MeetingpadMeetingpad
PricingDocsSupportDownload

Privacy Policy

Effective 2026-09-01

This Privacy Policy explains how Meetingpad ("we", "us", "our") collects, uses, discloses, and safeguards your information when you use our service, including the macOS application, meetingpad.io website, and related services (the "Service").

1. Information we collect

Account information: when you sign up, we collect your name, email address, and an identifier from your chosen sign-in provider (Apple, Google, or magic link via email). Authentication is provided by Clerk.

Identity data: for each Google account you connect as an "identity", we store the identity's display name, timezone, email address, and an encrypted OAuth refresh token issued by Google.

Product data: event types you configure, polls you create, votes cast on your polls (including voter name and email), and bookings made through your links (guest name, email, and chosen time).

Payment data: if you upgrade to Pro, our payment processor (Stripe) collects and processes your billing information. We do not store your full card details; we receive a customer ID and subscription status.

AI key: if you provide an Anthropic API key to enable AI features, we store it encrypted at rest and use it only to make API calls to Anthropic on your behalf.

Usage & diagnostics: we log requests to our API (timestamps, endpoints, IP addresses) for security and reliability. The macOS app logs errors locally on your Mac; we only see them if you send us feedback.

2. Information we do not collect

We do not read the contents of your calendar events. No titles, descriptions, attendees, or attachments. To compute your availability across accounts, our server queries Google's freeBusy API for each connected Google account, which returns only start/end times of busy intervals. Event contents never leave Google's servers to reach ours.

We do not have your Google password. We do not sell or share personal data with advertisers. We do not use your Google user data to train, improve, or evaluate any generalized artificial intelligence or machine learning models.

3. How we use information

We use your information to: (a) provide, maintain, and improve the Service; (b) authenticate you; (c) send booking invites, poll invitations, nudges, and follow-up emails on your behalf using the identities you have connected; (d) process payments and manage subscriptions; (e) communicate with you about the Service, updates, and support; (f) detect and prevent fraud and abuse; (g) comply with legal obligations.

4. Sharing and third-party services

We share information only with service providers necessary to run the Service:

  • Clerk, authentication and account management.
  • Stripe, payment processing and subscription management.
  • Google, see section 5 below for the full disclosure of Google user data access.
  • Anthropic, AI drafting, only when you have provided your own API key and only for content you explicitly generate.
  • Resend, transactional email delivery (account emails, receipts).
  • Cloudflare, DNS, CDN, and hosting for our marketing site.
  • Hostinger, server infrastructure for our API and database.

We may disclose information if required by law, subpoena, or to protect the rights, property, or safety of Meetingpad, our users, or others.

5. Google API Services User Data

Meetingpad's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect a Google account as an identity, Meetingpad requests the following OAuth scopes and uses the resulting access only for the purposes described:

  • openid, email: to identify the connected Google account (email address only; used as the sender address on invites and to display which account is linked in the Meetingpad UI).
  • https://www.googleapis.com/auth/calendar.events: to (a) create the calendar invite when a guest books your Meetingpad link, (b) update or cancel that invite if the booking changes, (c) create small titleless "Busy" placeholder events on your other connected calendars so cross-account double-booking is prevented, and (d) query start/end times of busy intervals via Google's freeBusy API to compute your unified availability. We do not read event titles, descriptions, attendees, or attachments.
  • https://www.googleapis.com/auth/gmail.send: to send booking confirmations, poll invitations, nudges, and follow-up emails from the connected Gmail address so recipients see them from the account they know. We do not read, list, modify, or delete any messages in your Gmail. We only send.
  • https://www.googleapis.com/auth/drive.file: when you attach a Google Doc, Sheet, or Slide to a follow-up email, this per-file scope lets us grant view/comment access on that specific file to the meeting recipients you designate. We never access files you did not attach.

What we do NOT do with Google user data:

  • We do not use it to train, improve, or evaluate any generalized artificial intelligence or machine learning models, ours or third parties'.
  • We do not sell, rent, or lease it to any party.
  • We do not use it to serve advertising.
  • We do not transfer it to third parties except (a) as necessary to provide the Service (e.g. Google itself, to send an email you asked us to send), (b) for security purposes (e.g. to investigate abuse), or (c) to comply with applicable law.
  • We do not allow any humans to read your Google user data except (i) with your affirmative agreement, (ii) as necessary for security purposes such as investigating abuse, (iii) to comply with applicable law, or (iv) where the data has been aggregated and anonymized.

How Google user data is stored and secured: OAuth refresh tokens are encrypted at rest with AES-256-GCM using a server-held key. Access tokens are short-lived (1 hour) and held only in memory during a request. Free/busy interval data cached to speed up booking page loads is retained for at most 5 minutes and never contains event contents. Calendar events we create on your behalf carry only the metadata you and your guest entered on the booking form.

Revoking access: you can revoke Meetingpad's access to any connected Google account at any time by (a) removing the identity in the Meetingpad app (Settings → Delete identity), which deletes the refresh token from our server, or (b) revoking Meetingpad in your Google Account permissions at myaccount.google.com/permissions.

6. Data retention

We retain your data while your account is active. If you delete your account: identity data (OAuth tokens, Anthropic key) is deleted immediately; polls, votes, and bookings are deleted after a 30-day recovery window; account records may be retained longer to comply with legal, tax, and audit obligations.

7. Security

OAuth tokens and Anthropic keys are stored encrypted at rest. Traffic between the app and our server is over TLS. Access to production infrastructure is limited to authorized team members. No system is perfectly secure; we cannot guarantee absolute security.

8. Your rights

Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to: access, correct, or delete your personal data; object to or restrict processing; port your data to another service; withdraw consent for optional processing. To exercise these rights, use the export/delete controls in the app (Settings → Account) or email [email protected].

9. Children

The Service is not directed to individuals under 18. We do not knowingly collect information from children. If you believe we have inadvertently done so, please contact us and we will delete it.

10. International transfers

Our server infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

11. Cookies and tracking

Our marketing site (meetingpad.io) uses privacy-friendly analytics that do not set cookies or collect personal data. The Meetingpad Mac app does not use cookies. Sign-in flows may set cookies necessary for authentication.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice at least 15 days before they take effect. The "Effective" date at the top of this page indicates the latest revision.

13. Contact

For privacy questions or to exercise your rights, email [email protected] or chat with support.

MeetingpadMeetingpad

© 2026 Meetingpad LLC.

Product
Download
Pricing
Support
Documentation
Contact us
Chat with support
Legal
Terms
Privacy