Encrypted at rest and in transit
Access tokens are encrypted at rest, and everything moves over an encrypted connection.
What we store
The calendar data we store, field by field: what is kept and why, what stays off until you switch it on, and what no setting moves. It is the Privacy Policy’s commitment in plain language.
The one-sentence version
Of your events, we keep the times you are busy, and nothing more unless you ask us to.
Held
Data
Why it exists
How long
Your email address
To have an account at all, and to email you when a sync breaks.
Until you delete the account.
An access token per connected calendar
To read free/busy and to write the blocks. Encrypted at rest, revocable by you from either end.
Until you disconnect that calendar.
A list of your calendars, by name
So you can pick which ones take part. The name is the one piece of calendar text we hold.
Until you disconnect the account.
Start and end times of events in synced calendars
This is the sync. Without the times there is nothing to mirror.
Rolling — dropped as the events pass out of your sync window.
An opaque ID linking an event to its mirrors
So that moving or cancelling one updates the others instead of orphaning them.
For the life of the event.
Bookings made through your links
The name, email and any answers the person booking chose to give you. Their email address is also used to send them the confirmation.
Until you delete the link it came through, or your account.
Any field you have switched on for a sync
Titles, guests, notes or locations, where you have decided a particular sync should carry them. Off unless you set it.
Until you switch it off or disconnect the calendar.
Not held by default
Titles, guests and notes are not stored or copied by default. The fields on the left can be switched on, one sync at a time, by you. The ones on the right have no switch at all.
Off until you turn it on
Per sync, never per account. Turning titles on between your two work calendars does nothing to the one you share with a client.
Never, at any setting
There is no toggle for these, no plan that includes them and no support request that will.
Access tokens are encrypted at rest, and everything moves over an encrypted connection.
Your data is held in the EU, and every service that handles it is named on the sub-processor register.
Delete your account and the record goes, including tokens and stored times. Backups age out afterwards.
Straight answers
The limits of the above, stated plainly.
The binding version is the Privacy Policy. Questions that this page does not answer go to privacy@busywait.ai.
Busy-only, whether you pay us or not. Paid plans let you switch fields on for a sync. No plan switches anything on for you, and no plan moves the floor.