information to: (a) provide, maintain, and improve the Service; (b) authenticate you; (c) send booking invites, poll invitations, nudges, and follow-up emails on your behalf using the identities you have connected; (d) process payments and manage subscriptions; (e) communicate with you about the Service, updates, and support; (f) detect and prevent fraud and abuse; (g) comply with legal obligations.
We share information only with service providers necessary to run the Service:
We may disclose information if required by law, subpoena, or to protect the rights, property, or safety of Meetingpad, our users, or others.
Meetingpad's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account as an identity, Meetingpad requests the following OAuth scopes and uses the resulting access only for the purposes described:
openid, email: to identify the connected Google account (email address only; used as the sender address on invites and to display which account is linked in the Meetingpad UI).https://www.googleapis.com/auth/calendar.events: to (a) create the calendar invite when a guest books your Meetingpad link, (b) update or cancel that invite if the booking changes, (c) create small titleless "Busy" placeholder events on your other connected calendars so cross-account double-booking is prevented, and (d) query start/end times of busy intervals via Google's freeBusy API to compute your unified availability. We do not read event titles, descriptions, attendees, or attachments.https://www.googleapis.com/auth/gmail.send: to send booking confirmations, poll invitations, nudges, and follow-up emails from the connected Gmail address so recipients see them from the account they know. We do not read, list, modify, or delete any messages in your Gmail. We only send.https://www.googleapis.com/auth/drive.file: when you attach a Google Doc, Sheet, or Slide to a follow-up email, this per-file scope lets us grant view/comment access on that specific file to the meeting recipients you designate. We never access files you did not attach.What we do NOT do with Google user data:
How Google user data is stored and secured: OAuth refresh tokens are encrypted at rest with AES-256-GCM using a server-held key. Access tokens are short-lived (1 hour) and held only in memory during a request. Free/busy interval data cached to speed up booking page loads is retained for at most 5 minutes and never contains event contents. Calendar events we create on your behalf carry only the metadata you and your guest entered on the booking form.
Revoking access: you can revoke Meetingpad's access to any connected Google account at any time by (a) removing the identity in the Meetingpad app (Settings → Delete identity), which deletes the refresh token from our server, or (b) revoking Meetingpad in your Google Account permissions at myaccount.google.com/permissions.
We retain your data while your account is active. If you delete your account: identity data (OAuth tokens, Anthropic key) is deleted immediately; polls, votes, and bookings are deleted after a 30-day recovery window; account records may be retained longer to comply with legal, tax, and audit obligations.
OAuth tokens and Anthropic keys are stored encrypted at rest. Traffic between the app and our server is over TLS. Access to production infrastructure is limited to authorized team members. No system is perfectly secure; we cannot guarantee absolute security.
Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to: access, correct, or delete your personal data; object to or restrict processing; port your data to another service; withdraw consent for optional processing. To exercise these rights, use the export/delete controls in the app (Settings → Account) or email [email protected].
The Service is not directed to individuals under 18. We do not knowingly collect information from children. If you believe we have inadvertently done so, please contact us and we will delete it.
Our server infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
Our marketing site (meetingpad.io) uses privacy-friendly analytics that do not set cookies or collect personal data. The Meetingpad Mac app does not use cookies. Sign-in flows may set cookies necessary for authentication.
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice at least 15 days before they take effect. The "Effective" date at the top of this page indicates the latest revision.
For privacy questions or to exercise your rights, email [email protected] or chat with support.