Schedule-X Cloud
Privacy Policy
Last updated: September 17, 2026
This policy explains how Schedule-X Cloud ("Schedule-X", "we", "us") handles information when you visit our website, use the developer console or API, or connect Google Calendar. For privacy questions or requests, contact tom@schedule-x.dev.
1. Information we handle
- Account and workspace information: names, email addresses, organization names, memberships, invitations, account settings, and authentication records. Passwords are stored as hashes, not readable passwords.
- Calendar information: application user identifiers, calendar names and settings, event titles, descriptions, locations, dates, times, recurrence details, and other supported event metadata supplied by you or a connected service.
- Connected account information: Google account email, provider calendar identifiers and permissions, authorization scopes, OAuth access and refresh tokens, and sync status.
- Technical information: IP addresses, request details, timestamps, device or browser information available in requests, errors, and security or operational logs.
- Communications: information you send when requesting support, and service emails such as invitations or password reset messages.
Applications built by our customers may collect additional information under their own privacy policies. Avoid placing unnecessary sensitive personal information in calendar content.
2. Why we use information
We use information to provide accounts and workspaces, authenticate users, deliver calendar and sync features, send requested service messages, answer support requests, prevent abuse, troubleshoot failures, and meet legal obligations. We do not sell personal information or use calendar content for targeted advertising.
Where the GDPR or UK GDPR applies, our legal bases include performing a contract, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations. Google authorization permits access to your Google data; you can withdraw that access at any time.
3. Google Calendar data and Limited Use
Connecting Google Calendar is optional. After you authorize access, we access your calendar list, calendar names, identifiers, display colors, access roles, account email associated with the connection, and event data from calendars selected for synchronization. Supported event data can include titles, descriptions, locations, start and end times, time zones, recurrence, and provider identifiers. We store synchronized data and authorization tokens to keep your connected calendar features working.
The current integration requests Google's Calendar permission (https://www.googleapis.com/auth/calendar). This permission can allow viewing, editing, sharing, and deleting calendars you can access. Our integration uses it to list calendars and synchronize events, including creating, updating, or deleting events when requested through the connected application and permitted by your calendar access role.
We use Google data only to provide or improve the calendar features you use and for permitted security or legal purposes. We do not sell Google data, use it for advertising, transfer it to data brokers, use it for credit decisions, or use it to train general-purpose AI or machine learning models.
Schedule-X Cloud's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. These restrictions also apply to data derived from Google data.
Human access to Google data is restricted to situations allowed by that policy, such as your affirmative agreement to inspect specific data for support, necessary security investigations, legal obligations, or permitted aggregated internal operations. Service providers receive access only as needed for permitted purposes and subject to these restrictions.
You can disconnect through an application using our integration or ask your workspace administrator for help. You can also revoke authorization in your Google Account connections. Disconnecting stops future sync; it does not automatically delete calendar data already imported into Schedule-X Cloud or events already written to Google. To request deletion of stored connection data, tokens, or imported calendar data, contact us or the application or workspace that manages your account.
5. Storage, retention, and security
Our production infrastructure is hosted with Hetzner in Finland. Other service providers may process information in other countries. Where required, international transfers must use an applicable legal mechanism, such as an adequacy decision or approved contractual safeguards.
We retain account and calendar data while needed to provide the service, and retain logs, security records, and backups for operational, legal, or security needs. Data awaiting deletion may remain in restricted backups until those backups expire. Contact us for information about retention or to request deletion; we may retain limited records when required by law or to establish or defend legal claims.
We use HTTPS, access controls, password hashing, and application-level encryption for Google authorization tokens. No service can guarantee absolute security. Keep credentials private and report suspected unauthorized access promptly.
6. Cookies and local storage
The console uses necessary session cookies for authentication. Applications using our SDK may use browser storage for session restoration or calendar preferences under their own policies. These public pages do not set advertising cookies or include advertising trackers.
7. Your privacy rights
Depending on your location and circumstances, you may have rights to access, correct, delete, or obtain a copy of your information, restrict processing, object to processing, or withdraw consent. EEA and UK residents may complain to their local data protection authority. Withdrawing consent does not affect the lawfulness of earlier processing.
Residents of California and other US states may have rights to know the categories and specific pieces of information collected, request access, correction, or deletion, and appeal a denied request where applicable. The categories described above include identifiers, internet or network activity, and information you provide in calendar content or communications. We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out to exercise. We will not unlawfully discriminate against you for exercising your rights.
Send requests to tom@schedule-x.dev. We may need to verify your identity or an authorized agent's authority. Where we process calendar data on behalf of an application or workspace, we may direct your request to that customer and assist them in responding.
8. Our role and customer responsibilities
For console accounts, website operation, and our direct business communications, we determine how information is processed. For calendar data hosted on behalf of a customer's application or workspace, that customer generally determines the purposes of processing and we act on their instructions. Customers are responsible for their own notices, lawful instructions, permissions, and any required data processing agreement with us.
9. Children
Schedule-X Cloud is a developer service and is not directed to children under 16. If you believe a child has provided personal information without appropriate authorization, contact us.
10. Changes and contact
We will update this page when practices change and give additional notice where required. If we introduce a new use of Google data, we will update our disclosures and obtain renewed consent before that use where required. Questions and requests: tom@schedule-x.dev.