Privacy Policy
Last updated: July 6, 2026
Who we are
Meets (“Meets”, “we”, “us”) is a calendar-synchronization service operated by [Legal entity name], based in the Philippines. We are the data controller for the personal data described here. For any privacy question or request, contact privacy@meets.rsvp.
What Meets does
Meets connects to the calendar accounts you authorize (Google Calendar, Microsoft Outlook, Apple iCloud) to prevent double-bookings: when an event makes you busy in one calendar, we create a “Busy” blocker in your other connected calendars and keep it up to date. That is the entire purpose we process your data for.
Data we access and store
- Account data: your email address, an optional display name, and authentication identifiers, to operate your account.
- Calendar metadata: the list of calendars in each connected account (names, colors, time zones), so you can choose what to sync.
- Event data: event times, busy/free status, your attendance response, and event titles, within a rolling window (roughly 90 days back and 12 months forward). We store what is needed to compute and maintain blockers and to render your unified calendar view. Blockers we create contain no details from the source event unless you explicitly enable title copying.
- Credentials: OAuth refresh tokens and (for Apple) app-specific passwords, encrypted at rest with AES-256-GCM. They are used only server-side to sync your calendars and are never exposed to your browser or third parties.
- Billing data: your plan and subscription status. Card details are handled entirely by our payment provider (see Sharing) and never reach our servers.
Why we can process it (legal bases)
Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the sync you signed up for), your consent (when you connect each calendar account, which you can withdraw at any time by disconnecting it), and our legitimate interests in securing and improving the service. We do not seek special-category data and ask that you not put it in blocker titles.
Google user data (Limited Use disclosure)
Meets’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google Calendar data to provide the calendar-synchronization features you request; we do not transfer it to others except as necessary to provide the service; we do not use it for advertising; and we do not allow humans to read it except with your consent, for security, or to comply with law.
What we never do
- Sell your data. To anyone. Ever.
- Use your calendar data for advertising or profiling.
- Train machine-learning models on your calendar content.
Sharing
We use a small set of processors to run the service: cloud hosting for our servers and database, Supabase for authentication, an email provider for transactional email (sign-in links and invitations), and Lemon Squeezy (a Stripe company, acting as merchant of record) for payments. Payment card details go directly to Lemon Squeezy and never touch our servers. We share data with these processors only as needed to run Meets, and we may disclose data if required by law.
Where your data is processed
Our infrastructure and processors may store and process data outside your country, including in regions such as the United States and the European Union. Where required, such transfers rely on appropriate safeguards (for example, Standard Contractual Clauses).
Your rights & choices
- Access, correction, deletion, and portability of your personal data — email privacy@meets.rsvp and we will respond within the timeframe your law requires.
- Disconnect a calendar anytime in the app to stop processing that account and remove the blockers it produced.
- Revoke our access at the provider directly: Google, Microsoft, or by deleting the app-specific password at appleid.apple.com for Apple.
- Complain to your local data-protection authority if you believe we have mishandled your data.
Retention and deletion
We keep your data only while your account is active. Disconnecting an account stops syncing and removes its blockers where possible. Deleting your Meets account deletes your stored calendar data, credentials, and profile within 30 days, except where we must retain limited records (e.g. billing) to meet legal obligations.
Security
Credentials are encrypted at rest (AES-256-GCM); all traffic is encrypted in transit (TLS). Provider tokens are used only server-side and are never sent to your browser. No system is perfectly secure, but we design Meets to touch the minimum data needed and to keep the most sensitive data (tokens) isolated.
Cookies & local storage
We use a session cookie to keep you signed in and browser local storage to remember preferences such as your theme and calendar colors. We do not use advertising or cross-site tracking cookies.
Children
Meets is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy; we will revise the date above and, for material changes, notify you by email or in-app before they take effect.
Contact
Privacy questions or requests: privacy@meets.rsvp.