Encrypted at rest and in transit
Tokens are encrypted with keys held separately from the database. Everything moves over TLS.
What we store
Privacy policies are written to survive lawyers. This page is written to be read. It is the same commitment in plain language, and if the two ever disagree, treat it as a bug and tell us.
The one-sentence version
We hold the times your calendars are busy, and nothing more than that unless you ask us to.
Held
Data
Why it exists
How long
Your email address
To have an account at all, and to email you when a sync breaks.
Until you delete the account.
An access token per connected calendar
To read free/busy and to write the blocks. Encrypted at rest, revocable by you from either end.
Until you disconnect that calendar.
A list of your calendars, by name
So you can pick which ones take part. The name is the one piece of calendar text we hold.
Until you disconnect the account.
Start and end times of events in synced calendars
This is the sync. Without the times there is nothing to mirror.
Rolling — dropped as the events pass out of your sync window.
An opaque ID linking an event to its mirrors
So that moving or cancelling one updates the others instead of orphaning them.
For the life of the event.
Bookings made through your links
The name, email and any answers the person booking chose to give you.
Until you delete the booking or the account.
Any field you have switched on for a sync
Titles, guests, notes or locations, where you have decided a particular sync should carry them. Off unless you set it.
Until you switch it off or disconnect the calendar.
Not held by default
Busy-only is the floor, not the ceiling. Some syncs genuinely want more — two calendars that are both yours, or a client who should be able to tell a movable call from time you set aside. So the fields on the left can be switched on, one sync at a time, by you. The ones on the right have no switch at all.
Off until you turn it on
Per sync, never per account — turning titles on between your two work calendars does nothing to the one you share with a client. Every switch says plainly what changes before you flip it, and flipping it back stops the copying from the next sync onward.
Never, at any setting
There is no toggle for these, no plan that unlocks them and no support request that will. A field we never ask for is one that cannot leak, cannot be subpoenaed and cannot be sold by whoever buys us in ten years.
In practice
In the calendar it was made in
What crosses by default
Three fields, unless you have told this particular sync to carry more. Nothing on the left reaches the other calendars because you have not asked it to — not because it is queued up behind a setting we hope you never find.
Tokens are encrypted with keys held separately from the database. Everything moves over TLS.
Your data is held on infrastructure in the UK and EU and stays there. GDPR is the baseline it was built to, not a mode switched on for one market.
Delete your account and the record goes, including tokens and cached times. Backups age out within 30 days.
Straight answers
Any privacy claim that will not name its own limits is an advertisement. Here are ours.
The binding version is the Privacy Policy. Questions that this page does not answer go to privacy@busywait.ai.
Busy-only, whether you pay us or not. Paid plans let you switch fields on for a sync; no plan switches anything on for you, and no plan moves the floor.